floridaHired lists Florida jobs read from employers’ own careers pages. This page says exactly what we store, what we deliberately don’t, and how to have your data deleted.
You can use the site without an account
Browsing and searching require no account and no sign-in. If you save a job while signed out, the job’s id is kept in your own browser’s local storage and is never sent to us — clearing your browser data clears those saves, and they are not visible to anyone but you. Your browser also keeps today’s date and which kinds of page you have opened today (the board, a posting, a document…), so that a page’s animation plays the first time you open it each day and not on every visit; that is never sent to us either.
What we store if you sign in with Google
Signing in is optional, and its only purpose is to make your saved jobs follow you between devices. When you sign in, Google gives us a small set of profile fields, and we store:
- your Google account’s subject id — a stable identifier Google issues for our app;
- your email address;
- your first or display name, used to label the account menu;
- the URL of your Google profile picture. We store it but never display or load it, because loading it would tell Google which pages you read on this site. The circle in the header is drawn from your initials instead.
We ask Google for the openid, email and profile scopes and
nothing else. We cannot read your Gmail, your contacts, your calendar or your files, and we never
receive your Google password.
What an account records as you use it
The jobs you save, as a job id and the time you saved it.
If you use the resume builder, everything you type into it: your name, title, contact details, summary, the employers and roles you list, the bullets under them, your skills, your schools, the resumes you cut from that library, and any job posting you paste in to check a resume against. It is stored so the builder can show it back to you and turn it into a document, and for nothing else — it is never shared with an employer, never used to target an ad, and never read by anyone here except to fix a fault you have reported. It is deleted with your account.
If you have a resume prepared for a job, we also store what the preparation produced on that resume — the opening paragraph it wrote, the bullets it rephrased, the selection it made and its notes — plus the count of preparations you have bought and run. The preparation itself is described under Resume preparation below.
If you buy preparations, we record the payment’s reference number, the amount, the currency and the number of preparations it added. We never see or store your card details — see Payments below.
Cookies
We set two, both strictly functional, and neither is used for advertising or tracking:
- a session cookie when you sign in, holding a random token. Only a hash of that token is stored on our server, so our database cannot be used to log in as you. It lasts 90 days;
- a short-lived sign-in cookie that exists only during the round trip to Google, to verify the response really came from the request you started. It expires in 15 minutes.
We set no cookie for analytics or advertising, and we use no analytics service. Fonts, icons and every other asset are served from this site rather than a CDN, and no page loads another company’s script, so reading this site makes no request to anyone but us and nobody else can set a cookie through it.
Server logs
Our server records each request’s method, the path and query string that was asked for
(a query string can carry what you typed into the search box — “/jobs?q=nurse” — or the
filters you chose), the response status, how long it took, the IP
address it came from, the user-agent string your browser sent, and how many of
the three standard Sec-Fetch browser headers the request carried — a count from 0
to 3, never the headers’ values. Real browsers always send them, so their absence helps tell an
automated client pretending to be a browser apart from a person; nothing is served differently
because of it. These entries are deleted after seven days. Cookie contents are never
recorded.
We keep the address and the user-agent for one reason: security and abuse. This site is crawled and scanned constantly, and an address is what tells one client rapidly walking every posting apart from a person reading a few — a distinction nothing else here can make, because the counts below are deliberately incapable of it. We use the log to investigate abuse, errors and scraping, and for nothing else: it is not analysed for marketing, not used to build a profile of you, not joined to your account, and never sold or shared. Nobody outside this site’s operator can read it.
The log is separate from the counts described next, and stays separate. None of the totals below records an address or a user-agent string, so the number of times a posting was opened cannot be traced back to who opened it, and deleting your account does not depend on it — the log entries expire on their own within a week.
Counts kept from the request lines
From those same request lines we keep running totals — how many times a page was viewed on a given day, how often a search term was used, and which filters the board was asked for. They are counts and nothing else: there is no visitor, session or device attached to them, so they can tell us that a posting was opened forty times but never that you were one of them. We also count how many different people visited on a given day, which is described in Counting visitors below; that too is a total, and it is not attached to any of these.
Two request headers are read to build those counts, and neither is stored in the counts (the user-agent is written to the seven-day server log described above; the referrer is not):
- the referrer — the address of the page you followed a link from. We keep only its hostname (“google.com”), never the path or the query string, because a full referring URL can carry the search someone typed on another site. Links followed inside this site are not counted at all. If your browser sends no referrer, the visit is counted as “direct”, which is not a record of anything about you;
- the user-agent, read to tell an automated crawler from a person. What we keep is a coarse label for the software — “googlebot”, “other crawler” — and never the header itself, which would describe your device and browser. Crawler visits are counted separately and left out of every other number. Nothing is served differently because of this: crawlers get exactly the pages everyone else gets. It is also one of the ingredients of the visitor fingerprint described in Counting visitors, which stores nothing either.
If you add tags to a link to this site (utm_source and the like), those tag values are
counted the same way, so we can tell which link somebody followed. They are values we or you put in
the link, not anything read from your browser.
One more signal comes from the page itself rather than from the request line, and it is what decides whether a request is counted as a person at all. Each public page carries a few lines of our own script which, once the page has loaded, send one request back to our server saying so. That request carries the page’s own path and nothing else — no cookie, no timing, nothing about your device — and it is matched to the request our server received moments before using the same in-memory visitor fingerprint described in Counting visitors, then discarded. Only a page view the browser confirmed this way is counted as a view, a search, an arrival or a visitor; a request that no browser confirmed is counted once, as an unconfirmed request, and in nothing else. An automated client fetching pages does not run our script, and most of what fetches this site is automated, so this is how the counts stay a picture of people. It also means that if your browser runs no scripts, or you leave before the page finishes loading, you are not counted. Once the page has loaded, the same script also tells us once whether you interacted with the page — scrolled, moved the pointer, touched it or pressed a key — as a yes and the page’s path, nothing more: not which of those, not when, not how far. We keep a per-day total of pages that were interacted with beside the total of views, which is how we tell a page people read from one they left. Nothing is served differently because of any of it, no third party is involved, and blocking either request costs you nothing.
Counting visitors
Page views on their own flatter: one person reading five postings is five of them. So that we can tell how many people read the site on a day, each visit is counted like this:
- when a page loads and your browser confirms it (the request described above), our server combines your IP address and your browser’s user-agent string with a random secret value, and runs the three through a one-way hash. The result is a short number that means nothing on its own;
- that number is held in the server’s memory alongside the day’s others, purely so the same visitor is not counted twice. Only the day’s total is saved — one number per day;
- the random secret is generated fresh every day, kept only in memory, and never written down or shared. Because it is a new secret each day, the number your visit produces today cannot be matched to the one it produced yesterday, and nobody — including us — can work backwards from a stored total to an address;
- at midnight UTC the secret and the day’s numbers are discarded together. Nothing derived from your address outlives the day.
The fingerprint itself is never attached to a page you opened, a search you made or a link you followed: it answers one question — “has this visitor already been counted today” — and is deliberately incapable of answering any other, including whether a particular person has ever been here. Your IP address is not stored in this count; only the hash is held, in memory, until midnight. It is written to the server log described above, which is a separate record kept for seven days for security, and the two are never joined: the visitor total is one number a day with nothing else in it. We do not use a cookie, a device identifier or an analytics service for this, and the count is not shared with anyone.
Being an estimate, it is imperfect in ways worth naming: people sharing a network and the same browser version are counted as one, one person using a phone and a laptop is counted as two, and a restart of our server may count a returning visitor again on the same day. It is a gauge of how busy the site is, not a measurement of individuals.
Who your data goes to
We do not sell it, rent it, or share it for advertising. It is not shared with the employers whose jobs you save — saving a job is invisible to them, and applying happens on the employer’s own site under their privacy policy, not ours. Your data is handled by Google, when you choose to sign in, under Google’s privacy policy, and by exe.dev, which hosts the server this site runs on. If you have a resume prepared for a job, the text of your library and the posting go to Anthropic, under Resume preparation below. If you buy preparations, the payment is handled by Stripe under Payments below. We may also disclose information if the law requires it.
Resume preparation
The resume builder is free. What we sell is the preparation: when you ask for a resume to be prepared for a posting, we send the text of your library — your profile, summary, skills, roles, bullets and schools — together with the posting you pasted and the employer and role you named to Anthropic, whose Claude model writes the preparation and sends it back. Nothing else about you goes with it: no email address, no account identifier, no address beyond what you typed into the profile. Anthropic processes it under Anthropic’s privacy policy and its commercial terms, which say that data sent through its API is not used to train its models. Nothing is sent unless you press the button, and what comes back is stored on that one resume as described above.
Payments
Buying preparations sends you to a checkout page hosted by Stripe, which takes your card details and processes the payment under Stripe’s privacy policy. Your card number never touches this site. We tell Stripe the email address on your account so the checkout can be prefilled, and an identifier for your account so the purchase can be matched back to it. Stripe tells us that the payment succeeded, its reference number, the amount and the currency, and that is what we keep. Nothing else about the purchase is shared with anyone.
Advertising
This site carries no advertising. No ad network’s code loads on any page, no employer pays for placement, and nothing you do here — signed in or not — is used to target an ad or shared with anyone for advertising. If that ever changes, this policy changes first.
Deleting your data
You can do this yourself, immediately: open the account menu and choose Delete account. It removes your account, your saved jobs, your resume library and every resume cut from it, any preparations you had left, and every session in one step, and it does not go through anyone here. There is nothing to retain afterwards — we keep no backup copy of an account once it is deleted.
If you would rather we did it, or you have lost access to the Google account you signed in with, email privacy-florida-hired@floridahired.com and we will delete it for you.
You can also sign out at any time from the account menu, which immediately invalidates that session on the server, and you can remove any individual saved job by tapping its heart again. Revoking this app from your Google account permissions stops future sign-ins but does not by itself delete what we already hold — email us for that.
Children
This site is not directed at children under 13 and we do not knowingly collect their information.
Changes
If this policy changes, the date at the top changes with it.
Contact
floridaHired is operated by Pinova, LLC. Questions about this policy: privacy-florida-hired@floridahired.com.