← Back to the site

Privacy policy

Who is responsible, what is stored, what leaves the server, and what you can ask us to do about it.

This policy covers the website jobblower.com, the campaign page welcome.jobblower.com and the Job Blower app at app.jobblower.com. It is meant to be read: what is stored, why, who else ever sees it, and how to make us change or delete it.

Who is responsible

ibt Personal AG, Rosenbergstrasse 62, CH-9000 St. Gallen, Switzerland. Job Blower is built and operated by this company, which trades as persolution.swiss. Questions about this policy or about your own data: [email protected] · +41 71 227 90 70

The website asks nothing of you, unless you write to us

jobblower.com has no account and no newsletter. You can read every page, in every language, without telling us anything. Three things still happen while you read, and there is one form you may choose to fill in.

  • Every request leaves one line in the server log: IP address, time, the page asked for, the page you came from and the browser identifier. Those logs are rotated away after 14 days and are used only to keep the site running and to look into abuse.
  • Cloudflare sits in front of the site: it terminates the encrypted connection and filters attacks, and therefore sees the same request. It also tells us the two-letter country code of your IP address, and that is how the site opens in your market and your language. The code is read for that redirect and is not stored, with one exception: if you send the price request form, it is written into that one e-mail, as described below.
  • Google Analytics and Microsoft Clarity run only if you accept them in the banner. Clarity also records the visit as a replay: which pages you open, how far you scroll and where you click. The one form on the site is masked, so what you type into it never reaches that recording, and there is no sign-in here to capture. Reject, or leave the banner alone, and neither script is ever requested and no measurement cookie is ever written. Every cookie is listed in the cookie policy.
  • The price request form at the bottom of the home page is the one place on this site where you type something. What you send us, your name, your company, your e-mail address, your phone number if you give one, the two choices you make and your message, reaches us as an e-mail and nowhere else. It is not saved in a database, and it is never used to advertise to you. One line of that e-mail is not something you type: the approximate place your connection points to, which Cloudflare works out from your IP address. It is as coarse as a town or a country, it tells us roughly which market an enquiry comes from, and the IP address itself is not in the e-mail. We keep that e-mail for as long as we are in contact and delete it once the enquiry is closed.

The campaign page on welcome.jobblower.com

An advertising campaign sometimes leads to welcome.jobblower.com. That page is not built or hosted like the rest of this site: it is made with Perspective, a German service (Perspective Software GmbH, Berlin), and it runs on their servers. It asks about cookies with its own banner, and the answer you give there counts for that page alone: the banner on jobblower.com does not answer for it, and it does not answer for jobblower.com. Accept there, and the same measurement described in the cookie policy runs on that page too.

What you fill in on that page is stored in our account at Perspective and reaches us from there. It is the same kind of enquiry as the price request above, it is never used to advertise to you, and we delete it once the enquiry is closed.

The app, and whose data it is

app.jobblower.com is only for the recruiters of a customer company and for the candidate data they upload. Two different roles apply there.

  • For the user accounts and for running the service, we are the controller.
  • For the candidate data a customer uploads, that customer decides what goes in and how long it stays; we process it on their instruction and for nobody else. A candidate who wants their data corrected or deleted should ask the company that holds them. They may write to us as well, and we will pass it on and act on it.

What the app stores

  • The account: name, e-mail address, a hashed password (never the password itself), optionally a second factor and one-time backup codes, and a signed session cookie so you stay signed in.
  • A record of what happened: sign-ins, scans and changes to a profile. It exists so a customer can always reconstruct who did what, and when.
  • The CV files that were uploaded and the profile read out of them: name and contact details, year of birth, gender, place of residence, years of experience, target roles, skills, languages, work permit, salary expectation and a short summary.

Gender is stored for one reason only: so that the sentences the system writes about a candidate use the right pronouns.

A CV never leaves the server

A CV is read on our own server by a language model that runs on that same server. The text of a CV is not sent to any AI provider, is not used to train any model, and is never visible to another customer.

What does leave the server

A job advert is public: anyone can read it where it was published. Judging one is heavy work, so two language-model providers do that part: Mistral AI in France and Bonsai. What they receive is the public advert plus an anonymised profile with the name and the contact details already removed. Never a CV, never a name.

There is one further exception, and it stays switched off until a customer switches it on: the app can be connected to an AI assistant such as Claude, ChatGPT or Grok, so recruiters can ask about their own data in plain language. Whatever they ask then goes to the provider they chose. It is off by default precisely because it is the one place where candidate data leaves on purpose.

Where everything is hosted

On one dedicated server at Hetzner Online GmbH in Nuremberg, Germany. Every connection is encrypted. One customer’s candidate data is separated from every other customer’s; job adverts, being public, are shared.

Who else processes data for us

  • Hetzner Online GmbH, Germany: the server everything runs on.
  • Cloudflare: DNS, encryption and attack filtering in front of both the website and the app.
  • Mistral AI (France) and Bonsai: the written verdict on a public job advert, from an anonymised profile.
  • Brevo (France): the password resets and invitations the app sends by e-mail. They receive the address and the name in that message, nothing more.
  • Perspective Software GmbH (Germany): the campaign page welcome.jobblower.com and whatever you fill in on it.
  • Google: Google Analytics, on the website and the campaign page, never in the app, and only after you accept it.
  • Microsoft: Microsoft Clarity, on the website only, and only after you accept it.

The services used to find job adverts (an advert aggregator, a web search interface and a geocoder for places) receive job data only. No candidate data is ever sent to them.

Nobody is decided about by a machine

Job Blower scores a candidate against a job and writes down its reasoning. That is a suggestion for a recruiter, not a decision: no application is rejected by it, nobody is filtered out of the market, and no legal or similarly significant consequence follows from a score. A person reads it and decides.

How long things are kept

  • Server logs: 14 days.
  • Account data: as long as the account exists, then deleted.
  • Candidate data: as long as the customer keeps that candidate. Deleting a candidate deletes the CV files and the profile with them.
  • The activity record: as long as the account it belongs to, so a customer can audit their own history.
  • Analytics: only if you accepted it. Google’s own cookie lasts up to 24 months. Microsoft deletes a session replay after 30 days and keeps the aggregated heatmaps for 9 months.

Your rights

You can ask us for a copy of everything we hold about you, have it corrected, have it deleted, have its use restricted, object to it, or receive it in a portable form. Where we asked for your consent (the analytics banner is the only place we do), you can withdraw it at any time, and nothing else changes when you do.

Write to [email protected]. It costs nothing and we answer within 30 days. If you think we handled it badly, you may complain to the Federal Data Protection and Information Commissioner in Switzerland or, in the EU and the EEA, to the supervisory authority of the country you live in.

Changes

When this policy changes, the date underneath it changes with it. That date tells you which version you are reading.

Last updated: