Privacy
Plainly: we collect the least we can, we do not sell it, and you can get rid of it by asking.
What we collect
- If you subscribe to the newsletter: your email address and which topics you chose.
- If you buy or are granted API access: your email address, and a hash of your API secret — never the secret itself.
- If you donate: your email and name, if you give them. Card details go to the payment provider and never reach us.
- If you write to us: your message and the address you gave, so we can reply.
- If you submit a listing: what you typed, plus a one-way hash of your IP address to stop flooding.
What we do not collect
- No advertising or cross-site tracking cookies. The ad slot on this site promotes our own products and is not personalised.
- We do not sell, rent or share your personal data with anyone for their own purposes.
- We never store your API secret in a form we could read, so we cannot recover it for you — and neither can anyone who steals our database.
How it is kept safe
- Everything travels over HTTPS. The site and the API refuse plain HTTP, and certificates are renewed automatically.
- Your API secret is never stored. We keep a SHA-256 hash of it, which is why we can check a key and still cannot tell you what it is — and why a stolen database yields no working keys.
- Card details never reach our servers at any point. Payment happens on the provider's own hosted page; we receive the outcome and an order reference, nothing else.
- Access to the production database is limited to the operator, over an authenticated tunnel, and is not exposed to the public internet.
- Backups are encrypted and kept off the machine that made them.
- If personal data of yours is ever exposed, we will tell you and the Hellenic Data Protection Authority within 72 hours of finding out, as the GDPR requires — even if the number of affected people is small.
Who else processes it
- Cloudflare — serves the site, and runs the bot check that keeps scrapers out.
- Lettermint — sends our email.
- Mistral AI, Cloudflare Workers AI and Anthropic — classify job postings and tidy company names. They receive the text of public job adverts, never your data. The AI disclosure explains exactly which fields are involved.
- Viva.com — takes the card payment. We receive only the outcome and an order reference, never the card number. Your invoice is issued by us, from the company name, address and VAT number you give at checkout.
- PostHog — records the account events listed above (signing in, subscribing, checking out, writing to us), against your email address, on their EU infrastructure. It does not run in your browser: there is no analytics script on this site, and nothing is recorded while you are only reading.
The shared list
- We run one mailing list across jobopportunitiesapi.org, erioun.com and kaeros.app, all operated by the same company.
- Unsubscribing stops mail from every one of them, not just the site you signed up on.
Your rights
- You can unsubscribe from any email using the link in its footer, with no login.
- You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Use the contact form and we will action it.
- We keep contact messages and enquiries only as long as we need them to answer you and keep our accounts straight.
Questions, or want your data removed? Contact us. See also Cookies and the AI disclosure.