Privacy Policy
Last updated: 29 September 2026
The short version
- You can check your CV without signing up. Accounts are optional, for the paid CV tools (see CV tools).
- Your CV text is sent to Anthropic (the company behind the Claude AI model) in the United States to identify your skills. We do not keep the raw CV text once the analysis has finished, unless you apply for a job posted here, choose to add it to an employer-visible profile, or use the CV tools (it is then kept inside your job pack).
- To find live jobs for you we send job titles and the place you typed (never your name, email or CV) to the job boards we search.
- We keep your results (skills, career matches, the job title you gave, and for a CV a few paraphrased achievements, short notes on where each skill shows and what you said matters to you) for 12 months so your results link keeps working, then delete them.
- Recruiters from Flintstone Associates, our recruitment partner, review applications and profiles to prepare shortlists for employers, but only for people who applied for a job here or switched on ‘Let employers find me’.
- Payments are handled by Stripe. We keep purchase records for 6 years for tax.
- Google Analytics cookies are only used if you click Accept.
- We do not sell your data. An employer only gets your CV and contact details if you apply for their job on MatchMySkillset (ticking a box that names them) or accept their request to contact you.
1. Who we are
MatchMySkillset (matchmyskillset.com) is run by MatchMySkillset, the controller of the personal data described here. MatchMySkillset is a joint venture with Flintstone Associates, a specialist recruitment firm whose recruiters prepare the shortlists employers can ask for (see “Recruiter shortlists for employers”). You can contact us about anything in this policy at hello@matchmyskillset.com.
2. What we collect and why
Your CV or job title
When you use the free check, you either paste or upload your CV, or type your current job title. We send that text to Anthropic to pick out your skills and compare them with UK occupations. The raw CV text, and any file you upload, is used only for that analysis and is not stored by us afterwards, except when you ask us to: when you apply for a job posted on MatchMySkillset (see “Applying for a job posted here”), or when you add your CV to a profile employers can find (see “Letting employers find you”).
So you do not have to upload it again, your browser keeps a copy of your CV text in its session storage for the tab you used, until you close that tab. It stays on your device and is only sent to us if you use it to apply for a job or add it to a profile.
Lawful basis: contract. We need the text to give you the result you asked for.
Your results
We store the output of the analysis: the skills we found, your career matches, the job title you gave (if any), the town, postcode or region you typed for where you want to work (if any), the list of live jobs we found and scored for you, and a random code that makes up your private results link. For a CV we also store 4 to 8 short achievement points, a short summary of anything you said matters to you, and for each skill a note of up to 10 words on where it shows in your CV (for example “led a department of four teachers”), all paraphrased by the AI model without names or contact details, so the results page and the paid report can use them. Anyone who has the link can open the results, so only share it with people you trust.
Lawful basis: contract, so the link you are given keeps working.
Your email address (optional)
If you ask us to email your results or a report, we use your email address to send it. We do not add you to a mailing list, and we will not send you marketing emails unless you have separately agreed to receive them.
Lawful basis: contract.
Paid reports
If you buy a report, Stripe takes the payment. We never see your full card details. Stripe tells us your email address, the amount, the payment status and a payment reference, and we record which report you bought so we can deliver it and deal with any questions.
Lawful basis: contract, and legal obligation for the tax records we must keep.
Job searches
On your results page we search for live jobs for you: we send the job title of your own job and of your closest career matches, and the town, postcode or region you typed, to Reed, Adzuna and Himalayas (GOV.UK Teaching Vacancies and Remotive listings are fetched in bulk and filtered on our side). No board receives your name, email or CV. We work out the match scores ourselves. When you type a town, the letters you type are sent from our server to postcodes.io (a free UK postcode and place-name service) to suggest places and find the region; your IP address is not passed to it.
When you search for jobs, the words and location you type are sent to the job boards we use (Reed, Adzuna and Himalayas, and Careerjet and Jooble when we use them) to fetch live listings. GOV.UK Teaching Vacancies and Remotive listings are fetched in bulk and filtered on our side, so they receive nothing about your search. Careerjet also requires the IP address and browser details of the person searching, so those are passed to it with your search. No board receives your name, email or CV. When you click a listing, we record the listing (its source, reference, title and link) but not who you are, so we can see which listings are useful. The listing opens on the job board's own site, where its privacy policy applies.
Lawful basis: legitimate interests in running and improving the service.
Job alerts
If you ask for job alerts, we keep your email address, how often you want them, the skill codes and job titles from your results (not your CV), the place you searched and a list of jobs we have already sent you, so we never send the same job twice. The box you tick reads: “Email me new jobs that match my results. I can change how often or unsubscribe with one click in any email.” Every alert email has a link to change or pause the alert, and a one-click unsubscribe, which deletes it.
Lawful basis: consent, which you can withdraw at any time by unsubscribing.
Applying for a job posted here
Some jobs are posted on MatchMySkillset by employers. When you apply for one, you tick a box that names the employer and the job. We then make your name, email address, phone number (if you gave it), CV, note (if you wrote one), your match score and the skills from the advert we found in your CV available to that employer in their MatchMySkillset account, and email them to say you applied. For a job we posted for an employer without an account, we email the application to the address they gave us instead. We keep the application so the employer can see it and so you can ask us about it, and we email you a receipt. Once the employer has your application they are a separate controller and handle it under their own privacy policy.
Lawful basis: consent, given by the tick box, and contract, to send the application you asked us to send.
Letting employers find you
You can choose to create a profile that employers using MatchMySkillset can search. The box is unticked until you tick it, and reads: “Let employers who use MatchMySkillset find my anonymous profile and ask to contact me. They see my headline, job title, region, years of experience and skills, never my name, email or CV, unless I accept their request. I can switch this off or delete my profile at any time.” We keep your first name, email address, headline, job title, town, region, years of experience, skills and, only if you add it, your CV. The profile stays hidden until you switch it on from the email we send you, so we know the address is yours.
Employers see only the headline, job title, region, years of experience and skills. They never see your name, email or CV unless they ask to contact you and you accept, from the link we email you. If you accept, that employer can see your first name, email address and CV (if you added one) in their MatchMySkillset account, we email them to say you accepted, and they become a separate controller for those details. If you decline, they are told, and get nothing about you. You can edit the profile, switch it off or delete it, with your contact requests and our copies of your applications and job alerts, from your private profile link at any time.
Lawful basis: consent, which you can withdraw at any time by switching the profile off or deleting it.
Recruiter shortlists for employers
If you apply to a job, or switch on ‘Let employers find me’, recruiters from Flintstone Associates, our recruitment partner, may review your application or profile to put together shortlists for employers on Growth and Enterprise plans. They only see people who applied for a job here or switched on ‘Let employers find me’, and use what they see only to prepare those shortlists. Employers only see your name and contact details if you applied to them or you accept their request.
A shortlist lists the people a recruiter thinks fit a job best, in order, with a short note on each. If you applied to that employer, they see your application as described above. If you did not, they see only your anonymous profile (headline, job title, region, years of experience and skills) and the recruiter's note, which must not identify you (we also remove your first name, email addresses, phone numbers and links from it); to talk to you they have to send a contact request, which you can accept or decline. The recruiter reviewing a profile sees the profile and, if you added one, your CV. Your place on a shortlist, and the note about you, are deleted when your application or profile is deleted, and a profile you switch off stops showing on shortlists straight away.
Lawful basis: this is part of sending your application or showing your profile to employers, so it rests on the same consent, which you can withdraw as described above.
Security and abuse prevention
Our hosting provider receives your IP address and browser details with every request, as any website does, and keeps server logs for a short period. To stop automated abuse, we count requests per IP address. We store only a scrambled (keyed hash) version of the address for this, and delete it within 24 hours.
Lawful basis: legitimate interests in keeping the service secure and available.
Analytics
With your consent, we use Google Analytics to understand how people use the site, such as which pages they visit and whether they complete a check. We also use Vercel Web Analytics, which does not use cookies and reports only aggregated figures such as page views.
Lawful basis: consent for Google Analytics cookies; legitimate interests for aggregated, cookieless statistics.
3. Sensitive information in your CV
CVs often contain more than work history. Please remove anything you would rather we did not process before you submit, especially information about your health or disability, ethnicity, religion or beliefs, sexual orientation, political opinions, trade union membership or criminal record. We do not need any of it, and it plays no part in your matches. If it is included, it is sent to Anthropic with the rest of the text for the analysis and is not stored by us afterwards.
4. Who we share it with
We use these service providers. They process data on our behalf and under our instructions, except where noted.
- Anthropic, PBC (United States): analyses your CV text or job title. By default Anthropic does not use data sent through its API to train its models, and it deletes API inputs and outputs within 30 days, except where it has to keep them longer to enforce its usage policies or by law.
- Vercel Inc. (United States): hosts the website, keeps server logs and provides cookieless web analytics.
- Supabase: stores your results and purchase records in a database hosted in the European Union (Ireland).
- Resend (United States): sends the emails you ask for, including job alerts and the application and contact emails we send to employers for you.
- postcodes.io (a free service from Ideal Postcodes): receives the place names and postcodes typed into the location box, from our server, to suggest places and find the region.
- Employers who post jobs on MatchMySkillset: only when you apply for their job or accept their request to contact you, as described in section 2. They receive your details as separate controllers. Employers on Growth and Enterprise plans may also see your anonymous profile on a recruiter shortlist, without your name or contact details (see “Recruiter shortlists for employers”).
- Flintstone Associates(specialist recruitment firm, our joint venture partner): its recruiters see applications for jobs posted here and profiles people have chosen to make findable (including a CV they added) to prepare recruiter shortlists for employers, as described in “Recruiter shortlists for employers”. Only people who applied or switched on ‘Let employers find me’ are included, and the details are used only for that.
- Stripe: processes payments. For some purposes, such as preventing fraud and meeting its own legal duties, Stripe acts as a separate controller under its own privacy policy.
- Google: Google Analytics, only if you accept analytics cookies.
- Reed, Adzuna, Himalayas, and Careerjet and Jooble when we use them: receive the search words and location you type when you search for jobs. Careerjet also receives your IP address and browser details, which it requires. None of them receives your name, email or CV.
We may also disclose information if the law requires it. We do not sell personal data, and we only share your CV or contact details with an employer when you ask us to.
5. International transfers
Some of these providers process data in the United States. Where they do, the transfer is covered by the UK Extension to the EU-US Data Privacy Framework (where the provider is certified) or by the International Data Transfer Addendum to the EU standard contractual clauses in the provider's data processing terms.
6. How long we keep it
- Raw CV text and uploaded files: not stored by us after the analysis, except inside a job pack you ask for (see CV tools). Anthropic keeps API data for up to 30 days, as described above.
- Results (skills, matches, job title, results link, and your email if you gave it): 12 months, then deleted.
- Purchase records (email, amount, payment reference, report reference): 6 years from the purchase, for tax, then deleted.
- Job alerts: until you unsubscribe, or 12 months after you set the alert up, whichever is sooner.
- Profiles employers can find (including a CV you added): until you delete the profile, or 12 months after you created it. A profile you never switch on is deleted after 14 days. Contact requests are deleted with the profile.
- Applications for jobs posted here: our copy is deleted 12 months after you applied, or sooner if you ask. The employer keeps the copy we sent them under their own policy.
- Hashed IP addresses used for abuse prevention: up to 24 hours.
- Job click records: these contain no personal details.
- Google Analytics data: no longer than 14 months.
- Emails you send us: as long as we need to deal with your message.
7. Cookies and local storage
We only use analytics cookies if you click Accept on the cookie banner. If you do, Google Analytics sets the _ga and _ga_* cookies, which last up to 2 years. If you click Reject, Google Analytics does not load at all. Your choice is saved in your browser's local storage so we do not ask again on every page; that is necessary for the banner to work and does not track you.
Two more things are kept in your browser to make features you use work, not to track you: your latest results link is kept in local storage for up to 30 days so the job search page can show how well each job matches you (you can clear it there with “Stop using them”), and your CV text is kept in session storage for the tab you used until you close it (see section 2). Neither is sent anywhere unless you use it.
Vercel Web Analytics does not use cookies. When you pay, Stripe's checkout page sets its own cookies on stripe.com to process the payment and prevent fraud.
You can change or withdraw your choice at any time: .
8. Automated suggestions
Your career matches and job match scores are produced automatically by software, including an AI model for reading your CV. They are suggestions for you to consider, not decisions about you. When you apply for a job posted here, the employer sees your match score with an explanation of how it is worked out; it is a rough, automatic indicator, and the employer makes its own decisions. Check anything important, such as pay or entry requirements, before relying on it.
9. Your rights
Under UK data protection law you have the right to:
- get a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it, including where we rely on legitimate interests;
- receive data you gave us in a portable format;
- withdraw consent at any time, for example to analytics cookies.
To use any of these rights, email hello@matchmyskillset.com. As there are no accounts, please include your results link or the email address you used, so we can find your data. We will reply within one month.
10. Complaints
If you are unhappy with how we have handled your data, please tell us first at hello@matchmyskillset.com. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint or 0303 123 1113.
11. Children
The site is designed for adults thinking about their careers and is not aimed at children.
12. Changes to this policy
If we change how we use personal data, we will update this page and the date at the top. See also our Terms of Service.
If you use the CV tools (job packs, Plus and accounts)
This part covers the optional CV tools: a tailored CV, cover letter and interview prep for one job (a “job pack”, £2.99 or your one free tailored CV), the £7 a month Plus plan, and job seeker accounts. Matching your CV to jobs does not need any of this.
What we collect and why
- Your account (optional): your email address, when you signed up and last signed in, your plan, whether you have used your free tailored CV, and the choices you make in your account settings. Sign-in is by an emailed link: links and sessions are stored only as a scrambled (hashed) version; a link works once, within 20 minutes, and a session lasts 30 days. Lawful basis: our contract with you, and our legitimate interest in keeping accounts secure.
- Job packs: the job advert, the CV text you gave us for that pack, and what we wrote (your tailored CV, including the name and contact details from your CV, the cover letter, the interview prep, the gaps and our check notes), plus any edits you make. We keep the CV text inside the pack so we can finish, redo or add to it; it is deleted with the pack. Lawful basis: our contract with you.
- A saved CV, only if you tick “Keep this CV on my account”. You can delete it from your account at any time. Lawful basis: your consent.
- Results pages linked to your account, when you open them while signed in, and your employer profile if you have one (found by your email address), so your account can show them. Lawful basis: our contract with you.
- Usage counts: when you use a Plus job pack or Check any job, so we can apply the fair use limit of 30 packs a billing month. Lawful basis: our contract with you.
- Optional settings: application tracking (keeping a record of jobs you apply for and asking you afterwards how they went) and news emails are off unless you switch them on, and you can switch them off at any time. Lawful basis: your consent.
- Payments: Stripe handles card details; we never see them. We keep the Stripe customer and subscription references, your plan, when it renews, and a record of each payment. Lawful basis: our contract with you, and our legal duty to keep tax records.
How a job pack is written
We send your CV text and the job advert to Anthropic, PBC (United States), the company behind the Claude AI model, which writes the pack. We also send a list of the advert's skills that our own software found in your CV. Anthropic acts as our processor and, by default, does not use data sent through its API to train its models; it deletes API inputs and outputs within 30 days, except where it has to keep them longer to enforce its usage policies or by law. Our own checks then take out anything the pack says that is not in your CV. The pack is a draft for you to check and edit; it is not a decision about you.
Who else sees it
Nobody, unless you send it. We do not send your pack to employers: you download it and use it as you choose. The same service providers as the rest of the site store and send it (Supabase stores it in the European Union; Vercel hosts the site; Resend sends your sign-in links and pack emails), and Stripe processes payments.
How long we keep it
- Job packs in an account (with the CV text inside them): while your account exists. You can delete any pack at any time; deleting your account deletes them all.
- Job packs bought without an account: 12 months from the purchase, then deleted. You can delete one sooner from its page. If you later sign in with the email address the pack was sent to, it moves into your account and is kept as above.
- Packs started but never paid for: deleted after a day.
- Your saved CV: until you delete it or your account.
- Your account, usage counts and linked results list: until you delete your account. Deleting your account also deletes the linked results pages if you leave that box ticked.
- Payment records (email, amount, date and Stripe reference): 6 years from the payment, for tax, even after you delete your account.
Cookies and browser storage
Signing in sets one cookie, mms_candidate, which keeps you signed in for up to 30 days. It is strictly necessary for the account to work, so it is set without asking. An advert you pass from Check any job to the tailor page is kept in your browser's session storage for that tab only.
Your rights
In your account you can download everything we hold for it (“Download my data”), delete your saved CV, delete any pack, and delete the whole account. For anything else, or a pack bought without an account, email hello@matchmyskillset.com. See also the MatchMySkillset CV tools terms.
Application tracking, outcomes and placements
We follow what happens after people apply, so you can keep track of your applications and so we can see whether the service leads to interviews and jobs. This part explains what that involves.
When tracking starts
- When you apply for a job posted on MatchMySkillset. The apply form says: “We'll email you at 7 and 21 days to ask how it went. You can stop these any time.” The application is added to a private application tracker for your email address.
- When you tell us you applied for a job on another site.After you open a job from your results or the job search, the card can ask “Did you apply for this job?”. Nothing is tracked unless you say yes and, if we do not already have it, give your email address next to the same notice. The first time, we email you the private link to your tracker.
What we keep for each tracked application
Your email address; the private tracker link; the job's title, company, location, link, pay (if the advert showed it) and the job site it came from; the results link you came from, if any; when you applied; how it stands (applied, no response yet, interview, offer, got the job, or withdrawn); when we sent check-in emails and whether you stopped them; and the family of work (for example “IT and software”) we work out from the job title. Anyone with your tracker link can see and change your tracker, so keep it private.
“Did you hear back?” emails
We email you 7 and 21 days after you apply, from jobs@matchmyskillset.com, with one-tap answers: no response yet, interview, offer, or placed. Opening a link records nothing; your answer is saved only when you press Confirm on the page it opens. Every email lets you stop asking about that job, or stop all check-in emails (your email app's unsubscribe button does the same). We stop asking once you tell us you got the job or withdrew.
What employers see
Employers who post jobs here can mark where your application to them stands: viewed, shortlisted, interview, offer, hired or not taken forward. We record each change. For a job you applied to through MatchMySkillset, the employer also sees your own answer to a check-in, but only if it is interview, offer or placed, shown as “Candidate says: interview” (or offer, or placed) next to your application. Employers never see your tracker, your other applications, outside jobs you track, or an answer of no response or withdrawn.
Our journey records
We keep a log of these steps (applications, status changes, check-ins sent and answered, placements and case-study answers) so our team can count how many applications lead to interviews, offers and jobs, by period, family of work and employer. The log holds no names or email addresses: where it needs to link steps for the same person, it holds a scrambled version of the email address made with a secret key, which cannot be turned back into the address without that key.
Placements and case studies
When an employer marks you hired, you tell us you got the job, or our team records it (for example when you or the employer tells us directly), we record a placement: the job title, company, location, family of work, which employer account it was with, who confirmed it and when, and your email address.
About a day later we send one separate email asking: “Can we mention your move, anonymised, in our case studies?”. It links to a page with a box that is not ticked, which reads: “Yes, MatchMySkillset may mention my move in its case studies and marketing, without my name, contact details or anything else that identifies me. I can withdraw this at any time from this page.” We save your answer with the time and that exact wording. Unless you tick it, we do not use your placement in any marketing; if you do, we still never name you or say anything that identifies you. You can change your answer at any time from the same link. Separately, placements are counted, as numbers only, in our internal totals.
Lawful basis
- Tracking a job you tell us you applied for, and emailing you about it: your consent, which you can withdraw by stopping the emails or deleting it.
- Check-ins for applications made through MatchMySkillset, employers' status updates, the journey records and placement records: our legitimate interests in following up applications made through our service and measuring whether it works. You can stop the emails at any time and object by emailing us.
- Case studies: your consent, given by ticking the box, which you can withdraw at any time.
How long we keep it
- Tracked applications: 12 months after you add them, or sooner if you delete them from your tracker page.
- Journey records: 24 months. They contain no names or email addresses.
- Placement records: 6 years, because a placement can be the basis of a pay-per-hire fee to the employer, which we keep for tax. Your email address is removed from the placement 12 months after it is recorded. Your case-study answer is kept with the placement.
Your choices
From your tracker page you can update, stop check-ins for, or delete any application, or delete the whole tracker. Deleting your “Let employers find me” profile also deletes tracked applications for the same email address. The emails are sent through Resend and the records are stored with Supabase, the providers listed above. For anything else, including a copy of your data, email hello@matchmyskillset.com. See also the terms for the tracker.
If you use MatchMySkillset as an employer
This part covers people who open an employer account to post jobs or contact candidates, and people who send us an employer enquiry.
What we collect and why
- Your account: your work email address, your name, your company name and website, the text of your company page if you have one, and when you accepted the employer terms. We use them to run your account and show your jobs. Lawful basis: our contract with you.
- Signing in: sign-in links and sessions are stored only as a scrambled (hashed) version. Sign-in links expire after 20 minutes and are cleared out regularly; sessions last 30 days. Lawful basis: our contract with you, and our legitimate interest in keeping accounts secure.
- Jobs you post: everything in the job form, the skills we find in it, and how many times it is viewed. Job seekers see your jobs, and your company page if you have one.
- Payments: Stripe handles card details; we never see them. We keep your Stripe customer and subscription references, your plan and when it renews, the monthly price you pay, and any partner rate we have agreed with you. Lawful basis: our contract with you, and our legal duty to keep tax records.
- Applicant status and placements: each status you give an applicant (viewed, shortlisted, interview, offer, hired or not taken forward) and when, and a placement record when you mark someone hired (job, your company, dates). We use them to measure how well the service works; the log of status changes names no one. Lawful basis: our legitimate interest in running and improving the service.
- Enquiries: what you send through the enquiry form, so we can reply. Lawful basis: our legitimate interest in answering you.
- Contact requests: the message you write and which candidate and job it is about. We email it to the candidate with your company name.
- Recruiter shortlists (Growth and Enterprise):whether you asked for one for each job, and the shortlist itself: who was picked, in what order, the recruiter's notes and summary, and when it was asked for and sent. Recruiters from Flintstone Associates, our recruitment partner, see the job and its applicants to put it together, but not your plan or billing details. Lawful basis: our contract with you.
Cookies for employers
When you sign in we set one strictly necessary cookie, mms_employer, which keeps you signed in for 30 days. It is marked httpOnly, so page scripts cannot read it, and signing out removes it. It is not used for tracking.
Who else handles it
The same service providers listed above: Supabase (database), Vercel (hosting), Resend (sign-in links and notification emails) and Stripe (payments). We also send ourselves short alerts on Telegram when an employer signs up, submits a job, sends an enquiry, changes plan, or has a recruiter shortlist requested or sent; these name the company, not the person.
Candidate details you receive
When a candidate applies to your job or accepts your contact request, we share their name, contact details and CV with you at their request. From then on you are a separate controller for that copy and must handle it under UK data protection law and our employer terms. We keep applications for 12 months from when they were made, then delete them.
How long we keep employer data
- Your account, jobs and company page: while your account is open. Ask us to close it and we delete them within 30 days.
- Billing records: six years from the payment, for tax.
- Enquiries: as long as we need to deal with them.
Your rights are the same as everyone's (see “Your rights” above). For anything about an employer account, email jobs@matchmyskillset.com.