JobMedium Platform Privacy Policy
Last updated: September 23, 2026
This policy explains what SSBFY LLC ("JobMedium") collects, why, who sees it, and the controls you have, across our pre-launch waitlist and, at launch, the JobMedium platform. The short version of our stance: your data is yours, we never sell it, and your job search is private by default.
1. Who we are & what this covers
SSBFY LLC ("JobMedium", "we", "our", "us") operates jobmedium.com and its subdomains (the "Service"): the pre-launch waitlist today and, at launch, the JobMedium platform, covering job search and career profiles for job seekers, posting and applicant tracking for employers, and a split-fee placement network for independent recruiters.
This policy is part of your agreement with us together with our Terms of Service. We act as the data controller for personal information collected through the Service.
2. Our core privacy commitments
These are the promises the product is built around, and they are the same ones published on our landing pages:
- We never sell your personal information. Not to data brokers, not to advertisers, not to anyone. That is our business model, not a marketing line: employers and recruiters pay for tools; your data is not the product.
- Your job search is private by default. We never notify your current employer that you are searching, and your profile is visible only on your terms, to hiring teams you apply to or consent to be introduced to.
- Your data is yours to delete. You can request deletion of your account and personal information at any time (Section 10; some records must be retained for legal, financial-audit, or dispute-resolution reasons, described in Section 9).
- No hidden analysis. Where AI features process your material, we say so, and we minimize the personal identifiers sent for AI processing where reasonably practicable (Section 5).
3. What we collect
Waitlist (pre-launch). Name, email, and the details you choose to provide: phone, company name, job category, country, your audience type (job seeker / employer / recruiter), your consents, and, for attribution, the campaign parameters and IP address of your signup. If you book a 15-minute intro call, we also collect your requested time slot and any note you add.
Accounts & profiles (at launch). Account details, and the content you add: for job seekers, your profile, resume, applications, and saved searches; for employers, company and role information and applicant pipeline activity; for recruiters, your practice details, roles, candidate submissions, staked ("claimed") candidates, and placement records; for coaches, your public coach profile and the sessions you deliver.
Candidate information from recruiters. Recruiters may provide professional and contact information about candidates they represent, including to stake (claim) a candidate they intend to submit. Where a staked candidate is not yet a user, we hold limited contact information solely to confirm the relationship and obtain the candidate's consent before any credit attaches (Section 6).
Career services. If you book AI resume review or a coaching session, we collect your booking, the material you submit for review, and any feedback or notes exchanged for the session.
Payments. Card and bank details are collected and stored by our payment processor, Stripe, and we do not store full card numbers. We keep transaction records (amounts, dates, invoice and payout status).
Automatically. Usage data (pages, actions, timestamps), device and log data, and bot-protection signals processed by Cloudflare Turnstile when you submit protected forms.
4. How we use it
- Operating the waitlist and founding-member program: confirmations, verification, queue and referral tracking, launch invitations, and applying founding terms to qualifying accounts.
- Operating the platform: matching roles and candidates, running application and placement workflows, processing payments and payouts, and keeping the timestamped introduction ledger that makes split placements fair.
- Communications: service messages (always), and marketing messages only with your consent, and every marketing email has a working unsubscribe (Section 10).
- Trust and safety: preventing bots, fraud, fee circumvention, and abuse; enforcing our Terms.
- Improving the Service, and complying with law.
We do not use your personal information for cross-context behavioral advertising.
5. AI-assisted processing of resumes & candidate information
What AI is used for. We may use artificial intelligence and machine-learning technologies to help process resumes, candidate profiles, job information, and other material submitted through the Service, most visibly resume parsing (turning a resume into a structured profile) and the resume review (an overall score, section-by-section feedback, and missing keywords). Purposes may include extracting and organizing skills, employment history, education, certifications, and qualifications; standardizing or summarizing professional information; comparing qualifications with job requirements; assisting recruiters and employers in reviewing candidates; improving search and matching; and supporting administrative recruiting workflows.
Information that may be processed. Depending on what a resume or submission contains, this may include employment history, job titles and responsibilities, skills, education, certifications and licenses, project experience, work-location information, professional profile information, and other information in the material you submit. Resumes may also contain personal information such as your name, email address, phone number, or address.
Data minimization. We seek to limit the information provided to AI systems to what is reasonably necessary for the processing purpose. Where reasonably practicable, we use technical measures to remove, mask, or exclude certain personal identifiers (such as direct contact details) before submitting material for AI processing. Automated identification of personal information cannot catch every instance, particularly across different resume formats, layouts, and languages, so we do not represent that all personal information will be removed before AI processing. Some information may be processed when necessary to provide the requested feature or when automated controls do not identify it.
AI service provider. We currently use Microsoft Azure AI services (including Azure OpenAI models and other models Microsoft designates as "Models sold by Azure") to perform this processing. Material submitted for AI processing is transmitted to and processed by Microsoft Azure as needed to provide the feature. According to Microsoft's current documentation, for Models sold by Azure, customer prompts, outputs, and embeddings are not made available to other customers or to underlying model providers such as OpenAI, are not used by those providers to improve their models or services, and are not used to train generative AI foundation models without the customer's permission or instruction. Microsoft also states that these models are hosted in Microsoft's Azure environment and do not interact with provider-operated services such as ChatGPT or the OpenAI API, and that base models are stateless (prompts and completions are not stored in the model). These are Microsoft's statements, not ours, and they are subject to Microsoft's service terms, product configuration, and data-processing terms, which may change. Some optional Azure features (such as stored completions and certain stateful or agent functionality) can store content, and we limit the use of such features where they are not needed.
Model training. We do not intentionally use resumes or personal information to train general-purpose foundation AI models unless we provide appropriate notice and have a lawful basis to do so. Our use of Azure AI services should not be read as providing your resume to OpenAI's consumer services or public API.
Safety and abuse monitoring. Azure AI services are subject to Microsoft's security, content-safety, and abuse-monitoring processes. Microsoft states that it uses automated mechanisms to detect potentially abusive use and that, under its default procedures, content identified as potentially abusive may in certain circumstances be subject to further automated review and authorized human review by Microsoft. We therefore do not represent that material submitted for AI processing cannot be processed by those systems.
Data location. Where AI requests are processed depends on the Azure deployment type and configuration we use. Microsoft states that standard deployments generally process data within the customer-specified geography, while its Global and DataZone deployment types may process data in other regions where the model is deployed or within a Microsoft-defined data zone, respectively. Where geographic restrictions are required, we may configure our Azure resources accordingly.
Accuracy. AI-generated information, including parsed profile fields, scores, and feedback, may contain errors, omissions, or misinterpretations and may not accurately reflect your qualifications or experience. Please review parsed results before saving them to your profile, and correct them or tell us about material inaccuracies. AI output should be considered together with the original resume, information you provide, and human review.
Human review and automated decisions. AI-generated recommendations, scores, summaries, or matches are decision-support information, not guarantees about a candidate's qualifications, suitability, or eligibility for any position, and we encourage recruiters and employers to review candidate information independently before making employment decisions. We do not use AI as the sole means of making final hiring, rejection, or other decisions that produce legal or similarly significant effects concerning candidates, and AI on the Service does not auto-reject candidates. You may direct questions or objections about automated processing to [email protected].
Retention, rights, and other tools. Resumes, parsed profiles, and AI-generated information are retained as described in Section 9, and you can exercise your access, correction, and deletion rights as described in Section 10. If an AI feature ever communicates with a service outside our Azure environment, information sent to that service may be subject to that provider's terms, and we seek to limit such access to what the feature needs. The AI models, providers, and configurations we use may change as the Service evolves, and we will update this policy to reflect material changes in how AI processes personal information.
6. Candidate information in the split network
The split network involves a data flow worth spelling out plainly. When a recruiter submits a candidate for a role, the candidate's relevant professional information (profile/resume material provided for the submission) is shared with:
- the role-holding recruiter, to evaluate the submission; and
- the hiring client, as part of the placement process.
Submitting recruiters are contractually required to have the candidate's consent for the specific submission. Each submission is timestamped and tagged to the submitting recruiter; we retain those attribution records for at least the 12-month attribution window plus any dispute period, because they are the record that protects both the candidate's introduction and the recruiters' fees.
Staking and candidate consent. A recruiter may stake (claim) a candidate to record that they represent them, on a first-come basis. Before a stake first credits an introduction, we contact the candidate, using the limited contact details the recruiter provided, to confirm the relationship through a secure, expiring link. A candidate who declines (or never confirms) is not credited to that recruiter and may ask us to remove the contact information held for this purpose. We keep the consent outcome (confirmed or declined) as part of the attribution ledger.
Candidate information shared in a hiring workflow may only be used for that workflow, and recipients may not scrape, resell, or repurpose it (Terms, Acceptable Use).
7. Who we share with
We share personal information only as needed to run the Service:
- Service providers (processing on our instructions): Stripe (payments, payouts, identity verification for payout accounts), email and messaging delivery providers (currently Resend; SMS only with your prior express TCPA consent, and reply STOP to opt out), Cloudflare (bot protection on protected forms), Microsoft Azure (hosting and data storage), and Microsoft Teams (meeting links when you book an intro call). We may add or replace service providers that perform the same function; this section reflects the providers we currently use.
- Google Analytics, only if and when analytics are enabled with consent; analytics and advertising measurement are currently disabled by default. You can also use Google's browser opt-out.
- Other users, by your action, such as applying to a role, being submitted for one, or posting one shares the relevant information with the counterparty (Sections 3 and 6).
- Independent coaches, so that when you book a coaching session, the information needed to deliver it (your booking and any material or feedback exchanged for the session) is shared with the Coach you booked. Coaches publish their own profiles to a directory visible to Service users.
- Legal, where required by law, to enforce our Terms, or to protect rights, safety, and the integrity of the Service.
- Business transfer, if we are involved in a merger, acquisition, or asset sale, this policy continues to apply to transferred data and we will provide notice of any successor.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
8. Cookies & analytics
We use essential cookies to keep the Service working (sessions, security, preferences). Analytics and advertising measurement are off by default; if we enable them, they run behind a consent mechanism, and this section will name the tools in use. Your browser's cookie controls apply to all of the above.
9. How long we keep data
- Waitlist records are kept until your account converts at launch, or until you ask us to remove you, whichever comes first (plus a short operational period).
- Account data is kept while your account is active, then deleted or de-identified on request or after prolonged inactivity, except as below.
- Introduction / attribution ledger is kept for at least the 12-month attribution window plus any active dispute period, because it is the contractual record of who introduced whom.
- Financial records (invoices, payouts, tax documents) are retained for the periods required by tax and accounting law.
- Activity and security logs cover routine account activity records, which are kept for up to 90 days; activity records tied to applications, payments, or subscriptions are kept for up to 24 months, because they may be needed to resolve disputes between parties or investigate security incidents. Clearing your activity history removes it from your view immediately, but does not shorten these retention periods; the records then expire automatically.
10. Your rights & choices
Everyone: unsubscribe from marketing at any time (every email has a link, and a preference center lets you manage categories); access, correct, or delete your information by contacting [email protected], or close your account and download a copy of your data directly from your account settings. Closing your account takes effect immediately; your personal information is then permanently deleted or de-identified after a 30-day grace window, during which you can reopen the account and recover everything. Deletion requests do not shorten the activity- and security-log retention periods described in Section 9; those records are hidden from your account and expire automatically.
California residents (CCPA/CPRA): you have the rights to know, access, correct, and delete personal information; to opt out of sale or sharing (we do not sell or share for cross-context behavioral advertising, and you can register your preference any time via our Do Not Sell or Share My Personal Information page); to limit use of sensitive personal information; to know retention periods (Section 9); to opt out of solely automated decision-making with significant effects (we do not do this; see Section 5); and to non-discrimination for exercising any right.
We honor rights requests within the timeframes your state law requires, generally within 45 days, extendable once by 45 days for complex requests, with notice. We will verify your identity before acting on a request, and an authorized agent may act for you with proof of authorization.
11. Security
We protect personal information with measures appropriate to its sensitivity: encryption in transit, access controls, payment handling delegated to a PCI-compliant processor (Stripe), and signed, expiring tokens for email-link actions. No method of transmission or storage is 100% secure; if a breach affecting your personal information occurs, we will notify you and regulators as required by law.
12. Children
The Service is for users 18 and older. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided us data, contact [email protected] and we will remove it.
13. Changes to this policy
We may update this policy as the Service evolves. For material changes we will give notice (email or in-product) before they take effect, and we will not weaken the Section 2 commitments without clear, prior, prominent notice.
14. Contact
Privacy questions and rights requests: [email protected].
SSBFY LLC, operator of JobMedium.