R Privacy NoticeRoleSift data handling
Privacy notice

How RoleSift uses your personal information.

RoleSift is a UK-based web app and Chrome extension for student, graduate, and early-career job-fit screening. This notice adapts the ICO-generated template for RoleSift's actual product data flows. It should receive final legal review before wider public launch.

Contact details

For privacy, account, security, or support requests, contact RoleSift at sebcolliedog@gmail.com. A domain-based support mailbox should be configured before full public launch.

Do not submit secrets

Do not paste passwords, banking details, National Insurance numbers, passport details, API keys, employer confidential material, medical information, special-category information, or other secrets into RoleSift job scans, CV fields, profile settings, or support messages.

Decision support only

RoleSift provides job-fit guidance and risk signals for you to consider. It does not make hiring decisions, employment decisions, credit decisions, or other legally significant decisions about you.

Private MVP status

Some account, extension, export, deletion, subscription, and saved-CV flows are still being completed for MVP testing. This notice describes the intended MVP behaviour and flags areas that need final legal and technical review.

Information we collect and use

RoleSift data categories

We collect personal information directly from you, from your use of the RoleSift site or extension, and from service providers such as Supabase and Stripe.

Account and profile data

Email address, user ID, display name, profile preferences, target roles, skills, dealbreakers, location preferences, salary preferences, remote/contract preferences, career goals, email confirmation status, and account timestamps.

Job descriptions and selected job text

Job listing text, selected page text, job URL, job title, company name, role location, salary or contract details where present, and other text you choose to scan through the website or Chrome extension.

CV text and profile preferences

You may paste a CV, redacted CV, short profile summary, or supported CV file to extract factual CV details such as education, experience, skills, projects, certifications, and leadership examples. Job search preferences, such as target roles, locations, work style, and right-to-work summary, are added separately by you. After processing consent, CV/profile text is sent to OpenAI API server-side for extraction. RoleSift asks for separate storage consent before saving the reviewed CV details and job search preferences. Current profile setup stores only structured job-fit fields after consent, not the original CV text or file.

Scan results and usage events

AI-generated scan results, scores, recommendations, risk flags, scan type, cached-result fingerprints, credit usage, scan-credit ledger entries, timestamps, and whether a result was fresh or loaded from cache. Cache records should not store raw CV text or raw job descriptions.

Subscription and payment status

Plan, subscription status, Stripe customer/subscription identifiers, checkout events, billing status, current period dates, and payment-event metadata needed to provide paid plans. Stripe handles card details; RoleSift should not store full card numbers.

Chrome extension data

Extension settings such as backend URL, authentication bridge state, scan preferences, the current tab or selected text you choose to scan, and local extension state needed to show results and account status. The extension should not contain server secrets.

Technical and security data

IP address, device/browser information, request logs, error logs, fraud-prevention signals, rate-limit events, authentication events, deployment/security logs, and other technical data needed to operate and secure the service.

Support and tester contact data

If you contact RoleSift, test the product, or help administer it, we may process your name, email address, message content, issue details, and support history. If RoleSift later needs a separate workforce or contractor privacy notice, that should be handled outside this product notice.

Why we use it

Purposes and lawful bases

The lawful basis may depend on the feature. This section should be reviewed before public launch, especially for saved CVs, analytics, and marketing.

Providing RoleSift

We use account, profile, job, CV, scan, subscription, and usage data to provide the website, extension, job-fit scans, dashboards, credit limits, cached results, and subscription access. The likely lawful basis is contract, or steps taken before entering into a contract.

Security, fraud prevention, and reliability

We use technical logs, authentication events, rate limits, usage events, and credit-ledger records to protect accounts, prevent abuse, maintain scan limits, debug faults, and operate the service. The likely lawful basis is legitimate interests.

Payments and records

We use subscription and payment-status data to provide paid plans, handle billing events, reconcile Stripe webhooks, and keep records required for accounting or legal compliance. The likely lawful bases are contract and legal obligation.

Optional saved CVs and future features

If RoleSift later stores CV text or offers optional marketing or product research, the feature should clearly explain what is stored, why, for how long, and whether consent is required. Users must be able to withdraw consent where consent is used.

AI processing

OpenAI and job/CV analysis

RoleSift calls OpenAI from the server side, not directly from the Chrome extension or browser frontend.

What may be sent

For profile extraction, after your processing consent, RoleSift sends CV/profile text to OpenAI API server-side to extract factual CV details for a structured JobFitProfile. For a scan, RoleSift may send job text, selected page text, role metadata, your user-entered job search preferences, and your reviewed structured job-fit profile to OpenAI to generate fit scores, risk indicators, questions, recommendations, and application guidance.

What is returned

RoleSift receives structured analysis such as scores, matched strengths, CV gaps, red flags, questions, and suggested next actions. Results may be cached for the authenticated user to avoid duplicate credit charges.

Current storage boundary

OpenAI calls happen from RoleSift's backend, not the browser or extension. RoleSift stores structured job-fit profile fields, scan fingerprints, and structured results, not raw CV text or raw job descriptions, unless a separate consent, encryption, retention, and deletion flow has been implemented and explained.

OpenAI training note

OpenAI states that data submitted through its API is not used to train or improve OpenAI models by default unless the API customer opts in. RoleSift should not opt in to model training for submitted CV/profile text before live testing.

CV and profile data

What to submit, save, or delete

RoleSift only needs information that helps judge job fit. A redacted CV or short profile summary is enough for MVP testing.

What is useful

For CV extraction, RoleSift needs factual CV details such as education level, degree subject, relevant skills, tools, projects, experience summaries, certifications, and leadership examples. In the preferences step, you can separately add target roles, target industries, target locations, work style, role type preferences, availability, salary expectations, and a short work-authorisation summary where relevant.

What is not needed

Passport numbers, National Insurance numbers, full home address, banking details, medical information, disability information, ethnicity, religion, political opinions, trade union membership, or anything else not needed for job-fit scanning.

What is stored

If you choose to save the profile, RoleSift stores the reviewed structured JobFitProfile, including reviewed CV facts and user-entered job search preferences, plus scan results, feedback, account data, consent records, and credit/subscription records needed to run the service. The original CV/profile text or uploaded file is not saved to your profile in the current setup flow.

Deletion and admin views

Signed-in users can delete their saved structured profile from Settings where implemented. Internal validation dashboards should show outcomes, decision changes, usefulness/trust scores, willingness-to-pay signals, and feedback, not raw CV/profile text. RoleSift is a decision aid, not a guarantee of job success or a replacement for professional careers advice.

Processors and sharing

Who we share personal information with

We use service providers to run RoleSift. They process personal information for the purposes described below and under their applicable data processing terms.

Supabase

Authentication and database services, including user accounts, profiles, preferences, subscriptions/account status, scan cache metadata, usage events, and app data.

Vercel

Website hosting, backend functions, deployment infrastructure, request handling, logs, and security/operational monitoring.

Stripe

Checkout, card/payment processing, invoices, billing events, customer IDs, subscription IDs, subscription status, and payment-related fraud prevention.

OpenAI

Server-side extraction of CV/profile text into factual CV details after processing consent, plus AI analysis of job descriptions, selected job text, user-entered job preferences, and structured job-fit profile evidence where you request a scan that uses AI.

Google / Chrome Web Store

If the extension is published, Google may process extension listing, review, installation, browser, and account-related information under its own terms. RoleSift should not imply public Chrome Web Store availability until approval is complete.

Professional advisers or authorities

Where necessary, we may share limited information with professional advisers, regulators, payment dispute handlers, or law enforcement where legally required or to protect rights and security.

Transfers and retention

Where information is processed and how long it is kept

International transfers

Supabase, Vercel, Stripe, OpenAI, and Google may process data outside the UK, including in the United States or other locations. Where personal information is transferred internationally, RoleSift should rely on appropriate safeguards such as UK-approved contractual protections, relevant data processing terms, or other lawful transfer mechanisms.

Retention

Account and profile data is kept while your account is active. Scan results and profile/preferences data can be deleted through available settings where implemented. Billing, subscription, security, and credit-ledger records may be retained for longer where needed for accounting, fraud prevention, dispute handling, scan allowance integrity, or legal obligations.

Export and deletion controls

Signed-in users can export RoleSift account-associated data, delete scan history, and delete profile/preferences data where those controls are implemented. These controls do not cancel Stripe subscriptions or delete Stripe records. Some immutable credit/billing records may be retained to prevent credit reset abuse and preserve payment integrity.

Retention schedule review

A full production retention schedule should be finalised before public launch, especially for logs, scan cache expiry, saved CVs, support messages, and billing records.

Your rights

Your UK data protection rights

Depending on the lawful basis and any exemptions, you may have the following rights over your personal information.

Access

You can ask for copies of your personal information and supporting information about how it is used.

Rectification

You can ask us to correct personal information you think is inaccurate or incomplete.

Erasure

You can ask us to delete personal information, subject to legal, billing, security, and abuse-prevention limits.

Restriction and objection

You can ask us to restrict certain processing or object to processing in certain circumstances.

Portability

You can ask for certain information you provided to be transferred to you or another organisation where this right applies.

Withdraw consent

Where RoleSift relies on consent, you can withdraw it at any time. This does not affect processing that happened before withdrawal.

To make a rights request, use the contact details above. We will respond without undue delay and within one month where required by law.

Complaints

How to complain

If you have concerns about RoleSift's use of your personal information, please contact us first so we can investigate. If you remain unhappy, you can complain to the Information Commissioner's Office.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Helpline: 0303 123 1113

ico.org.uk/make-a-complaint

Last updated

4 May 2026.

This notice replaces a generic ICO template with RoleSift-specific product privacy information.