Skip to content
YoungNug
For employersLog inSign up

Privacy Policy

Last updated 14 August 2026 (corrected against what the code actually does: read/thumbs/hidden markers on jobs, ranking personalisation, the browser hash in a consent record, and the full list of who receives anything; added the 30-day recoverable deletion window and the narrowed export; rewrote the erasure sections when closing an account became a request we acknowledge and record rather than a button, which did not change what happens or how fast it happens; and added the conditional Indeed sections: the recipient entry for employer listing publication, the record we would hold if Indeed ever delivered applications to our employers, the retention limit on applicant records held for employers, and the rights channel for people without an account)

YoungNug Privacy Policy

YoungNug helps UK students find jobs and build tailored CVs and cover letters. That means we hold information about you, including your education record, and we take that seriously. This notice explains what we collect, why, what we do with it, and the rights you have over it. It is written to be read, not skimmed past. If anything is unclear, ask us through the in-app Feedback form.

1. Who we are

YoungNug is the data controller for the personal data described in this notice. The service is operated by its developer in the United Kingdom and is registered with the Information Commissioner's Office under registration number C1986274. The full registered controller details appear on the ICO's public register of data controllers under that number. You can contact us about anything in this notice through the Feedback form inside the app (Settings, then Feedback).

2. Who this service is for (age 15 and over)

YoungNug is for students aged 15 or over. We check your date of birth at sign-up and refuse accounts below 15. UK law sets 13 as the age at which a young person can consent to online services themselves (UK GDPR Article 8), so users aged 15 to 17 can hold a YoungNug account without parental permission.

Because many of our users are under 18, we follow the ICO's Age Appropriate Design Code: privacy-protective settings are the default for under-18s and for anyone whose age we do not know. For those accounts the activity log described below is off unless you opt in. For adult accounts we keep a minimal record of the core actions your account completes (see "Essential activity records" below), with a one-click off switch in Settings. Optional behavioural analytics are off unless you turn them on, for everyone.

Two things are true for every account, whatever your age and whatever you choose, and we would rather say so here than have you find out later. First, your job list remembers what you did to it: which listings you opened, which you gave a thumbs up or down, and which you hid. That is how read-and-unread works, how "not for me" survives the next collection, and how your list stops showing you more of what you rejected. Second, the order of that list adapts to those signals. You can switch the adapting off in Settings, and it is described under "Ranking personalisation" below. Neither is used for advertising and neither leaves our systems.

Your date of birth is used only for the age check and to suggest a sensible starting study level. It is stored encrypted and is never printed on a CV, cover letter, or any document.

3. What we collect

We only collect what the service needs to work:

  • Account data: email address, password (stored only as a one-way argon2 hash, we cannot read it), full name, date of birth, and your consent record. A consent record stores the choice you made, when, which version of the banner you saw, and a short one-way hash of your browser's user-agent string. That hash exists so we can tell one browser's choice from another's when a record is questioned; it cannot be turned back into your browser details and we do not use it for anything else.
  • Profile data you add: education history (schools, colleges, university, GCSE, A-level, BTEC and degree results, modules and grades), work experience, volunteering, projects, skills, achievements, certifications, links you choose to share (for example GitHub or LinkedIn), and your job preferences.
  • Home address (optional): if you add it, it is used as the sender block on your cover letters, and your town or city (never the street or postcode) appears in the location line of your CV, which is where employers expect it. If you use the browser extension to fill in an employer's application form, the address you saved is one of the things it offers to type into that form, in your own browser, on a form you are filling in yourself. Leave the field blank if you would rather none of that happened.
  • Home location (optional, off by default): if you switch on the Location setting, we store your postcode and the single map position (latitude and longitude) that postcode resolves to. That is postcode-level only, never GPS, and never movement tracking (data minimisation under the Children's Code). It is used for two things: centring your job map on home, and showing how far each job is from you as one labelled part of its suitability score. Switching the setting off deletes the stored postcode and coordinates immediately.
  • Job-search activity: jobs collected for you, saved and skipped jobs, applications and their stages, interview notes, generated CVs and cover letters and your edits to them. On each job in your own list we also store when you first opened it, your thumbs up or down if you gave one, and whether you hid it. These are markers on your own job rows, not a browsing log: they exist so read-and-unread works, so a hidden job stays hidden after the next collection, and so the list can stop showing you more of what you rejected. They are part of the service rather than analytics, so they are not behind the cookie banner; they are deleted with your account and are in your data export.
  • Ranking personalisation: the order of your job list adapts to what you have applied to, thumbed and hidden. It only ever re-orders jobs you would have been shown anyway; it never hides a job from you, never changes the suitability score or its reasons, and never uses anything about who you are. It is on by default and you can switch it off, or reset what it has learned, on the Jobs page. Nothing about it leaves our systems.
  • Essential activity records: for adult accounts we keep a minimal record of the core actions your account completes, for example that a CV was generated, an application was submitted, a networking contact was added, or a document was deleted. Each record holds the action, what it was about, when it happened, and occasionally one small technical detail such as how many milliseconds a generation took. They never hold your browsing history, your searches, or anything you type. We use them to run and improve the service (our legitimate interests; the assessment is documented). You can turn this off with one click in Settings, and doing so also deletes what we hold. For under-18s, and for any account whose date of birth we do not hold, these records are OFF unless you opt into usage counts yourself.
  • Optional usage events: if (and only if) you accept optional analytics in the cookie banner, we record first-party counts of which pages and features you use and job interaction events, to improve the product and your job matching. Page records store the path of the page you were on. Reading time is recorded only as a coarse bucket (for example "under 30 seconds" or "2 to 10 minutes"), never as a precise duration, and we never record keystrokes or the words you type. Nothing is ever recorded for advertising. Today these counts stay on our own systems and go to no one else. We have not switched on any third-party analytics tool; if we ever do, we will name the provider (for example Google Analytics) as a processor in section 7, describe the cookies it sets in section 12, and ask for your consent again before it starts.
  • Technical data: IP address and request logs, used for security, abuse prevention and rate-limiting; short-lived session tokens.
  • Employer accounts: employers who register to post roles give us their company name, an optional website and Companies House number, and the contact person's name, work email and (optionally) phone number. This is business contact data, held to run the employer account, to let our moderators check listings are genuine, and to answer the account about its submissions. The contact name and phone number are encrypted at rest like every other personal field. Employer accounts have the same export and delete-my-account rights as every account; the listings themselves belong to the public job corpus, so deleting an employer account removes the account's data but does not silently unpublish roles students may be acting on.
  • Applicants who apply on Indeed (none yet): employers will be able to ask us to publish one of their listings on Indeed (section 7 explains what that shares, and with whom). If Indeed ever delivers applications for such a listing back to us, each one arrives with the applicant's name, email address and the answers they gave in Indeed's own apply form. We hold that record on the posting employer's behalf, so the employer can read and manage all of their applications in one place: the recruitment is the employer's, and for this record the employer is the controller of their own hiring while we store and display it for them. The record is encrypted at rest exactly like an application a YoungNug student sends, it is never shown to any student or any other account, and it is removed on the schedule in section 9. If you applied on Indeed and have no YoungNug account, section 10 explains how to exercise your rights over this record without one. None of this has happened yet: the Indeed connection is not switched on and we hold no such records today. This entry exists so the first person it ever applies to was told before it happened, not after.

We do not ask for and do not want special category data (such as health, religion, or ethnicity). Please do not put it in free-text fields.

4. Why we can use it (lawful bases)

| Purpose | Lawful basis (UK GDPR Art. 6) | |---|---| | Running your account, storing your profile, generating your documents, tracking your applications | Contract (6(1)(b)): this IS the service | | Age checks and privacy-protective defaults for under-18s | Legal obligation and legitimate interests (Children's Code compliance) | | Security logs, rate-limiting, abuse prevention | Legitimate interests (6(1)(f)): keeping the service safe | | Essential activity records (core feature-outcome counts, adult accounts) | Legitimate interests (6(1)(f)): minimal, expected, documented; one-click off in Settings which also erases | | Optional usage analytics and behavioural job-matching signals | Consent (6(1)(a)): off by default, withdraw any time | | Read, thumbs and hidden markers on the jobs in your own list | Contract (6(1)(b)): read-and-unread, "not for me", and not re-showing what you rejected are the list working as described | | Ranking personalisation (re-ordering your list from what you applied to, thumbed and hid) | Legitimate interests (6(1)(f)): it only re-orders jobs you would see anyway, never changes a score, and has an off switch and a reset | | Optional home location (postcode and its coordinates) for the job map and commute distance | Consent (6(1)(a)): off by default; switching it off deletes the stored data | | Optional profile imports (GitHub, or your own LinkedIn page read by the extension in your own browser) | Consent (6(1)(a)): each import is an explicit action you take, and lands as a draft you review before anything is kept | | Signing in with Google, if you choose to | Consent (6(1)(a)): only if you press the Google button; email and password sign-in works without it | | Sharing your application with an employer when you apply through YoungNug | Consent (6(1)(a)): a per-application consent step that lists exactly what will be shared, given before anything is sent | | Running employer accounts (business contact data, moderation of listings) | Contract (6(1)(b)) with the employer, and legitimate interests (6(1)(f)): keeping fake listings away from students |

5. What we never do

  • We never share your data with data brokers.
  • We never use it to train models for anyone else.
  • We never post or submit anything on your behalf without your explicit approval. Approving is the only thing that starts an application, and it always names the jobs it covers: one when you approve one, and the list you ticked when you approve several at once.
  • We never take a payment you have not seen and agreed to first (see the Terms, section 7). Under-18s cannot buy a plan at all, so if you are 15 to 17 we hold no payment details for you.

6. Automated decision-making

YoungNug computes a suitability score (0 to 100) between your profile and each job, and shows you the full breakdown with reasons for and against. This is advisory only: you decide where to apply, and no decision with legal or similarly significant effect is ever made about you solely by automation (UK GDPR Article 22). The score never uses protected characteristics.

7. Who else sees data (processors and recipients)

  • Job listing sources (Adzuna, Reed, public employer career sites and applicant-tracking systems such as Greenhouse, Companies House): when we collect jobs for you we send search terms and nothing that identifies you: no name, no email, no account id. Those search terms are built from your profile, so in practice they can include your town or city, the industry you said you were aiming at, and your two strongest listed skills. If you would rather a source did not see your town, leave the city field blank; the collection still runs.
  • Employer background and logos (Wikipedia, Wikidata, Wikimedia Commons, and the employer's own website or careers page): to show a company summary and logo on a job, our server fetches them by employer name or logo address only. Nothing about you is sent, but the request happens because you looked at that job, so those sites see our server, not you.
  • Postcode lookup (postcodes.io): if you switch on the optional Location setting, we send only your postcode to this free UK service to find its map coordinates. Your identity is never sent with it, and nothing is sent at all while the setting is off.
  • Document generation runs on the service's own infrastructure. Your profile is not sent to third-party AI services.
  • The employer who posted a role, when you apply to it through YoungNug: some roles are posted to us directly by employers (they are labelled "Posted directly by the employer"). If you choose to apply to one inside the app, the posting employer receives exactly what the consent step listed and nothing else: your name, your contact email, and the CV and cover letter you generated for that job (each only if it exists; the consent screen says which). You are told all of this at the consent step, before anything reaches the employer, and nothing is sent unless you confirm. What is shared is a copy taken at that moment, so your later edits and documents stay yours. Applying on an employer's own website (the normal apply route for every other job) sends them nothing through us. The employer is a separate data controller for the application you send them, exactly as if you had emailed it to them yourself.
  • Indeed (operated by Recruit Holdings), if an employer chooses to post a listing there: employers can ask us to publish one of their approved listings on Indeed. When an employer does, the listing content and the employer contact details carried with the posting (the company name and the employer's contact email address, which Indeed requires with every posting) are shared with Indeed as a recipient. This is employer listing data only: nothing about any student, and nothing about any applicant, is ever sent to Indeed by us. The capability exists in the product today but has transmitted nothing so far, because the connection works only once our application to Indeed's partner programme is approved. This entry is here so the recipient is named before the first listing ever leaves, not after.
  • Email: we send you transactional emails such as address verification and password reset. Delivery goes through Google (Gmail SMTP), which acts as our processor and receives only your email address, your first name and the message being delivered. Brevo remains configured as a fallback provider and is listed here for as long as that remains true. We do not send you marketing email.
  • Google, if you choose to sign in with Google: pressing the Google button sends your browser to Google to sign in, and Google therefore knows you hold a YoungNug account. We receive back your Google account identifier, your email address and your name; we never receive your Google password and we ask Google for nothing else. This only happens if you press that button; email and password sign-in never involves Google.
  • Payments (Stripe): if you ever start a checkout, Stripe receives your email address and a reference to the plan. Nothing is charged today.
  • Analytics: we currently use no third-party analytics service, so no analytics provider receives your data. If we ever switch on a third-party analytics tool (for example Google Analytics), we will name it here as a processor, describe the cookies it sets in section 12, and ask for your consent again first.
  • If we are legally required to disclose data (for example by a court order), we will, and where lawful we will tell you.

Your data is stored in the United Kingdom. The one exception is email: our email provider may store a verification or reset message on its own servers, which for Google may be outside the UK; Google provides UK-recognised safeguards for such transfers (the UK Addendum to the standard contractual clauses), and the message carries only what section 7 describes. We do not otherwise transfer your data outside the UK.

8. How we protect it

  • Passwords are hashed with argon2; we can never read them.
  • Personal profile data, your name, date of birth and home address are encrypted at rest (Fernet/AES).
  • Every account's data is isolated: the server checks ownership on every request, so no other user can ever read your rows.
  • Sessions use short-lived tokens and httpOnly cookies; all auth endpoints are rate-limited; the production service runs over HTTPS only.

9. How long we keep it (retention)

  • Account and profile data: kept while your account exists. You close your account by asking us to, in Settings under "Delete my account". We act on the request as soon as it arrives: the account is deactivated straight away (nobody can sign in to it, every signed-in device is signed out, and it does not appear anywhere on the service) and we schedule permanent erasure 30 days later, or sooner if 30 days would fall outside the one calendar month the law gives us. We tell you that exact date on screen and again in an email that contains a link to bring everything back if you change your mind. On that date every row you own (profile, jobs, applications, documents, activity records, messages) and every file we generated for you are erased. There is no copy after that.

If you do not want the 30 days, you do not have to have them: the same screen offers erase everything now, and that is immediate and final. Waiting is an option we offer you, never a delay we impose on you.

Asking rather than clicking does not make it slower and it does not mean waiting for a human. We email you an acknowledgement of the request with a reference number the moment we receive it, the deactivation or the erasure has already happened by then, and we record the request with its statutory deadline so that a request we failed to complete would show up as a compliance failure on our side rather than being forgotten. - Generated documents: kept while your account exists so your application history stays complete. The .docx and .pdf files themselves are erased along with the rows, not left behind on disk. - Security logs: kept for a short rolling window for abuse prevention. - Consent-gated usage events: kept while your account exists, deleted with it, and you can withdraw consent at any time to stop new recording. - Home location: kept only while your Location setting is switched on. Switching it off deletes the stored postcode and coordinates immediately (deleting your account does too). - Applications you sent to employers through YoungNug: the shared copy is kept while your account exists, so both you and the employer can refer back to what was sent. Deleting your account deletes it everywhere, including from the employer's view inside YoungNug. We cannot recall a copy the employer has already downloaded or acted on, the same as any application you send anywhere. - Employer account data: kept while the employer account exists and deleted with it. Listings the account posted stay in the corpus (see section 3), with the link to the deleted account removed. - Applicant records we hold for employers: an application an employer receives through YoungNug stays available to them while their recruitment is live. Once the recruitment has concluded (the applicant was rejected or offered the role, or the listing has closed), an automatic daily sweep clears the record once it is older than 365 days, and the operator can configure a shorter window. For an applicant who came from Indeed the whole record is deleted, because it exists only as the employer's hiring pipeline. For an application a student sent through YoungNug, the employer's access to it is removed while the student's own copy stays in the student's account, because it is the student's application history (see "Applications you sent to employers through YoungNug" above). A recruitment that is still live is never touched, whatever its age.

10. Your rights (and the buttons that actually do them)

You have every UK GDPR data-subject right, and the two big ones are wired directly into the app:

  • Access and portability: Settings, then "Export my data" downloads your personal data as readable JSON, decrypted: your profile, your documents, your applications and tracker, your messages to us, your consent records, and your job list with what you did to each job.

Some things are deliberately left out, and the file says so at the top and gives a reason for each. We leave out anything that is a credential (password hashes, sign-in tokens, the identifier Google uses for you), file paths on our servers, internal keys, and the full advertising text of the job listings themselves. A job advert is the employer's writing, not information about you, and each listing keeps its title, employer and link so you can still find it. If you want something we left out, ask through the Feedback form and we will give it to you. - Erasure: Settings, then "Delete my account", then "Request account deletion". You choose between closing the account with a 30-day window to change your mind, and erasing everything immediately. Either way we ask you to confirm who you are first, with your password, or with a fresh Google sign-in if that is how you sign in. That check is there so that somebody else at your computer cannot close your account.

There is no separate form to find, nobody asks you why, and nothing is offered to talk you out of it. The request is acted on when you send it, and the acknowledgement email with your reference number arrives immediately. If you chose "erase everything now", everything is already gone by the time you read it. - Rectification: edit anything in your Profile at any time. - Withdraw consent: change your cookie choice from the banner or footer at any time; analytics recording stops immediately. For home location, switch the Location setting off in Settings, and the stored postcode and coordinates are deleted there and then. - Restriction and objection: contact us via the Feedback form and we will action it within one month. - If you do not have a YoungNug account (for example, you applied to one of our employers on Indeed): every right above still applies to any record we hold about you. Email [email protected] from the address your application used, saying what you want: a copy of the record, a correction, or its erasure. Because there is no account to sign in to, we verify it is really you before acting: we reply only to the address the record itself holds, and we may ask you to confirm a detail of the application that only its author would know. Where we hold the record on an employer's behalf, we action your request against that record and it takes effect for the employer too.

We respond to any data-protection request within one calendar month, free of charge.

11. Complaints

From 19 June 2026 UK law gives you a formal right to complain to us first and have it handled properly (Data (Use and Access) Act 2025). Raise a complaint through the in-app Feedback form marked "privacy complaint" and we will acknowledge it within 30 days and respond without undue delay.

You also always have the right to complain directly to the UK regulator:

> Information Commissioner's Office (ICO) > Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF > Helpline: 0303 123 1113 | [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/)

12. Cookies

YoungNug sets two essential first-party cookies and stores a little data in your browser. The cookies are the sign-in cookie that keeps your session alive (it is httpOnly, so page scripts cannot read it) and a small cookie recording your cookie choice so we do not ask again. In your browser's local storage we also keep where you had got to in the sign-up walkthrough and the job filters you last used, so the app looks the same when you come back. That is your browser's storage, not something sent to us, and clearing your browser data clears it. Essential cookies and storage of this kind do not require consent (PECR). Optional first-party analytics are controlled by the consent banner and are declined by default. Today there are no advertising cookies and no third-party cookies at all. If we ever switch on a third-party analytics tool such as Google Analytics, it would set its own cookies (for example the `_ga` cookies); we would list them in the cookie notice and ask for your consent again before that happened. The full breakdown is in our cookie notice inside the consent banner.

13. Changes to this notice

If we change what we collect or why, we will update this notice, change the date at the top, and flag material changes in the app before they take effect.

See also Privacy Policy · Terms of Use · Ads

Privacy PolicyTerms of UseAdsWhat's new
ICO registration C1986274

Cookie choices

One essential cookie keeps you signed in and secure. You can also let us count which features you use to improve YoungNug. Turning that off later deletes what we recorded.

Adult accounts also keep a minimal record of core actions, like generating a CV. Turn off in Settings.

We show no ads and set no third-party cookies. Why · Privacy Policy · Terms