Cookie Policy
Short version: we use the handful of cookies needed to keep you signed in, plus one that remembers your answer to the cookie banner. No advertising cookies, no tracking pixels, no third-party analytics of any kind. There is one optional thing: a first-party usage log we run on our own servers, off by default, which only starts if you switch the analytics toggle on — and it is named and described in section 4. Here is the complete list, by real cookie and storage name.
1. What these things are
Cookies are small text files a site stores in your browser and reads back on later requests. Local storage and session storagedo a similar job with different rules: local storage persists until it is cleared, session storage is wiped when you close the tab. Cookie law (the UK’s PECR and the EU ePrivacy Directive) covers all three, so all three are listed below.
Strictly necessary items are the ones without which the service cannot do what you asked — keeping you signed in, protecting the sign-in form. Those do not require consent. Everything else does, and we ask first.
3. Local and session storage
| Key | Store | Purpose | Type | Duration |
|---|---|---|---|---|
clb_cookie_consent | localStorage | The same cookie preference, mirrored locally so the banner can decide whether to show itself before the page finishes loading — which is what stops it flashing at you on every navigation. | Essential (consent record) | Until you clear it or change your choice |
clb-theme | localStorage | Whether you asked for the light theme, the dark theme, or for the app to follow your device. A single word — light, dark or system. No identifier, and it is never sent to us or to anyone else. | Essential (functional) | Until you clear it or change your choice |
mindset-auto-<signal> | sessionStorage | A one-shot flag so a coaching insight is generated at most once per browsing session for a given trigger, instead of regenerating in a loop. Value is literally "1". | Essential (functional) | Until you close the tab |
review.readyToSend.opened | sessionStorage | Same job, on your Review screen: remembers which draft you just opened (a job posting, your mail app or LinkedIn), so that when you come back we can ask whether you actually sent it. Holds the item’s internal id, where you were sent and a timestamp — nothing about the recipient or the content. Cleared as soon as you answer. | Essential (functional) | Until you close the tab |
outreach.sendQueue.opened | sessionStorage | Remembers which outreach message you just opened in your mail app, so that when you come back we can ask whether you actually sent it. Holds the message’s internal id, the channel used and a timestamp — nothing about the recipient or the content. Cleared as soon as you answer. | Essential (functional) | Until you close the tab |
reconfirm-notice.dismissed:<campaign> | sessionStorage | Remembers that you tapped “Not now” on the note telling you your search targeting changed, so it does not follow you from screen to screen for the rest of the sitting. Holds your own search’s internal id and the value "1" — nothing else. | Essential (functional) | Until you close the tab |
clb_analytics_session | sessionStorage | A random identifier for our first-party usage log (section 4), so we can tell that a sequence of events belongs to one sitting without knowing anything else about the browser. Pure chance — not derived from your account, your device or anything at all. Only ever written after you opt in to analytics; with the toggle off this key does not exist. | Analytics (opt-in) | Until you close the tab |
4. Analytics — the one optional thing, and what we still do not use
In plain English: An earlier version of this page promised that if we ever added analytics, we would list it here by name before it ships. This is that listing.
What the analytics toggle now controls
The tool is our own: a first-party, self-hosted usage-event log, written by this app into this app’s database. No analytics company is involved — no script is loaded from anyone else’s server, and nothing is sent to one. When the toggle is on, the app records named events about how you use the product — for example page_view, approval_approved or marked_sent — each with a few coarse properties (the kind of item, a bucketed length — never the text), the path of the page you were on, and the random per-tab session id from the table above.
What it deliberately never records: your IP address, your user-agent, or free text of any kind — nothing you typed, no résumé or message content, no names or email addresses. Events are deleted automatically after 180 days. The whole thing is off by default: until you switch the analytics toggle on — in the cookie banner or in Settings — not a single event is recorded, and switching it off stops recording immediately.
What we still do not use
- No third-party advertising cookies. No ad networks, no retargeting pixels, no conversion tags, no social-media tracking pixels.
- No third-party analytics. No Google Analytics, no PostHog, no Mixpanel, no telemetry SaaS of any kind — the first-party log above is the whole story, and it never leaves our servers.
- No session replay, heatmaps or fingerprinting.
- No cross-site tracking. Every cookie above is first-party and
SameSite=Lax; none of them follows you to another site.
No third-party requests either
Cookies are not the only way a page can leak who you are — an embedded font, script or image loaded from someone else’s server discloses your IP address and browser to them without ever setting a cookie. There are none here. Our typeface is self-hosted and served from this domain at build time, so loading a page in Career Love Builder does not contact Google or anyone else.
5. Your choice, and how to change it
We ask before storing anything that is not strictly necessary. Nothing optional runs until you have actively said yes — no pre-ticked boxes, and closing or ignoring the banner counts as “no”, not as agreement.
- In the app: update your cookie preferences any time in Settings → Privacy & your data. Withdrawing is as easy as giving — one toggle, effective immediately.
- In your browser: every major browser lets you view, block and delete cookies and clear local storage from its privacy settings. Blocking the essential cookies above will break sign-in — the service genuinely cannot keep you logged in without them.
- Clearing your data also clears your recorded cookie choice, so the banner will ask again next time. That is the system working, not a bug.
We keep a record of the consent you gave — what you agreed to, which version of the policy, and when — because GDPR art.7 requires us to be able to demonstrate it. That record is described in the Privacy Policy.
6. Changes and contact
If we add or remove a cookie, we will update this page and its last-updated date, and where the new item is non-essential we will ask for your consent before it runs. Questions about anything here go to [email protected]. For the wider picture — what data we hold and why — see the Privacy Policy, and for the rules of the service itself see the Terms of Service.