Privacy
What Exerio keeps about you, who can see it, and how to make it stop existing.
What we store
- Your account — name, email address, and a bcrypt password hash (cost 12). The password itself is never stored, and nobody at Exerio can read it back.
- Your profile — bio, interests, location, experience, skills, projects, certificates, and whether you are open to work outside your fields.
- What you post — your listings, their targeting choices, and their state.
- Messages — the threads and messages between you and the people you contact.
- How you used the app — views, saves, skips, likes, applications and contacts, with timestamps. The ranking engine reads these to learn what suits you.
What we do not do
- We send no email. There is no mail transport in this product. Alerts appear in the app, in the Alerts tab — nothing arrives in your inbox, and there is nothing to unsubscribe from.
- No third-party analytics or trackers. The behaviour above is stored in our own database and read only by our own ranking code.
- No payment details. Distribution credits are a form field today: nothing is charged and no card data is collected.
- We do not sell or share your data with advertisers or anyone else.
Who can see what
A poster sees your name, your profile and your application when you apply or message them. Your contact details are not on a listing. The list of people who fit a listing is visible only to the person who posted it — and it is ranked from the profiles members chose to fill in, not from anything we infer behind their back. Your profile is never shared with a poster unless you apply or message.
Where it lives, and for how long
The database is hosted on Neon (Postgres); the application runs on Vercel. Both are in the European Union for the deployments we control. Data is kept until you delete it — we do not run a retention purge, because the honest answer to “how long do you keep my messages” is “until you ask us not to”.
Deleting yourself
Settings → Delete my account removes you and everything attached to you in one transaction: listings, messages, alerts, reviews, applications and history. It is immediate and it is not recoverable. There is no soft delete and no backup copy kept “just in case”.
On your device
Two cookies from the sign-in system (a session token and a CSRF token) and one small localStorage entry holding your theme, language and motion preference. That preference belongs to the device, not to your account: a signed-out visitor can set it and it survives, and it is the only thing we keep in the browser.
Questions, or a request you cannot do through the app yourself: ask through a listing’s contact route, or see the terms.