Ntern

Privacy Policy

Version 2026-08-26 · Effective August 26, 2026

Ntern is a browse-first early-career job radar operated by JD Krasnick. This policy explains what the mobile app and public web service collect, why, and how people can control their information.

Who can use Ntern

Ntern is intended for people age 18 and older. Account creation requires an age attestation. We do not intentionally collect personal information from anyone under 18.

Information we collect

Account and consent information

If you create an account, we collect your email address, a one-way password hash and salt, verification and session records, and the versions and time of your age and policy acknowledgments. We do not store your password in readable form.

Optional profile and application information

If you choose these features, we collect the name, email, phone number, location, education, work-authorization information, links, reusable answers, application statuses and notes, and résumé or other documents you provide. When Resume Tuner is enabled, it also keeps your Master Bank entries, saved résumé bases, pasted job descriptions, review decisions, and private generated PDF, TeX, and preview files. It may use account-isolated derived embeddings to rank your saved bases; the database remains the source of truth and the derived cache is removed with your account. Some reusable answers may include sensitive information that you choose to save. Do not upload information you do not want stored.

Optional Gmail application detection

If you connect one Gmail account, Google gives Ntern an encrypted OAuth refresh credential and read-only access to Gmail. We request only the restricted gmail.readonly scope. When you open an official application through the signed-in app, Ntern records a short-lived check for that catalog role and checks Gmail after 5 minutes, 10 minutes, 30 minutes, and 24 hours. For Inbox messages received after that Apply click, it processes the sender, subject, received date, labels, and a limited portion of message text needed to confirm the employer and role. Message text is processed transiently and is not stored or logged. Attachments are not processed. Gmail message identifiers are stored only as keyed, non-reversible deduplication values.

Ntern uses deterministic rules—not AI—to compare confirmation evidence only with roles whose official application forms you recently opened. A unique match may create or advance that role to Applied; uncertain matches wait for your review. Gmail data is not used for advertising, generalized profiling, model training, or any purpose unrelated to this user-facing feature. Ntern’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Device alerts and app settings

The app creates a random installation identifier. When you enable alerts, we store that identifier with your Expo push token, platform, alert filters, notification wording, quiet hours, app-opening time, and delivery receipts. Installation data is deliberately separate from your account, so signing out or deleting an account does not turn off alerts or erase settings for that device.

Local device information

The app keeps its installation credential, sign-in session, public catalog cache, hidden-role choices, and notification scheduling identifiers in app storage on your device. Ntern does not request your contacts, precise device location, photos, microphone, or advertising identifier.

Security, operations, and support

We process request metadata and a cryptographic rate-limit key derived from an IP address or account email to prevent abuse. Cloudflare may record short-lived request, error, and performance logs. If you contact support, we receive the information you include in your email or public GitHub issue. Never put passwords, identity documents, or résumé files in a public issue.

Employer workspace information

If you represent an employer, we store the organization name and domain, your account’s organization role, invitation email addresses, verification status and hashed challenge tokens, reviewed source connections, structured role submissions, short private review notes, metadata proposals, trust reports, publishing decisions, and immutable audit events. Public role attribution names the employer, not its individual members. Ntern does not accept or store a full job description through direct submission.

How we use information

We use information only to operate requested app features, authenticate accounts, sync saved applications and profiles, detect application confirmations when Gmail is connected, deliver alerts, support application-form assistance that the user controls, answer support and rights requests, prevent abuse, and keep the service reliable. We do not sell personal information, show targeted advertising, or use personal information to track people across other companies’ apps or websites.

Service providers and external sites

Opening an employer’s official application form takes you to a third-party site with its own privacy practices. Ntern does not submit an application for you unless a separately authorized partner integration is clearly identified and you remain in control of final submission.

Retention and deletion

The detailed Data Retention Policy is part of this Privacy Policy. In summary, account data remains until deletion, abandoned unverified accounts are removed after seven days, inactive anonymous installations after twelve months, delivery records after ninety days, application-assistance and pending Gmail-detection evidence after thirty days, and active employer records until closure plus a one-year operational retention period.

Disconnect Gmail in App & account to revoke the Google grant when possible and delete the local OAuth credential, sync state, short-lived application checks, deduplication values, and pending detections immediately. Existing application status and timestamp remain, but Gmail provenance is removed. Account deletion performs the same Gmail cleanup before removing the account, profile, synced applications, assistance records, documents, Resume Tuner records, and active sign-in sessions. Local Gmail data is deleted even if Google’s revocation endpoint is temporarily unavailable. Device alerts and app settings remain because they are not linked to the account. Cloudflare’s point-in-time recovery history may retain database changes for up to 30 days before aging out.

Your choices and requests

You may browse without an account, decline notification permission, leave Gmail disconnected, disconnect Gmail at any time, disable alerts, omit optional profile fields, delete individual documents, or delete your account. To request access, correction, a portable copy, or help with deletion, email [email protected]. We may request limited information to verify the request and target completion within 30 days.

Security and international use

We use access controls, encrypted network connections, restricted document storage, independently keyed encryption for Gmail OAuth credentials, keyed message-identifier deduplication, and bounded credentials. No system is perfectly secure. The primary service storage region is in North America, and the providers above may process information in other locations under their own data-protection commitments.

Changes

We will post revisions here with a new version and effective date. When a material change affects account holders’ rights or how their personal information is used, we will also provide reasonable notice in the app or by email when practical.

Contact

Ntern is operated by JD Krasnick in Pennsylvania, United States. For private privacy questions, email [email protected]. For non-sensitive public bugs, use the GitHub issue tracker.