Skip to main content

Privacy

Local by default. Sync only when you choose it.

Browsing, saving roles, tracking applications, saved searches, and in-app alerts work without an account and start in this browser. Where account continuity is configured, signing in still uploads nothing until you explicitly select data categories and sync.

Last updated July 26, 2026

On your device

Browser persistence

Timley uses your browser's local storage for these records. It does not silently send personal notes, contact information, saved searches, or alert history to a server.

Filter preferences

timley:filters:v1

Your job filters. URL query parameters take priority when they are present.

Filter update time

timley:filters:updated-at:v1

When optional continuity handles filters, this adjacent timestamp lets the newest local or cloud filter set win without changing the established filter value.

View preference

timley:view

Your card or table density choice.

Tracker view preference

timley:tracker-view:v1

Your list or board choice for the application workspace.

Saved jobs

timley:saved

The application URLs you chose to bookmark. These URLs are included in a JSON backup you create.

Application workspace

timley:applications:v3

Your stages, dates, next actions, interview dates, personal notes, optional contact, compensation notes, location or work arrangement, and application URL. Older Timley stage and saved-job records are migrated locally when present.

Saved searches

timley:saved-searches:v1

The names, complete filters, frequencies, and channel choices you save. These are not included in a Tracker JSON backup.

Saved-search deletion markers

timley:saved-searches:tombstones:v1

Bounded local deletion markers that prevent an older browser-tab write from restoring a search you deleted.

Search-alert inbox

timley:search-alerts:v1

The local in-app inbox, per-search run times, and a bounded role-ID list used to avoid alerting the same role more than once.

Search-alert browser setting

timley:search-alerts:browser-enabled:v1

Whether you explicitly enabled foreground browser notices for saved searches. A search must also have its Browser channel enabled.

Legacy company follows

timley:followed-companies:v1

A bounded list created by the retired company pages. It stays in this browser until you clear local product data.

Browser reminder setting

timley:reminders:browser:v1

Whether you explicitly enabled Timley to use an already granted browser-notification permission.

Reminder deduplication

timley:reminders:last-notification:v1

A local date-and-item marker that prevents Timley from repeating the same foreground reminder that day.

Optional continuity session

timley:continuity:auth:v1

When account continuity is configured and you sign in, Supabase uses this browser key for its persistent PKCE authentication session. It is not created by anonymous browsing.

Per-account sync preference

timley:continuity:preference:v1:<user-id>

For a signed-in account, this stores whether first-sync consent was completed, the selected categories, and the last successful sync time. After consent, selected local changes can sync automatically while Timley is open.

Per-account sync recovery

timley:continuity:recovery:v1:<user-id>

A bounded pre-sync recovery envelope saved before any cloud write. It can include notes, contacts, or compensation notes when tracker data was selected.

Control and deletion

Deleting an application removes that local record from the current browser. Archiving is different: an archived application remains stored locally and is included in later JSON backups. Previously downloaded files remain wherever you saved them until you remove those files.

Clearing Timley's site data, using a private window, changing browsers, or changing devices can make unexported records unavailable. Unless you previously completed an explicit sync of the relevant category, there is no account copy to restore. Create a JSON backup before clearing browser data if you want a portable tracker copy.

Deleting a saved search removes its settings and visible alerts. A bounded role-ID deduplication list remains until site data is cleared so the same role is not alerted twice. Signing out does not clear any of this browser-local data.

If the account workspace offers and you choose Clear local data, Timley removes only its documented product-data and preference keys. It also removes legacy timley:applications:v2 and timley:appliedinputs so they cannot remigrate. The checkbox does not directly clear the continuity authentication session or recovery state; the provider handles its session and removes the deleted account's per-user sync preference and recovery keys after successful account deletion. Timley does not call a broad browser-storage clear or remove unrelated origin data.

Your exports

Backups, calendars, and notifications

These features start with an action you choose in the tracker.

JSON backup

A JSON backup is created as a local download. It includes application records, personal notes, optional contact details, and saved-job URLs so you can restore them later. Treat the downloaded file as private.

CSV and calendar files

CSV and ICS exports are generated as local downloads. Timley does not import them into another service for you. If you import an ICS file, the calendar app you select receives the event details in that file and handles them under its own privacy terms.

Browser notifications

Timley asks for notification permission only after you explicitly choose to enable tracker reminders or saved-search browser alerts. Tracker reminders are best-effort foreground notices in the tracker. Saved-search browser checks run only while the Alerts page is open, including after it returns to focus. Your browser and operating system process the notification content and control how it appears.

Saved-search alerts

While the Alerts page is open, Timley refreshes its server jobs snapshot about every five minutes and on return to focus, then evaluates due searches in your browser. Delivery history retains why a role matched, the triggering search, its frequency, and a filtered results link for both in-app and browser-only matches. Email alerts are scaffolded but unavailable, and Timley does not collect an email address for alert delivery.

Continuity recovery data

A sync plan creates bounded recovery data with the exact selected local state from before the merge and the intended merged state. If a browser write cannot finish after the cloud save, Timley can provide that recovery JSON. It may contain notes or contacts when tracker sync was selected, so treat it as private.

Service data

What Timley processes to deliver the site

Job listing records

Timley's server reads public job repositories and stores normalized listing fields in Supabase. Those records describe jobs and sources; they are not tied to a Timley user account.

Ordinary network metadata

Hosting and data-delivery providers may process routine request information, such as IP address, browser details, timestamps, and requested pages, to serve and protect the site under their own policies.

Privacy-conscious product events

Timley can emit a small, provider-neutral set of product events for search, filters, job actions, saved searches, alerts, sharing, and tracker return visits. Search length and counts are bucketed. Events never include raw search text, saved-search names, company or job identity, public or private URLs, personal notes, contact information, or compensation notes. No analytics network destination is configured by this code.

Optional account continuity

On a configured deployment, Supabase processes your email, authentication session, and the data categories you explicitly select for sync. Selecting tracker data includes application records, personal notes, and optional contacts; Timley warns about those fields before the first sync.

Company images

When a company image is available, your browser may request it from Vemetric's favicon service. Timley uses a no-referrer request and shows a letter fallback when an image cannot be loaded.

Third-party destinations

Source repositories and employer application pages have their own privacy practices. Their policies apply after you follow an external link from Timley.

Optional accounts and device access

Account continuity is available only when a deployment has Supabase authentication, the continuity database table and policies, email delivery, and allowed redirect URLs configured. If any required provider setup is missing, Timley keeps the feature unavailable rather than substituting credentials.

Signing in never uploads browser data by itself. The first sync requires category selection. Merge keeps the newest application record for each role and unions set-like categories. Timley saves the merged cloud snapshot first and updates local data only after that save succeeds; if it fails, the existing browser copy remains available. If a later browser write is partial, the precomputed recovery data preserves both the pre-sync and intended merged states.

Completing the first sync records consent for those selected categories. Later changes to selected data can sync automatically while Timley is open, including after focus returns. Change the category selection before editing if you no longer want a category included.

The selectable cloud categories are saved-job URLs, application records, filter preferences, and saved searches. Search-alert inbox history, delivered-role IDs, browser-notification preferences, and tracker reminder markers are not included in the continuity snapshot. Tracker JSON backup is also separate from account continuity.

Signing out ends the local account session but leaves browser data in place. When the server-side account-deletion credential is configured, deleting an account removes the Supabase account and its continuity snapshot, ends the local session, and removes that account's local sync preference and recovery envelope. Anonymous product data is separate and is cleared only if you make that additional choice. Previously downloaded exports remain wherever you saved them.

Because local tracker data is readable by anyone with access to your browser profile, use your device's security controls on shared computers.