Job Opportunities API

Check the data. Then trust it.

Cookies

This site sets no advertising, analytics or cross-site cookies. Not fewer than most — none. What is left is five small ones that make signing in work, and they are listed below.

Every cookie this site can set

NameWhat it is forLifetime & flags
joa_sessionKeeps you signed in after you click the link in your sign-in email. Without it you would be signed out on every page.30 days · HttpOnly · Secure · SameSite=Lax
joa_nextRemembers the page you were heading to when you asked to sign in, so you land back there instead of the home page. Erased the moment you arrive.10 minutes · HttpOnly · Secure · SameSite=Lax
joa_adminThe operator's own session for the admin dashboard. It is never set for customers.12 hours · HttpOnly · Secure · SameSite=Lax
joa_consentRecords that you have seen the notice at the bottom of the page, so it does not follow you around the site.400 days · Secure · SameSite=Lax
joa_consent_idA random identifier — no name, no email, no account reference — that lets us show you the record of what you were told, and lets you withdraw it.400 days · Secure · SameSite=Lax

HttpOnly means your browser will not let any script read it, including ours. Secure means it is never sent over plain HTTP. SameSite=Lax means it is not sent when another site links into ours.

What this site does not set

  • No advertising cookies. No cross-site or third-party tracking cookies of any kind.
  • No analytics cookies. There is no Google tag, no PostHog browser SDK, no Hotjar, no Segment, no Plausible — no measurement script of any kind runs in your browser on this site.
  • No fingerprinting, no session replay, no scroll or mouse tracking.
  • Nothing is set at all until you do something. Load the ledger, read a listing, browse the pricing page: the server returns no Set-Cookie header. You can check that yourself with your browser's network tab, and we would rather you did.

Why there is no Accept / Reject banner

  • Because you would be choosing between two identical outcomes, which is not a choice.
  • Under the ePrivacy Directive (art. 5(3)) consent is needed to store or read anything on your device — unless it is strictly necessary to provide the service you asked for. Every cookie in the table above is in that exception: a session you asked for by signing in, a redirect you asked for by clicking sign in, a notice you asked to stop seeing.
  • So there is nothing here to accept or reject, and we will not present a banner that implies otherwise. Dismissing the notice does not switch anything on or off — it only stops the notice reappearing.

What is recorded when you dismiss the notice

  • That a disclosure of this version was shown and acknowledged, the random identifier above, the page you were on, and your browser's language.
  • A one-way hash of your IP address and of your user agent — kept so the record cannot be repudiated, and so that neither can be read back out.
  • It is held by our own consent service on our own infrastructure, and it is append-only: we can add to it, and we cannot quietly rewrite it. That is the point of keeping it.

What the server records, cookie or no cookie

  • Ordinary web server logs — request path, timestamp, and an IP address — kept to keep the service up and to stop abuse. This happens on every website you have ever visited and is not done with cookies.
  • When you take an action on your account — sign in, subscribe to the newsletter, start a checkout, write to us, submit a listing, create or rotate an API key — we record that the action happened, against your email address. This is how the business runs; it is not browsing history, and nothing is recorded when you are only reading.
  • Those event records are processed for us by PostHog, on their EU infrastructure. The full list of who processes what is on the privacy page.

Some listing fields are machine-generated — the AI disclosure says which. For everything else, see Privacy, or write to us.