Draft for reviewNot yet reviewed, and not yet in effect.
Privacy Policy
Privacy Policy
This page says what 1stSeen keeps about you, why, where it is stored, and how to get a copy or delete it. If something here is unclear, write to hello@1stseen.win.
Last updated
The short version
- You can read 1stSeen without an account. Then it keeps nothing about you beyond the questions you ask its agent.
- An account keeps your email address, a hash of your password, the roles you follow, your first-run answers, and your preparation plans.
- Google Calendar and Gmail are used only if you connect them, and their access tokens are stored encrypted.
- 1stSeen does not sell your data, shows no advertising, and runs no analytics or advertising trackers.
- You can download everything your account holds, and delete the account, from Settings.
Your account
Sign-in is run by Supabase Auth. It stores your email address and a one-way hash of your password, never the password itself. It also records when you signed up and last signed in, and keeps a record of each signed-in session and of sign-in events, with the network address and software that made each request. Supabase sends the email that confirms your address and the one that resets your password.
1stSeen keeps a profile for the account: a display name, taken from the part of your email address before the @, and a time zone, which is UTC unless changed.
These exist so that you can sign in and your follows and plans stay yours. They are used for nothing else.
What you tell 1stSeen
- Follows. Each company, role, field, or program type you follow, and whether alerts are on for it. Your watchlist, dashboard, calendar, and digest are built from these.
- First-run answers. The kinds of role you chose, your graduation year, the season, and the places you gave, and when you finished or skipped the questions. They choose which roles to suggest, and you can change them in Settings. The same record can hold company-size preferences and priority companies, which no page asks for today.
- Preparation plans. For a followed role with a forecast, the milestones worked back from it, such as when to have a résumé ready, with their due dates, and when you mark one done.
Questions you ask the agent
When you ask the recruiting agent a question, 1stSeen stores a record of the run:
- the question, with any email address or phone number in it replaced, cut to its first 1,000 characters;
- the role you asked from, if you asked on a role's page;
- which tools the agent ran, when, whether each worked, and a short summary with counts of what it found;
- the answer it gave, with the evidence and forecast it cited.
If you are signed in, the record is linked to your account. If you are not, it is stored with no account and no network address. The site's public activity panel can show the tools the latest question without an account ran, and their summaries, but never a question's text, and never a run started by a signed-in person.
Questions without an account are counted per network address for one minute, to limit them. The address is used as that count's key by Cloudflare and is not stored by 1stSeen.
By default the agent uses no language model: fixed rules read your question. The operator can turn on model-assisted reading. Then a question the rules cannot place, up to its first 2,000 characters, is sent to the configured model provider only to choose which of the agent's tools to run, and 1stSeen records which provider and model answered and how many tokens it used, not the question again.
Google Calendar and Gmail
These are optional, and each is connected separately. Nothing about them is stored unless you connect one. Access tokens are encrypted with AES-256-GCM before they are stored, and each is bound to your account and to the service it belongs to, so it cannot be used for anyone else.
- Google Calendar keeps the encrypted tokens, the permission Google granted, when you connected, and, for each date you added, the Google event's ID and a fingerprint of what was written, so adding it again updates the event instead of copying it.
- Gmail keeps the encrypted tokens, the permissions granted, and your Google account's email address, which is where a digest is sent. For each digest you send, it keeps the recipient, subject, contents, whether it was sent, and Gmail's ID for the message.
Google data use lists the exact permissions each one asks for and everything done with them.
Where it is stored, and who hosts it
1stSeen shares your data with no one. These services host it or run the code that handles it:
- Supabase runs the Postgres database where everything above is stored, and sign-in.
- Cloudflare runs the website on Cloudflare Workers. Every page request passes through it.
- Google Cloud Run runs the agent service. It receives your question and, if you are signed in, your account ID, from the website, not from your browser.
- GitHub Actions runs the scheduled jobs that refresh forecasts, and writes preparation plans for the accounts that follow a role, by account ID.
- Google, only if you connect Google Calendar or Gmail.
- A language model provider, only if the operator turns on model-assisted question reading, as above.
1stSeen would disclose data to anyone else only where the law requires it.
How long it is kept, and what is logged
- Your account and everything it owns are kept until you delete the account.
- Disconnecting Google Calendar or Gmail asks Google to revoke 1stSeen's access and deletes the stored tokens straight away.
- Questions asked without an account are kept, with no link to a person. There is no automatic expiry yet.
- 1stSeen's own logs record a failed background sign-in step by its error code and status only, never an email address. Supabase, Cloudflare, and Google Cloud keep their own operational logs of the requests they handle.
Getting a copy, and deleting it
In Settings, under Your data:
- Download your data gives you a JSON file of everything your account owns.
- Delete account asks you to type a confirmation, and cannot be undone. It deletes every record your account owns and deletes your sign-in. That is 1stSeen's to guarantee, and nothing another service does can stop it.
Deleting your account also asks Google to revoke any access you gave 1stSeen to your Google Calendar or Gmail. Only Google can revoke that access, so 1stSeen cannot guarantee it. If Google does not confirm, your account is deleted all the same, 1stSeen asks Google again for a short while without keeping the token anywhere, and the page you land on tells you to remove the access yourself at myaccount.google.com/connections.
Dates you already added to Google Calendar are in your calendar, not in 1stSeen, and a digest you sent is in your mailbox. When you delete your account you can choose to have 1stSeen remove the calendar dates it added. If Google Calendar does not let it, the account is deleted anyway and you are told some dates may remain.
You can change your first-run answers and follows at any time. If you cannot sign in, or want something the Settings page does not offer, write to hello@1stseen.win.
Changes to this policy
When this policy changes in substance, the date at the top of the page changes with it.