Privacy policy
What we hold, why we hold it, and how to take it back.
Futureful is free for job seekers and we do not make money from your information. This document says exactly what we collect, who else touches it, how long it stays, and which button removes it. Every clause was written from the code that enforces it.
- Effective
- Questions
- info@futureful.app
- Also read
- Terms of ServiceYour protections
We do not sell you
No advertising trackers, no ad profile, no data broker. Nothing about you is sold, rented or shared for advertising, and employers pay for the platform so that you never do.
You raise your hand first
An employer's candidate list is built from the people who applied to or saved one of their jobs. Browse as long as you like: until you act on a role, you are not on anybody's list.
You can take it all back
See it, correct it, download the whole file, or delete the account outright. Your uploaded files are removed before the account is, and never after.
What this covers
This policy covers futureful.app and the Futureful product: the job board, the career tools, your account, and the employer and partner consoles that run on the same platform. Where it says “we” it means Futureful, the operator of that service. Where it says “you” it means the person using it.
If you want the same information without the legal register, Your protections says it in plain words and is written to the same facts. If the two ever disagree, that is a bug in one of them, and we would like to know: write to info@futureful.app.
What we collect
Only what a real job match needs, and you can see the whole of it at any time by downloading it.
- Your account. An email address, and a password held by our authentication provider in hashed form. We never see or store your password ourselves.
- Who you are. Your name, and your date of birth if you give us one. The general area you are looking in, meaning a city and state, never a street address.
- What you are looking for. Your answers in the intake and the career tools: the kinds of work you are drawn to, your goals, your education level, certifications, whether you have served in the military, how far you are willing to travel, and similar.
- Your résumé, if you add one. The file itself and the text we read out of it. You can upload one, paste one, write one here, or skip it entirely.
- What you do here. The jobs you save, the jobs you apply to, the matches we showed you and the reasons we showed them, the plan steps and reminders you create.
- Your settings. Your language, and your accessibility and motion preferences.
- Ordinary technical records. The requests your browser makes to our servers, kept by our hosting and database providers so the service can run and so we can investigate abuse and faults.
We never ask you for a Social Security number. We do not track your precise location. We do not put advertising trackers on you. There are none on this page or on any other page of this product.
Where it comes from
Almost all of it comes from you, directly, because you typed it. Three things do not, and it is worth being precise about them:
- Job postings come from public job sources and employer job feeds. Those are postings, not people, and they are not information about you.
- Careers reference data comes from public datasets published by the United States government, including O*NET and public wage data. Again, not information about you.
- A parent or guardian’s name and email, when someone under 18 gives it to us so consent can be recorded.
We do not buy personal information about job seekers from data brokers, and we do not build a profile of you from anywhere other than what you told us and what you did here.
Why we use it
For one purpose, and everything below is downstream of it: to match you with real, paid work.
- To rank real, currently open jobs against what you told us, and to show you the reasons behind each match.
- To run your account, remember your saved jobs and applications, and send you the messages you asked for.
- To let an employer see you after you have raised your hand, on the terms in clause 09.
- To keep the platform safe, detect abuse, and fix faults.
- To understand, in aggregate, which parts of the product help people get hired.
We do not use your information to build an advertising profile, we do not sell or rent it, and we do not charge job seekers anything, ever. Employers pay for the platform, which is the whole reason you do not have to.
Age: Futureful is for 13 and up
You must be at least 13 to have a Futureful account. This is not a notice sitting on top of an open door. Someone under 13 cannot complete signup: the flow stops and hands them to a parent, and the server refuses the account creation independently of anything the browser says.
When we cannot establish an age, we treat the person as a minor rather than as an adult. Unknown is never resolved in the direction that collects more.
If you believe a child under 13 has given us information anyway, write to info@futureful.app and we will delete it and close the account.
If you are under 18
You get the same tools as everyone else. What changes is what we are willing to hold about you and who can reach you, and those changes are enforced by the code and the database, not by a setting.
- We keep less. Phone number, city, state and postal code are written as empty, and your name is stored as your first name alone. That happens on our servers, on our own reading of your age, so it cannot be undone by anything sent from a browser.
- You are not in any recruiting list. A person we can prove is a minor cannot be present in our outbound contact tables at all. That is enforced by the database itself, so it holds even for internal tools.
- No employer can message you. Introductions go through consent, described in clause 09.
- We do not send text messages to anyone, and the age check on that system is built so that it can only ever refuse more people, never fewer. See clause 11.
Parents and guardians
A person aged 13 to 17 who signs up is asked for a parent or guardian’s name and email, and we record that consent, including exactly what was agreed to and when.
A parent or guardian can ask us what we hold about their child, ask us to correct it, or ask us to delete it and close the account. Write from any address and we will verify the connection to the account before we act, because doing otherwise would let a stranger delete a child’s account by asking.
Schools, districts and workforce programs
Futureful is used by schools, districts and workforce programs. When a school or program shares student records with us, we act on the school’s instructions: we use those records only for the purpose the school agreed to, we do not use them to build our own marketing, and we do not pass them on. That is the posture FERPA requires of a school service provider, and it is the one we hold.
A school or district can ask us for what we hold about its students, ask us to correct it, or ask us to return or delete it at the end of the relationship.
Yes, it personalizes, and that is the service. A district usually asks this first, so here is the plain answer. Futureful shows one student different work than it shows another, because that is what a career tool is for. The laws written for student data say so directly: California’s SOPIPA (Business & Professions Code 22584(i)) expressly preserves use of student information “for adaptive learning or customized pupil learning purposes,” and the National Data Privacy Agreement many districts sign carves out, at section 4.7, adaptive learning and generating personalized learning recommendations.
What those carve-outs do not permit, and what we do not do: advertising, building a profile for a purpose the school did not agree to, selling anything, or handing student records to anyone else.
A student account is a job-seeking account, not a graded one. Nothing a student does here is reported to a teacher as performance, and there is no score about a person anywhere in this product.
What an employer can see, and when
You raise your hand first. An employer’s candidate list is built from the people who applied to one of their jobs, saved one of their jobs, or connected with them. It is built that way in the query itself, not by a filter on a screen. Until you act on one of their roles you are not on their list at all, and the screen they use tells them so in plain words rather than showing them you.
When you have raised your hand, an employer can see what you chose to put in front of them: your name, the work you are looking for, your general area, your résumé if you added one, and the application itself. For anyone under 18, the fields an employer can see are restricted at the query level and no employer messaging path exists.
Employers who use Futureful agree to use what they see for hiring and for nothing else. That obligation is in the terms.
AI, and what it does with your words
We use AI models as a language layer: to read a résumé you upload, to write the explanation next to a match, to answer a question you ask a tool. Every number in this product, including every ranking, is computed by our own code from your own answers and real job postings. An AI model does not invent a score, a wage, or a fact about you.
- Where your words go. To Anthropic directly, or to OpenRouter with the request pinned so it can only be served by providers that neither retain nor train on it. That pin is in the code on every call, and the reason written next to it is that these prompts can carry a minor’s information.
- Résumés. If you upload a photo or a scan, the whole page image is sent to a model that can read it, under the same terms.
- The spoken practice interview. Your actual audio for the current turn is sent to the model so it can hear you. We do not store your recorded audio. The only audio we keep is the speech we generate ourselves.
- No training. We do not sell your information to anyone to train a model, and we do not train a model of our own on your personal information.
Nothing here makes a legally significant decision about you on its own. We do not decide whether you are hired. An employer does.
We do not send text messages
Present tense, and it is a fact about the running system rather than a promise about the future: there is no text-message sending capability in this product. Nothing you do here causes an SMS.
If that ever changes it will be opt-in, it will record exactly what you agreed to, and it will never apply to anyone under 18. This clause changes in the same release, or the release does not ship.
Who else handles your information
These are the companies that process personal information on our behalf, so that the product can run. They act on our instructions and for no purpose of their own. This is the complete list as of the effective date above.
- What it does
- Database, sign-in, and file storage
- What it sees
- Your account, your profile and answers, your uploaded files
- What it does
- Hosting and content delivery
- What it sees
- Ordinary web request records
- What it does
- AI models for reading and writing language
- What it sees
- The text or document image sent with a request
- What it does
- Routes some AI requests, pinned to providers that do not retain or train on them
- What it sees
- The text or audio sent with a request
- What it does
- Turns written text into spoken audio, for the practice interview
- What it sees
- The text we speak aloud, which can be written for you
- What it does
- Sends platform email
- What it sees
- Your email address and the content of that message
- What it does
- Alternate email sender
- What it sees
- Your email address and the content of that message
- What it does
- Checks that an email address is deliverable, on the public sign-up form
- What it sees
- The email address only
Supabase
Netlify
Anthropic
OpenRouter
ElevenLabs
Google Workspace
Resend
MillionVerifier
Connections you make yourself are a separate thing and are not in that table. If you connect a calendar, Google Calendar or Microsoft, we create and read the interview events we agreed to put there, in your own account, at your instruction. You can disconnect it at any time and we stop.
Three notes so this table is not read for more than it says. HubSpot appears in this product and holds employer contacts only; no job seeker’s account information reaches it. Stripe handles employer payment and never sees a job seeker, who is never charged for anything. And our type is self-hosted, so loading a page here does not make a request to a font network or to any other third party.
What we do not do
Stated as flatly as we can, because these are the four things people actually worry about:
- We do not sell or rent your personal information. Not to employers, not to schools, not to anyone.
- We do not share it for cross-context behavioral advertising. There is no ad network in this product.
- We do not profile you for advertising, and we do not run ads here at all.
- We do not use your personal information to train AI models, ours or anyone else’s.
How long we keep it
While your account is open, we keep what is described in clause 02, because that is what the product is made of. When you delete your account, we delete it, and clause 16 describes exactly how that runs and the one case where it stops and asks a person to finish it by hand.
Three things outlive an account, and we would rather name them than let you find them:
- Records of consent. Where the law expects us to be able to show that consent was given, we keep the record of that consent itself. It is deliberately not editable, including by us.
- Records of messages we sent you. A log that a message was sent, so we can honor an unsubscribe and answer a complaint.
- Counts, with a floor. Aggregate totals, for example how many people used a tool in a month. Every published figure is floored at 10 distinct people: a value derived from fewer than ten is suppressed rather than shown. That is the same floor the United States Centers for Medicare & Medicaid Services uses in its Cell Size Suppression Policy. Anyone we cannot prove is an adult is excluded from that corpus entirely, so a minor is never one of the ten.
- How long we keep it
- For as long as your account exists
- What ends it
- You delete the account
- How long we keep it
- For as long as your account exists
- What ends it
- You remove the file, or delete the account. Files are erased before the account is
- How long we keep it
- For as long as your account exists
- What ends it
- You delete the account
- How long we keep it
- For as long as your account exists
- What ends it
- You delete the account
- How long we keep it
- Kept after the account, on purpose
- What ends it
- Nothing. They are the proof consent was given, and are not editable, including by us
- How long we keep it
- Kept after the account, on purpose
- What ends it
- Nothing. It is how we honor an unsubscribe and answer a complaint
- How long we keep it
- Kept indefinitely
- What ends it
- Not applicable. A figure derived from fewer than ten people is suppressed rather than published, and anyone we cannot prove is an adult is not in that corpus at all
- How long we keep it
- Our hosting and database providers' own schedules
- What ends it
- Their retention windows, not a Futureful setting
- How long we keep it
- The provider's own rolling schedule
- What ends it
- The backup ages out, which is how every hosted database works
Your account, profile and answers
Your résumé and uploaded files
Applications, saved jobs and matches
Your language and display settings
Records of consent
A log that we sent you a message
Aggregate counts, floored at 10 distinct people
Ordinary web request records
Database backups
The honest shape of this policy: your information is kept for the life of your account, not for a fixed number of days. No automated job deletes account data on a timer today. clause 16 is the control that ends it, and it works the moment you use it. If your school, district or employer needs fixed maximum periods per field, or a contractual return-or-destroy window on termination, ask us: that is an agreement we would sign, not a setting we already run, and we would rather say so than let you assume it.
Your rights, and the buttons that actually do them
These are not requests you file. Three of the four are controls in the product:
- See it. Your profile and everything attached to it is visible in your account.
- Fix it. Change any answer, any time. The product is built to be re-answered.
- Download it. Settings gives you a single file containing your account, profile, applications, saved jobs, matches and their reasons, résumés, reminders and plans.
- Delete it. Settings, then “Delete my account”. You are asked to type DELETE so it cannot happen by accident. Your uploaded files are removed first, and if any of them cannot be removed the deletion stops rather than leaving your résumé behind with no account to link it to.
One honest limit. If you have an active referral or placement running through us, the automatic delete stops and asks you to email a person, because those are records of something that happened between you and an employer. Write to us and we will close the account and remove your data by hand.
You never have to tell us why, and using any of these will never make the product worse for you.
If you are in California
The CCPA and CPRA give you the right to know what we collect and why, to get a copy, to correct it, to delete it, and to opt out of sale or sharing. The first four are the controls in clause 16, available to everyone regardless of where they live.
The fifth needs no button here: we do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We also do not use sensitive personal information to infer characteristics about you.
We will never charge you a different price or give you a worse service for exercising any of these rights. The product is free to job seekers, so there is no price to change.
How we protect it
Your information is encrypted in transit and at rest. Access is scoped at the database level so one account cannot read another’s records. Only a small number of Futureful staff can open an individual’s details, so the platform can be run and supported.
Our demo environment runs on made-up people, kept separate from real accounts, so that showing the product to somebody never means showing them you.
No service can promise it will never be breached, and we are not going to be the ones who do. If a breach affects your information we will tell you, and we will tell you what we know rather than what sounds best.
Where your information is handled
Futureful is operated from the United States and your information is processed in the United States, including by the providers in clause 12. If you use Futureful from outside the United States, you are sending your information here. We do not currently offer a European or United Kingdom data-transfer arrangement, and we would rather say so than claim a posture we have not built.
Changes to this policy
If we change it, the effective date at the top of this page changes with it. If a change materially reduces the protections described here, we will tell account holders directly rather than quietly reposting the page. This document is written from the code, so a change in what the product does and a change to this page are meant to be the same commit.
Reaching a person
Write to info@futureful.app for anything in this document: a question, a correction, a copy of your data, a deletion, a parent or guardian asking about a child’s account, or a school asking about its students. A real person reads it.
You can also reach us through support.
FUTUREFUL · PRIVACY POLICY · REV A