Privacy Policy
Last updated 7 September 2026
Roleset is operated by Roleset.io, registered in Israel. This page describes what we collect, what we deliberately do not, and who else processes it. Contact us at index@roleset.io.
The index itself contains no personal data. Roleset indexes companies and roles, never people. Person-shaped fields are discarded at the point a feed is parsed, and email addresses and telephone numbers are stripped out of job descriptions before anything reaches our database.
There are no applicants, no recruiter names and no contact details in the product, and we have no way to produce them.
What we collect about you as a customer
| Data | Why | Kept |
|---|---|---|
| A cryptographic hash of your API key, and a short prefix of it | To authenticate your requests and let you identify a key. We never store the key itself. | While the account exists |
| Usage records: which endpoint, how many records, and when | To meter usage, produce invoices, and warn you before your allowance runs out. No query text or result content is retained. | 24 months, then deleted |
| An account label you give us, and your Paddle customer and subscription identifiers | To connect usage to the right invoice. | While the account exists |
| A salted hash of your IP address, if you claim a free key on this site | To stop one person taking an unlimited number of free keys. It is a salted hash, not the address: it can be compared with itself and nothing else, so it cannot be turned back into an address or used to tell where you were. | While the key exists |
| Server logs: IP address, request path, response status, timestamp | Security, abuse prevention and debugging. | 30 days, then rotated away |
What we do not store
- Any account details for a free key. Claiming a free key on this site asks for no email, no name and no card. The key is shown once and we keep only a hash of it.
- Your email address. Paddle holds it as Merchant of Record. When we need to email you about your usage, we read the address from Paddle at the moment of sending and do not keep a copy. A second copy would be one more thing to protect, and to delete on request, for no benefit to you.
- Payment details. Card numbers never touch our systems. Paddle handles payment entirely.
- The content of your queries or results beyond the count of records served.
Cookies and tracking
This website sets no cookies and runs no analytics, advertising or
tracking scripts. It loads fonts from Google Fonts, which means your browser makes a
request to fonts.googleapis.com and fonts.gstatic.com. The
API sets no cookies at all.
Who else processes your data
| Processor | What for | Where |
|---|---|---|
| Paddle.com Market Ltd | Payments, invoicing, tax. Merchant of Record — they hold your billing details and email address. | United Kingdom / EU |
| Resend | Sending usage notification emails. | United States |
| Hetzner Online GmbH | Servers and encrypted backups. | Finland / Germany (EU) |
We do not sell your data, and we do not share it with anyone beyond the processors above except where the law requires it.
Legal basis
Where the GDPR applies, we process the data above to perform our contract with you (authentication, metering, billing) and on the basis of our legitimate interest in keeping the service secure and working. We do not rely on consent, because we do not do anything with your data that would need it.
Your rights
You can ask us to show you what we hold about you, correct it, delete it, or export it. Email index@roleset.io and we will respond within 30 days. Since we hold very little, these requests are usually quick.
For billing details and your email address, Paddle is the controller — you can also ask them directly. If you are unhappy with how we have handled a request, you may complain to your local data protection authority.
Job postings and the people mentioned in them
Job descriptions are written by employers and occasionally name an individual. Our parsers remove email addresses and telephone numbers before storage, and never copy fields that identify a person. If you find personal information in the index that we have missed, email index@roleset.io and we will remove it — this is a bug on our side and we treat it as one.
Security
- All traffic is served over TLS.
- API keys are stored only as SHA-256 hashes.
- Backups are encrypted at rest and held separately from the server they protect.
- Credentials live in a root-owned file readable only by the service account.
Changes
We will update this page if what we do changes, and the date at the top always reflects the current version. Material changes are notified by email.