Skip to content
NewEligibility scores are liveSee if you qualify

Privacy

Your CV is read once, and then it is gone.

This page says exactly what is kept, for how long, and who else ever sees it. It describes what the software does — if the software changes, this page changes with it.

Last updated 20 September 2026

The short version

  • The CV file itself is never stored. It is read once, in memory, and dropped. What is kept is the structured reading of it.
  • Nobody but you can read your profile. Not another candidate, not a hiring platform, not the machines that read job listings.
  • Your profile is never sent to a hiring platform. When you apply you go to their site and apply there, under their terms.
  • Nothing is sold, and there is no advertising on this site.
  • Analytics only run if you said yes, and you can change that answer.

What is held, and why

Your email address

So that you have an account and can sign back in. Held for as long as the account exists. Needed to provide the service you asked for.

Your profile

First and last name, country, city, LinkedIn address, the languages you speak and at what level, the fields you work in, a headline, the hourly rate you will work for, the hours a week you have, and when you can start. All of it is what you typed or confirmed. It exists to work out which roles you qualify for.

The reading of your CV

Your work history, education, skills and a written summary, as the reader understood them. This is what the matching uses. The file you uploaded is not part of this and is not kept anywhere. Its name, size, type and the date you uploaded it are kept, so the profile can say where its contents came from.

A count of CV readings

Your account id, a timestamp and the size in bytes, each time a CV is read. Reading a CV costs money, so there is a daily limit per person and for the site; this is the counter behind it. It holds no part of the CV.

Analytics, only if you allow it

Which pages were opened and which roles were applied to, tied to a random identifier in a cookie. It is how we learn which roles are worth listing. It carries no name, no email, no CV and nothing from your profile — see “Analytics” below.

There is no tracking of you across other websites, no advertising network, no data broker, and no profile bought from anyone.

Who else ever sees it

Four companies process some of this on our behalf. They may not use it for anything of their own.

Supabase

Hosts the database and runs the sign-in. Your account and profile live here, in the EU (Frankfurt). Row-level security means a signed-in person can read and write their own row and no other.

OpenRouter, and the model behind it

This one leaves the EEA, and it is the one that carries your CV. To turn your CV into a profile, its text is sent to OpenRouter, which passes it to the language model that reads it — currently Google’s Gemini, running in the United States. It is sent once, at the moment you upload, and is not used to train anything. If you would rather that did not happen, do not upload a CV: every question in onboarding can be answered by hand.

PostHog

Product analytics, and only if you allowed it — decline and it is never contacted at all. Our project is hosted in the United States, so this is the second thing on this page that leaves the EEA. What reaches it is which pages were opened and which roles were applied to, against a random identifier: no name, no email, no CV and nothing from your profile.

Our hosting provider

Serves the pages. It sees the ordinary things a web server sees: the address requested, your IP address, your browser.

Analytics and cookies

The site sets no cookie for analytics until you have said yes to the question at the bottom of the page. If you say no, the analytics library is never even downloaded.

Two things are stored in your browser regardless, because the site cannot work without them and they are never sent anywhere: the sign-in session that keeps you logged in, and a copy of your own profile so that the board can tell you what you qualify for without waiting for the network.

To change your answer, clear this site’s data in your browser and the question will be asked again.

How long it is kept

Your profile is kept until you delete it, and there is a button for that on your own profile screen. Pressing it removes the profile and the whole reading of your CV immediately and for good.

One thing that button cannot reach: the login itself. Deleting the account behind the email address needs a privileged key, and this site deliberately does not have one — a key that could delete any account would also be a key that could read any profile. So after you delete your data the email address survives as a login with nothing attached to it. Write to privacy@tier1.work and that is removed too.

The count of CV readings only matters for a rolling twenty-four hours, which is the window the daily limit is measured over.

What you can ask for

If you are in the EU or the UK, the law gives you the right to get a copy of what is held about you, to correct it, to have it deleted, to restrict or object to what is done with it, to receive it in a portable form, and to withdraw consent you have given. You can also complain to your national data protection authority.

Most of these you can do yourself: your profile screen shows everything held about you and lets you change or delete it. For anything else, write to privacy@tier1.work.

Who to contact

Tier1 decides what is collected here and why. Questions about any of it, or a request under the section above: privacy@tier1.work.

How the money works is a separate question, answered in full on how it works, and the rules of using the site are in the terms.