Privacy Policy
Last updated: September 2026
PhysicalAIJobs is operated by Koding Studio.
This policy explains how we collect and use information when you use https://physicalai.jobs.
1. Information We Collect
Information you provide
You may provide information such as:
- email address and account information
- candidate profile, skills, job preferences, saved jobs, and job-match feedback
- resume files and resume metadata when you choose to upload a resume
- employer company claims, membership records, and verification evidence such as account email domain and company website domain
- job submissions
- messages or feedback
Automatically collected data
When you use the Site we may collect:
- IP address
- browser type
- device information
- pages visited
- interaction data
2. Analytics
We may use analytics services such as:
- Google Analytics
- other traffic measurement tools
These services help us understand how users interact with the Site.
3. How We Use Data
We use collected data to:
- operate and improve the Site
- understand usage patterns
- create and maintain candidate-controlled profiles
- personalize and explain job recommendations
- securely store and process resume files when that feature is enabled
- review employer company claims and verify employer identity
- detect abuse, fraud, or malicious files
- communicate with users
4. Candidate Profiles, Resumes, and Matching
Candidate profiles start private and are used to provide job recommendations. Employer discovery is a separate candidate-controlled choice. Anonymous discovery consent is time-limited, can be turned off immediately, and includes an employer-preview screen showing the fields eligible for future anonymous discovery.
Candidates may also block named companies from future discovery. Company blocks are stored against the canonical company record. Blocking reduces unwanted exposure but cannot guarantee that another party could never infer identity from an otherwise distinctive professional background.
The first anonymous preview excludes contact details, raw resumes and resume filenames, private storage links, account identifiers, salary preferences, saved jobs, match feedback, newsletter state, and exact street address. Employer candidate access remains separately permissioned and is not enabled merely because a candidate records discovery consent or an employer is verified.
Where the employer candidate-access pilot is explicitly enabled for a verified, allowlisted employer, job-linked matching uses only anonymous-preview-compatible role family, skills, workplace preference, seniority, and employment-type signals. It does not use candidate salary preferences in the employer score or reasons. The same pilot may also provide a secondary structured talent search limited to anonymous-preview fields. That search requires at least one filter, returns at most 50 profiles, does not provide a blank browse-all mode, and does not provide contact or introduction actions. For pilot analytics, each valid structured search stores only the number of active filters and the number of results returned; the actual filter values are not copied into the analytics event. Employer outreach remains tied to a current job through the separate candidate-controlled introduction flow. Candidates with expired consent, a block against that company, or membership in the same employer account are excluded before cards are returned.
Employer access to candidate-derived information is recorded in an append-only pilot audit. Audit records identify the employer account, acting employer user, candidate profile, access surface, optional job or introduction record, and timestamp needed for accountability. They do not store resume text, salary preferences, employer message content, candidate contact content, or employer team-note text. Candidate data exports include a sanitized access history with employer company, event, surface, job, and time but omit recruiter identity and internal database IDs. Candidate-specific audit rows are deleted when the candidate profile is permanently deleted.
Where employer candidate lists are enabled, any active member of the authorized hiring workspace may save an anonymous candidate reference to a shared shortlist and add internal, job-related notes. Saving a candidate does not override later privacy changes: each list view rechecks current discovery consent, consent expiry, company blocks, same-employer exclusions, and employer access. If access is no longer valid, candidate details, team notes, saver identity, and prior workspace context are hidden from the employer until eligibility returns. Notes cannot contain direct email addresses, phone numbers, or URLs and should not record protected or sensitive personal traits. Candidate JSON exports include the employer company, list, workspace context, note text, and time for notes about that candidate, but omit the individual recruiter identity and internal database IDs. Candidate deletion removes saved-list entries and notes linked to that candidate.
Where the employer introduction pilot is explicitly enabled, an employer may send a bounded introduction message from a job-linked anonymous match. The message cannot contain direct email, phone, or URL contact details. Requests expire, are rate-limited, and do not reveal candidate contact information. A candidate must explicitly choose “Accept & share my email” before their account email is snapshotted and revealed for that request. When declining, the candidate selects a fixed job-related reason or “Prefer not to say.” That individual reason remains visible to the candidate and in their data export but is not shown in the employer’s individual request view; employer analytics shows decline reasons only after at least five declined requests exist in the reporting period. After an accepted introduction, the employer may record the fixed workflow outcome Interviewing, Hired, or Not proceeding. This is an employer-reported pipeline status, not a candidate score or automated decision, and it is included in the candidate’s data export. Declining, expiry, withdrawal, or a blocked/ineligible employer shares no candidate email. Raw resume access is not granted by accepting an introduction.
Candidates may report an employer introduction using one fixed policy reason such as spam/irrelevance, misleading role information, harassment/pressure, discriminatory or inappropriate content, attempted contact bypass, suspicious/fraudulent activity, or other policy concern. The report form collects no free-text note. Reporting a pending request closes it as declined without sharing contact, and the employer sees only the ordinary decline state, not the report reason. Reporting an already accepted request cannot retract an email that was previously shared, but it immediately revokes structured ATS consent and blocks future ATS exports. Reports are reviewed manually in an administrator queue; one report does not automatically suspend, rank, score, or penalize an employer. An administrator must explicitly dismiss the report, record a warning disposition, revoke talent-pilot access, or suspend the employer. The candidate's own data export includes the report reason/status/review outcome without internal IDs.
After an introduction is accepted, structured ATS handoff remains a separate candidate-controlled permission and is disabled by default unless `TALENT_EMPLOYER_ATS_HANDOFF_ENABLED=true`. If the candidate explicitly enables it for that introduction, any active member of the same authorized hiring workspace may download a bounded CSV only while that workspace remains approved for talent access, its candidate-access and introduction pilot entitlements remain active, and the candidate-access/introduction/ATS deployment feature gates remain enabled. The CSV contains the already-shared email plus the candidate's current confirmed headline, role, seniority, coarse location, role families, domains, skills, workplace/employment preferences, relocation and sponsorship flags, availability, the role/company context, and any employer-reported workflow outcome. The export excludes raw resume files/text, resume filenames/storage links, salary preferences, saved jobs, match feedback, employer notes, newsletter state, candidate database IDs, and anonymous talent references. A company block, candidate revocation, employer pilot-access revocation, deployment kill switch, or candidate report stops future downloads. Revocation cannot retract a CSV already downloaded, so the candidate UI shows when a prior download was recorded. Each successful download creates an audited `structured_export` access event and an introduction lifecycle event. CSV values are quoted and formula-leading content is neutralized to reduce spreadsheet-injection risk.
During the unmetered employer design-partner pilot, each accepted introduction is also recorded exactly once in a first-party usage ledger. Pilot ledger rows record the employer account, candidate profile, usage period, one accepted-introduction unit, billing mode/reason, and internal idempotency/relationship keys. Pilot rows are non-billable and consume zero credits; there is no talent subscription checkout or charge. Candidate data exports include a sanitized view of usage associated with their profile (employer company, period, units, credit delta, billable state, and billing reason) while excluding internal source/relationship keys and payment identifiers. Candidate deletion removes these unmetered candidate-linked usage rows; any future paid-billing retention rules require a separate legal/privacy review before charging is enabled.
Resume files, when upload is enabled and you choose to provide one, are treated as private documents. They are stored separately from public site media, checked for file type and malicious content, and are not published as public URLs.
Where local resume parsing is enabled, extracted text is used transiently to propose a structured draft for your review. The first-pilot parser does not retain a standalone copy of extracted resume text, and obvious email, phone, and URL content is removed before taxonomy matching. Parser suggestions do not change your confirmed candidate profile until you explicitly apply the reviewed draft.
Matching may use structured information such as role interests, skills, seniority, location, work preferences, employment type, and compensation preferences. Match scores are recommendation aids and are not automated hiring decisions or automatic candidate rejections.
5. Data Sharing
We do not sell personal information.
We may share limited data with service providers such as:
- hosting and private object-storage providers
- security and malware-scanning providers or software
- email-delivery providers
- analytics providers
- other infrastructure services
These providers help operate the Site and receive only the information needed for their function.
Candidate profile or contact information is not made available to employers merely because an employer pays PhysicalAIJobs or verifies a company claim. Employer discovery must pass the candidate's current consent, expiry, company-block, and employer-access controls. Candidate email is shared only after explicit acceptance of a specific introduction request. Raw resume access is not included in the anonymous matching or introduction flows.
6. Cookies
The Site uses cookies to:
- analyze traffic
- remember preferences
- improve performance
Users can control cookies through browser settings.
7. Data Retention
Information is retained only as long as necessary to operate the Site and comply with legal obligations.
Candidates can replace or delete stored resume versions, pause their candidate profile, download a structured copy of candidate-owned data, and separately download private resume files through recent-authenticated Privacy & data controls.
Candidates can also permanently delete the candidate account and candidate-owned database records. Private resume objects are removed before account deletion is completed. A separate editorial newsletter subscription is not silently changed by deleting the candidate account.
8. Security
We implement reasonable measures to protect data, including access controls and separate private storage for candidate documents where applicable.
However, no online system can guarantee absolute security.
9. External Links
The Site may link to third-party websites.
We are not responsible for their privacy practices.
10. Children's Privacy
The Site is not intended for children under 13.
11. Policy Updates
This policy may be updated periodically.