Privacy Policy
Last updated: 2026-08-20
1. Data controller
The data controller (administrator danych) for personal data processed through Proud of Work (proudof.work) is Rafał Ciok, ul. Agrestowa 3, 82-200 Malbork, Poland, contact: hello@proudof.work.
The controller is a natural person based in Poland. No Data Protection Officer (Inspektor Ochrony Danych) has been appointed, as this is not required under Article 37 RODO for processing of this scale and profile. Requests concerning personal data should be sent to the contact e-mail address above; see Section 14.
This Privacy Policy takes effect on 2026-08-20.
2. Categories of personal data
Depending on how a User interacts with the Service, the controller processes the following categories of personal data:
- Account data — name, e-mail address (and whether it has been verified), profile image and whether it is the sign-in provider's photo or a generated illustration, account type (Talent or Company), the time the Account was created, and, collected automatically at sign-in and during each session, IP address and browser/device information (user-agent).
- Sign-in data — where an Account is created or accessed via Google OAuth or GitHub OAuth, the access token, refresh token, ID token, and granted scope issued by the OAuth provider for maintaining the session; where created via e-mail, the one-time sign-in code.
- Talent profile data — full name, professional role, specialization, the month and year the Talent's career began (from which total years of experience is calculated), minimum and maximum expected salary and its currency, country of residence, GitHub/X (Twitter)/LinkedIn handles, a short mission statement, preferred employment types, the time zone bands the Talent is available to work across, the skills, domains, and spoken languages associated with the Profile, the time of the Talent's last activity on the Service, and a random public identifier used in the Profile's page address, which is never derived from the Talent's name.
- Free-text proof content — achievements, projects, and public-presence entries that a Talent writes to describe their work. This free text may incidentally include names of employers, clients, or third parties; the Talent's own confidentiality obligations regarding this content are addressed in the Terms of Service (Section 7 — NDA disclaimer).
- Content-check results — for each free-text field, the outcome of the automated anonymity check described in Section 12, any excerpt it flagged, and whether the Profile is cleared for the Board.
- Terms acceptance — which version of the Terms a User accepted, when they accepted it, and a hash of the accepted text.
- Invitation records — where access is by invitation: the invited e-mail address, the role it grants, an internal note, and whether it has been used.
- Share links — for each link a Talent creates: the link's own random identifier, when it was created, how long it was set to last, when it expires, and whether it has been revoked. The link is tied to the Talent's Profile, which is what lets it reveal their identity to whoever holds it.
- Abuse-prevention counters — for rate limiting: a key derived from the request (an IP address, or the e-mail address a sign-in code was requested for), how many attempts it has made, and when the last one was.
- Waitlist contact — where a visitor asks to be told when Company access opens: their e-mail address and internal labels recording which audience the request came from. No Account is created, and no other data is collected.
- Browser error reports — where an error occurs in the User's browser: the error message, its source, the stack trace, the address of the page it occurred on, and browser information. These go to server logs only. They are not written to the database and are not passed to any third party.
3. Purposes and legal bases
Personal data is processed for the following purposes, each on the legal basis (Article 6 RODO) indicated:
- Creating and maintaining an Account, authenticating sign-in, and providing the Service (including the Profile editor and, where applicable, Board access) — performance of a contract, Article 6(1)(b) RODO.
- Publishing a Profile on the public Board in anonymized form — performance of a contract, Article 6(1)(b) RODO. Presence on the Board is the core of the Service a Talent Account is created for, and a Profile reaches the Board once the fields required to publish it are filled in. A Talent can take their Profile off the Board at any time from their settings and put it back — the data is kept either way. Publication ends permanently when the contract is terminated under Terms Section 5, at which point the Profile is removed from the Board immediately on receipt of the request.
- Revealing a Talent's identity to a third party — full name, social handles, and the links on their projects and public-presence entries. The only route that works today is a share link the Talent creates — consent, Article 6(1)(a) RODO, given by creating that link. A link can be revoked at any time, which ends the disclosure going forward, without affecting the lawfulness of processing carried out before withdrawal. Expected salary is never revealed. The second route — a Company unlocking a Profile under Terms Section 8 — is not active. Before it is, this Policy will set out its legal basis and how consent is given, in line with Section 15.
- Automatically screening free-text Profile content for information that would identify the Talent before a Company unlocks their Profile — performance of a contract, Article 6(1)(b) RODO: the anonymity of a published Profile is the core of what the Service provides. The check is described in Section 12.
- Sending optional product updates — consent, Article 6(1)(a) RODO, withdrawable at any time from Account settings.
- Telling a visitor when Company access opens, where they asked to be told — consent, Article 6(1)(a) RODO, given by submitting the waitlist form. That consent covers the notice and nothing else: it is not consent to marketing, and it can be withdrawn at any time using the unsubscribe link in any message or by e-mailing the address in Section 14.
- Security monitoring, abuse and fraud prevention, and rate limiting — the controller's legitimate interest, Article 6(1)(f) RODO; see Section 4.
- Compliance with legal and tax obligations (for example, once paid features under Terms Section 8 are active, invoicing and accounting records) — legal obligation, Article 6(1)(c) RODO.
4. Legitimate interests
Where processing relies on Article 6(1)(f) RODO, the legitimate interests pursued by the controller are: keeping the Service and its Users' Accounts secure; detecting and preventing abuse, fraud, fake accounts, and unauthorized scraping of Board or Profile data; enforcing the Terms of Service; and maintaining the overall integrity and reliability of the product for all Users. These interests have been weighed against Users' rights and freedoms; the processing involved (primarily IP address, user-agent, and session/request logs) is limited to what is necessary for these purposes and is not used for any incompatible purpose.
5. Recipients / processors
Personal data may be disclosed to the following categories of recipients, each acting as a processor (or, for OAuth sign-in, as an independent controller of its own service) under a data-processing agreement or the provider's own terms:
- Cloudflare — hosting (Workers), content delivery network, and DDoS and bot protection. Processes technical data including IP address (as
CF-Connecting-IP). - Cloudflare Turnstile — the anti-bot check on the sign-in and waitlist forms. Loaded from Cloudflare, it processes the visitor's IP address and browser/device signals in order to score whether a submission is automated. It does not receive the contents of the form.
- Supabase — PostgreSQL database hosting. The database is located in Switzerland (region eu-central-2, Zurich) — see Section 6.
- Resend — delivery of transactional e-mail, in particular the one-time sign-in code, and delivery of optional product updates and the Company-access notice to those who have asked for them. Waitlist contacts are stored with Resend even where no Account exists.
- OpenAI — the automated anonymity check described in Section 12. Receives the free-text field being checked and its field name only; no name, e-mail address, or account identifier is sent, although the text itself may be identifying. US-based; see Section 6.
- Google and GitHub — OAuth sign-in providers. When a User signs in with Google or GitHub, these providers process the User's authentication and act as independent controllers for their own services; see Section 11 on the source of this data.
- Umami — a cookieless analytics tool, the only one used in the Service. The Umami Cloud service of Umami Software Inc. is used, with its data region set to the EU — see Section 6.
DiceBear avatar generation runs locally within the Service and does not send any personal data to a third party; it is not a subprocessor and is not listed above.
Beyond service providers, a Talent's identity is disclosed to the recipient of a share link the Talent creates and — once Company features under Terms Section 8 are active — a Company that unlocks their Profile. Neither is a processor: each is an independent controller of what it receives, and remains one after a share link is revoked or an Account is deleted. Section 3 describes what is revealed.
6. International transfers
The database is hosted with Supabase in Switzerland (region eu-central-2, Zurich). Switzerland is a third country covered by a European Commission adequacy decision, so the transfer relies on Article 45 RODO and requires no additional safeguards. The party to the data-processing agreement, however, is Supabase Pte. Ltd, incorporated in Singapore, so data may be accessed from outside the EEA. Those transfers rely on the Standard Contractual Clauses incorporated into that provider's data-processing agreement, which also covers transfers subject to Swiss data-protection law.
Umami analytics data is stored in that service's EU region. Umami Software Inc. is nonetheless US-based, so it may be accessed from outside the EEA, on the terms described below.
Cloudflare, Resend, Google, GitHub, and OpenAI are US-based providers and may process data outside the EEA. Such transfers rely on the European Commission's Standard Contractual Clauses (SCC) or another valid transfer mechanism recognized under Chapter V RODO. A copy of the applicable safeguards can be requested by e-mailing hello@proudof.work.
7. Retention period
- Account and talent profile data is retained for as long as the Account exists. When a User deletes their Account (Terms Section 5), the Account and the associated Profile and Content are permanently deleted, subject only to any data that must be retained under the security-log or legal-obligation categories below. A deletion request takes the Profile off the Board immediately and the data is erased 14 days later — the interval exists so the request can be undone, and so that anyone already in a conversation can save what they need before it takes effect (Terms Section 5).
- Session and security data is kept only while valid and removed on a periodic cleanup sweep once it expires: a sign-in session is valid 7 days from when it is created, the signed cookie-cache 300 seconds, and abuse-prevention counters last their window — 60 seconds by default, 600 seconds for sign-in code requests, and a 1-hour window for the per-recipient limit on how many sign-in codes an address may be sent (this last one clears itself as its window rolls over). A one-time sign-in code is kept until it expires. IP address and user-agent recorded in request logs, and browser error reports, are kept for the hosting provider's log retention period.
- Share links expire after the validity period the Talent sets (90 days by default on renewal), or sooner if the Talent revokes them.
- Legal and tax records (once applicable, per Terms Section 8) are retained for the period required by Polish tax and accounting law.
- Waitlist contacts are retained until the person unsubscribes, or until the Company-access notice they asked for has been sent — whichever comes first — after which the contact and the list it belongs to are retired.
- Data held by processors — each provider listed in Section 5 also stores what it receives under its own retention schedule, for as long as it needs it to provide its service. In particular, free-text content sent for the anonymity check (Section 12) may be retained by OpenAI for a short period for its own abuse monitoring before being deleted.
8. Your rights
Subject to the conditions set out in RODO, a data subject has the right to:
- access their personal data and obtain a copy of it (Article 15);
- rectification of inaccurate or incomplete data (Article 16);
- erasure ("right to be forgotten") of their data (Article 17);
- restriction of processing in specific circumstances (Article 18);
- data portability — to receive their data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible (Article 20);
- object to processing carried out on the basis of legitimate interest (Article 21);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal, where processing is based on consent (Article 7(3)).
These rights can be exercised by e-mailing hello@proudof.work — see Section 14.
9. Complaint to the supervisory authority
A data subject who considers that the processing of their personal data infringes RODO has the right to lodge a complaint with the supervisory authority, without prejudice to any other administrative or judicial remedy (Article 77 RODO). In Poland, the competent authority is:
Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warszawa, Poland.
10. Whether providing data is required
Providing name, e-mail address, and the data exchanged during OAuth or one-time-code sign-in is a requirement for creating an Account and using the Service; without it, an Account cannot be created and the Service cannot be provided (Article 6(1)(b) basis, Section 3). Providing talent-profile fields, including social handles, and free-text proof content is voluntary — the Talent decides what to describe. That data is processed under the contract (Article 6(1)(b), see Section 3), because without it a Profile cannot be built or published. Declining to provide some or all of it does not prevent Account creation, but may mean a Profile is incomplete and is not published on the public Board.
Joining the Company-access waitlist is entirely voluntary and needs only an e-mail address. Declining has no effect on any other use of the Service.
11. Source of data
Personal data is normally collected directly from the User when they create an Account, complete their Profile, or otherwise use the Service. Where a User signs in via Google OAuth or GitHub OAuth, the controller additionally receives identity data — such as name, e-mail address, and profile image — directly from Google or GitHub as part of the OAuth authentication flow (Article 14 RODO).
12. Automated decision-making
The Board applies ranking and filtering to the list of anonymized Talent Profiles shown to anyone browsing it (for example, ordering or filtering Profiles by criteria such as role, country, time zone, skills, or search terms). This processing is automated but does not produce a legal effect or similarly significantly affect a User: it only determines the order or visibility of Profiles within a search result, does not itself grant or deny access to any opportunity, and does not replace a visitor's or, once active, a Company's own hiring decision.
Before a Profile is published, and again whenever its free-text content changes, that content is checked automatically for information that would identify the Talent ahead of an Unlock — a named employer or client, for example. The check combines pattern matching with a large-language-model classifier operated by OpenAI (Section 5). Flagged content is held back from the public Board until it is edited or re-checked.
A Talent can re-run the check at any time from their dashboard, and can request review by a person using the contact address in Section 14. Where a Talent contests the automated result, the Service Provider does not rely on it. Where this check, or the Board ranking described above, were to be regarded as automated decision-making within the meaning of Article 22 RODO, that right to human intervention applies.
The check looks only for information identifying the Talent. It is not a review of the Talent's own confidentiality or non-disclosure obligations, and content clearing the check is not an assurance that publishing it is permitted — see Terms of Service Section 7.
13. Cookies and local storage
The Service writes nothing to a User's device, and reads nothing from it, for marketing or tracking purposes. Everything described below is either necessary to provide the Service or a setting the User chose themselves.
The Service itself sets the following cookies:
- a session cookie set by the authentication system (better-auth) to keep a User signed in,
- a signed cookie-cache, used to reduce repeated session lookups during authentication,
- a
pending_user_typecookie, used temporarily to remember the account type (Talent/Company) a User selected during sign-in.
When signing in with Google or GitHub, the authentication system additionally sets short-lived cookies that secure the sign-in exchange itself. They tie the return from the provider to the sign-in attempt that started it, and are cleared once it completes.
Three values are kept in the browser's localStorage rather than in a cookie, and never leave the User's device. Two are settings the User chose themselves: the theme, and which language of these documents they last viewed. The third is a flag written by the Service recording whether the last session was signed in, so that the navigation renders correctly before the session is confirmed. None of them is used for analytics or tracking.
Traffic analytics are provided by Umami. Umami sets no cookie and builds no persistent visitor identifier. A session identifier is derived as a one-way hash of the IP address, browser information, and the identifier of this particular website, with a periodically rotated salt. The IP address is not retained in that form, and because the website identifier is part of the hash, the same visitor cannot be recognised on any other site. The data processing agreement with the provider bars it from using this data for its own purposes, combining it with data from other sources, or using it for profiled advertising.
Cloudflare Turnstile, the anti-bot check described in Section 5, sets a cf_clearance cookie on the site's domain once a challenge has been passed, so that it is not repeated on every request. It is set by Cloudflare at the edge rather than by the Service, and it persists until it expires or Cloudflare re-issues the challenge. It carries no profile of the visitor and is strictly necessary to provide a security function, so it is treated as essential on that basis.
Storing information on, and gaining access to information already stored in, terminal equipment is governed by Article 399 of the Polish Act of 12 July 2024 — Electronic Communications Law (Prawo komunikacji elektronicznej), implementing Article 5(3) of Directive 2002/58/EC. Consent is not required where the storage or access is necessary to carry out a transmission or to provide a service requested by the user.
Every cookie and browser-storage value described above falls within that exemption — they keep a User signed in, secure the sign-in exchange, guard against bots, or restore a setting the User chose themselves. Traffic measurement is carried out solely for the Service's own purposes, without cookies, without a persistent identifier, and without any way to recognise a visitor on another site. For these reasons the Service does not use a cookie-consent banner — it neither writes nor reads anything on a User's device for which consent would be required.
A User can still view, block, or delete cookies at any time through their browser settings; doing so for the session cookie will require signing in again. Because these cookies are essential to the Service, disabling them may prevent parts of the Service from working.
14. Contact and exercising your rights
To exercise any of the rights described in Section 8, to ask a question about this Privacy Policy, or to request a copy of the international-transfer safeguards described in Section 6, contact the controller at: hello@proudof.work.
The controller will respond within one month of receiving a request, in accordance with Article 12(3) RODO; this period may be extended by a further two months for complex or numerous requests, in which case the User will be informed of the extension and the reasons for the delay.
15. Changes to this Privacy Policy
This Privacy Policy informs Users under Articles 13 and 14 RODO. It is not a contract — no acceptance is requested or recorded, and none is needed for it to apply.
Where a change is material — in particular a new purpose of processing, a new recipient or processor, a change to international transfers or retention, or a change to how rights are exercised — the controller will inform Users holding an active Account, by e-mail or a prominent in-Service notice, before it takes effect. Where a new purpose is introduced, Users will be informed before that processing begins, in accordance with Article 13(3) RODO.
Other changes are published with an updated date shown above the document, without individual notice.
The English version is shown for convenience. Wersja polska jest wiążąca dla konsumentów w Polsce / the English version governs for other users.