Privacy Policy
Last updated: September 4, 2026
This policy explains what personal data the Coder Horizon job board collects, why we collect it, how long we keep it, and what rights you have over it.
1. Data controller
The Coder Horizon team is the data controller for this service. Contact details are at the bottom of this page.
2. Data we collect
Account data from Google (name, email, avatar), used to sign you in.
Profile data you add yourself (headline, skills, community member flag), used to present you to employers.
Application data (full name, email, phone, note, CV file or link), shared only with the company whose job you apply to, for that specific recruitment.
Employer data (company profile, members, job posts), published on the board after moderation.
Technical data (request logs with user ids, never emails or phone numbers, plus error monitoring data), used to keep the service running.
Email log (hashed recipient address, event type, delivery status), used to debug delivery issues.
Email preferences (saved-search filters and your instant, weekly or off choice), used to send the job alerts and weekly digest you ask for. Every alert email carries a one-click unsubscribe link that works without signing in.
AI-derived data, only after your explicit per-feature consent: a structured CV profile (skills, seniority, roles, highlights - never the raw CV text or contact details), job match scores with reasons, and a public GitHub summary. Each feature asks separately and works only after you allow it.
Employer AI assessment: when you apply, the hiring company may ask AI to summarize the structured data you shared (parsed CV profile fields, public GitHub metrics, your application note with contact details stripped). Your name, contact details and raw CV text are never sent to the AI provider for this. AI scores are advisory only - they never hide or reorder your application, and every assessment is audit-logged for one year.
Mock interview conversations are not stored on our servers: the transcript stays in your browser's local storage between turns, is relayed only to generate the next interviewer message, and is never shared with employers.
3. Lawful basis
The lawful basis for processing your data is your explicit consent, given at the point of sign-in, upload or submission, consistent with Decree 13/2023/ND-CP on personal data protection.
Employer AI assessment runs on the basis of this disclosure plus the employer's legitimate recruitment interest; it processes only the structured profile data you chose to share, never your contact details or raw CV.
4. Retention
CV files and application contact details are kept for 12 months after the application date, then deleted or nulled.
Account data is kept until you request deletion. At that point the account is anonymised in place: email and Google id are replaced with placeholder values, the name is set to "Deleted user", the avatar, skills and CV are removed, and related applications are anonymised too.
Moderation history is kept without personal data.
AI-derived data (structured CV profile, cached match scores, GitHub summary) is deleted the moment you withdraw the related consent, and with your account. Withdrawing consent removes every derived row in the same request.
AI assessment audit records (the allowlisted input, the model output and the score shown to an employer) are kept for 12 months, then pruned.
5. Processors
Google (sign-in), headquartered in the United States, global infrastructure.
Vercel (web hosting), headquartered in the United States, global infrastructure.
Railway (API and database hosting), headquartered in the United States, global infrastructure.
Cloudflare (DNS, CDN and R2 file storage), headquartered in the United States, global infrastructure.
Resend (transactional email), headquartered in the United States, global infrastructure.
Anthropic and one embedding provider, Voyage AI or OpenAI (optional AI features: job-posting text for enrichment and embeddings, search queries for signed-in users, - only with your explicit consent - your CV file for structured profile parsing with the raw text never stored, employers' job-description drafts for rewrite suggestions, and applicants' allowlisted structured profile fields for employer-side summaries), headquartered in the United States.
Sentry (error monitoring, optional), headquartered in the United States, global infrastructure.
GitHub (public profile lookup, only with your explicit consent; read-only, no account data sent), headquartered in the United States.
6. Sharing your data
Your data is shared only with the company you apply to and with the processors listed above. We never sell personal data.
7. Security
Private files are kept in access-restricted storage with download links that expire after 10 minutes, HTTPS everywhere, HttpOnly session cookies, role-based access control, and a full moderation log.
8. Your rights
You have the right to request access, correction or deletion of your data, to withdraw consent, or to file a complaint.
To exercise these rights, contact us using the details at the bottom of this page. We respond within 30 days.
9. Cookies
The service uses only two strictly necessary session cookies: access_token (15 minutes) and refresh_token (7 days). No advertising or analytics cookies are used.
If analytics is added later, it will either be cookie-less or disclosed here before it ships.
10. Children
This service is intended for people aged 16 and older.
11. Changes to this policy
We may update this policy from time to time. The latest version is always posted on this page with its update date.
Contact
- Phone
- 0906179145
- Website
- https://coderhorizon.com