Hunt

Privacy policy

Effective September 26, 2026

The short version

Who we are

Hunt helps developers find the roles worth their time and apply with every answer ready.

Hunt is run from the United States by an independent developer trading as Hunt ("we"). We decide how your personal data is used, which makes us the "controller" of that data in legal terms. For our legal name and postal address, write to privacy@usehunt.dev and we'll send them. When a company takes over running Hunt, we'll name it here first.

This policy covers:

During the beta, the Hunt app is offered only to people who live in the United States.

Hunt is also being built to help teams find the developers who fit. That side, the head hunt, isn't open. Before it opens, we'll update this policy to say what it collects from recruiters, what a recruiter can see about you (only what you agree to share, role by role), and how any ranking works.

usehunt.dev is Hunt's home during the beta. If Hunt moves to another domain or changes its name, this policy moves with it, and we'll say so here.

Privacy questions, requests and complaints go to privacy@usehunt.dev. Everything else goes to hello@usehunt.dev.

We haven't appointed representatives in the EU or the UK. Before the app opens to people there, we'll appoint them and name them here.

What the website collects

usehunt.dev is a set of static pages. There's no account, no sign-up, no waitlist and no email field. Hunt runs no server code of its own for the site and keeps no server logs. The records of your visit are Cloudflare's (below) and the Google Analytics data collected for us (see Google Analytics and cookies).

Our own code stores nothing in your browser: no cookies and no local storage. Google Analytics, which our code loads, sets two cookies (see Cookies).

The invite box

The home page has one form, a box for an invite code. The code is checked in your browser and never sent anywhere. The page stops the form from submitting, and the site's security policy blocks it from submitting even with JavaScript turned off. For now, a valid-looking code only shows a message that invites open soon. Nothing is looked up or stored.

If you open an invite link (usehunt.dev/i/…), your browser asks Cloudflare, our host, for that address. So the code reaches Cloudflare as part of the web address, the same way any address you visit does. Hunt doesn't store it, and Google Analytics sees only /i/, never the code.

"Come back later…" is just text. It collects nothing.

Cloudflare

Cloudflare hosts the site. To deliver a page, Cloudflare's network receives what any web server receives: your IP address, the address you asked for, and the standard details your browser sends with each request, such as its type and language. Hunt hasn't turned on any request logging of its own. Cloudflare's dashboard does show us traffic statistics for the site, which may include the addresses people asked for, so an invite link's code may appear there. What Cloudflare keeps is covered under How long we keep it.

Network error reports

Cloudflare adds a standard instruction to the site's responses called Network Error Logging. If loading the site fails, your browser may send Cloudflare a short report about the failure: the address that failed to load (on an invite link, that includes the code), the page that led there, if any, which Cloudflare server answered, your browser type, how long it took, the kind of request, the stage it failed at, the protocol, the status code and the type of error. Cloudflare also receives your IP address with it, as with any request. Successful page loads aren't reported.

Google Analytics and cookies

We use Google Analytics 4 on every page of usehunt.dev, including this one, to count visits and see which pages work. Apart from Cloudflare, Google is the only company the site's pages talk to. The fonts and images come from usehunt.dev itself.

What Google Analytics receives

We've turned off Google signals and ad personalization in our code. Those are the features that tie visits to Google accounts and to ads. Our pages also tell your browser never to pass their own address on, whether to Google's requests or to the next page you open, so an invite link's address can't reach Google that way either.

Google Analytics works for us as our service provider. We keep Google's data-sharing settings off and have accepted Google's data processing terms, so Google may use this data only to run Analytics for us, not for its own purposes or for ads. Google explains how it handles data from sites that use its services here: How Google uses information from sites or apps that use our services.

Cookies

CookieSet byWhat it's forLasts
_gaGoogle Analytics, on usehunt.dev and its subdomainsTells visitors apart2 years from your last visit
_ga_RJZ8MX2T97Google Analytics, on usehunt.dev and its subdomainsKeeps track of your current visit2 years from your last visit

Hunt sets no cookies of its own. Cloudflare may set a short-lived security cookie to tell people from bots, such as __cf_bm (up to 30 minutes) or cf_clearance (after a bot check). These are strictly necessary, and they aren't used for analytics.

Saying no

The site doesn't show a cookie banner. Where you are decides what Google Analytics does:

If you'd rather Google Analytics didn't run at all, block cookies for usehunt.dev or block Google Analytics, in your browser's settings or with a content blocker. You can delete the cookies above at any time. The site works the same without them.

Do Not Track and Global Privacy Control: our code doesn't read these signals, and Google Analytics loads either way. We don't sell or share personal information, so there's no sale or sharing for those signals to stop.

In the app

When the app opens, it will use Google Analytics too, under a stricter rule: analytics count visits and screens, never which role, company, fact or email. Screens are reported by their shape (like /jobs/:id) with generic titles, and links you follow by their domain only. No event may carry a job, company, fact, email, search text, invite code or token. Google signals and ad personalization stay off. The _ga cookie belongs to usehunt.dev and its subdomains, so the same ID can link your visits to this site with your use of the app.

The app will also set a few strictly necessary cookies of its own: one keeps you signed in, and short-lived ones carry a sign-in or an invite. None is used for analytics.

What the app collects, and why

The app isn't built yet. Nothing in this section is live. It describes what the app is designed to collect and why, so you know before you accept an invite. If what ships differs, we'll update this policy first.

You need an email address, through your sign-in, to have an account. Everything else is optional. Hunt works with what you choose to give it, and does less without it.

Your account

Hunt's sign-in has no passwords. Sign-in starts with GitHub. Google, a one-time code by email, and passkeys come later.

Why: to know it's you, keep you signed in, and keep the beta invite-only.

Your search

What you're looking for (titles, remote or location, minimum pay, tech stack). The roles Hunt finds or you add: title, company, links, pay, the posting's text, and Hunt's scores and vetting notes. Where each role stands: status, rank, applied, heard back. Your notes and drafts, the companies you watch, the searches Hunt runs for you and their logs, and an activity feed.

When you delete a role Hunt found, Hunt keeps a small record of it (where it came from, company, title and link) so the next search doesn't bring it back.

Your resume, if you give Hunt one.

Why: this is the tracker. It's what Hunt is for.

Your identity vault

Facts you tell Hunt about yourself, so it can answer application questions the way you would: contact details, links, work authorization, education, experience, pay, preferences, your story, and rules you set (like "never name my current employer"). Also answers you've saved to application questions.

Every fact is optional. Nothing about you is made up or upgraded: what Hunt doesn't know, it asks.

Each fact has a sensitivity level, which decides where it can go:

You can change a fact's level, except that demographic facts always stay sensitive.

Sensitive facts get extra care:

When you replace a fact, Hunt keeps the old version as history. When you forget a fact, Hunt stops using it at once, but keeps it as history so you can trace an old answer. Forgetting a fact doesn't erase it. You'll be able to erase all your facts, their history and your saved answers for good, in one step.

Why: so Hunt drafts answers from things you've confirmed, instead of guessing.

Your mailbox, if you connect one

Connecting a mailbox is optional, and it isn't available in the app yet. This is how it works:

Why: so replies, rejections and interview invites update your tracker without you copying them over.

Google user data

This covers Sign in with Google and a Gmail account you connect. Hunt's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Chat and AI

Hunt uses Anthropic's Claude models to chat with you, find and vet roles, draft answers and notes, and sort job mail it can't place on its own. For each task, Hunt sends Anthropic the text that task needs. That can include your resume, your confirmed facts that aren't sensitive, your criteria (including the minimum pay you set), your roles, notes and calendar, a job posting, and emails the task reads. Anything you type in chat goes too, so leave out what you'd rather Anthropic didn't see.

To sort an unclear email, Hunt sends its subject, sender, date, the first 4,000 characters of its text, any calendar summary, and the companies and jobs it might match. That's at most 20 messages per sync, the model gets no tools, and you can switch this step off.

Hunt keeps your chat history. For every AI run, it will record which provider and model ran it, how many tokens it used and what it cost.

There will be two ways to run Hunt's AI:

Why: this is how Hunt does the work you ask of it. AI output can be wrong, so read every draft before you use it. You press Submit.

Notifications and email from Hunt

Hunt's own email is limited to sign-in codes and the Brief, a summary of your search. Emailing the Brief is off unless you turn it on, and every Brief email has a one-click unsubscribe.

If you turn on browser notifications, Hunt keeps your browser's push subscription so it can reach you. In discreet mode, a notification says only something like "2 updates", never a role, company or title.

The browser extension (later)

Hunt's browser extension isn't built yet. It's designed to run only on a tab where you turn it on, never across all sites. It sends the app only what you capture: the page's address and title, the form's questions (labels, types and options, not anything you've already typed), the page's text up to about 30,000 characters, and a screenshot only if you tick the box. A screenshot shows whatever is on screen, including anything you've typed. It shows you a receipt for each capture.

It fills an answer only when you press Fill. It never answers consent, AI-disclosure or demographic questions for you, and it never clicks Submit. We'll update this policy before it's released.

Payments

Hunt takes no payments today. If that changes, this policy will name the payment processor first.

Other people in your data

A job search involves other people. The emails Hunt will keep from your mailbox, and the notes and calendar events in your tracker, can hold recruiters' and interviewers' names, email addresses and messages. Job postings Hunt reads are public pages, and some name a hiring contact.

Hunt keeps this only inside your own workspace, to run the tracker you asked for. That's our legitimate interest. It comes from your mailbox, from what you add, or from public job pages. It isn't used for anything else, and it never reaches anyone else's workspace.

Our providers handle it for us: Cloudflare stores it, and Anthropic reads an email when Hunt sorts one it can't place or when a task needs it. It's kept as long as the user keeps it (see How long we keep it).

If you're one of those people, you can ask what we hold about you, object to our keeping it, or ask us to delete it. Write to privacy@usehunt.dev. We can't always tell which workspace holds your data, so tell us the email address you wrote from.

Why we use it: our legal bases

In the EU and the UK, data protection law asks us to name a legal basis for each use of your data.

What we doLegal basis
Sign you in and run your account (account and sign-in data, sign-in codes by email)Contract: we need it to provide Hunt to you.
Run your tracker (your search, resume, facts, chat, AI drafting and vetting, and your mail if you connect a mailbox)Contract.
Store special-category facts you add, such as ethnicity or health, once you've given explicit consentYour explicit consent. You can withdraw it at any time, which erases the fact.
Keep sensitive details that arrive in job mail, such as a health noteYour explicit consent, given when you connect a mailbox. You withdraw it by disconnecting.
Keep the people in your mail and notes in your trackerLegitimate interests: running the tracker you asked for.
Keep accounts and invites safe (per-IP rate limits on invite lookups, sign-in and invite records)Legitimate interests: preventing abuse and protecting your account.
Keep Hunt running and fix problems (logs, AI usage and cost records, error reports)Legitimate interests: keeping the service working and secure.
Email you the Brief and send browser notifications, if you turn them onYour consent.
Analytics on the siteOur legitimate interest in knowing how many people visit and which pages work. In the EU, the EEA, the UK and Switzerland, where the law asks for consent before analytics cookies are set, the site sets none and sends only cookieless pings: see Saying no.
Analytics in the appYour consent where the law requires it, as in the EU and the UK. Elsewhere, our legitimate interest in knowing which screens work.
Answer your messages, privacy requests and complaintsLegal obligation, for privacy requests and complaints. Legitimate interests (answering you), for everything else.
Pass Hunt to a company formed to run it, if that happensLegitimate interests: keeping Hunt running for you.
Meet legal obligations, and establish or defend legal claimsLegal obligation, or legitimate interests (protecting our rights).

Automated decisions

Hunt scores and ranks roles for you. It compares each role's title, remote and location rules, pay and stack with the criteria you set, and its AI can vet a role in depth. That's advice for you. You make every decision, and Hunt never applies for you.

Hunt makes no decision about you based solely on automated processing that has legal or similarly significant effects on you.

Who handles your data

We use a few providers to run Hunt. Each gets only what its job needs.

WhoRoleWhat forWhat they receiveWhen
Cloudflare, Inc.Our processorHosts usehunt.dev, and forwards mail sent to privacy@usehunt.dev and hello@usehunt.dev. Will host the app, its database and live updates.Site requests (IP address, the address asked for, browser details, error reports). Mail you send us. In the app, what you store in Hunt.The site and our mail: now. The app: when it opens.
Google LLC (Google Analytics)Our service provider, with Google's data sharing offCounts visitsWhat's listed under Google AnalyticsThe site: now. The app: when it opens.
Anthropic, PBCOur processor on Hunt AI. With your own key, your own provider, under your agreement with Anthropic.Runs the Claude AI modelsThe text each AI task needs (see Chat and AI)When you use Hunt's AI in the app
The service that runs Hunt's AI agentsOur processorRuns Hunt AI, and runs on a key you store in HuntThe text each task needs, for the length of the runNot chosen yet. We'll name it here before Hunt AI runs.
GitHub, Inc.Independent: its own privacy policy appliesSign-inGitHub tells Hunt your GitHub ID, profile and primary verified email, and learns that you signed in to Hunt.When you sign in with GitHub
Google LLC (Sign in with Google)Independent: its own privacy policy appliesSign-inGoogle tells Hunt your basic profile and email, and learns that you signed in to Hunt.Later, when you sign in with Google
Your mailbox provider (Gmail, iCloud, Outlook, Yahoo, Fastmail or another IMAP service)Your own provider, under your agreement with itHunt reads your job mail, read-onlyHunt's read-only access to your mailboxOnly if you connect one
An email delivery serviceOur processorSends sign-in codes and the BriefYour email address and the messageNot chosen yet. We'll name it here before Hunt sends any email.
Your browser's push service (run by your browser's maker, such as Google, Apple or Mozilla)Part of your browser, under its maker's policyDelivers browser notificationsEach notification, encrypted so the push service can't read itOnly if you turn on notifications
The provider that hosts our inboxOur providerHolds the mail you send us, after Cloudflare forwards itYour message and email addressWhen you write to us

Each of our processors works only on our instructions, under a written data processing agreement. We'll name any error-reporting service here before we use one.

Beyond these, your data goes somewhere else only when you choose to send it, or when the law requires it. We may also share data with professional advisers or authorities when we need to establish or defend a legal claim. When you share a role, you share the role, never your status, notes, scores or targets unless you add them.

If Hunt moves to a company formed to run it, or is ever sold, your data moves with it only under this policy's promises. We'll tell you first, and you can leave with your data before it moves.

What we never do

International transfers

Hunt is run from the United States, and your data is processed there. Cloudflare's network also handles each request at the data center nearest you, which may be in your own country or another one.

When we pass personal data about people in the EU or the UK to our providers, we rely on:

How long we keep it

DataHow long
A record of your visit to usehunt.devHunt keeps no logs of its own. Cloudflare handles each request to serve and protect the site and keeps its own records of it under Cloudflare's privacy policy; we don't collect or keep request logs. Google Analytics: see below.
Invite codes typed on the siteNever sent or stored.
Google Analytics dataGoogle keeps user- and event-level data for 2 months, then deletes it. Aggregated counts (like visits per page) stay in our reports. The cookies last 2 years from your last visit, unless you delete them.
Mail you send to privacy@usehunt.dev or hello@usehunt.devUp to 12 months after the matter is closed.
Your account, search, resume, facts, notes and chatUntil you delete them or your account. Once deleted, they're gone from the live service within 30 days, and from backups within 30 days.
Working copies of chats and runs kept by the AI toolsDeleted with the chat or run they belong to, and with your account.
Old versions of facts you replaced or forgotKept as history until you erase your facts or delete your account. A special-category fact and its history are erased as soon as you withdraw consent.
Emails and reminders from a connected mailboxUntil you disconnect the mailbox or delete your account (or ask us to delete one). Calendar events stay until you delete them.
Roles you deletedA small record stays, so they don't come back, until you delete your account.
AI requests on Hunt AIAnthropic deletes them within 30 days by default. It may keep a request flagged under its Usage Policy for up to 2 years, and its safety scores for up to 7. It keeps data longer when the law requires. With your own key, your agreement with Anthropic applies.
Sign-in codes15 minutes, single use. Codes for connecting a device: 10 minutes.
InvitesA code is stored only as a hash (a one-way fingerprint) and shown once, when it's made. It expires after 30 days by default.
Push subscriptionsUntil you turn notifications off.
App logsUp to 30 days
Sessions, sign-in, invite and security records (such as per-IP rate limits)Up to 90 days, except invite records, which we keep until the beta ends
Records of privacy requests, and of consent you gave or withdrew24 months, to show we handled them.

The app isn't built yet, so the app rows are the rules it's designed to follow.

Your rights

Wherever you live, you can ask us to:

How: write to privacy@usehunt.dev. We may ask you to confirm it's you, for example by writing from the email on your account. We'll answer within one month.

In the app, export and account deletion will sit in Settings, two clicks away, with no survey. They aren't built yet. Until they are, email us and we'll do it for you. Leaving never holds your search hostage: you can take everything with you.

Your right to object

You can object at any time, for reasons relating to your situation, to any use of your data that relies on our legitimate interests (see Why we use it). We'll stop, unless we have compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims. To object, write to privacy@usehunt.dev. To object to analytics on the site, block or delete the Google Analytics cookies as described in Saying no.

Complaints

Tell us first if you can, at privacy@usehunt.dev. We'll acknowledge your complaint within 30 days, look into it, and tell you what we found and what we did.

You can also complain to a data protection authority. In the EU, that's the authority where you live, work, or where you think the problem happened. The EDPB lists them all: edpb.europa.eu. In the UK, it's the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113.

California

We give California residents this notice whether or not the California Consumer Privacy Act applies to Hunt yet.

Washington and Nevada

Hunt may hold health data you choose to give it, such as a disability in your vault or a health detail in a job email. In Washington and Nevada, the law calls this consumer health data.

We collect it only to provide what you ask for. We never sell it, and we never share it beyond the providers that run Hunt for us, or as the law requires. Before the app opens to anyone in Washington or Nevada, we'll publish a separate consumer health data privacy policy and link it from our home page.

Children

Hunt is for adults. It isn't for anyone under 18, and you confirm you're 18 or older when you create an account. If we learn an account belongs to someone under 18, we'll close it and delete its data. We don't knowingly collect personal data from anyone under 16. If we learn that we have, we'll delete it. If you think a child has given us data, write to privacy@usehunt.dev.

Security

On usehunt.dev today:

The app isn't built yet, so its protections are commitments rather than measures you can check. Signing in to Hunt will never use a password. Invite codes and device tokens will be stored only as hashes. An AI key or mailbox credential you give Hunt will be encrypted, used only for your work and never shown again. No tool, API or export will return a password or token. Each workspace will be walled off from every other. And Hunt's agents are built to treat text in emails and job pages as data, never as instructions.

No system is perfectly secure. If a breach puts your personal data at risk, we'll tell you and the authorities as the law requires. If you find a security problem, tell us at hello@usehunt.dev.

Changes to this policy

When we change this policy, we'll post the new version here and update the effective date at the top. For a change that matters, such as a new kind of data or a new use, we'll tell you in the app and on this page at least 30 days before it takes effect, and say why.

We'll never apply a looser practice, such as AI training or new sharing, to data we already hold without your clear, affirmative consent.

This is the first version of this policy. When we change it, we'll list the earlier versions here.

Contact

Hunt. Our legal name and postal address are yours on request at privacy@usehunt.dev.

Mail to both addresses passes through Cloudflare Email Routing to the inbox where we read it.