Privacy
Privacy
What softon.dev collects about you, why, who else handles it, and how long it is kept. Written from what the code does rather than from a template, so where there is a gap, this page names it instead of papering over it.
The short version
- We collect what it takes to run an account and an API key, and to answer you when you write. None of it is sold, rented, or used for advertising.
- Google Analytics runs only if you accept it, and nothing from it is on a page before you do. You can change your answer at any time.
- One outside company sees every visit regardless: Google serves the site's typefaces, so it receives your IP address with each page you open. More below.
- To see, correct or delete what we hold about you, write to us.
When you read the site
Reading the site, the documentation and the notes needs no account and sets no cookie. Three things happen anyway, and you should know all three.
- Our web server logs each request: your IP address, the time, the address you asked for including anything after the
?, your browser's user-agent string and the other headers it sends, and how the server answered. The values of cookie and authorisation headers are not written to it. It is kept on the server in rotating files capped at 30 MB per service, so the oldest lines are overwritten as new ones arrive. - The application logs less: the method, the path without its query string, the status and the timing of each request, and no IP address. A few account events are logged by email address — for example, an attempt to sign up with an address that already has an account.
- Your browser fetches the site's typefaces from Google Fonts —
fonts.googleapis.comandfonts.gstatic.com— on every page. So Google receives your IP address and user-agent string with those requests — and, from the public pages, this site's address — whether or not you accept analytics. Google states that no cookies are sent with them.
Analytics
softon.dev can count visits with Google Analytics 4. It is off until you say otherwise: before you answer, no Google Analytics script is on the page, no analytics cookie is set, and the page's security policy would refuse Google's script if it were there. Declining is one click, the same as accepting.
If you accept, Google Analytics:
- sets two cookies on this site,
_gaand_ga_followed by an identifier for this site, which tell one browser's visits apart. They expire 180 days after your last visit; - records which pages you view and for how long, the site that sent you here, your browser and device type, an approximate location Google works out from your IP address, and interactions such as scrolling down a page or following a link away from it;
- is given each page's address without its query string — the part after the
?, which on this site is where the sign-up box carries your email address and a confirmation link carries its token. Campaign tags (utm_…) are kept, and so is the short code in the sign-in page's address that picks the notice it shows, such asverified; - runs with Google's advertising features off: no Google signals, no ad personalisation, and Google's consent mode is told advertising storage is denied.
It runs on the public pages and on the account pages you see before signing in — sign-up, sign-in, the contact form and the email confirmation link. Never on the dashboard, and never on the forgotten-password or password-reset pages, whatever you answered: those are where a new API key is shown and a password is reset, and no third-party script runs on them. Google processes what it collects under its own terms, and may do so outside the EU, including in the United States.
Your answer is kept in a cookie for 180 days, after which you are asked again. Declining after accepting also deletes the _ga cookies.
You have not answered yet, so analytics is off in this browser.
Cookies
None before you sign in or answer the analytics question. Ours are first-party and HttpOnly: only softon.dev receives them, and no script on the page can read them.
| Cookie | Set when | What it holds | How long |
|---|---|---|---|
__Host-softon_customer | You sign in | A random session token. We store only a digest of it. | Until you sign out, after 14 days unused, or 30 days after you signed in |
__Host-softon_analytics | You answer the analytics question | Your answer: granted or denied | 180 days |
_ga, _ga_… | You accept analytics | Google Analytics' identifier for your browser | 180 days after your last visit |
Your account
When you create an account we keep:
- your name and email address and, if you give them, your company and what you are building — to run the account, to reach you about it, and to understand a key request;
- your password as a salted PBKDF2-SHA256 hash, which cannot be turned back into the password;
- the plan you asked for, and when you confirmed your email address;
- the IP address you signed up from, which is how one address is limited to five new accounts an hour;
- for each browser you sign in with, a digest of its session token, its IP address and user-agent, and when it was last used;
- an audit trail of what happened to the account: sign-up, email confirmation, each sign-in, password resets, and requesting, collecting, renaming or revoking a key, each with the IP address and user-agent it came from. Failed sign-ins are not recorded;
- the messages you send from your dashboard.
An email confirmation link works for 24 hours and a password reset link for an hour. Both are stored only as digests, and a reset request also records the IP address it came from.
API keys and requests
- A key is shown to you once. Until you collect it — and for 72 hours at most — it is held so your dashboard can show it. After that this site keeps only its SHA-256 digest — enough to recognise the key, and useless for recovering it — and so does the API's server, with one exception: a key an operator had to install by hand, because the automatic path to the API was down, sits in the API server's configuration until it is revoked.
- Each request to the API is recorded with its time, the key's name (made from your account's name), your plan, the method, the endpoint's pattern —
GET /v1/jobs/{id}, not the id you asked for, and not your query, so not what you searched for — the status, the size and duration of the response, and whether it counted against your allowance. No IP address. These rows are kept for 90 days. The deletion is a command we run rather than a timer, so a row can outlive 90 days until the next run. - A monthly count per key is kept, because it is what your allowance is measured against.
- Two logs on the API's server see more than that record does. Its web server logs each request the way the site's does — IP address, the full address including the query string, user-agent — with the value of the
Authorizationheader, which carries your key, left out; those files are capped at 30 MB. The API's own log has the method, the path, the query string, the status and the timing, with no IP address and no key; its files are capped at 50 MB. So what you searched for is in those logs until they rotate, even though the request record above leaves it out.
When you write to us
The contact form takes your name if you give it, your email address, a subject and your message, and records the IP address it came from — which is how one address is limited to five messages an hour. The message is stored and emailed to us, and a short acknowledgement goes to the address you gave, quoting only the subject. Messages are not deleted automatically: they are how we answer you, and how we look back at what was asked.
Email we send
Only email about your account or a message you sent: the address confirmation, password reset and password-changed notices, a note when a key is ready, a warning when somebody tries to sign up with your address, and the acknowledgement of a contact message. No newsletter and no marketing. Each one is delivered by Sweego, which receives the address and the message. Our own log of sent mail records the subject and a masked form of the address.
Who else handles it
Three outside companies handle personal data for us:
- Hetzner Online hosts both of our servers, in the EU: one runs this site and its accounts, the other runs the API and its database. Hetzner also keeps nightly images of the first.
- Sweego delivers our email.
- Google serves the typefaces on every page, and runs Google Analytics if you accept it.
There is no payment processor. This site never asks for card details: a paid plan is arranged with you directly, by email.
How long we keep it
| What | How long |
|---|---|
| Your account, its keys and your dashboard messages | Until the account is deleted |
| A sign-in session | It ends when you sign out, after 14 days unused, or 30 days after you signed in. Its row is deleted a week after that 30-day limit. |
| Confirmation and reset links | Usable for 24 hours and an hour; deleted a week after they expire |
| A key you have not collected | Until you see it, or 72 hours |
| The per-request API log | 90 days, deleted by a command we run |
| Monthly request counts | Kept |
| Contact messages | Kept; nothing deletes them automatically |
| The audit trail | Kept. It is append-only by design. |
| Server logs | Overwritten as they pass their cap: 30 MB per service, and 50 MB for the API's own log |
| Your analytics answer | 180 days |
| Backups | Hetzner keeps seven nightly images of the site's server. The API database is copied every night to the site's server, and each copy is kept for 14 days. |
People in our datasets
The datasets are built from public pages, and some of what those pages publish is about people: a job posting can name a recruiter and give their email address or phone number. Our crawler also stores profiles that job seekers publish on Azerbaijani job boards. The API does not serve those, and no plan includes them.
If you are in any of it and want out, write to us and say so. We suppress the record by your email address or by the source's own id, so it leaves every response, the archive included, and a request about your own personal data is handled as an erasure request. Our crawler's page says how removal works.
What you can ask for
Write to us, and you can ask for:
- a copy of what we hold about you;
- a correction;
- your account to be deleted. There is no button for it: a person does it. The account goes, and with it everything attached to it on the site's server — sessions, links, keys, key requests and dashboard messages — and its keys are switched off on the API's server. What stays: the audit trail's record that the account existed and what was done to it, because the trail is append-only; the monthly request counts; the request log until it ages out; and the backups until they do;
- your analytics consent to be withdrawn — or withdraw it yourself, above.
Changes to this page
The date at the top is when this page last changed. Several of its figures — how long sessions, links and uncollected keys last, the per-address limits, the log caps, and how long the request log and the backups are kept — are checked against the code and configuration that enforce them, so changing one of those without changing it here fails the build.