Last updated: August 5, 2026
Your Roster (“Your Roster,” “we,” “us,” or “our”) helps you find warm introductions at companies that are hiring by matching your professional network against live job openings. This policy explains what information we collect, why we collect it, and the choices you have. We built this product on a simple rule — keep what we need to make it work, and nothing else — and this policy is meant to describe that honestly, not to maximize what we can do with your data.
This policy covers the Your Roster website and app at yourrosterapp.com (the “Service”). It applies to anyone who visits the site, creates an account, or uploads information to it. It does not apply to third-party sites we link to (LinkedIn, a company’s own career page, an applicant-tracking system you apply through) — those have their own privacy practices.
Account information. When you register with email and password, we store your email address and a salted, one-way hash of your password — never the password itself. If you use “Continue with LinkedIn,” LinkedIn shares your name, email address, and profile photo with us through its Sign-In flow; we do not receive your LinkedIn connections, messages, or activity through that flow (see §3).
Your connections export. If you upload the “Connections.csv” file LinkedIn lets you export, we parse it and keep only the fields the matching algorithm actually uses — first and last name, job title, company, LinkedIn profile URL (if the export included one), connection date, and whether an email address was present. We do not store the email addresses themselves, and we do not keep the uploaded file — it is parsed once, in memory, and discarded. If you also upload a LinkedIn profile export, we read your headline, summary, industry, and location to understand what kind of role you’re looking for.
Your résumé. If you upload a résumé (PDF or Word), we extract the text — work history, titles, skills — to refine your profile. We store the extracted text, not the original file. The file’s name, type, and size are recorded alongside it; the file contents are not.
Usage data. We store the things you do on the Service that make it work for you: ratings on job openings (thumbs up/down), saved openings, companies you’re watching, search and matching preferences, and invite links you’ve created or accepted.
Device and log data. Like most web services, our servers log standard technical information — IP address, browser type, timestamps, and pages requested — used for security, abuse prevention, and diagnosing problems. We do not use this to build an advertising profile of you.
Your Roster is not affiliated with, endorsed by, or sponsored by LinkedIn Corporation. We use two LinkedIn-adjacent features, and they work differently:
Sign In with LinkedIn (OpenID Connect). This is an authentication convenience. It returns only your name, email address, and profile photo — the same information you could hand over by typing it into a registration form. It does not give us access to your connections, posts, messages, or any other LinkedIn data.
Your Connections.csv export. LinkedIn’s own network graph is not available to third-party apps — we do not, and cannot, pull your connections through any LinkedIn API. The only way your network reaches Your Roster is the file you export from LinkedIn yourself and choose to upload, and, as described in §2, we discard that file immediately after reading the fields we need out of it.
By uploading your own connections export, you confirm you have the right to share that information with us for the purpose of finding introduction paths, consistent with LinkedIn’s User Agreement. We rely on you to only upload your own export, not one obtained from someone else.
We use the information above to:
We do not use your data to train third-party AI models, and we do not run your personal profile or network data through an AI system. The one place this product uses AI (Anthropic’s Claude) is unrelated to your personal data — it classifies public company news and SEC filings to generate hiring-signal alerts (see §6).
This is the section most specific to how Your Roster works, so we want to be precise about it. The product’s core feature is showing you who you already know at a hiring company — sometimes that person is someone you uploaded, and sometimes it’s a path that runs through someone else’s uploaded network, if that person is also a Your Roster user.
If you are a registered user, your profile is discoverable for path-finding by default — meaning another user whose own connections include you may see a path like “You → [your name], [your title] at [your company] → [their target]” if you sit between them and a role. That path shows only your name, title, and company — the same information already visible on your public LinkedIn profile — never your email, résumé content, ratings, or anything else you’ve added to your account. You can turn this off at any time from your Profile settings; doing so removes you from other users’ paths going forward.
We never send a message to your connections, or to anyone, on your behalf. If a path exists through you, the asking user is shown how to reach out themselves — Your Roster does not act as a messenger.
A person who appears in someone’s uploaded connections but has never created a Your Roster account is never used as an intermediate step in anyone else’s path — only as the final, named target of one, since there is no account to extend a path through and nothing for them to consent to.
We keep your account information for as long as your account is active. Parsed connection and résumé data (never the original files — see §2) is retained to keep your matches current and is replaced each time you upload a newer export. If you delete your account, we delete your personal information, remove you as a traversable step in other users’ introduction paths, and disassociate any connection rows that referenced you, keeping only what we’re legally required to retain (for example, financial or fraud records, where applicable).
Passwords are hashed with scrypt, never stored or logged in plain text. Traffic to the Service is encrypted in transit (HTTPS), and our database connections use TLS. No method of transmission or storage is perfectly secure, and we can’t guarantee absolute security, but we design the system to keep as little sensitive data as possible in the first place — the fastest way to reduce what a breach could expose is to not be holding it.
You can, at any time:
If you are located in the European Economic Area, the UK, California, or another jurisdiction with its own data protection law, you may have additional rights under that law (such as the right to access, correct, port, or object to certain processing of your data); we honor requests under those laws to the extent they apply to you, using the same contact method in §14.
The Service is intended for working professionals and is not directed at anyone under 18. We do not knowingly collect information from anyone under 18; if you believe a minor has provided us information, contact us and we will delete it.
Our infrastructure is hosted in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.
We may update this policy as the Service changes. If we make a material change, we’ll update the “Last updated” date above and, where appropriate, notify you by email. Continuing to use the Service after a change takes effect means you accept the updated policy.
Questions about this policy, or a request under §10, can be sent to [email protected].
See also our Terms of Service.