Skip to content
NextCryptoJobSign in

NextCryptoJob Privacy Policy

DRAFT. Not in force. For review by a French lawyer before launch. This text is not legal advice. Points marked "[to confirm with lawyer]" are open. Version: 0.1 (draft), 2026-09-12.

This policy explains what personal data NextCryptoJob processes, why, on what legal basis, who receives it, how long we keep it, and what rights you have. It covers the information required by articles 13 and 14 of the GDPR (https://gdpr-info.eu/art-13-gdpr/, https://gdpr-info.eu/art-14-gdpr/).

1. Summary

2. Who is responsible for your data

The controller is:

We have not appointed a data protection officer. [to confirm with lawyer: whether article 37(1)(b) GDPR applies, https://gdpr-info.eu/art-37-gdpr/]

3. What data we process

3.1 Data you give us

DataWhen
Email addressIf you sign in by email
Telegram user ID and usernameIf you sign in with Telegram
What job you seek, in your own wordsFirst sign-in
Roles you chooseFirst sign-in, settings
Remote or cityFirst sign-in, settings
Minimum salaryOptional
X handleWhen you connect X
Wallet addresses (EVM and Solana)When you paste them
GitHub login, YouTube channel, website addressOptional
Your settings and choices (channel, digest hour, visibility, contact mode, consents)Settings
Messages you send us, such as a score appealWhen you write to us

3.2 Data we collect from public sources

When you consent to scoring, we collect public data about the accounts and wallets you connected. This is the information that article 14 GDPR requires about data we did not get from you directly.

SourceWhat we collectThrough
XFollower count; how many known accounts follow you; on your own recent posts: likes, reposts, views, replies; how often you post6551 (third-party X data provider)
GitHubPull requests merged into other people's repositories, stars, reviews, followers, commits, active repositories, repositories with a websiteGitHub API
EVM walletsWallet age, number of sent transactions, networks used, swaps (by method name)Etherscan (Ethereum, Arbitrum), Blockscout (Base, Optimism)
HyperliquidNumber of recent trades, trading volumeHyperliquid public API
Solana walletsTransaction signatures, wallet age, swapsHelius (Solana RPC)
YouTubeSubscribers, views of recent videos, how often you publishYouTube Data API (Google)
WebsiteNumber of posts and how recent they areYour site's RSS feed and sitemap

We store counts and dates, not the full content of your posts or transactions. The data passes through our scoring engine to compute these counts. [to confirm with lawyer and in code: no post text or transaction list is kept after the counts are computed]

3.3 Data we create

3.4 Technical data

3.5 Data we do not collect

We do not ask for, and do not store, your age, gender, nationality, origin, photo, health, religion, political opinion or any other special category of data under article 9 GDPR (https://gdpr-info.eu/art-9-gdpr/). Companies cannot filter candidates by such characteristics. We do not try to infer them from your data.

3.6 Company users

For people who use NextCryptoJob on behalf of a company, we process: name, work email, company name, role in the team, billing details, subscription status, invoices, API keys (stored as a hash), usage records, saved searches, pipeline stages, notes and tags, and, for x402 payments, the paying wallet address and the transaction hash.

PurposeMain dataLegal basis
Create and run your account, sign you inEmail or Telegram ID, settingsContract, art. 6(1)(b) GDPR https://gdpr-info.eu/art-6-gdpr/
Verify that you control your X accountX handle, verification codeContract, art. 6(1)(b)
Collect public data and compute your score (profiling)Sections 3.1 to 3.3Your consent, art. 6(1)(a) GDPR, and explicit consent under art. 22(2)(c) GDPR https://gdpr-info.eu/art-22-gdpr/
Write the plain-language explanation of your scoreScore breakdown and countsYour consent (part of the scoring consent)
Publish your card pageScore, role, level, patternYour consent (you choose to publish) [to confirm product behaviour: card page public only after you publish it]
Show your profile to companiesScore, roles, level, networks, badgesYour consent, art. 6(1)(a)
Share your contact with a companyTelegram handle or other contact you chooseYour consent, per request or in "direct" mode, art. 6(1)(a)
Send your daily job digest by email or TelegramEmail or Telegram ID, roles, place, salaryYour consent, art. 6(1)(a). The digest can include jobs posted by paying companies, so we also treat it as covered by art. L34-5 of the French Postal and Electronic Communications Code https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000042155961/ [to confirm with lawyer: consent or contract basis for the digest]
Review your score by a person when you appealYour appeal, score dataContract, and our duty to offer human review under art. 22(3) GDPR
Answer your rights requestsIdentity check data, requestLegal obligation, art. 6(1)(c) GDPR
Keep the service secure, stop abuse and fraud (rate limits, one wallet per account, logs)Technical data, identifiersLegitimate interest in protecting users and the service, art. 6(1)(f) GDPR
Measure site audience without cookiesPage views, aggregatedLegitimate interest, art. 6(1)(f)
Send service messages (security, changes to terms, inactivity warning)Email or Telegram IDContract, art. 6(1)(b), and legal obligation where it applies
Manage company subscriptions, invoices and accountingCompany user and billing dataContract, art. 6(1)(b); legal obligation to keep accounting records, art. L123-22 French Commercial Code https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000006219327
Test the scoring formula against a reference set (see section 12)Public data of reference peopleLegitimate interest, art. 6(1)(f) [to confirm with lawyer]

You can use your account and receive the job digest without consenting to scoring. [to confirm product behaviour]

You can withdraw any consent at any time in Settings. Withdrawal does not affect processing that happened before (art. 7(3) GDPR, https://gdpr-info.eu/art-7-gdpr/). If you withdraw the scoring consent, we stop collecting public data, delete your scores and source data, and hide your profile from companies.

5. Profiling and automated decisions

This section gives the information required by articles 13(2)(f), 14(2)(g) and 15(1)(h) GDPR (https://gdpr-info.eu/art-15-gdpr/).

What happens. Your score is profiling under article 4(4) GDPR (https://gdpr-info.eu/art-4-gdpr/). A formula evaluates public signals about your work in crypto.

The logic. People wrote the formula. It is deterministic: the same data always gives the same score. The steps are:

  1. We turn each source into facts (counts and dates).
  2. We turn the facts into a source score from 0 to 100, on scales set so that the best people in the industry score 90 to 100.
  3. Each role has main sources and optional extras. Your role score is the main part plus up to 10 bonus points, and never more than 100.
  4. If a source did not answer or gave no value, we leave it out. We never count it as zero.
  5. Your level is your score divided by 10, rounded down, plus 1, with a maximum of 10.

The full explanation is on our public page "How scoring works" (see how-scoring-works.md). Each score in your account shows its breakdown.

The language model. A language model (Anthropic) writes the plain-language text that explains your score. It does not calculate, change or rank your score.

What it means for you. If you switch on "Show me to companies", companies can search, sort and filter candidates by score. A low score can mean that fewer companies find you. A score does not decide whether you get a job. Our terms forbid companies to make hiring or rejection decisions based solely on automated processing, including the score.

Our position on article 22 GDPR. We do not take hiring decisions. But the Court of Justice of the EU held that a score can be an automated decision when a third party "draws strongly" on it (SCHUFA, case C-634/21, 7 December 2023, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62021CJ0634). So we apply the safeguards of article 22 anyway:

How to appeal. Use the "Appeal this score" button next to any score, or write to [CONTACT EMAIL]. A person reviews your data, the breakdown and your arguments. We answer within one month (art. 12(3) GDPR, https://gdpr-info.eu/art-12-gdpr/). If we find an error, we correct the score. If the formula is wrong for a whole group, we fix the formula and publish a new version.

6. Who receives your data

We do not sell your data. We do not share it with advertising networks.

7. Service providers and data sources

ProviderWhat they doLocationTransfer safeguard
Cloudflare, Inc.Hosting, D1 database, email sending, cookieless web analyticsUSA, global network [to confirm: D1 data location]EU-US Data Privacy Framework (DPF) [to confirm status]
Contabo GmbHServer for the scoring engineGermanyNone needed (EU)
StripeCard payments for companiesIreland and USA [to confirm contracting entity]DPF or SCCs [to confirm]
6551X (Twitter) public data[to confirm country and legal entity]SCCs [to confirm; data processing agreement not yet confirmed]
EtherscanEVM wallet data (Ethereum, Arbitrum)[to confirm][to confirm]
BlockscoutEVM wallet data (Base, Optimism)[to confirm][to confirm]
HeliusSolana wallet dataUSA [to confirm]DPF or SCCs [to confirm]
HyperliquidPublic trading data[to confirm][to confirm]
GitHub, Inc.Public GitHub dataUSADPF [to confirm status]
Google LLCYouTube Data APIUSADPF [to confirm status]
TelegramSign-in, messages, digest[to confirm: UAE or other][to confirm with lawyer]
AnthropicWrites explanation textUSA [to confirm contracting entity]DPF or SCCs [to confirm]

Some data sources (for example Hyperliquid, Etherscan, GitHub, Google) are public services that we query. They may act as independent controllers, not as our processors. [to confirm with lawyer for each provider]

We send Anthropic only the counts and score breakdown needed to write the text. We do not send your email, Telegram ID or wallet addresses. [to confirm in implementation]

8. Transfers outside the EU

Some providers are in the USA or other countries outside the European Economic Area. We transfer data only with a safeguard required by chapter V GDPR (https://gdpr-info.eu/chapter-5/):

Companies outside the EU. Some companies that pay for access may be outside the EU. If you switch on "Show me to companies", they can see your profile data. If you approve their request, they receive your contact. [to confirm with lawyer: safeguard for these disclosures, for example standard contractual clauses in the company terms, or explicit consent under art. 49(1)(a) GDPR, https://gdpr-info.eu/art-49-gdpr/]

You can ask us for a copy of the safeguards at [CONTACT EMAIL].

9. How long we keep your data

DataHow long
Account, profile, scores, source dataWhile your account is active. If you do not sign in or use the service for 24 months, we warn you, then delete the account. This follows the CNIL guidance of 2 years after the last contact for candidate data (https://www.cnil.fr/fr/cnil-direct/question/recrutement-un-employeur-peut-il-conserver-mon-dossier).
Source data (counts)Replaced at each weekly refresh. Deleted with your account or when you withdraw scoring consent.
Sign-in codes10 minutes
SessionsUntil you sign out or the session expires [to confirm duration]
Security logs6 months to 1 year, as the CNIL recommends (https://www.cnil.fr/fr/la-cnil-publie-une-recommandation-relative-aux-mesures-de-journalisation) [to confirm exact period]
Consent recordsFor the life of the account, then 5 years as proof [to confirm with lawyer]
AppealsFor the life of the account
Company invoices and accounting records10 years (art. L123-22 French Commercial Code)
Database backupsUp to 30 days (Cloudflare D1 point-in-time recovery, https://developers.cloudflare.com/d1/reference/time-travel/)
Data a company received after you approved contactControlled by that company. Our terms ask them to follow the CNIL 2-year rule.

Blockchain transactions are public and permanent. We cannot delete them. We can only delete our copy of the counts.

10. Your rights

You have the right to:

How. Settings has "Download my data" and "Delete my account". For anything else, write to [CONTACT EMAIL]. We answer within one month. We may ask you to confirm your identity by signing in.

Complaint. You can complain to the CNIL, the French data protection authority (art. 77 GDPR, https://gdpr-info.eu/art-77-gdpr/): https://www.cnil.fr/fr/plaintes, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07. You can also complain to the authority in the EU country where you live or work.

11. Cookies and similar technologies

Because we use only strictly necessary storage, we do not show a cookie banner. [to confirm with lawyer]

12. People who are not our users

Reference set. To test the formula, we keep a reference set of about 50 people who are publicly known in crypto. We collected public data about them from the sources in section 3.2 and labelled their level by hand. We use it only to check that the formula is accurate before we apply it to users. We do not show these people's scores to anyone, and we do not contact companies about them. If you think you are in this set, you can object and ask for deletion at [CONTACT EMAIL]. We publish this notice here to meet article 14(5)(b) GDPR. [to confirm with lawyer: legal basis and whether this notice is enough]

Other people in your data. Your transactions involve other wallets. Your followers include other accounts. We do not store these other people's data. We store only counts (for example "12 known accounts follow you").

13. Minimum age

You must be at least 18 to use NextCryptoJob. [to confirm with lawyer: 18 or 16; French digital consent age is 15, art. 45 French Data Protection Act, https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000037823135]

14. Security

If a breach puts your rights at high risk, we will tell you without undue delay (art. 34 GDPR, https://gdpr-info.eu/art-34-gdpr/).

15. Changes

If we change this policy in a way that matters to you, we tell you by email or Telegram before the change takes effect. If a change needs new consent, we ask for it again.

16. Contact

[LEGAL NAME], [ADDRESS], [CONTACT EMAIL].