How RoleSift uses your personal information.
RoleSift is a UK-based web app and Chrome extension for student, graduate, and early-career job-fit screening. This notice explains the personal information RoleSift uses to provide accounts, profile setup, job scans, subscriptions, support, export, and deletion controls.
Overview and contact
RoleSift is operated by the configured privacy controller, the controller of personal information processed for the RoleSift website, account service, and Chrome extension. Postal address: the configured controller address.
For privacy, account, security, or support requests, contact RoleSift at the configured support address or use the Contact/Support page.
Do not paste passwords, banking details, National Insurance numbers, passport details, API keys, employer confidential material, medical information, special-category information, or other secrets into RoleSift job scans, CV fields, profile settings, or support messages.
RoleSift provides job-fit guidance and risk signals for you to consider. It does not make hiring decisions, employment decisions, credit decisions, or other legally significant decisions about you.
A redacted CV or short profile summary is usually enough. RoleSift is designed for job-fit context, not sensitive identity, financial, medical, or employer-confidential information.
RoleSift accounts are for people aged 18 or over. Do not create an account or submit personal information if you are under 18.
Information we collect and use
We collect personal information directly from you, from your use of the RoleSift site or extension, and from service providers such as Supabase and Stripe.
Email address, user ID, display name, profile preferences, target roles, skills, dealbreakers, location preferences, salary preferences, remote/contract preferences, career goals, email confirmation status, and account timestamps.
Job description text you paste into RoleSift or explicitly scan from a RoleSift-approved direct-scan page, plus the job URL, title, company, location, salary or contract details where present, and other role text you choose to submit.
You may paste a CV, redacted CV, short profile summary, or supported CV file to extract factual CV details such as education, experience, skills, projects, certifications, and leadership examples. Job-search preferences, such as target roles, locations, work style, and right-to-work summary, are added separately by you. When you request extraction, CV/profile text is processed server-side and may be sent to OpenAI API. RoleSift separately asks you to confirm before saving the reviewed structured CV facts and preferences. RoleSift does not save the original CV text or uploaded file.
AI-generated scan results, scores, recommendations, risk flags, scan type, cached-result fingerprints, credit usage, scan-credit ledger entries, timestamps, and whether a result was fresh or loaded from cache. Structured results may contain short exact excerpts from the submitted job description as evidence. RoleSift does not store the full submitted job description as part of the saved scan result.
Applications you add or derive from scans, application stages and notes, priority-plan settings and ranked roles, RolePath steps and progress, beta feedback, validation events, and other account actions used to provide the dashboard and job-search planning features.
Plan, subscription status, Stripe customer/subscription identifiers, checkout events, billing status, current period dates, and payment-event metadata needed to provide paid plans. Stripe handles card details; RoleSift stores subscription status rather than full card numbers.
The extension stores authentication session tokens, cached profile/account/credit state, scan preferences, scan identity and handoff state, and privacy-safe failure events in Chrome extension storage. It reads the active tab URL, title, and domain locally to determine whether direct capture is permitted. Job text is read and transmitted only after you initiate an approved direct scan or paste it manually. Restricted or unknown page content is not read. An optional job URL may be submitted with a scan.
IP address, device/browser information, request logs, error logs, fraud-prevention signals, rate-limit events, authentication events, deployment/security logs, and other technical data needed to operate and secure the service.
If you contact RoleSift, test the product, or help administer it, we may process your name, email address, message content, issue details, and support history. This product notice covers RoleSift user and support data, not separate workforce or contractor records.
Purposes and lawful bases
The lawful basis depends on the feature and purpose. RoleSift uses the bases listed below.
We use account, profile, job, CV, scan, application, planning, subscription, and usage data because it is necessary to create and operate your account, perform the extraction or scan you request, provide dashboards and account controls, enforce credits, and provide subscription access, or to take steps you request before entering a contract.
We use proportionate technical logs, authentication events, rate limits, privacy-safe failure events, cached fingerprints, and credit-ledger records to protect accounts, prevent abuse and duplicate charging, debug faults, and keep the service reliable. Our legitimate interests are protecting users, the service, and allowance integrity.
We use subscription and payment-status data to provide paid plans and manage billing under our contract with you. We keep records required for tax, accounting, dispute, and other applicable legal duties under legal obligation.
Where a feature expressly relies on consent, you may refuse without losing unrelated service access and may withdraw it as easily as you gave it. Withdrawal does not affect earlier lawful processing. The CV extraction and structured-profile save confirmations record the specific action you requested; they do not override your statutory rights.
AI processing — OpenAI
RoleSift calls OpenAI from the server side, not directly from the Chrome extension or browser frontend.
For profile extraction, when you request it, RoleSift may send CV/profile text to OpenAI API server-side to extract factual details for a structured JobFitProfile. For a scan, RoleSift sends the job description text you pasted or explicitly scanned, role metadata, the user-entered preferences relevant to that scan, and the reviewed structured profile evidence needed to generate fit scores, risk indicators, questions, recommendations, and application guidance.
RoleSift receives structured analysis such as scores, matched strengths, CV gaps, red flags, questions, and suggested next actions. Results may be cached for the authenticated user to avoid duplicate credit charges.
OpenAI calls happen from RoleSift's backend, not the browser or extension. RoleSift stores structured job-fit profile fields, scan fingerprints, and structured results. In the current setup flow, RoleSift does not save the original CV text or uploaded CV file to your profile.
OpenAI states that API content is not used to train its models unless the API customer opts in. Under OpenAI's default API data controls, abuse-monitoring logs may contain prompts and outputs and may be retained for up to 30 days. RoleSift does not opt submitted API content into model training. OpenAI may retain content longer where legally required or for security reasons under its applicable terms.
OpenAI processes submitted content only for the AI features you request and under RoleSift's provider arrangements. RoleSift does not expose OpenAI API keys to the browser, extension, or support workflows.
CV and profile data
RoleSift only needs information that helps judge job fit. A redacted CV or short profile summary is usually enough.
For CV extraction, RoleSift needs factual CV details such as education level, degree subject, relevant skills, tools, projects, experience summaries, certifications, and leadership examples. In the preferences step, you can separately add target roles, target industries, target locations, work style, role type preferences, availability, salary expectations, and a short work-authorisation summary where relevant.
Passport numbers, National Insurance numbers, full home address, banking details, medical information, disability information, ethnicity, religion, political opinions, trade union membership, or anything else not needed for job-fit scanning.
If you choose to save the profile, RoleSift stores the reviewed structured JobFitProfile, including reviewed CV facts and user-entered job search preferences, plus scan results, feedback, account data, consent records, and credit/subscription records needed to run the service. The original CV/profile text or uploaded file is not saved to your profile in the current setup flow.
Signed-in users can use Settings to export account-associated data, delete scan history or profile/preferences data, and request full account deletion. Full account deletion requires the current password and an explicit confirmation. RoleSift is a decision aid, not a guarantee of job success or a replacement for professional careers advice.
Transfers and retention
Supabase, Vercel, Stripe, OpenAI, and Google may process data outside the UK, including in the United States or other locations. Where personal information is transferred internationally, RoleSift relies on applicable provider terms, data processing terms, and lawful transfer safeguards where required.
Account and profile data is kept while your account is active. Scan results and profile/preferences data can be deleted through Settings. Once a full-account request is accepted, RoleSift blocks new purchases, checkpoints billing closure and account-data deletion for safe retry, and removes account-linked application data and the Supabase Auth user when the workflow completes. A minimal deletion audit record containing identifiers, state, timestamps, retry counts, and privacy-safe error codes may remain so interrupted requests can be recovered and completion can be evidenced. Stripe, payment, security, support, dispute, tax, accounting, and legal records may be retained by RoleSift or its providers where reasonably needed or legally required.
Signed-in users can export RoleSift account-associated data, delete scan history, delete profile/preferences data, or delete the full RoleSift account through Settings. The full-account control verifies the current password, accepts and checkpoints the request, closes RoleSift billing, removes non-cascading application records, and then deletes the Supabase Auth user and remaining account-linked rows. If a provider or database step is temporarily unavailable, the response says that deletion is pending and the stored checkpoint supports a safe retry. It does not promise deletion of records Stripe or another provider must retain for legal, tax, accounting, dispute, fraud-prevention, or security purposes. Contact support if a deletion request cannot be completed.
Technical, security, support, billing, and immutable credit-ledger records are retained only for as long as reasonably needed for the purpose collected, considering account security, service reliability, dispute and abuse risk, applicable limitation periods, and tax/accounting duties. RoleSift periodically reviews these criteria and deletes or anonymises records when they are no longer needed.
Your UK data protection rights
Depending on the lawful basis and any exemptions, you may have the following rights over your personal information.
You can ask for copies of your personal information and supporting information about how it is used.
You can ask us to correct personal information you think is inaccurate or incomplete.
You can ask us to delete personal information, subject to legal, billing, security, and abuse-prevention limits.
You can ask us to restrict certain processing or object to processing in certain circumstances.
You can ask for certain information you provided to be transferred to you or another organisation where this right applies.
Where RoleSift relies on consent, you can withdraw it at any time. This does not affect processing that happened before withdrawal.
To make a rights request, use the contact details above. We will respond without undue delay and within one month where required by law.
Complaints
Send a privacy complaint to the configured support address or use the Contact/Support page. Put “Privacy complaint” in the subject and describe the account, issue, relevant dates, and outcome you want, without including passwords, identity numbers, card details, or unnecessary CV data. RoleSift will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, keep you informed about progress, and explain the outcome. If you remain unhappy, or prefer not to contact RoleSift first, you may complain to the Information Commissioner's Office.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113.