Dear linkedin
Job searching asks people to scatter a surprisingly detailed version of their lives across dozens of systems. Resume, phone number, address, work history, sometimes immigration information, then we mostly have to trust that every form, vendor, and database will handle it responsibly forever.
That trust becomes especially uncomfortable when a company you barely remember applying to emails about an incident. Candidate privacy deserves the same product thinking as customer privacy: collect less, explain why, define retention, control vendor access, and delete data when the relationship never begins. Being open to work should not mean being open to indefinite exposure.
#opentowork members,
tldr; uploaded my resume everywhere while job hunting and ended up with random outreach + now a “security incident” email from a company as someone who works in privacy, it’s wild how little privacy candidate data actually has :(
i graduated last may, doing contract work rn, and am still on the hunt for a full-time role like everyone else, i did the usual thing.. uploaded my resume on indeed, dice, monster, ziprecruiter, greenhouse, ashby, sorce, even linkedin
and then… chaos
random calls consultants roles that don’t match even insurance companies somehow??
idk which platform is the culprit, or if it’s all of them but at some point it stops feeling like “opportunities” and starts feeling like your data is just floating around
and then i get an email from mercor about a “security incident” (also mentioning “along with thousands of other organizations worldwide”… what are we proving here?) no details, just vibes i had literally uploaded my full profile, done video interviews, shared way more than just a resume
and now i’m like… cool 👍 where did all that go
funny enough, my dad texted me “hey apply with mercor, i heard it’s a good platform” and i didn’t even know how to reply like how do you explain that you trusted a platform with your data and now you don’t even know where it is or what’s happened to it
what’s funny (not funny) is i actually work in this space i’ve built systems where we reduced re-identification risk in user data by ~99.96% inside virtual reality
and yet as a candidate, i have zero visibility into how my own data is handled
This is still one of the threads running through almost everything I build: useful technology should not require people to surrender more of themselves than the experience truly needs. Privacy is not a final checkbox. It is part of the product architecture.
