1. The short version
- A few necessary cookies and browser storage entries keep you signed in, protect sign-in, remember your cookie choice, keep your help-assistant conversation, and let an interview recording resume after a dropped connection. The site cannot work without them, so they do not need your consent.
- Analytics, meaning Google Analytics and a replay of how our public pages are used, runs only if you choose "Accept analytics", and only on our public pages.
- Our own server also counts visits without cookies, as section 7 explains.
- We do not use advertising or retargeting cookies.
2. Your choice
Necessary storage is always on. Analytics is off for every visitor, wherever you are, until you choose "Accept analytics": before that, nothing for analytics is loaded or stored. The banner offering the choice (Reject, Accept analytics, or Choose) appears on the pages where analytics could run. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a refusal and do not show the banner; if you then switch analytics on in cookie settings, that choice is the one we follow.
Your choice is kept in the c1_consent cookie, which holds only the choice and
when you made it, for 180 days. It is written only when you choose, or when this browser
had already refused session recording on an earlier version of the site (a choice kept in
local storage as c1_rec_consent), which is carried over as a refusal. When it
expires, or when we change what we are asking, we ask again. You can change it at any time:
Choosing Reject, or switching analytics off later, turns Google Analytics off on the page you are on, removes its cookies from your browser, stops a session recording at once, discards anything it had not yet sent, and deletes the replay's keys from your browser; later pages carry no analytics code at all. It does not recall what was already sent: what Google Analytics already received stays there, and replays already uploaded are deleted after 30 days, or sooner if you email hello@career1.ai and tell us roughly when you visited. Both analytics tools are started by script, so with JavaScript turned off neither runs at all.
3. Necessary cookies and storage
These are set on our own domain and are needed for the site to work.
| Name | Kind | What it does | How long | Set by |
|---|---|---|---|---|
c2_session |
Cookie | Keeps you signed in | 14 days, or 90 days with “remember me” | First-party |
c1_consent |
Cookie | Remembers your cookie choice | 180 days | First-party |
c1_ex |
Cookie | Set only in the browsers of Career1's own team, to leave their visits out of the statistics | 1 year | First-party |
g_login_state, g_login_verifier |
Cookie | Protects Google sign-in against forgery | 10 minutes | First-party |
gh_oauth_state |
Cookie | Protects GitHub sign-in against forgery | 10 minutes | First-party |
g_oauth_state |
Cookie | Protects connecting a Google Calendar | 10 minutes | First-party |
c1help:email, c1help:thread, c1help:messages |
Local storage | Keeps your conversation with the help assistant when you reload | Until you clear it | First-party |
c1seg:* |
Session storage | Lets an interview recording resume after a dropped connection | Until the tab closes | First-party |
4. Analytics cookies and storage
These are set only after you choose "Accept analytics".
| Name | Kind | What it does | How long | Set by |
|---|---|---|---|---|
_ga, _ga_* |
Cookie | Google Analytics: counts visits and pages | Up to 2 years | Third-party (Google) |
c1rec:* |
Session storage | Session replay: ties one visit's recording together | Until the tab closes | First-party |
c1rec:visited |
Local storage | Session replay: notes a returning visitor | Until you clear it | First-party |
5. Google Analytics
If you accept analytics, our public pages load Google Analytics 4. It sets the
_ga cookies and sends Google the address and title of the page you are on,
your device and browser, and your approximate location, which Google works out from your
IP address; Google states that Google Analytics 4 does not log or store IP addresses. We
use it to count visits and see which pages people read. Google processes this data in the
United States; its safeguard is on the sub-processor list.
We run it with Google's consent mode set so that only analytics storage is ever granted, and only after you accept. Advertising storage, the use of your data for advertising, and ad personalisation are always refused, advertising data redaction is on, and IP anonymisation is requested.
It runs only on our public pages, including companies' careers pages and job posts. It never runs in the signed-in product, on sign-in or password-reset pages, or in interview rooms, because the addresses and titles of those pages can carry private information.
6. Session replay
What. If you accept analytics, our public marketing pages (the homepage, pricing, FAQ, about, help, the free tools, the blog, interview guides, hiring and careers pages, and the talent landing page and job board) record a replay of how the page is used: page layout, scrolling, mouse movement and clicks. We never record inside the signed-in product, sign-in and signup pages, interview rooms, or the admin area.
Why. To find where the site is confusing or broken, for example a button people click repeatedly that does nothing.
Masking. Masking happens in your browser, before anything is sent. Everything typed into any form field is replaced before it leaves your device, password and file fields are not recorded at all, password, email and phone fields can never be recorded whatever a page says, and the results the free tools produce from your resume or text, and your conversation with the help assistant, are masked, as are the name and size of a resume chosen on a careers page. Video, audio, drawing canvases and embedded frames are not recorded. Page addresses are stored without their query strings, and the private token in an address such as an interview or password-reset link is replaced by a placeholder.
What it is linked to. A recording is tied together by a random id kept in
your browser's session storage while the tab is open, and a yes/no marker in local storage
notes whether this browser has visited before (the c1rec keys in
section 4). A recording is not linked to an account. It is linked to the record
of your visit described in section 7, and it stores your country and your
device, browser and operating system. As with every request to this site, the internet
address it came from is recorded with it, and is visible only to us.
What else is kept beside the replay. A short list of what happened, so the replay can be read rather than only watched: which page, clicks, scroll depth, which form field was used and whether it ended up filled, when a form was sent or left unfinished, when the tab was switched away from and for how long, when the window was resized, and browser errors. Each entry is named from the page's own markup, such as a button's visible text or its accessibility label, a field's name, placeholder or type, or a link's address, and never from anything you typed. What you type is never stored in any form, only its length; clipboard contents are never stored, only that a copy or paste happened. Anything that looks like an email address or phone number is replaced before it is saved. We also keep how long the tab was open, how much of that time you were actively using it, your window size, and whether this browser had visited before (a yes/no marker in your browser's own storage, with nothing in it that identifies you). A recording stops after four hours, and half an hour of inactivity begins a new one.
Where it is kept. In our own database, on our servers in France. Recordings are not sent to any analytics or advertising company. Like everything else in the database, they are included in the nightly backups we keep on Amazon S3 in Sweden.
Retention. Recordings, and the list of what happened in them, are deleted automatically after 30 days. Copies inside database backups last as long as those backups, which are not yet deleted on a schedule.
Opting out. Choose Reject in the banner, or switch analytics off in cookie settings; while a recording runs, a note at the foot of the page says so and carries the same button. If your browser sends Global Privacy Control or Do Not Track, nothing is recorded unless you switch analytics on yourself, and automated browsers are never recorded.
7. Counting visits without cookies
What. Our own server records each page request, except in the admin area, for files such as images and stylesheets, and for the site's own machine-to-machine requests: the page address, the time, the response status, how long the server took, the browser's user-agent string (and the device, browser and operating system read from it), the referring site, any campaign tags in the link, and the IP address the request came from. The address is kept because it is how a spam or scraping campaign is identified and blocked. A background job looks up the approximate country and city of each new IP address with ip-api.com and keeps the result. That lookup is the only outside service involved; the records themselves stay on our server. Google Analytics, if you accept it, collects its own data separately, as section 5 describes. This counting happens whatever you choose in the banner, because it stores nothing on your device.
Private links. Some addresses carry a private token, such as an interview, email-confirmation, password-reset, invitation, share or call link. The token is replaced by a placeholder before these records, session-replay journeys or our application logs store the address. Our web server's own access log, which notes every request with its IP address and browser, still records the full address.
No cookie. Visits are grouped by a salted one-way hash of the IP address, the user-agent string and the calendar date. It identifies one visitor for one day and cannot follow anyone into the next, by design. Because the IP address itself is also kept today, these records are personal data, and we treat them as such.
The confirmation. Most pages also run a few hundred bytes of script that posts back the identifier of that page's own visit record, so we can tell a real browser from the automated traffic that makes up most of the requests to any website. It sets nothing and stores nothing on your device. Where a session replay is running in the tab, it reads the replay's identifier from session storage and sends that too, so the two records are linked and a visit can be watched back.
How long, and why. There is no automatic deletion of these records yet. We keep them on the basis of our legitimate interests in understanding how the site is used and keeping abuse out, and you can object by emailing us.
8. Other sites' cookies
Signing in with Google or GitHub, paying through Stripe's checkout, or connecting a Google Calendar takes you to that company's own site, which sets its own cookies under its own policy. Interview rooms also connect to OpenAI and to a Google server to carry the voice conversation, as the Privacy Policy explains.
9. Changes and contact
When we add or change a cookie or a storage key, this page changes with it, and the date at the top moves. Questions to hello@career1.ai.