Acceptable Use Policy
- Last updated
- Sections
- 12
- Unresolved
- 15 marked in the text
This is a draft. No lawyer has read it. Every decision still outstanding is marked in the text, and counted at the top of this page. This policy forms part of the Terms of Service; where the two disagree, the Terms govern. Unresolved: REVIEW: confirm that ordering with counsel.
On this page — 12 sections
In plain language
Crossing prepares applications. You send them. Everything below follows from that.
Don't automate the Send button, don't put things on an application that aren't true, don't use Crossing to make decisions about other people, don't hammer an employer's site, and don't resell the job index. Be careful with the personal data of the recruiters and interviewers you track — they never signed up for anything.
If you break these rules we will usually warn you first and give you a chance to fix it. For the serious ones — attacking our systems, impersonating someone, using Crossing to screen candidates — we will close the account. You can always export your data.
1Who this applies to
Anyone who uses Crossing: through the web app, through the public API with an API key, through the apply-assist bookmarklet, or by fetching our public pages. It applies to what you do yourself and to anything you build on top of us.
2The rule the product is built on
Crossing never submits an application, and you must not make it.
This is not a policy preference bolted on afterwards — it is how the code is written. The module that prepares an application makes no network calls at all, and its result type has no "submitted" state. The bookmarklet that types your prepared answers into an employer's form never calls click(), never dispatches a submit event, and never touches an iframe or a captcha widget. It fills the fields and stops.
So, concretely, you may not:
- Wrap, script, patch or drive Crossing so that something other than a human presses Send — including browser automation, headless browsers, macro recorders, or an agent you built on our API.
- Use Crossing as part of a "mass apply", "auto apply" or "apply to 500 jobs overnight" workflow, whether the submitting step is ours or somebody else's.
- Modify the bookmarklet, or ship a fork of it, so that it submits, presses buttons, fills fields on pages the user has not opened, or solves or bypasses a captcha.
- Present Crossing to anyone as a product that applies on their behalf.
Why we care this much: an application sent without a person reading it is how bad applications happen, how a wrong salary expectation or a wrong work-authorisation answer gets into an employer's system permanently, and how job boards end up throttling everyone. The one-job-one-card queue is slower on purpose.
3Honesty in what you send
Crossing tailors your résumé by rewriting your own bullets to match a posting's language. A guard runs on every tailoring path, including the offline one, and rejects any rewrite that introduces a number, a proper noun, a date or a credential the source bullet did not already contain. A posting mentioning Kubernetes does not license a bullet claiming Kubernetes.
That guard can only check that a claim came from your résumé. It cannot check that your résumé is true. Everything you send is your statement to an employer. So you may not use Crossing to:
- Claim employers, titles, dates, degrees, certifications, clearances or licences you do not have.
- Apply as, or on behalf of, someone else without their authority; or use someone else's résumé, identity, photograph or work history as your own.
- Give false answers to work-authorisation or sponsorship questions. (Crossing deliberately leaves these blank rather than guessing when a board splits "yes" into specific visa categories — a specific immigration claim you never made must not appear on your application.)
- Run a résumé-writing or application service for other people through a single account without disclosing it. Unresolved: REVIEW: decide whether career coaches and résumé writers are an allowed segment with their own terms, or prohibited. This is a real business decision, not a legal formality.
Demographic and EEO questions are yours alone. Crossing's default is to answer nothing; it will select "I don't wish to answer" only if you set that mode, and it will only use a stored answer if it exactly matches one of that employer's own published options. You may not use the product to answer these questions for another person.
4Other people's data
The tracker holds real people who never signed up: recruiters, hiring managers, interviewers, referrers — their names, titles, emails, phone numbers, LinkedIn profiles and your notes about them. You are responsible for what you put there. You may not:
- Upload purchased contact lists, scraped lead lists, or a former employer's CRM export.
- Store information about a contact that you obtained unlawfully, or that you would not be willing to show them. Assume anything you type may one day be read by the person it is about — in many jurisdictions they can require exactly that.
- Use outreach drafts to send bulk unsolicited mail. Crossing drafts messages; it does not send them to third parties. What you do with a draft is subject to the anti-spam and marketing rules where you and the recipient are. Unresolved: REVIEW: CAN-SPAM / PECR / GDPR direct-marketing analysis — probably light today because no message is sent by us to a third party, but confirm.
- Record covert audio, video or notes about an interview in violation of the recording-consent laws where you or the interviewer are.
5Employers, job boards and applicant tracking systems
Crossing reads employers' published application forms so it can show you the questions before you open the page. Every one of those reads goes to a fixed, compiled-in list of applicant-tracking hosts, over HTTPS only, with a 12-second timeout and a 3 MB cap, and no adapter posts anything. Keep it that way. You may not:
- Use Crossing, or anything built on it, to send an employer more traffic than a person could generate — repeated re-preparation of the same posting in a loop, parallel runs across many accounts, or scripted re-fetching.
- Attempt to reach hosts outside that allowlist through the product, or use the "add a job by URL" importer to make our server fetch internal, private, or non-public addresses. (It refuses; trying is still a violation, and see §6.)
- Circumvent an employer's or a board's captcha, login wall, rate limit, or robots directives using Crossing.
- Use the product to apply to postings you know to be fake, or to submit applications you have no interest in, in order to farm responses.
6Our systems
You may not:
- Access, or try to access, another user's account, résumé, applications, contacts or API key.
- Probe, scan or attack the service — except as expressly permitted by our security disclosure policy, which authorises good-faith research within a defined scope. Read that page before you test anything.
- Evade rate limits by cycling IPs, creating multiple accounts, or splitting work across accounts. The defaults are 240 requests per minute per account, 12 per minute on sign-in routes, and a per-account budget of 8 failed sign-ins per 15 minutes.
- Share, publish or resell an API key. Keys are shown once and stored only as a hash — a leaked key is revoked, never recovered. Every key belongs to one account and is charged to it.
- Create accounts by script, create an account for someone else without their permission, or keep more than one account to get around a plan limit or a suspension. Unresolved: REVIEW: confirm the one-account rule against the pricing model — Teams plans, if they exist, need an exception.
- Scrape the app's pages instead of using the API, or bulk-export the job index for republication, resale, or to build a competing index. This is not just our rule: several of the boards we ingest from require attribution and restrict redistribution, and one restricts commercial reuse outright. See the job listings and sources policy.
- Upload malware, or files designed to exploit the parsers. Résumé uploads are capped at 10 MB and limited to PDF, DOCX, RTF, TXT and Markdown, and are parsed locally.
- Use the product to store or transmit content that is unlawful where you are.
7Crossing is a candidate-side tool
Crossing ranks jobs for one person. It is not built, tested, audited or documented as a tool for ranking people, and you may not use it as one. Specifically, you may not use Crossing or its outputs to screen, score, shortlist, rank or reject candidates, or to make or substantially assist any employment decision about another person.
This matters beyond our preferences. A tool used that way can be an "automated employment decision tool" under New York City Local Law 144, which requires an annual independent bias audit, a published summary of it, and notice to candidates; and it can be a high-risk AI system in recruitment under the EU AI Act, with its own obligations on whoever deploys it. Crossing has had no bias audit, publishes no audit summary, and is not documented for that purpose. Using it that way puts you in scope of obligations we have not built for.
8Fairness and legality
You may not use Crossing to discriminate against anyone, to harass anyone, or in the furtherance of any unlawful scheme — including recruitment fraud, advance-fee "job" scams, or money-mule recruiting dressed as remote work. If a posting in our index looks like one of those, report it; a listing appearing in Crossing is not a verification that the employer is real.
9What happens if you break these rules
We would rather keep you as a user than win an argument, so the normal path is graduated:
- A note. We tell you what we saw and what needs to stop.
- A throttle or a feature switch-off. Usually the narrowest thing that works — revoking one API key, disabling imports, or lowering a limit — rather than closing the account.
- Suspension. Sign-in blocked, data intact, and you can still export it. Unresolved: REVIEW: confirm export remains available during suspension — it is the right answer and it is also close to a GDPR Art. 20 obligation.
- Termination. The account and its data are deleted. Unresolved: REVIEW: notice period and export window before deletion — suggest 30 days.
We may skip straight to suspension or termination, without warning, for: attacking or attempting to compromise the service; accessing another person's data; impersonating someone in an application; automating submission at scale; using the product to make employment decisions about other people; or anything that exposes us or other users to legal risk we cannot absorb.
Two things we will not pretend to be able to do:
- We cannot unsend an application, because we never sent one. If you sent something you regret, the employer is the only party who can act on it.
- We cannot remove your data from an employer's applicant tracking system. Once you press Send on their page, it is their record under their policy.
Repeated or automated violations may also lead us to block an IP range or a payment method.
10Appeals and reports
- To appeal an enforcement decision: Unresolved: REVIEW: contact address. Tell us what you think happened; a human reads it. Unresolved: REVIEW: response commitment — pick something keepable, e.g. 5 business days.
- To report abuse of Crossing by another user: Unresolved: REVIEW: contact address.
- To report a security issue: see the security and responsible-disclosure policy. Do not report vulnerabilities to the abuse address; the disclosure policy has the safe-harbour terms.
- To report a job posting (scam, expired, or one that should not be listed): see the job listings and sources policy, which also covers employer takedown requests.
11Changes
We will update this page when the product changes. Material changes will be announced before they take effect. Unresolved: REVIEW: notice mechanism and period — in-app notice plus email is normal; note that email delivery is not yet wired to a real transport.
Who to ask
Who "we" is: Unresolved: REVIEW: legal entity name and registered address
Governing law: