Skip to content
← Way In

Privacy Policy

Last updated

Way In collects what it needs to match you with opportunities and nothing else. There are no ads, no analytics, no trackers, and your information is never sold. Much of what you do here is kept in your own browser rather than on our servers — see Where your data lives.

01Who we are

Way In is an independent project built by a student at UC Santa Cruz. It is not affiliated with, endorsed by, or operated by the University of California, Santa Cruz, or by any employer or organization whose listings appear on it.

This policy covers the Way In website and application. It explains what we collect, why, who can see it, and how to get it back or delete it.

02What we collect

Only what you give us, plus the minimum needed to keep you signed in.

Account
Your email address, display name, and account type (student, business, or faculty). Required — it is what an account is.
Profile
Anything you choose to add: school, year, major and minor, graduation year, GPA, bio, headline, location, links, skills, past experience, what you're open to, availability, work preferences, and work authorization or sponsorship needs. All of it is optional. A blank profile still works; it just matches less well.
Resume
If you upload one, we store the PDF itself. Please read section 5 before you do.
What you post
Listings, projects, and any images or logos you attach to them.
What you decide
Which opportunities you save and which you pass on. This is what makes the feed get better rather than repeat itself. Today this is kept in your browser, not on our servers.
Your record
Roles and projects you say you completed, the people you name as having worked with you, and confirmations or disputes that others attach to your entries. A confirmation names the person who gave it.
Messages
What you write to another account. Today messages are kept in your browser and are not delivered to the other person; when delivery exists, both sides will be able to read a conversation.
Profile picture
If you set one, it is kept in your browser, not on our servers, so it appears only on the device that uploaded it.
Sponsored listings
If a listing you see is sponsored, we record that you saw it and whether you saved, passed or applied, so the employer can be billed for reach without ever being told who you are.
Session
An authentication cookie that keeps you signed in. It is set by Supabase, our authentication provider, and is required for the site to function — it is not used to track you.
Server logs
Our hosting provider keeps standard request logs (IP address, browser, page requested, time) for a short period for security and debugging. We do not build profiles from them.

03What we don't do

This is a short list because it is meant to be verifiable rather than reassuring. Way In runs no advertising, no analytics, and no third-party tracking scripts of any kind. There is no Google Analytics, no pixel, no session recorder, no heatmap, no A/B testing service.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — under any definition, including California’s. We have never done so and there is no mechanism in the product that would allow it.

We do not use your resume, profile, or messages to train machine learning models.

04How we use it

To run the product: sign you in, show you listings ranked against your profile, let you save things, let you message people, and let you apply.

The match percentage on a listing is computed from your own profile — your major, what you say you’re open to, your skills and availability, against the listing’s requirements. That computation happens for you and is not shared with the poster.

We use your email address to send account email — confirming the address, resetting a password — and for nothing else. There are no marketing emails and no notification emails today; if we add them, each will carry an unsubscribe link and will be off until you turn it on.

05Who can see what

Your resume is readable only by you. It lives in a private bucket, is served to you through a short-lived link, and no other account — student, employer or admin dashboard — can open it through the product. When applying through Way In exists, an employer will see your resume only for a role you apply to, and this policy will say so before that ships.

You can remove a resume at any time from your profile. Everything else on Way In works without one.

Public to anyone
Listings and projects that you post, including any logo or cover image attached to them. Assume anything you post is public.
Visible to signed-in accounts
Your profile basics — name, school, year, major, and for employers the organisation — and your record: what you say you completed and who confirmed it. Signed-out visitors see none of it.
Visible to employers, only if you switch it on
Your full profile, once a 'discoverable' setting exists and you have turned it on. It is off for everyone today, and nothing about you is shown to an employer you have not contacted.
Visible to the other person only
Messages, once delivery exists — readable by you and the account you're talking to, and nobody else.
Visible only to you
Your resume, your saved and passed decisions, and the fit each listing shows you. Posters are not told that you passed on their listing, and no employer sees your fit.

06Where your data lives

Way In uses Supabase for its database, authentication, and file storage, and Vercel for hosting. They process data on our behalf and are bound by their own agreements. Data is stored in the United States.

More of your activity than you might expect is kept in your own browser’s local storage rather than on a server: which listings you saved or passed, messages you have written, your profile picture, your record entries, and roles or projects you post. It stays on that device, it is not backed up by us, and clearing your browser data clears it. This is a stage, not a design; as each of these moves to our servers this policy will say so.

Way In also mirrors publicly posted listings from other job boards and public APIs — UC Santa Cruz Academic Recruit, the public boards of employers who publish through Greenhouse, Ashby, Lever, SmartRecruiters and Workday, USAJobs, EdJoin, and the US Department of Labor’s CareerOneStop. Each is a one-way copy of a public posting into our database, and no information about you is sent to any of them. When you apply, you leave Way In for the employer’s own site, and their privacy policy applies from there.

07Keeping and deleting

We keep your information while your account exists. Delete your account from Settings and we delete your profile, your resume and any images you uploaded, your record and the confirmations you gave, and everything else keyed to the account, immediately. Anything kept in your browser is yours to clear.

Two honest caveats. A message you sent to someone else remains visible in their conversation, the same way a sent email does. And backups persist for a short period after deletion before they roll off.

08Your rights

Wherever you live, you can ask us to do all of the following, and we will not treat you differently for asking:

Know
What we hold about you and where it came from.
Get a copy
In a portable, machine-readable format.
Correct
Fix anything inaccurate. Most of it you can edit yourself in your profile.
Delete
Remove your account and its contents.
Opt out
Of any notification, at any time, in Settings.

Email us and we will respond within 45 days. We may need to confirm you control the account’s email address before acting on a request — that check exists to stop someone else deleting your data.

09California residents

Under the California Consumer Privacy Act as amended by the CPRA, you have the rights listed above, plus the right to know whether we sell or share your personal information and the right to limit the use of sensitive personal information.

We do not sell or share personal information, so there is no opt-out to offer you — there is nothing to opt out of.

California law also asks how a site responds to a browser’s “Do Not Track” signal. Way In does not track you in the first place, so the signal changes nothing: it is honoured by default.

Some of what you may choose to give us is treated as sensitive personal information under California law, including work authorization status and precise education records such as GPA. We use it only to show you relevant listings and to let you apply. We do not use or disclose it for any other purpose, which means the right to limit its use is already the default.

If you are a resident of another state with a comprehensive privacy law — Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others — the same rights are available to you on the same terms. We chose not to write a separate section per state, because our answer does not change by state.

10Security

Access to your data is enforced at the database level, not just in the interface: every table has row-level security policies, so a request for someone else’s private data is rejected by the database itself even if the application asked for it.

Resumes live in a private bucket readable only by their owner and are served through short-lived signed links. Uploads are limited by type and size at the storage layer, and files that are not what they claim to be are rejected.

Being straight with you about the limits: we do not currently run malware scanning on uploaded files. No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If we discover a breach affecting your personal information, we will notify you and any regulator that the law requires, without unreasonable delay.

11Age

Way In is for university students and the people who hire them. It is not intended for anyone under 16, and we do not knowingly collect information from children. If you believe a child has created an account, email us and we will remove it.

12Changes

If this policy changes we will update the date at the top. If a change materially affects how your information is used, we will tell you before it takes effect rather than quietly revising the page.

13Contact

Questions, requests, or corrections: sethkvc@gmail.com.

See also our Terms of Service and what Way In is.