What we collect, why we collect it, and the choices you have over your data.
Last updated: September 13, 2026
Ranked.jp (“we”, “our”, or “the site”) operates a job board and professional network for software engineers and related professionals in Japan. This Privacy Policy explains what data we collect, how we use it, and the choices you have. It applies to ranked.jp and our related subdomains, including employers.ranked.jp and the chat assistant at chat.ranked.jp.
When you create an account or profile, we collect information you provide directly, including:
When you apply to a job hosted on Ranked, we collect the application details you submit, including your name, email address, resume, language abilities, work authorization answer, and role-specific message. After a successful application, your browser also keeps the applicant details and resume on that device to prefill the next application form. It does not keep the role-specific message. This works without an account, and clearing Ranked site data in your browser removes the device-local copy.
If you use the chat assistant, we process the messages you send it. Section 6 describes that in full — what is sent onwards to produce a reply, what we keep, and what does not survive the page.
We also automatically collect limited technical and usage data through Google Analytics, including:
Chat analytics use a random identifier created for the conversation on that page. Events may also say which language is in use, whether the visitor is signed in, and whether personalization is enabled. We do not send Google Analytics the text of a message or reply, an email address, resume or profile contents, search requirements, or an account identifier. We may export the same analytics events to Google BigQuery for our own analysis.
Separately from analytics, our own servers process one further piece of technical data: when a signed-out visitor uses the chat assistant, we derive a one-way salted hash of their IP address and use it to count how many messages and enquiry emails have come from that visitor today. We store the hash, never the address itself, we do not use it for anything except those limits, and the record deletes itself seven days after it is written. Signed-in visitors are counted against their account instead, and no address is hashed.
Your profile is private by default. Creating an account, accepting these documents, or keeping an earlier sharing permission does not enable either of the optional permissions below. The public Talent directory and its visibility control are not launched. Any earlier public visibility choice is separate; contact admin@ranked.jp to withdraw it.
Let employers discover me. This optional permission allows verified employers and their authorized AI tools to search and compare an approved talent profile through Ranked. The profile can contain skills, broad experience, languages, location and job preferences you choose to show. Names, photos, contact details, resume files, identifying links and exact employer history are excluded from discovery. Before any profile becomes discoverable, you must approve what will be shown. Identity or resume disclosure requires a separate approval naming the recipient, or your instruction to send an application. This is not permission to publish your profile to the open web or public search engines.
Discovery does not by itself enable contact or arrange an introduction. We enforce the visibility choices you have approved, and the same restrictions apply to browser and API/AI access alike. Hiding identifying details is not a guarantee that nobody could recognize you from the remaining facts.
Help improve matching. This separate optional permission allows Ranked to use your structured profile, saved jobs and application status/outcomes to evaluate and improve matching for all users. Such information may remain linked to your account. The scope excludes resume files, names, contact details and chat text; it does not authorize external AI providers to train their general models. It is separate from providing your own requested profile analysis and recommendations, and from the content-free analytics described above.
Both choices are optional and off unless you explicitly enable them in Settings. You may withdraw them there at any time. We record the permission, wording/version, language, server timestamp and source, including withdrawal history. Earlier evidence is not converted into new grants. A materially different use requires a new choice. Withdrawal stops further use under that permission; it cannot recall information already delivered to a recipient.
To protect your real email address, we may issue you a proxy address at our messages subdomain. Messages sent to that address are filtered and forwarded to your real email, so other users can reach you without seeing your actual address. We process the contents of these messages only as needed to deliver and filter them. The current automated checks cover detected spam or viruses and configured blocked terms; they do not yet compare messages with your profile interests. Disabling the earlier permission for opportunity messages removes the relay from public profile data and contact controls; new inbound relay messages are also blocked, even if a sender already knows the address.
The assistant at chat.ranked.jp — also reachable at /en/chat/ and /ja/chat/ — is open to everyone, with or without an account. This section describes what happens to a candidate conversation.
What we send in order to answer. Replies are generated by a language model operated by OpenAI in the United States. To produce one we send OpenAI: a limited window of the most recent messages in the conversation (each one truncated), any search requirements you have stated in it (for example a salary floor or that you need visa sponsorship), short labels for the matching facts in play (for example “React”, “JLPT N2”), and job and company information drawn from Ranked’s own listings. We do not send your name, your uploaded resume, or the text extracted from it, and we do not send your account email address — with one exception: if you ask the assistant to send us an enquiry, the address the reply will go to is part of that exchange. Anything you type into the chat yourself is part of the conversation and is sent with it.
What we keep. We do not store your conversation. It is held in your browser while you are on the page and sent up with each message so the assistant has context, and it is gone as soon as you reload, close the tab, or move to another page — including the round trip through a sign-in link. The facts the assistant records as you talk (shown in the “Memories” list under the message box) live in the same place and disappear with it. Nothing you say in a conversation is written to your profile.
What can change your account. Two things, and both are deliberate actions rather than side effects of talking:
Personalize. When you are signed in, a toggle under the message box decides whether your saved profile and resume are applied to the conversation. Turning it off stops the assistant reading them; it never edits or deletes anything on your profile.
Emailing us from the chat. If you ask the assistant to send an enquiry to Ranked Group, it writes the message out in the conversation, asks you to confirm it, and only then sends it to admin@ranked.jp. When you are signed in, the reply address is your verified account address. When you are signed out, it is the address you type into the chat, and the email states plainly that the address is not verified. Every such email is marked as having been sent from the assistant on a visitor’s behalf. We keep these enquiries as ordinary business correspondence.
Limits and usage analytics. We count how many messages and enquiry emails come from one visitor per day — keyed to your account when you are signed in, and to the salted IP hash described in Section 2 when you are not — and we keep a running monthly total of what the assistant costs us to run. Neither record contains any part of a conversation. Separately, Google Analytics receives the content-free interaction events described in Section 2. These events let us measure, for example, how many messages are sent in one conversation, whether answers succeed, how long they take, and whether they lead to job cards, saves, applications, or enquiries. Google Analytics does not receive the text of the conversation.
Employer AI tools. On employers.ranked.jp, authenticated company administrators can use AI to manage company/job information and application statuses. Requests to OpenAI may include the employer conversation, company/job facts and an applicant roster containing names, applied-for jobs, application dates/statuses, language levels and work-authorization answers. The roster excludes applicant email addresses, resumes, links and application messages, although information typed by an employer into the conversation is transmitted. Company-scope requests can include this roster even when the question is not about applicants. This application-management processing is separate from the employer-discovery permission in Section 4. The AI can execute requested shortlist/rejection changes; employers remain responsible for reviewing the affected people and decisions.
We use a strictly necessary, HttpOnly session cookie to keep you signed in. It is set for ranked.jp and its subdomains, so it is also sent to our API and chat hosts — that is how the chat knows you are signed in. Google Analytics also sets cookies to collect the usage data described above. You can control or disable cookies through your browser settings; disabling the session cookie will prevent you from staying signed in.
Your account and profile data are stored on Amazon Web Services (AWS) in the Tokyo (ap-northeast-1) region. Uploaded profile images are stored in AWS S3. Uploaded resumes are stored in a separate S3 bucket that blocks all public access — the only way in or out is a signed, time-limited link scoped to your own account. Account emails are sent using AWS Simple Email Service (SES).
Some processing takes place outside Japan. When you upload a resume, its contents are sent to OpenAI (in the United States) to extract structured profile details; we use OpenAI to analyze job and profile text for the ranking and matching described above; and chat messages are sent to OpenAI to generate the assistant’s replies. This means some of your data is transferred to and processed in the United States. We send only what is needed for these purposes.
We use the following third-party providers, who may process data according to their own privacy policies:
How OpenAI handles what we send. OpenAI does not use data sent through its API to train or improve its models, and we have not opted in to any programme that would change that. It keeps API inputs and outputs for up to 30 days for abuse monitoring and then deletes them, unless it is required to keep them longer by law.
Transfers outside Japan. Amazon Web Services stores your data in its Tokyo region. Google, OpenAI, and Anthropic are established in the United States and process data there. We provide personal data to these providers only as processors acting on our instructions, under each provider’s data processing terms. Information about the personal-data protection regime of the receiving country, and about the measures each provider takes to protect personal data, is available on request from admin@ranked.jp.
We do not sell or rent your personal data. When you apply to a hosted job, we send the submitted details to the employer's company administrators and the job's configured application email recipient. Notification emails contain application details and the applicant's reply address. Authorized company administrators can view applications and download the submitted resume through a time-limited link. Uploaded application resumes are separate snapshots, so later replacing or deleting an account resume does not change an application already sent.
We retain the submitted application and the employer's current status update (new, shortlisted or rejected), including when and by whom the status was changed, to operate the application service. A complete candidate-facing tracker and interview, offer and hire reporting are future features, not currently available. External applications follow the destination site's policies.
Profile details reach an employer under the discovery permission in Section 4 only within the limits described there, and never your account email or uploaded resume. Earlier private-introduction permission is retained as a historical record, not used to arrange introductions. An enquiry you ask the candidate chat assistant to send goes to Ranked itself. We otherwise share data with the service providers described above for the disclosed purposes, on your specific instruction, or where required by law.
We retain your account and profile data — including any resume text and the profile vector derived from it — for as long as your account is active. When you ask us to delete your account or your data by emailing admin@ranked.jp, we remove your account, profile, resume, and the data derived from it from our systems within 30 days. Chat conversation contents are not retained, as described in Section 6. The per-visitor counting records behind the chat’s limits expire seven days after they are written. The monthly running total of what the assistant costs is kept as a business record and contains no personal data. Enquiries you asked the assistant to send are kept in our email as correspondence. Analytics data is retained according to Google Analytics settings.
Hosted application records and their resume snapshots have no automatic expiry currently. Contact admin@ranked.jp to request their deletion or correction, including if you applied without an account. We handle requests for copies under our control; removing them cannot recall employer emails or files already downloaded, which are subject to the recipient's obligations.
The application details and resume remembered by your browser remain on that device until they are replaced or you clear Ranked site data. They are separate from the application record sent to the employer.
Relay messages. A message sent to your messages.ranked.jp relay address is stored only as long as it takes to filter and deliver it: the message itself is deleted automatically 30 days after it arrives. We keep the surrounding thread record — the sender’s address, the subject line and the delivery timestamps — for as long as you use the relay, so that we can operate and secure it, trace delivery failures, and investigate spam and abuse. Ask us at admin@ranked.jp and we will delete your relay history along with the rest of your data.
Depending on your location (including Japan and other regions), you may have rights regarding your data, such as the right to access, correct, delete, or restrict processing of your information, and to object to processing. You can edit or remove most profile information yourself while signed in — including downloading or deleting your uploaded resume from your Resume page — or contact us using the details below. You can also opt out of Google Analytics using the browser add-on at https://tools.google.com/dlpage/gaoptout.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. A policy update or continued use does not enable optional permissions.
If you have any questions about this Privacy Policy, you can contact us at admin@ranked.jp.