Skip to content
← Way In

Privacy Policy

Last updated

Way In collects what it needs to match you with opportunities and to pass your applications to the people you send them to. There are no ads, no analytics and no trackers, and your information is never sold or shared for advertising. When you apply through Way In, the employer receives what you send and their inbox orders it automatically; a person decides, and you can ask for a review without the ordering. You can see, copy, correct or delete what we hold, from your account or by writing to sethkvc@gmail.com.

01Who we are and what this covers

Way In (“Way In”, “we”, “us”) is an independent service built by a student at UC Santa Cruz. It is not affiliated with, endorsed by, or operated by the University of California, Santa Cruz, or by any employer or organization whose listings appear on it.

This policy covers the Way In website, its iPhone app, and the emails and services that come with them (together, “Way In”). It explains what we collect, why, who can see it, how long we keep it, and the rights you have over it. It is also our notice at collection under California law. It does not cover an employer’s own website or application form, a site we link to, or GitHub or Apple when you sign in with them; their own policies apply there.

Where this policy says “personal information”, it means information that identifies, relates to or could reasonably be linked to you.

02What we collect

Only what you give us, what you ask us to fetch for you, and the minimum needed to keep the service running.

Account
Your email address, display name, a password (stored only as a one-way hash by our authentication provider; we never see it), and account type (student, business, or faculty), with the answers you give when you sign up: school, year and major, or organization, or department and lab. The same account works on the website and in the iPhone app. Required to have an account.
Your agreement
Which version of the Terms of Service and this Privacy Policy you agreed to, where (website or app), and when, by our server's clock. An employer post records the version of the Terms its sender agreed to. We keep this to be able to show that the agreement was made.
Sign in with Apple
Where the iPhone app offers Sign in with Apple and you use it, Apple tells us an email address (your own, or a private relay address if you choose to hide yours) and, the first time only, your name. We use them like any account's email and name. We never see your Apple ID password.
GitHub, if you link it
If you connect GitHub to show your work on your record, GitHub tells us your GitHub account's id, username, display name, profile picture and email address, which our authentication provider keeps with your account so the link persists. The repositories you choose to show are remembered in your browser. To draw a repository and its activity, your browser asks GitHub's public API for that public information directly. You can unlink GitHub at any time from your record.
Profile
Anything you choose to add: school, year, major and minor, graduation year, GPA, bio, headline, location, links, skills, past experience, what you're open to, availability, hours, work preferences, and work authorization or sponsorship needs. All of it is optional. A blank profile still works; it just matches less well.
Résumé
If you upload one, we store the PDF in a private bucket. Your browser also reads its text to suggest skills you can add with a tap; that text is not sent to us or stored. In the iPhone app a copy is also kept on your phone, in the app's own folder, so an application can attach it in one tap; signing out or deleting your account removes that copy.
Applications
When you apply to a role an employer posted on Way In and chose to take applications for: your name, email, phone if you give it, links, studies, graduation year, work authorization, availability, hours, the note you write, and a copy of your résumé as it was when you sent it, kept so the employer reads exactly what you sent. Also the status the employer gives it (submitted, reviewing, shortlisted, rejected, hired).
Requests to join a project
When you ask to join a student project: the role you want, your note, your links, and the email address you want the poster to answer at, with the poster's answer.
What you post
Listings, projects and requests for help, an organization's logo, and any images you attach to them.
What you decide
Which opportunities you save and which you pass on. On the website this is kept in your browser, not on our servers. In the iPhone app your saved roles are kept on the phone and, if you sign in, also with your account so they follow you to a new phone. Roles you pass on stay on the phone.
Your record
Roles and projects you say you completed or are working on, the people you name as having worked with you, the note a collaborator writes when they confirm your work, and confirmations or disputes that others attach to your entries. A confirmation names the person who gave it. If you tell the iPhone app that you applied to a role, that is noted on the phone and, signed in, added to your account.
Messages
What you write to another account. In the iPhone app, a message is stored on our servers with its conversation so that you and the other person, and nobody else, can read it. On the website, messages are kept in your browser and are not yet delivered.
Profile picture
If you set one on the website, it is kept in your browser, not on our servers.
Sponsored listings
If a sponsored listing is shown to you, we record that you saw it, opened it, or applied to it, with your fit verdict for it at that moment. The employer is shown only three counts of distinct viewers, never who you are or what any one person did.
Reports and blocks
If you report a listing, post or conversation, your email app sends us a message naming it and whatever you add; we use it only to review the report. People and conversations you block in the iPhone app are remembered on the phone, not on our servers.
Messages to us
If you email us, your address and what you write, kept to answer you and to keep a record of requests we have handled.
Session
An authentication cookie that keeps you signed in on the website, and in the iPhone app a sign-in token kept in the iPhone's Keychain. Both are issued by Supabase, our authentication provider, are required for signing in to work, and are not used to track you.
Technical data
Our hosting provider keeps standard request logs (IP address, browser, page requested, time) for a short period, for security and debugging. Our servers also use your IP address, in memory and briefly, to limit how often a form can be sent, which stops spam. We do not build profiles from either.

We do not ask for, and ask you not to give us, your Social Security number, financial account details, government ID, health information, or your race, ethnicity, religion, sexual orientation, gender identity, disability, veteran status or other characteristics protected by anti-discrimination law. Way In does not need them to work.

03Where it comes from

From you
Almost everything: what you enter, upload, post, send or decide.
From services you connect
Apple and GitHub, as described above, only when you choose to sign in with or link them.
From other people
A collaborator who confirms or disputes an entry on your record, a poster who names you on a project, an employer who changes the status of your application.
Automatically
Session tokens, request logs and the sponsored-listing events described above.

The listings on Way In come from employers and from public job boards and government sources (see Where your data lives). They are information about jobs, not about you, and nothing about you is sent to those sources.

04How we use it

To run the service
Create and secure your account, show you listings ranked against your profile, let you save, post, message, apply and request to join projects, and deliver what you send to the person you send it to.
To show your fit
Compare a listing with your profile, as described in the next section.
To keep Way In safe and lawful
Review posts before they go live, review reports, prevent spam, fraud and abuse, enforce our Terms, keep records of agreements and requests, and comply with the law.
To communicate with you
Account email (confirming your address, resetting a password), answers to what you write to us, and notice of changes to these documents. There are no marketing emails today; if we ever send any, they will be off until you turn them on and each will carry an unsubscribe link.
To fix and improve Way In
Debug problems from logs and from what you report. We do not run analytics on you to do it.

We use what you give us only for these purposes, or for a purpose compatible with the one it was given for. If we ever want to use personal information for a materially different purpose, we will ask you first.

05Fit, and how applications are ordered

Way In uses automated processing in two places, and is plain about both.

Your fit on a listing
The fit you see on a listing (a verdict such as “Good fit”, with its reasons) compares your profile with the posting: your major and studies, your year and graduation date against what the posting requires, the skills you listed, the work on your record, your hours and availability, the kind of work you are open to, and where the role is. On the website it is worked out in your browser; in the iPhone app our server works it out and returns it to you. It is shown to you and is not shown to employers, except as a count in a sponsored listing's receipt.
How an employer's inbox is ordered
When you apply through Way In, the employer's inbox can list applications in a “Best match” order. It reads your application the same way the fit reads a profile (your major, graduation year, hours, start date, work authorization, and the skills your note names, against what the posting asks), and then how fully your note and links speak to the role, and whether you attached a résumé. It does not read your résumé's text, and it does not use your name, age, sex, race, ethnicity, religion, disability or any other protected characteristic, which Way In does not collect. Each application is shown with the reasons for its place, in the words of the posting.

The order is a convenience for the reader, not a decision. Nothing on Way In rejects, hires or screens out anyone automatically: every application reaches the employer’s inbox, an employer can switch it to newest first, and a person at the employer reads and decides. Under our Terms, an employer must not use the order as the only basis for a decision.

You can ask us to explain how your application was ordered, or ask that the employer review it without the ordering. Write to sethkvc@gmail.com with the role you applied to; we will tell the employer, and answer you within the time set out in Your rights. If you need an accommodation in applying, tell the employer, or tell us and we will pass it on. Employers hiring in places with specific rules on automated tools in hiring, such as New York City, Illinois, Colorado and California, carry their own notice and review duties under those rules; our Terms require them to meet them.

06What we don't do

This is meant to be verifiable rather than reassuring. Way In runs no advertising, no analytics and no third-party tracking scripts of any kind: no Google Analytics, no pixels, no session recorders, no heatmaps, no A/B testing services.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising, under any state’s definition. We have never done so and the product has no mechanism that would allow it. We do not give personal information to data brokers.

We do not use your résumé, profile, applications or messages to train machine-learning or AI models, and we do not let anyone else do so with them.

Way In is not a consumer reporting agency, and nothing on Way In is a consumer report. We do not run background checks.

07Who can see what

Your résumé is private until you apply. It lives in a private bucket and no other account can open it, with one exception you choose: when you apply through Way In, the employer for that role can open the copy sent with that application, through a short-lived link, and nobody else can.

Public to anyone
Listings and projects that you post, including any logo or image attached to them. Listing pages can appear in search engines. Assume anything you post is public.
Visible to signed-in accounts
Your profile basics (name, school, year, major, and for employers the organization) and your record: what you say you completed and who confirmed it. Signed-out visitors see none of it.
Visible to employers, only if you switch it on
Your profile, but only if you turn on “Let employers find you”. It is off until you switch it on. With it on, an employer account can read your profile, never your résumé.
Sent to an employer when you apply
Everything in your application, résumé copy included, goes to the organization that posted the role. They receive it as their own and handle it under their own privacy policy; they may keep it under their own record-keeping duties even after you leave Way In.
Sent to a project's poster when you ask to join
Your name, the role you want, your note, your links and the email you give.
Visible to the other person only
Messages: readable by you and the account you're talking to.
Visible only to you
Your saved and passed decisions, the roles you mark as applied, the fit each listing shows you, and your résumé outside an application. Posters are not told that you passed on their listing.

The person who runs Way In can access the data it holds where that is needed to run it: to review posts and reports, answer your requests, fix problems, and meet legal obligations. That access is used for nothing else.

08Who else receives it

Beyond the people you choose to send things to, personal information goes only to:

Service providers
Companies that run parts of Way In for us and may use the information only to do so, under written terms: Supabase (database, sign-in, file storage and account emails) and Vercel (hosting). When you sign in with Apple or link GitHub, Apple and GitHub take part in signing you in under their own policies.
When the law requires it
To comply with a valid subpoena, court order or other legal process, after checking that it is valid and, where the law allows, telling you first.
To protect people
Where we believe in good faith that it is necessary to prevent fraud, abuse or harm to someone, or to protect the rights and safety of our users or Way In.
If Way In changes hands
If Way In is transferred to someone else, your information would go with it under this policy, and we would tell you before it did, so you could delete your account first.
With your consent
In any other case, only if you ask us to or agree to it.

09Where your data lives

Our database, sign-in and file storage are run by Supabase and our website is hosted by Vercel, on servers in the United States.

More of your activity than you might expect is kept in your own browser’s local storage rather than on a server: which listings you saved or passed, messages you have written on the website, your profile picture, your record entries on the website, roles or projects you draft, the GitHub repositories you show, and the public GitHub information drawn on them. It stays on that device, we cannot see it or back it up, and clearing your browser data clears it. As each of these moves to our servers, this policy will say so first. Your record already lives with your account in the iPhone app.

Two kinds of request leave your browser or the app for someone else, and carry nothing about your account. Company logos are loaded from Google’s public favicon service, which sees your IP address and which company’s icon was asked for. Repositories you show from GitHub are loaded from GitHub’s public API, which sees your IP address and which public repository was asked for.

Way In mirrors publicly posted listings from public job boards and government sources: UC Santa Cruz Academic Recruit; the public boards of employers who publish through Greenhouse, Ashby, Lever, SmartRecruiters and Workday; USAJobs; EdJoin; and the US Department of Labor’s CareerOneStop. When a listing opens or closes, its public address is sent to search engines (Google and IndexNow) so they show it correctly. None of this involves information about you. When you apply to a mirrored listing, you leave Way In for the employer’s own site, and their privacy policy applies from there.

10Cookies, local storage and browser signals

Way In sets only the cookies needed to keep you signed in. It uses your browser’s local storage for the things listed above, which are features you use rather than tracking. There are no advertising, analytics or third-party cookies, so there is no cookie banner: there is nothing optional to agree to.

Do Not Track and Global Privacy Control. We honor both. Because Way In does not track you across sites, sell personal information or share it for advertising, either signal is already in effect for everyone. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing, which is how we already operate.

11The iPhone app

The app is a way into the same Way In, and everything above applies to it. A few things are particular to the phone:

No account needed
The board, Discover, saving and applying all work signed out. Signing in adds your fit on every role, your profile and record, posting, messages, and your saved roles on a new phone.
Kept on the phone
A copy of the board, so the app opens at once and works without a connection; the roles you save, pass on or mark as applied; people and conversations you block; your appearance setting; and, signed in, a copy of your résumé. Your sign-in token is kept in the iPhone's Keychain. Deleting the app deletes all of it except the Keychain entry, which signing out removes.
Your fit
Signed in, the app asks our website for your fit on each listing, sending only your sign-in token. The fit is worked out from your profile on our servers, returned to you, and shown to nobody else.
Applying
For a mirrored listing, Apply opens the employer's own application in the app's built-in browser, which is Safari's. Way In cannot see into it: what you type there goes to the employer, under their privacy policy. When you close it, the app asks whether you applied, and remembers only your answer.
No tracking
The app contains no advertising, analytics or crash-reporting code, asks for no tracking permission, reads no device identifiers, and does not use your location, contacts, photos, camera or microphone. It sends nothing in the background and sends no notifications.

12How long we keep it

We keep personal information only as long as the purpose it was collected for needs it, and then delete it. In practice:

Account, profile, résumé, record, posts, messages
While your account exists. You can delete any of it yourself sooner.
Applications and requests you send
While your account exists, or until the listing or project is deleted. The copy the employer or poster received is theirs to keep under their own policy.
Records of your agreement
While your account exists. They are deleted with it.
Sponsored-listing events
While your account and the listing both exist.
Employer posts sent for review
While the listing they became is on Way In, and afterwards only as long as we need a record of who posted it, to answer questions or complaints about it. Posts we declined are deleted once we have answered them.
Emails with us and privacy requests
As long as we need to answer you, and a record of privacy requests and how we handled them for 24 months, as California's regulations require.
Request logs and backups
Rolled off on our providers' schedules, typically within days and in any case within 30 days.

Deleting your account. From Settings on the website, or in the iPhone app from Settings (the button at the top of Profile). It deletes your profile, your résumé and every copy of it sent with an application, any images you uploaded, your record and the confirmations you gave, your applications and requests, your messages and posts, your agreement records, and everything else keyed to the account, immediately. If you signed in with Apple, it also ends Way In’s access to your Apple ID. Copies already delivered to an employer or another person stay with them, backups roll off as above, and anything kept in your browser or on your phone is yours to clear.

13Your rights, and how to use them

Wherever you live, you can ask us to do any of the following, and we will not treat you differently for asking:

Know and access
Tell you what personal information we hold about you, where it came from, why we use it, and who receives it, and give you a copy.
Portability
Give you that copy in a structured, machine-readable format.
Correct
Fix anything inaccurate. Most of it you can edit yourself in your profile.
Delete
Delete your account and what is keyed to it, or a part of it. Most of it you can delete yourself.
Withdraw consent
Unlink GitHub, switch off “Let employers find you”, or withdraw anything else you agreed to, at any time.
Review of automated ordering
Explain how an application was ordered, or have it reviewed without the ordering (see Fit, and how applications are ordered).
Opt out and limit
Of sale, sharing, targeted advertising and profiling with legal or similarly significant effects. We do none of these, so this is already in effect.

How. Email sethkvc@gmail.com from the address on your account, and say what you would like. We may need to confirm that you control that address before acting, so that nobody else can see or delete your data; we will not ask for more than we need to be sure. An authorized agent can make a request for you with your signed permission, and we may ask you to confirm it directly.

When. We confirm receipt within 10 business days and answer within 45 days. If we need longer, up to a further 45 days, we will tell you why within the first 45. Requests are free; if a request is manifestly unfounded or excessive, we will tell you why before declining or charging for it.

Appeals. If we decline a request in whole or in part, you can appeal by replying to our answer with “Appeal” in the subject. Someone who did not make the original decision will review it and answer within 45 days, with the reasons. If you are not satisfied, you can contact your state’s attorney general (in California, the California Privacy Protection Agency at cppa.ca.gov).

14California residents

Way In is a small service and may not be a “business” that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA), applies to. We give California residents its rights anyway, and this section is written to its standard.

What we collect, by the CCPA’s categories, in the last 12 months and going forward:

Identifiers
Name, email address, account id, IP address, and a linked Apple or GitHub account id.
Customer records (Cal. Civ. Code § 1798.80(e))
Name, email, phone if you give it, education and employment information in your profile and applications.
Professional or employment information
Experience, skills, availability, record entries, work authorization or sponsorship needs, and applications.
Education information
School, year, major, graduation year and GPA, as you report them. Not records obtained from your school.
Internet or other electronic activity
Saved and passed listings (on your device), sponsored-listing events, request logs.
Inferences
Your fit for a listing and the order of an application in an employer's inbox.
Audio, visual or similar
Logos and images you upload.
Sensitive personal information
Account login (email and password), and citizenship or immigration status if you state your work authorization. Used only to sign you in, show your fit, and pass your application to an employer, which are uses the CCPA permits without a right to limit; we do not use or disclose it to infer characteristics about you.

Sources, purposes and recipients are as set out in sections 3, 4 and 8: we collect it from you, from services you connect and from people you work with; use it to run, secure and improve Way In; and disclose it, for a business purpose, to our service providers (all categories, as needed to run the service), to employers and project posters you send applications and requests to (identifiers, customer records, professional and education information, and the inference of your application’s order), and as the law requires. We have not sold or shared any category of personal information in the last 12 months, and we do not sell or share the personal information of anyone under 16. How long we keep each category is in section 12.

Your rights are those in section 13: to know, access, delete and correct, to opt out of sale and sharing, to limit the use of sensitive personal information, and not to be discriminated or retaliated against for using any of them.

Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing.

If you are under 18 (Cal. Bus. & Prof. Code § 22581). You can remove anything you have posted on Way In yourself, or ask us to remove it by writing to sethkvc@gmail.com. Removing it from Way In does not remove copies someone else has already made.

Do Not Track (CalOPPA). See section 10.

15Residents of other US states

Residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and any other state with a comprehensive privacy law have the rights in section 13, including the right to appeal, on the same terms, whether or not a given law applies to a service of Way In’s size. Our answer does not change by state, so we do not write a section for each.

Nevada residents: we do not sell covered information as Nevada law defines it.

16Outside the United States

Way In is run from, and for students in, the United States. If you use it from the European Economic Area, the United Kingdom or Switzerland, we are the controller of your personal information, and process it on these legal bases: to perform our contract with you (your account, and everything you ask Way In to do); our legitimate interests in keeping Way In secure, preventing abuse and improving it, which do not override your rights; your consent, where we ask for it (such as linking GitHub), which you can withdraw at any time; and legal obligations.

Your information is stored and processed in the United States. Where the law requires a safeguard for that transfer, we rely on our providers’ standard contractual clauses. You have the rights in section 13, and also the rights to object to processing based on legitimate interests and to restrict processing, and to complain to your local data protection authority.

17Security and breaches

Access to your data is enforced by the database itself, not just the interface: every table has row-level security policies, so a request for someone else’s private data is refused by the database even if the application asked for it. Data is encrypted in transit, and our providers encrypt it at rest.

Résumés live in a private bucket and are served only through short-lived signed links, to you, and to an employer for the copy you sent them. Uploads are limited by type and size, and files that are not what they claim to be are refused. Records of your agreement cannot be edited or deleted except with your account.

The limits, plainly: we do not currently scan uploaded files for malware, and no system is perfectly secure. If a breach affects your personal information, we will tell you, and every regulator the law requires, without unreasonable delay and within the time the law sets, with what happened, what was involved, and what you can do.

18Age and children

Way In is for students in college or about to start, and for the people who hire them. You must be at least 16 to have an account, and if you are under 18, a parent or guardian must agree to the Terms with you. Way In is not directed at children under 13, and we do not knowingly collect personal information from them. If we learn that we have, we delete it. If you believe a child has an account, write to sethkvc@gmail.com and we will remove it.

19Your school and your records

Way In is not your school, and is not acting for it. What you tell us about your studies, your GPA included, is information you choose to give us, not an education record we obtained from UC Santa Cruz or any institution, and we share none of it with your school. The federal law on school records (FERPA) governs your school; this policy governs us.

20Changes to this policy

If this policy changes, the date at the top changes with it. If a change materially affects how your personal information is used, we will tell you by email or in Way In before it takes effect, and where the law requires it, ask for your consent rather than assuming it. We will never apply a material change to information collected under an earlier version without your consent.

21Contact

Questions, requests, corrections and complaints: sethkvc@gmail.com. Please put “Privacy” in the subject.

See also our Terms of Service and what Way In is.