Privacy Policy
Last updated: August 6, 2026
1. Who we are
GigDisco is operated by Go Be Strong LLC, a Washington limited liability company. For anything in this policy — questions, requests, complaints — email michael@gobestrong.com. A person reads that inbox.
This policy covers gigdisco.com, app.gigdisco.com, and the emails we send.
2. What we collect
In short: Your account email, the profile and resume you give us, your search activity, and payment records. That's the list.
Almost everything GigDisco holds, you typed in on purpose — because the product only works if it knows what you're looking for:
- Account: your email address, used to sign you in and send you the digest.
- Profile: name, headline, location and commute radius, salary expectations, experience, strengths, interests, work preferences, and a LinkedIn URL if you share one.
- Resume: if you upload one, we extract and store its text so your suggestions can be grounded in your actual background.
- Outside work (optional): hobbies, causes, and affiliations you choose to share so we can suggest non-work gatherings. Answers here can reveal sensitive things about you — a faith community, veteran status. These fields are entirely optional, used only to suggest events, and deleted like everything else on request.
- Search activity: the Directions you explore, your conversations with the exploration assistant, which roles and events you accept or dismiss and why. This is the learning loop — it is how GigDisco stops showing you things you've said no to.
- Payments: records of what you bought (plan, amount, date) and a Stripe customer reference. Your card number goes to Stripe directly and never touches our servers.
- Approximate location, only if you press the button: some employers' job boards can return roles near you rather than every role in the country, which needs a coordinate rather than a city name. We ask only when you click, we round what your browser reports to about a kilometre before storing it — enough to know which metro you're in, not which building — and “Forget it” on the same screen removes it. Everything works without it.
- Technical basics: server logs from our hosting provider (IP address, request time) kept for security and debugging.
3. What we don't collect, and what we don't do
In short: No selling your data. No ad targeting. No data brokers. No background checks.
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not buy data about you from brokers, run background checks, or collect government identifiers or health information. If we ever wanted to change any of this, we would ask you first, in plain language — not bury it in an update.
4. How we use your information
In short: To run your search, and for nothing weirder than that.
We use what you give us to:
- generate your suggestions — Directions, employers, roles, events, recruiters — including by sending relevant parts of your profile and resume to our AI provider (see section 5);
- watch employers' public job boards and tell you what's new, what closed, and what needs a decision;
- send you the digest email and act on the one-tap links inside it;
- process payments and keep the records the tax authorities require;
- keep the service secure, debug problems, and understand product usage (see section 7);
- answer you when you write to us.
5. AI processing, named plainly
In short: Your profile and resume are sent to Anthropic's Claude to generate your suggestions. Anthropic doesn't train on that data.
GigDisco's suggestions are generated by Claude, an AI model from Anthropic. When you use the exploration assistant or ask us to find events and recruiters, we send Anthropic the parts of your profile relevant to the task — which can include your resume text and, for event suggestions, your outside-work interests. Anthropic processes this as a service provider and, per its API terms, does not use it to train its models.
AI-generated content can be wrong. We verify what we can — links are checked before they're stored, and event suggestions must come from pages actually retrieved from the live web — but you should treat suggestions as research assistance, not verified fact.
6. Who your data is shared with
In short: The service providers below, the friends you invite, and nobody else — unless the law compels us.
These providers process data on our behalf to run GigDisco. We share the minimum each needs:
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and sign-in (your account, profile, and search data live here) | United States (AWS) |
| Vercel | Application hosting (serves the website and app) | United States |
| Postmark | Email delivery (the digest and account emails) | United States |
| Anthropic | AI processing (generates your suggestions from your profile and resume) | United States |
| PostHog | Product analytics (pages visited, buttons clicked, page speed — only if you accept analytics cookies) | United States |
| Sentry | Error monitoring (what broke and where — no IP address or account details attached) | United States |
| Stripe | Payment processing (card details never touch our servers) | United States |
Analytics is the one entry above that only applies if you say yes — see section 7.
Friends you invite: if you invite someone to view your search, they see your board — your Directions, tracked employers, and progress. That sharing is under your control; un-invite someone and their access ends.
Legal requirements: we disclose information if legally compelled — a valid subpoena, court order, or similar. If the law allows it, we will tell you before we comply.
If Go Be Strong LLC is ever acquired or its assets transferred, your data would move with the service, under this policy's promises, and we would notify you.
7. Cookies and analytics
In short: Cookies that sign you in, always. Analytics only if you say yes — and declining means it genuinely never loads.
GigDisco sets essential cookies — the ones that keep you signed in — plus small amounts of in-browser storage for things like an unsaved exploration draft. Those are required for the service to work at all and are not optional.
For analytics we use PostHog, to understand how people arrive at GigDisco and where they get stuck. A banner asks before it loads. Choose “Essentials only” and it never loads — the code that would start it checks your answer first and stops, rather than starting anyway and pretending otherwise. Your choice is remembered in your own browser.
Session recording is switched off entirely — we do not record screens containing your CV. There is no advertising tracking, no fingerprinting, and no ad-network integration, and we never sell or share this data.
What analytics does record, if you accept it: which pages you visited and in what order; which things you clicked, including the visible label of what you clicked — a button name, a job title — but never what you type into a form field; clicks that landed on nothing, which is how we find buttons that look active and aren’t; and how quickly pages loaded for you. That last group exists because the alternative is us guessing whether the app is slow or broken, and guessing badly.
Separately from analytics, and whatever you choose above, we use Sentry to record technical diagnostics when something in the app actually breaks — the error itself, the page it happened on, and the kind of browser you were using. We do not put this behind the banner, because it is how we learn the service is broken for someone, and an error report that only arrives from people who opted in is not a safety net. It is configured not to attach your IP address or account details, it sets no cookies, and it records errors rather than behaviour.
If you have not seen a cookie banner, analytics is not yet switched on for this site.
8. Email, and how the one-tap links work
In short: Digest links act without a login — possession of your inbox is the key. Guard it accordingly.
GigDisco's main interface is honestly the digest email. The buttons in it — “not for me”, “I'm going”, “done” — work without signing in: each link carries a cryptographic signature that authorizes exactly that one action on your account. This is deliberate, because a nudge you must log in to answer is a nudge that gets ignored. The trade-off is that anyone with access to your inbox can click them, so treat your email account as part of your GigDisco security.
The digest only sends when there's something to say. When we later add renewal reminder emails, they will include an unsubscribe link, as commercial email law requires. To stop the digest entirely, email us — or let your plan lapse, which stops it automatically.
9. How long we keep things
In short: As long as your search might resume — and until you tell us to delete it.
When your plan expires, your data is not deleted: your board goes read-only so that renewing brings everything back exactly as you left it. A job search that pauses in March often resumes in September, and losing the record would mean starting over.
That means the retention decision is yours. Ask us to delete your account (section 10) and we will, within 30 days — keeping only what the law requires, such as payment records for tax purposes, and server backups that age out on their own within a further 30 days.
10. Your rights — everyone's rights
In short: Access, correction, export, deletion. You get these because you're a user, not because a statute says your state qualifies.
Various laws give various rights to residents of various places. We skip the residency argument: every GigDisco user can ask us to —
- tell you what personal data we hold about you (access);
- fix it if it's wrong (correction) — most of it you can edit yourself on the Profile page;
- give you a copy in a portable format (export);
- delete it (deletion), as described in section 9.
Email michael@gobestrong.com from your account email address — that's how we verify it's you. No fee, no forms, answered within 30 days. We will never treat you worse for exercising these rights.
11. Security
In short: Serious controls, honestly described — and no such thing as perfect.
Data is encrypted in transit and at rest. Access inside the application is enforced at the database layer with row-level security, so one user's search is walled off from another's even from most classes of application bug. Card data never touches our servers. Secrets are not stored in code.
No system is perfectly secure, and we won't pretend ours is the exception. If a breach ever affects your data, we will tell you promptly and plainly — what happened, what was exposed, and what we're doing about it.
12. Children
GigDisco is for adults: you must be 18 or older. The service is not directed at children, and we do not knowingly collect data from anyone under 18. If we learn we have, we will delete it.
13. Where your data lives
In short: In the United States. We're a US product and don't market elsewhere.
GigDisco is operated from the United States and all data is stored and processed there. We do not target or market the service to the European Economic Area or the United Kingdom. If you use GigDisco from outside the US anyway, you're welcome — but your data will be transferred to and processed in the US, and this policy (including the rights in section 10, which we grant to everyone) is the framework that governs it.
14. Changes to this policy
The date at the top is the date of the current version. If we change this policy in a way that matters — new data collected, a new category of sharing, analytics turning on — we will email account holders before the change takes effect, and say what changed in plain language.
See also our Terms of Service.