Skip to content

Legal

Privacy policy

Last updated 25 September 2026

1. Who we are

RoleScaler is run by RoleScaler, the "data controller" for the personal data described here. Questions about your data, or requests to use your rights, go to support@rolescaler.com.

RoleScaler is in beta. This policy covers the beta and will be updated before the full launch.

2. What we collect

  • Account: your email address and password (stored only as a secure hash by our authentication provider). If you sign in with Google, the name and email Google shares with us.
  • Profile: your name, current and target role, years of experience and tech stack, as you enter them.
  • What you add: CVs (including the contact details in them) and earlier copies of them kept so you can undo changes, job descriptions and links, notes, cover letters, match reports, interview prep and how useful you rated it, collections and saved searches.
  • Contacts you note: the names, roles, email addresses and links of people at employers (a recruiter, say) that you add to a job in your tracker. They're kept for you alone, and we never contact them.
  • Friends you invite: if you use Invite a friend with an email address, we send that person one invite email and keep the address so you can see who you've invited (and, during the beta, so the invite lets them sign up). We don't email them again unless they sign up. If they arrive through your share link and sign up, we note that you invited them.
  • Waiting list: if you ask for a beta invite, your email address and, if you give it, the role you're after, so we can invite you. We keep a scrambled form of your IP address for an hour's worth of requests, to stop the form being abused, never the address itself.
  • Browser extension: if you use it, the job advert on the page you click it on (title, company, location, description and link). It reads that page only when you click, sends nothing by itself, and nothing is saved until you press Add to tracker. It never reads other pages or your browsing history.
  • GitHub: if you import it, the public profile and repository information of the GitHub username you give. We never ask for access to private repositories.
  • Feedback: what you write in the feedback form, the page it's about and, if you're signed out, the email you give. We keep a scrambled (hashed) form of your IP address to stop the form being spammed; it can't be turned back into the address.
  • Usage records: which features you used and when (for example, one match report at 10:32), so we can apply fair-use limits and understand how the product is used. Not the content itself.
  • Error reports: when something breaks, a technical report of the error. We strip page content, cookies and your email from these before they're sent.
  • Hosting logs: our hosting and database providers record IP addresses and request details in their own logs, for security and reliability.

3. How we use it, and why we're allowed to

  • To provide RoleScaler: storing your documents, running the analysis, writing and checking tailored drafts, and sending account emails such as confirmations and password resets. This is needed for our agreement with you (the terms).
  • To send job alerts you asked for: if you turn on the bell next to a saved search, we email you when roles matching it appear, at most once a day. Every alert email has a one-click way to stop it, and turning it off stops that email and nothing else.
  • To send you a weekly summary: on Mondays, an email about your own tracker: applications that need you, follow-ups you planned, new roles for your saved searches. It's part of the service rather than marketing, and it's sent only in weeks with something to say. Turn it off in Settings or with the link in any of them.
  • To keep it secure and fair: rate limits, preventing abuse, and fixing errors. This is our legitimate interest in running a safe, working service.
  • To improve it: understanding which features are used, from usage records and feedback. Also a legitimate interest; you can object at any time.

We don't sell your data, we don't show ads, and we don't use your content to train AI models.

4. How the AI features handle your data

When you run a match report, tailoring, a cover letter, interview prep or a CV import, the relevant text (your CV and the job description) is sent to OpenAI and, for cover letters and interview prep, Anthropic, to produce and check the result. We use their business APIs. Under their API terms they don't use this data to train their models. They may keep it for a limited time to monitor for abuse, then delete it.

AI results are drafts. Check everything before you use it: you're responsible for what you send to employers.

5. Who else processes your data

These providers process data on our behalf, only to run RoleScaler:

  • Supabase: database and sign-in. Your data is stored in the EU (Frankfurt).
  • Cloudflare R2: our nightly database backups, encrypted before they leave our systems with a key only we hold, stored in Western Europe and deleted after 30 days.
  • Vercel: hosting, and anonymous page-view counts (Vercel Web Analytics: no cookies, nothing that identifies you, and addresses are stripped of anything personal before they're sent). The app runs in the EU (Frankfurt); requests pass through Vercel's global network.
  • OpenAI and Anthropic: the AI features (USA).
  • Resend: sending account and support emails (USA).
  • Sentry: error reports (see above).
  • Adzuna: the job search. Only the search terms and location you type are sent, never your CV.
  • GitHub: looking up the public profile you ask us to import.
  • Have I Been Pwned: checking new passwords against known data breaches. Only the first 5 characters of a scrambled (hashed) password are sent, never the password.
  • Google: only if you choose Sign in with Google.
  • Zoho: our support mailbox, if you email us.

Where a provider is outside the UK and EU, the transfer is protected by the safeguards those providers offer, such as standard data protection clauses or the UK–US data bridge.

6. How long we keep it

  • Your content: for as long as you keep it. Items you delete go to the recycle bin for 7 days, then are removed for good.
  • Your account: until you delete it in Settings. Deleting your account removes your profile, documents, jobs, reports and usage records straight away.
  • Feedback: kept after account deletion so we can act on it, but no longer linked to you. Ask us and we'll delete it.
  • Hosting logs, error reports and any backups are deleted on the providers' own schedules, typically within 30 days.

7. Your rights

Under UK data protection law (UK GDPR) you can:

  • get a copy of your data (Settings → Your data → Download my data, straight away; or email us and we'll send it within a month)
  • correct it (most of it you can edit yourself in the app)
  • delete it (Settings → Delete account, or email us)
  • object to or restrict how we use it
  • take it to another service: the download above is a plain JSON file, made to be read by you and by other software

Email support@rolescaler.com. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk), though we'd like the chance to put it right first.

8. Cookies

We only use what's needed for the site to work: sign-in cookies that keep you logged in, and a small note in your browser that you have an account (so the site can show Log in first). No analytics, advertising or tracking cookies, so there's no cookie banner.

9. Security

Data is encrypted in transit (HTTPS) and at rest by our providers. Database rules make sure each account can only read its own data, and access to our systems is limited to the people who run RoleScaler. No system is perfectly secure; if a breach affected your data, we'd tell you and the ICO as the law requires.

10. Age

RoleScaler is for people aged 18 and over.

11. Changes to this policy

We'll update this page when anything changes and tell signed-up users by email about significant changes.