Privacy Policy

Last updated: 2 June 2026

1. Who is responsible for your data

The data controller is [Operator name / sole trader], [address], England ([ICO registration number, once registered]). Contact us about privacy at [contact email].

2. What we collect

Account: email and password (passwords are stored hashed by our auth provider). Profile inputs: job title, salary, experience, location, skills, and any CV/documents you upload. Usage: features used, AI requests and token usage, and analytics/diagnostic data. Payment:handled by Stripe — we receive subscription status, not your full card details.

3. Why, and our lawful bases

To provide the Service and your salary/career insights (contract); to take payment and prevent fraud and abuse (contract / legitimate interests); to improve and secure the Service via analytics (consent for non-essential cookies — see our Cookie Policy — and otherwise legitimate interests); and to meet legal obligations (legal obligation).

4. Who we share it with (processors)

We use trusted providers who process data on our behalf: Supabase(database & authentication), Stripe (payments), Anthropic(AI generation), PostHog (product analytics), and Vercel/Railway (hosting). We don't sell your data.

5. International transfers

Some providers process data outside the UK. Where they do, transfers are protected by UK-approved safeguards (e.g. the UK addendum to the EU Standard Contractual Clauses or an adequacy decision).

6. How long we keep it

Account & profile data: kept while your account is active and deleted or anonymised within 30 days of account closure or a valid deletion request. Usage & AI/token logs: kept up to 24 months for billing, fraud-prevention and analytics, then deleted or anonymised. Backups: cycled out of routine backups within 90 days. We keep limited records longer only where the law requires (e.g. tax/accounting).

7. Your rights

You have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. You can edit your profile, change your email, and permanently delete your account and all associated data from your Account page. For data access, portability or any other request, email [contact email] and we'll respond within one month. You can also complain to the ICO (ico.org.uk).

8. Cookies

We use essential cookies to run the site and, with your consent, analytics cookies. See our Cookie Policy.

9. Changes & contact

We'll post updates here with a new date. Questions or requests: [contact email].