Privacy policy
Last updated 4 September 2026
JobsTrackr helps you find Indian government job notifications, check what you are eligible for, and track exam deadlines. This policy covers the website at jobstrackr.in and describes exactly what we store about you, who processes it, how long it stays, and how to have it removed. It is the whole of it — there is no second policy elsewhere.
We do not sell, rent or trade personal data. We run no advertising and no third-party analytics or tracking scripts.
Browsing without an account
Every job, exam update, syllabus and countdown on this site is readable without signing in, and we store nothing about you for it. Jobs you save as a guest are kept in your own browser’s local storage and never reach us until you create an account and choose to merge them.
What we store when you have an account
- Your email address, and a password if you set one. Handled by Supabase Auth. Passwords are stored only as a bcrypt hash — we never see or keep the password itself. If you only ever sign in with Google, there is no password at all.
- Profile details you enter: name, mobile number, date of birth, gender, reservation category, state and district.
- Eligibility details, because they are what the recommendations match against: your highest qualification, discipline, year of passing, institution and years of experience.
- What you have saved and tracked: saved jobs, saved updates, the exams on your tracker, your attempt history and any calendar entries you add.
- Your preferences: preferred sectors and states, and your notification settings.
- Documents you choose to scan, covered in its own section below.
Signing in with Google
Google sign-in is optional. Using it, we ask Google for three standard scopes and nothing else:
openid— a stable identifier for your Google account, so that signing in again returns you to the same JobsTrackr account.email— your email address and whether Google has verified it.profile— your name and the URL of your Google profile picture.
What we do with it. Those three things are used for one purpose: creating your JobsTrackr account and identifying you when you return. Your email address becomes your account address and is what we write to about your account. Your name pre-fills the name field on your profile, where you can change or clear it.
Where it is stored. In the same Supabase project as the rest of your account, in Supabase’s authentication tables, under the same row-level security as everything else. It is not copied anywhere else.
What we never ask for. We request no access to Gmail, Google Drive, Google Calendar, Google Contacts, Google Photos, or any other Google service. We cannot read, send or change anything in your Google account, and there is no scope on our client that would let us.
Who we share it with. Nobody. Google account data is not sold, transferred or disclosed to any third party, other than the infrastructure providers listed below that host the database it sits in, and except where the law requires it.
JobsTrackr’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Taking it back. You can revoke our access at any time from your Google account’s third-party access page. That stops future sign-ins. It does not delete your JobsTrackr account or the data already in it — to remove those, use the deletion route under “Your rights” below.
On the sign-in, sign-up and forgot-password screens only, your browser loads Google’s sign-in script from accounts.google.com so the button can work. It is not loaded anywhere else on the site, and it is not an analytics or advertising script.
Documents you scan
This is the most sensitive thing on the site, so it gets a plain description rather than a line in a list.
Scan a document lets you photograph an identity proof (Aadhaar, PAN or passport), a marksheet, a passing or degree certificate, a caste certificate, or another eligibility document such as EWS, disability or ex-serviceman proof — so that the details on it can fill your profile instead of being typed by hand. Nothing about it is automatic: the feature is entirely optional, and you see every field that was read and tick the ones you want kept before anything is written to your profile.
Using it means four things are true, and you should know all four:
- The file is stored. It goes into a private Supabase storage bucket, in a folder named after your user id, reachable only by your own signed-in session. The bucket is not public: there is no URL anyone can guess that serves it. We also record its type, size and upload time.
- The image is sent to Google’s Gemini API to be read. This is a transfer of your document to a third party, and it is the only way the feature works. What is sent is the image and an instruction to extract fields from it — not your account, your email address, or anything else from your profile.
- We use the free tier of that API, and you should know what that means before you upload anything. Under the Gemini API terms, content sent to the unpaid tier may be used by Google to develop and improve its products and machine learning models, and human reviewers may read it. Google says it disconnects such content from your API key and account before any human sees it. Google’s own terms tell developers not to send sensitive or personal information to the unpaid tier. We are saying so plainly rather than burying it, because the documents this feature is for are exactly that.
- Only what you approve is kept as profile data. Values you do not tick are discarded. We do not store the number from an Aadhaar, PAN, passport, or caste certificate as a profile field — the schema has no column for one — but the photograph you uploaded does contain it, and that photograph is retained until you delete it.
You can delete any scanned document at any time, from the same page. That removes both the stored file and its record — though it cannot recall a copy already sent to Google to be read.
Our advice, given the paragraph above: think twice before scanning an identity document. Every field this feature fills can be typed into your profile by hand in a minute, and doing that keeps the document on your own device. A marksheet carries less than an Aadhaar card does; treat them differently. If we move this feature to a paid tier — where Google does not use submitted content to improve its models — this page will say so and the date at the top will move.
What we do not collect
We do not run advertising, behavioural profiling, or third-party analytics. We do not store your Aadhaar, PAN, passport or certificate numbers as fields in your profile — an earlier version of this app did, and the database was rebuilt without columns for any of them, with those values discarded rather than migrated. We do not collect precise location, contacts, or anything from your device beyond what a web page ordinarily receives.
Information collected automatically
Like any website, this one is served by machines that keep operational logs. Vercel, our host, records the IP address, approximate location, user agent and requested URL of requests, and Supabase logs database and authentication activity. These are used to keep the site running, to investigate errors, and to stop abuse. They are not joined to your profile to build a picture of you, and they are not used for advertising.
Cookies and local storage
We set no advertising or tracking cookies. What is stored in your browser is:
- Session cookies from Supabase Auth, which are what keep you signed in. Clearing them signs you out.
- Local storage for your theme choice, jobs you saved before signing in, and a queue of changes made while offline so they are not lost.
- A service worker cache of pages and assets, so the site still opens on a poor connection. It holds published content, not your personal data.
Who processes your data
Only the providers below, and only so that the site can run. Each processes data on our behalf under its own terms; none of them is given your data for their own marketing.
- Supabase
- Database, authentication and document storage. Hosted in the Mumbai region.
- Vercel
- Hosting and content delivery for the site itself.
- Sign-in, if you use it; and the Gemini API, if you scan a document. Nothing else on the site sends data to Google.
- Resend
- Delivery of account email — address confirmation and password resets. It receives your email address and the contents of those messages, and nothing else.
Who else can see it
Your rows are readable only by your own signed-in session. This is enforced in the database itself through row-level security, not only in application code, so a bug in a page cannot expose another person’s data. Uploaded files are held in a private bucket whose access policies key on your user id in the same way.
We disclose personal data outside this list only where we are legally required to, and we will tell you if that happens unless we are prohibited from doing so.
Where your data is held
Your account and documents are stored in India, in Supabase’s Mumbai region. The site itself is delivered from servers worldwide, and the sign-in and document-reading requests described above are processed by Google, which may handle them outside India. That transfer is limited to what those two features need.
Security
Traffic is served over HTTPS only. Passwords are stored as bcrypt hashes. Access to your rows and files is enforced by the database rather than by page logic. The document bucket is private, and the URLs used to upload to it are single-use and short-lived. No system is perfect, and we do not claim otherwise — if we discover a breach affecting your data we will tell you and the relevant authority.
How long we keep it
Profile, eligibility, saved items, tracker entries and preferences are kept for as long as your account exists. Scanned documents are kept until you delete them or delete your account. Delete your account and all of it goes with it. Operational logs held by our providers expire on their own retention schedules, which are measured in weeks rather than years.
Your rights
Under India’s Digital Personal Data Protection Act, 2023, you may ask us for a copy of the personal data we hold about you, ask us to correct or complete it, ask us to erase it, and withdraw consent you have given. You can do most of it yourself, immediately:
- Edit or clear any profile field from your profile, and turn notifications off from the same page.
- Delete any scanned document, file and record together, from Scan a document.
- Revoke Google sign-in from your Google account.
- For a copy of everything, or to delete your account and everything attached to it, email contact@jobstrackr.in. We action requests within 30 days.
Children
The site is intended for people applying to government recruitment, which sets its own minimum ages. It is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will remove it.
Contact and grievances
For any question about this policy, any request under the rights above, or any complaint about how your data has been handled, write to contact@jobstrackr.in. Your complaint will be acknowledged and answered within 30 days. If you are not satisfied with the outcome, you may raise the matter with the Data Protection Board of India.
Changes
If what we store, or who processes it, changes, this page changes with it and the date at the top moves. Material changes will be announced on the site rather than made quietly.