Privacy Notice

This notice explains what personal data Beyond Tabs handles, why it is needed, how long it is kept, and the choices available to you.

Effective date:

Who is responsible for your data?

Beyond Tabs is a personal, non-profit project. The person below is the data controller for personal data processed by the site.

Data controller
Andrea Mancuso
Based in
Poland
Privacy contact
[email protected]

Personal data we process

You can browse public job listings and resources without creating an account or giving Beyond Tabs your name or email address.

Website requests and security logs
The hosting, network, and application infrastructure may process or record an IP address, traffic-routing data, request time, requested page, response status, system configuration information, and basic browser or device information. These records are used only to deliver, secure, and troubleshoot the service.
OAuth identity
If you sign in with GitHub or Discord, Beyond Tabs stores the provider name, your provider user ID, and your provider username. The provider may return other profile fields during sign-in, but Beyond Tabs does not retain them as part of your OAuth identity. Beyond Tabs does not request your email address.
Account and preference data
Beyond Tabs stores an internal account ID, role and status, account timestamps, followed languages, saved jobs, seen or hidden job state, and any optional job-alert preferences you choose to configure.
Authentication records
To keep you signed in securely, Beyond Tabs handles session identifiers and records such as token hashes, issue and expiry times, and revocation information. OAuth authorization codes and provider access tokens are used to complete sign-in and are not stored as account profile data.
Privacy correspondence
If you contact the privacy address, Beyond Tabs processes your email address, message content, and related correspondence so the request can be understood and answered. The email-routing and mailbox providers involved in delivering that message also handle this data.

GitHub and Discord sign-in

Signing in redirects your browser to the provider you select. GitHub is asked for read:user access and Discord is asked for identify access. The provider processes your visit and authorization under its own privacy terms. Beyond Tabs receives the authorization result and the profile information described above.

Cookies and storage on your device

Beyond Tabs does not use advertising cookies or analytics trackers. The session cookie is necessary for the requested security and account functionality, so it is not presented as an optional consent choice.

Session cookie
The site uses a first-party session cookie for security controls and, if you sign in, to associate your browser with your authenticated session. It is not used for advertising, cross-site tracking, or analytics.
Theme preference
If you use the theme switcher, your light or dark theme choice is saved in your browser's local storage. It remains on that device until you change it or clear the site's stored data.

Who receives data

Data is not sold and is not shared for advertising. It may be handled by the named infrastructure providers below, by GitHub or Discord when you choose their sign-in service, and by public authorities only where disclosure is legally required.

Some infrastructure and OAuth providers may process data in countries outside Poland or the European Economic Area. Their privacy notices explain their roles, international processing, and safeguards. Where Beyond Tabs is responsible for an international transfer, the safeguards required by GDPR Chapter V must be used.

Named infrastructure providers

The following providers handle data on behalf of Beyond Tabs or provide services involved in delivering the site and privacy correspondence.

Cloudflare

Services used: Authoritative DNS, Reverse proxy, CDN, and traffic delivery, Network security and abuse protection, Privacy-address email routing

Provider privacy notice

How long data is kept

Account data
OAuth identity, account details, and preferences are kept while your account exists. Deleting your account removes the account and its associated identities, preferences, and authentication records, unless a limited record must be kept to meet a legal obligation.
Authentication data
A Beyond Tabs access token is valid for no more than 12 hours. Server-side session data expires or is cleaned up automatically. Authentication records may remain until account deletion unless removed earlier by maintenance.
Technical logs
Hosting and application logs are kept only for the period set by the relevant provider or reasonably needed for security, abuse prevention, and troubleshooting. You can contact the controller for the current provider-specific retention details.
Privacy correspondence
Messages concerning privacy rights are kept only as long as needed to answer the request and retain evidence that the request was handled lawfully, then deleted when that purpose and any applicable legal period have ended.

Your data-protection rights

Depending on the circumstances, you may ask for access to or correction of your data, deletion, restriction of processing, or data portability, and you may object to processing based on legitimate interests. You can download an account-data export or delete your account from the Account page. You can also contact the controller using the address above.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland, or with the competent supervisory authority where you live or work. Requests are normally answered within one month.

Is the data required?

An account is optional. The OAuth identity and authentication data described above are necessary if you choose to use account features; without them, Beyond Tabs cannot create or operate an account. You can continue to browse the public site without signing in.

Beyond Tabs does not use your personal data for solely automated decisions that produce legal or similarly significant effects.

Changes to this notice

This notice may be updated when the service or its data handling changes. The effective date at the top of the page identifies the current version. Material changes will be highlighted on the site where appropriate.