Privacy Policy
Last updated: September 20, 2026
BabZituna ("we", "our", "the app") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how you can control it.
1. Data We Collect
Account Information
- Email address and display name (via email/password registration, Google Sign-In, or Sign in with Apple). If you use Sign in with Apple and choose to hide your email, we receive and store Apple's private relay address instead of your real one.
- Profile photo (optional, stored via Cloudinary)
- CV/resume file (optional, stored via Cloudinary)
- Professional details you provide: skills, experience, education, social links, job preferences
Swipe & Usage Data
- Swipe decisions (left/right) on job listings, including the job's title, company, type, location, and tags
- Match scores. Most are computed on your device; see section 3 for the two cases that run on our servers.
- Session metrics: session duration, swipe counts, time between swipes
- Saved jobs, application tracking status, and notes you add
Device & Technical Data
- Push notification tokens (for delivering notifications)
- App version and platform (iOS/Android)
- We do not collect device identifiers (IDFA/GAID), precise location, contacts, or call logs
2. How We Use Your Data
- Job Matching: Your profile and preferences are used to rank job listings and compute match scores. Ranking the jobs you browse happens on your device. Two things run on our servers, because they must work while the app is closed: the job-recommendation notification, which compares your stored profile against newly crawled jobs on a recurring schedule, and the match-count shown on job pages. Both read the profile you have already saved to your account.
- Improving Recommendations: Anonymized swipe patterns help us improve our ranking algorithms over time.
- Match Links: If a recruiter sends you a match link, your profile data is used to compute a compatibility score shown to both parties.
- Notifications: Push notifications for new matches, messages, and job alerts you've opted into.
- Analytics: Session metrics help us understand app usage patterns and improve the experience.
- Before you have an account: when you open the app and look at jobs without signing up, we count what happened: that the app was opened, that the preview was seen, how many cards were swiped, and whether sign-up was started. Those records carry a random identifier generated on your device, never an advertising id and nothing about the device itself. That identifier is never joined to an account. If you sign up, the earlier records stay separate and are only ever read as daily totals, and the identifier is thrown away when you sign out or delete your account.
3. Data Storage & Security
- Account data and swipe events are stored in Google Firebase (Firestore), hosted in the United States
- Files (photos, CVs) are stored via Cloudinary with secure HTTPS delivery
- Saved jobs, the applications you track and the notes you add are stored in your account (Firestore), so they follow you from one device to another. A copy is cached on your device.
- API requests to job boards are routed through our proxy server — your IP address is not shared with third-party job APIs
- All data transmission uses HTTPS encryption
4. Third-Party Services
These companies process personal data for us. Each one is listed with what it is for and what it receives.
- Google Firebase: sign-in, the database that holds your account, profile, matches, messages and usage events, and scheduled background jobs.
- Cloudinary: stores the profile photo and the CV file you upload.
- AI text providers: when you upload a CV, its text is sent to an AI model that extracts your skills, experience and education so you do not have to type them. AI models also draft content you ask for or that is shown to you or to an employer you are connected with: a cover note, interview questions, a short explanation of why a profile and a job fit. For that they receive the relevant parts of your profile and the job text. AI models are also used to help compute and explain match scores: a model can rate how well a profile fits a job, alongside the score our own formula computes. The request is handled by one of the following, depending on which is configured and available at the time: DeepSeek, DeepInfra, Groq, Mistral AI, Google Gemini, OpenRouter, OpenAI.
- OpenAI (embeddings): search text, job text and a skills summary of your profile are converted into numeric vectors so that search and ranking can match on meaning and not only on keywords. These vectors influence the order in which jobs and candidates are shown.
- Railway: hosts our API servers and the Redis cache they use. That cache holds, for a limited time, a snapshot of candidate profiles (skills, job title, location, preferences) used to send job recommendations, along with the crawled job listings.
- Sentry: crash and error reports from the app and from our servers. A report carries the technical context of the error (app version, device model, operating system) and your account identifier so that we can find the fault. It does not carry your email address or your name.
- Expo push service: delivers notifications to your phone. It receives your device's push token and the text of the notification.
- Resend: sends account emails such as the welcome message. It receives your email address and the content of the email. Every such email carries an unsubscribe link.
- Visitor statistics (Umami, hosted by us): our public web pages count visits with a self-hosted, cookieless tool. It sets no cookie, builds no profile, and is not loaded on pages that name a person, such as match links. It is not used inside the app.
- Third-party job APIs (Adzuna, JSearch, Reed, etc.): job listing data only; your personal data is never sent to these services.
- Google Sign-In: optional sign-in method (we receive only your email and display name).
- Sign in with Apple: optional sign-in method (we receive your email, or Apple's private relay address if you hide it, and the name you choose to share).
AI, match scores and who decides. AI is used in three ways: to extract the content of your CV, to draft text, and to help compute and explain match scores and ranking. BabZituna makes no hiring decision, automated or otherwise: a score orders a list and informs a person, and employers decide whom to contact, interview and hire. You can see why a score was given: each match score is broken down into six dimensions (skills, experience, location, salary, job type and work style), shown with the job. If you think a score is wrong, write to hello@babzituna.com and a person will look at it.
5. Data Sharing
We do not sell your personal data. We share data only in these cases:
- With recruiters who send you a match link — they see your name, profile photo and match score.
- Your professional profile is visible to employers. That is the service. BabZituna exists so that employers can find candidates, so if you have a candidate account, signed-in employers searching for people to hire can see your professional profile. Specifically: your name, profile photo, job title, city and country, your short bio, your skills, your work experience, your education, the languages you speak, any professional links you added (LinkedIn, GitHub, portfolio), the job types and work styles you are open to, and your match score against their role. There is no separate opt-in for this, because being found by employers is the reason the app exists — a job-seeking profile nobody can find would not be a service.
- What employers can never see from a search. The following are never included in the profile employers browse: your CV, your email address, your phone number, your postal address, your age, your salary expectations, your nationality, your work authorisation, your availability or notice period, your notification settings, and your account and billing state. These stay on your own record.
- Your CV and contact details require a connection. An employer can only open your CV and contact information after a relationship exists — you applied to their job, you accepted a match with them, or they added you to their hiring pipeline. That check runs on our servers on every request, not in the app, so it cannot be bypassed by a modified client.
- If you do not want to be visible. Because visibility to employers is the service itself rather than an add-on, we do not offer a switch that hides your profile while keeping your account. If you do not want employers to see you, delete your account — you can do this yourself at any time from Profile → Settings → Delete Account, and it removes your profile from employer search immediately.
- With service providers listed above, strictly to operate the app
- If required by law or to protect our legal rights
6. Your Rights
- Access: You can view your profile data in the Profile tab, and download everything else yourself (see Export below)
- Edit: You can update or remove any profile information at any time
- Delete: You can permanently delete your account and all associated data at any time from the app — go to Profile, open Settings, and tap Delete Account. You may also request deletion by emailing hello@babzituna.com.
- Export: You can download a copy of your data yourself, at any time, without asking us: in the app go to Profile, open Settings, and tap Download my data; on the website, open Account. You receive one JSON file with your profile, preferences, saved and applied jobs, matches, the messages you sent, notifications, match links and swipes. One export per hour.
7. Data Retention
- Account data is retained as long as your account is active
- Swipe events and application events are retained for up to 24 months, then deleted
- Session metrics, in-app analytics events, pre-signup counts and match link view records are retained for up to 12 months, then deleted
- Notifications are retained for up to 6 months, and the daily candidate digests sent to employers for up to 3 months, then deleted
- Deletion is automatic: each of these records carries its own expiry date, and the database removes it shortly after that date, usually within a day
- Deleted accounts are purged within 30 days
8. Children's Privacy
BabZituna is not intended for users under 16. We do not knowingly collect data from children. If we learn we have collected data from a child under 16, we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via in-app notification. Continued use of the app after changes constitutes acceptance.
10. Contact
For questions about this privacy policy or to exercise your data rights:
- Email: hello@babzituna.com
- In the app: open Profile to see the data we hold, and Settings → Delete Account to erase it.