Privacy policy
It's a Numbers Game is a job application tracker run by Shapes.io. This page says exactly what the app stores, who else it passes through, and how to make it all go away. It describes what the software actually does today — if the two ever disagree, the software is the bug.
What we collect
Only what you type in, plus the minimum needed to keep an account working:
- Your account — email address, a bcrypt hash of your password (never the password itself), an optional display name, and whether you've confirmed your email.
- Your profile — anything you choose to save for autofill: name, email, phone, country, and links to LinkedIn, GitHub or a personal site. It also holds your career history if you put one there — headline, the “about” text you write about yourself, roles and employers, education, and skills. If you import a resume, the extracted text is stored too.
- Your saved answers — the question and answer pairs you add for application forms.
- Your applications — company, role, link, status, dates, notes and the log entries you write against each one.
- Extension tokens — a hash of each browser-extension token you generate, its label, and when it was last used. Revoking a token disconnects that browser, and the copy of your profile it was holding is deleted from it on the next sync.
- Abuse-prevention records — when someone fails a sign-in or requests an account email, we record the IP address or email address involved and the time, purely to rate-limit it. These rows are deleted about an hour later.
- Feature-usage counts — six things are counted against your account so we can tell whether the product actually works: connecting a browser, importing a profile, filling in a form, capturing an application, being warned that you'd already applied, and a duplicate being refused. Each row holds the event name, whether it came from the website or the extension, a number where one applies (how many form fields were filled), and a one-word tag such as
resumeorposting. It never holds a company, a role, a web address, a file name or anything you typed — there is no field for it. These counts stay on our own database and are not sent to any analytics provider.
Two analytics tools count visits, and neither one sees your name, email or anything you typed. Vercel Web Analytics records page views and coarse details of the visit — referrer, country, device type and browser — with no cookie and no cross-site identifier, so it runs for everyone. Google Analytics 4 measures the same kind of thing across visits, but it needs cookies, so it stays switched off until you allow it in the banner.
Two of the feature-usage counts above — connecting a browser and importing a profile — are also sent to Google Analytics when you've allowed it, with the same one-word tag and nothing else, so they sit alongside the page views. The four that happen inside the browser extension are never sent to Google: the extension works on other companies' application forms, and we won't put a third-party tracker on a page you're filling in with your own details.
There is no advertising and no advertising pixel. Advertising storage, ad personalisation and ad user data are refused for every visitor, whichever way you answer the banner. We don't build a profile of you, and there is nothing to sell.
Cookies
Strictly necessary: the session cookie that keeps you signed in. The app can't work without it, so there is nothing to consent to. Signing out or deleting your account clears it.
Analytics, only if you allow them: the Google Analytics cookies. They start denied — Consent Mode v2 is set to denied before the Google script loads — so nothing is written unless you choose “Allow” in the banner. Choose “No thanks” and Google gets cookieless pings instead, which count the visit without identifying your browser. Your answer is remembered in this browser's local storage; clearing this site's data asks you again.
Why we're allowed to hold it
Everything above is here because you asked for an account and put it there: we hold it to provide the service you signed up for. The abuse-prevention records are the one exception — those exist so other people can't brute force your password or use the app to send mail to strangers.
Who else sees it
We use a small number of service providers to run the app. They only ever process data on our instructions:
- Vercel — application hosting and privacy-friendly page analytics. Requests to the site, including IP address and browser user agent. Vercel Web Analytics also records page views, referrer, country, device and browser — aggregated, with no cookie and no cross-site identifier.
- Google — google analytics 4, only if you allow analytics cookies. Which pages you open on this site, plus the referrer, approximate location, device and browser. Allowing it also lets Google set a cookie that recognises your browser on later visits; decline and it gets cookieless pings instead. It never receives your account, profile, applications or resume text.
- Neon — database hosting. Everything you store: account, profile, applications and notes.
- Anthropic — resume and profile extraction. The text of a resume or LinkedIn profile you choose to import.
- Resend — account email delivery. Your email address, and the contents of the message sent to it, for confirmation and password-reset emails. Resend is based in the United States, so these are processed there. It never receives your profile, applications or resume text.
Nobody else. We don't sell data, share it with advertisers, or hand it to anyone for their own purposes.
AI and your resume
When you import a resume, or use the browser extension to import your own LinkedIn profile, the text of that page or document is sent to Anthropic's API so a model can pick out the fields — name, contact details, headline, roles and employers, education, skills, and any recurring application answers it finds. The extracted fields come back and are saved to your profile, without overwriting anything already there.
- This only happens when you choose to import. Nothing is sent in the background.
- Under Anthropic's commercial API terms, inputs sent through the API are not used to train its models.
- Your applications, notes and account details are never sent to a model — only the document you explicitly import.
- The model can misread a document. Everything it extracts lands in an editable form for you to correct, and none of it is treated as advice.
How long we keep it
Your account data stays until you delete it — we don't expire accounts for inactivity. Password-reset and email-confirmation links expire on their own and are single-use. Abuse-prevention records are swept about an hour after they're written.
Deleting your data
You can delete your account yourself, at any time, from your profile page. It removes the account and everything attached to it — applications, log entries, profile, saved answers, extension tokens and the feature-usage counts — immediately and permanently. There is no grace period and no undo, so save anything you want to keep first.
Want a copy of your data instead, or want deletion handled for you? Email support@shapes.io and we'll action it by hand within 30 days.
Security
Passwords are stored as bcrypt hashes. Extension and email tokens are stored as hashes too, so a database leak doesn't hand anyone a working link. Changing your password signs out every other session. Every query is scoped to the signed-in account, so one account cannot read another's data.
Who we are, and how to complain
This site is operated by Shapes.io Ltd, a company registered in England and Wales (company no. 12749052), with its registered office at 124 City Road, London, EC1V 2NX. Shapes.io Ltd is the data controller for the personal data described on this page.
Reach us at support@shapes.io for anything on this page — access, correction, deletion, or a complaint. We would rather hear from you first and fix it.
If you are not satisfied with how we have handled your personal data, you can complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at https://ico.org.uk/make-a-complaint/. You do not have to contact us before doing so.
Changes
When the app starts collecting something new or adds a new provider, this page is updated in the same release, and the date below changes with it.
Last updated 25 September 2026.