Welcome to OneTap.Work
OneTap.Work
Login

Privacy Policy

Last updated: 21 August 2026
Effective date: 21 August 2026

This Policy explains what we do with your personal data. We have written it to describe what our systems actually do, not what a job platform typically does.

Two things worth knowing up front, because they shape everything below:

  • There are no employer accounts on OneTap.Work. No company can register, browse candidates, or see your profile. We never send your profile or CV to an employer. When you apply for a job, you do it yourself, on the employer's own website.
  • When you import a CV, the file is sent to an AI provider outside the EU so that your profile can be filled in automatically. Section 6 names the provider and the safeguards. If you would rather not have that happen, fill your profile in manually.

1. Who is responsible for your data

The controller is Sviatoslav Mysiv, trading as JDG Sviatoslav Mysiv, al. Jana Pawła II 3b/137, 80-462 Gdańsk, Poland (NIP 5842863282, REGON 540695811).

For anything to do with privacy or your rights, write to support@onetap.work. We have not appointed a Data Protection Officer; that address reaches the person responsible.

2. Who this Policy covers

  • Registered users — candidates who create an account.
  • Visitors — anyone browsing the public job catalogue without an account.
  • People named in job postings — occasionally a posting we index from a public source contains a contact person's name or work e-mail. Section 5 is for you.

3. What we collect

From you, when you register

Your name, e-mail address and a password, which we store only as a cryptographic hash. If you sign in with Google, we receive your e-mail address and a Google account identifier instead of a password.

From you, when you build a profile

All of it is optional and you decide how much to provide: contact details and phone number, a LinkedIn or other profile link, notice period, salary expectations (amount, currency, period, gross or net, contract type), preferred cities and countries, work experience, education, language skills with levels, skills, employment and workplace preferences, and free-text answers to application questions.

You may also upload a CV and a cover letter. These files are stored in Google Cloud Storage, separately from the database.

Please do not include special category data. Our profile deliberately has no fields for health, disability, ethnicity, religion, political views, trade union membership, sexual orientation, or criminal record — we removed them on purpose. The free-text fields cannot stop you from typing such information, but we do not ask for it, do not want it, and if you provide it anyway we process it only because you chose to make it public in your profile, and you can remove it at any time.

From you, as you use the Service

Saved jobs and applications with their status, your own notes on an application, the jobs you have already seen, your saved search filters and highlight words, and any job postings you add manually.

Automatically

Your IP address, browser and device information, and security events, in server logs. Analytics about how the Service is used — section 7 covers this and the Cookie Policy covers it in detail.

If you subscribe

An identifier for your customer record with our payment processor, plus your subscription status and billing period. We never receive or store your card details — the payment form belongs to Stripe and your card data goes straight to them.

If you connect an external application

If you authorise an external application to reach your account, we record which application, what it was granted, and when, so that the authorisation can be checked and revoked.

4. Why we use your data, and on what legal basis

| What we do | Why | Legal basis (GDPR) | |---|---|---| | Create and run your account; provide the catalogue, profile, saved jobs and application tracker | To give you the service you signed up for | Art. 6(1)(b) — performance of a contract | | Parse a CV you upload to pre-fill your profile | Because you asked us to import it | Art. 6(1)(b) | | Take payment, manage your subscription | To provide paid access | Art. 6(1)(b) | | Keep accounting and tax records | We are required to | Art. 6(1)(c) — legal obligation | | Keep the Service secure, prevent abuse, diagnose errors | To keep the Service working and safe for everyone | Art. 6(1)(f) — legitimate interests | | Measure how the Service is used, in a form that does not identify you | To understand what works and improve it | Art. 6(1)(f) — legitimate interests | | Analytics and marketing measurement that can identify you or your device | To measure our reach | Art. 6(1)(a) — your consent | | Index publicly available job postings | To provide a job catalogue | Art. 6(1)(f) — legitimate interests | | Answer your support requests | To help you and keep a record | Art. 6(1)(b) and (f) |

Where we rely on legitimate interests, we have weighed them against your rights and concluded that our processing is limited, expected, and does not override them. You can object at any time — see section 10 — and we will stop unless we have compelling grounds that override your objection.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect anything we did lawfully before you withdrew.

5. Job postings from public sources

We build the catalogue by collecting job postings from external sources — employers' career pages, job boards, and the interfaces they expose.

We are interested in the job, not in people. But a posting sometimes names a contact person, and we store the description as published. This is processing of your personal data that did not come from you, so under Article 14 GDPR you should know:

  • What we hold: whatever appears in the posting itself.
  • Where it came from: a publicly accessible web page. We do not buy data and we do not collect from private sources.
  • Why: to run a job catalogue (Art. 6(1)(f)).
  • How to make it stop: write to support@onetap.work and we will remove the posting from our systems within 14 days. A company can also ask us to stop collecting from its site entirely.

You have the same rights over this data as anyone else — see section 10.

6. Who else sees your data

We do not sell your data and we do not share it for anyone else's marketing. We use the following providers, each bound to process data only on our instructions:

| Provider | What it receives | Where | |---|---|---| | Railway | Hosting for our application, database and logs — technically all data passes through it | See provider terms | | Google Cloud Storage | Your CV and cover letter files | Google Cloud infrastructure | | OpenAI | The CV file you choose to import, in full, so it can be turned into profile fields | United States | | Stripe | Your e-mail address, and payment details you enter directly into Stripe's own form | EU / US | | Mailgun | Your e-mail address and the content of account e-mails we send you | See provider terms | | Sentry | Error reports. Reports from our servers include the IP address of the request | European Union | | Google (Analytics, Tag Manager) | Analytics events, after you consent | EU, with possible transfer to the US | | Umami | Analytics events. Self-hosted by us; see section 7 | Our own infrastructure | | Featurebase | Whatever you write if you send us product feedback | See provider terms |

We also disclose data to public authorities where the law requires it. We check that each request has a legal basis, disclose no more than necessary, and tell you where we are permitted to.

Transfers outside the EEA. We keep data in the EEA where we can — our error monitoring, for example, runs in the EU. Where a provider processes data outside the EEA, we rely on the EU Standard Contractual Clauses, or on the provider's certification under the EU–US Data Privacy Framework where it has one, together with technical measures such as encryption in transit and minimising what we send. The most significant transfer is the CV import to OpenAI in the United States; if you prefer to avoid it, complete your profile manually instead of importing a file.

Applications you authorise. If you connect an external application to your account — an AI assistant, for example — it can read your saved search filters, your application records including the notes you wrote on them, and your candidate profile including your CV and cover letter files, and it can change them on your behalf. There is one level of permission, so this is all-or-nothing rather than a choice per item.

That recipient is your choice and acts outside our control. It processes what it receives on its own infrastructure under its own privacy policy, and where it is an AI assistant your data reaches the model provider behind it, which may be outside the EEA. This is the largest disclosure of your data that you can trigger yourself — grant it only to applications you trust, and write to us if you want an authorisation revoked.

7. Cookies, analytics and error monitoring

The Cookie Policy is the detailed account, including the full list of what gets stored on your device. In summary:

  • Necessary storage — your session, your language, your cookie choice — is always active.
  • Google Analytics and any marketing tags run only after you consent, through Google Consent Mode. Before you answer the banner, they are blocked.
  • Umami, our self-hosted analytics, runs without a consent gate. It sets no cookies and stores no directly identifying data; it recognises a returning visitor from a daily rotating hash of IP address and browser. We rely on legitimate interests for this, we keep it because it is the only measurement that is not skewed by who answers a banner, and you can object under section 10. Your account identifier is attached to these events only if you have consented to analytics.
  • Error monitoring runs without a consent gate, because we need to know when the Service breaks. It is limited to errors — no session recording, no behaviour tracking. Reports from our servers include the IP address of the failing request.
  • Campaign attribution. If you have allowed marketing storage, and you arrive from a link containing campaign parameters, we store those parameters in your browser for up to 90 days so that we can tell which campaign a registration came from. Without that consent nothing is stored, and withdrawing it deletes what was.

Your consent choice is stored in your own browser. If you clear your browser storage, we will ask you again.

8. How long we keep data

| Data | Kept | |---|---| | Account, profile, CV and cover letter files | Until you delete them or delete your account | | Applications and their notes | While your account exists, and see section 9 | | Sessions | 30 days, then they expire | | Payment and subscription records | For as long as accounting and tax law requires — as a rule 5 years from the end of the relevant tax year | | Job postings in the catalogue | Until they expire, then 30 days more, after which they are moved to cold storage and removed from the live database | | Campaign attribution in your browser | Up to 90 days | | Server and security logs | A short period, for troubleshooting and security only | | Error reports | Only as long as needed to diagnose and fix the problem, then deleted automatically by our monitoring provider | | Support correspondence | As long as needed to handle the matter and to defend against claims |

9. What happens when you delete your account

We want you to know this before you press the button, because part of it is permanent and part of it is not what people expect.

Deleted immediately and irreversibly: your candidate profile and everything in it, your CV and cover letter files, your sessions, your subscription records with us, and your login details — e-mail address, password hash and Google identifier. Your customer record with our payment processor is deleted too.

Kept: your application records — which job, what status, when, and any notes you wrote on them. They remain in our database attached to a stripped account record that no longer holds your name, e-mail address, password or any means of signing in, so we can no longer link them back to you. We retain them as a record of activity on the platform.

Note that notes are free text. If you wrote anything personal in them, tell us and we will erase those records too — write to support@onetap.work before or after deleting your account. We will do it on request, no reason needed.

Kept separately: invoices and payment records, for as long as tax law requires.

10. Your rights

You have the right to access your data, to correct it, to erase it, to restrict how we use it, to object to processing based on legitimate interests, to receive your data in a portable form, and to withdraw consent at any time.

Most of this you can do yourself: edit or delete your profile in the app, delete your account in Settings, change your cookie choices from the footer. For anything else — including a copy of your data, which we do not yet offer as a self-service export — write to support@onetap.work from your account e-mail address so that we can identify you.

We answer within one month. If a request is complex we may take up to two months more, and we will tell you within the first month if that happens.

If you think we are handling your data wrongly, please tell us first — it is usually the fastest fix. You also have the right to complain to the supervisory authority: Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

11. Automated processing

We do not make decisions about you that produce legal effects or similarly significantly affect you by automated means alone.

We do use automation in two visible places. Job matching ranks and filters the catalogue against the criteria you set — it decides what appears at the top of your list, nothing more. CV import uses an AI model to read your uploaded file and propose profile fields; the result is a draft you review and correct before anything is saved. AI output can be wrong, which is why nothing it produces takes effect without you.

12. Security

We encrypt data in transit, store passwords only as hashes, restrict access to production data to those who need it, separate our environments, log security events, keep dependencies updated, and assess providers before we use them. Card data never reaches our systems at all.

No service is perfectly secure. If a breach occurs that is likely to result in a high risk to you, we will tell you without undue delay, and notify the supervisory authority as required.

13. Children

The Service is not for people under 16. We do not knowingly collect their data. If you believe a child has given us personal data, write to support@onetap.work and we will delete it.

14. Changes to this Policy

We will keep this Policy accurate as the Service changes. If a change materially affects how we use your data, we will notify you by e-mail or in the app at least 14 days before it takes effect. The current version, with its date, is always at this address.

15. Contact

JDG Sviatoslav Mysiv
al. Jana Pawła II 3b/137, 80-462 Gdańsk, Poland
support@onetap.work

This Policy is published in Polish and English. For users in Poland the Polish version prevails.

OneTap.Work

Making job search effortless and fast.