Skip to content
Features Pricing
Log in Add to Chrome
Features Pricing
Log in Add to Chrome
On this page
  1. 01. Overview and contact
  2. 02. Information we collect and use
  3. 03. Purposes and lawful bases
  4. 04. AI processing — OpenAI
  5. 05. CV and profile data
  6. 06. Who we share information with
  7. 07. Transfers and retention
  8. 08. Your UK data protection rights
  9. 09. Complaints
Last updated 31 July 2026
Privacy notice

How RoleSift uses your personal information.

RoleSift is a UK-based web app and Chrome extension for student, graduate, and early-career job-fit screening. This notice explains the personal information RoleSift uses to provide accounts, profile setup, job scans, subscriptions, support, export, and deletion controls.

Last updated 31 July 2026 · Applies to all RoleSift users
01

Overview and contact

Controller

RoleSift is operated by the configured privacy controller, the controller of personal information processed for the RoleSift website, account service, and Chrome extension. Postal address: the configured controller address.

Contact details

For privacy, account, security, or support requests, contact RoleSift at the configured support address or use the Contact/Support page.

Do not submit secrets

Do not paste passwords, banking details, National Insurance numbers, passport details, API keys, employer confidential material, medical information, special-category information, or other secrets into RoleSift job scans, CV fields, profile settings, or support messages.

Decision support only

RoleSift provides job-fit guidance and risk signals for you to consider. It does not make hiring decisions, employment decisions, credit decisions, or other legally significant decisions about you.

Use only what is needed

A redacted CV or short profile summary is usually enough. RoleSift is designed for job-fit context, not sensitive identity, financial, medical, or employer-confidential information.

Age requirement

RoleSift accounts are for people aged 18 or over. Do not create an account or submit personal information if you are under 18.

02

Information we collect and use

We collect personal information directly from you, from your use of the RoleSift site or extension, and from service providers such as Supabase and Stripe.

Account and profile data

Email address, user ID, display name, profile preferences, target roles, skills, dealbreakers, location preferences, salary preferences, remote/contract preferences, career goals, email confirmation status, and account timestamps.

Job descriptions and job metadata

Job description text you paste into RoleSift or explicitly scan from a RoleSift-approved direct-scan page, plus the job URL, title, company, location, salary or contract details where present, and other role text you choose to submit.

CV text and profile preferences

You may paste a CV, redacted CV, short profile summary, or supported CV file to extract factual CV details such as education, experience, skills, projects, certifications, and leadership examples. Job-search preferences, such as target roles, locations, work style, and right-to-work summary, are added separately by you. When you request extraction, CV/profile text is processed server-side and may be sent to OpenAI API. RoleSift separately asks you to confirm before saving the reviewed structured CV facts and preferences. RoleSift does not save the original CV text or uploaded file.

Scan results and usage events

AI-generated scan results, scores, recommendations, risk flags, scan type, cached-result fingerprints, credit usage, scan-credit ledger entries, timestamps, and whether a result was fresh or loaded from cache. Structured results may contain short exact excerpts from the submitted job description as evidence. RoleSift does not store the full submitted job description as part of the saved scan result.

Applications and planning

Applications you add or derive from scans, application stages and notes, priority-plan settings and ranked roles, RolePath steps and progress, beta feedback, validation events, and other account actions used to provide the dashboard and job-search planning features.

Subscription and payment status

Plan, subscription status, Stripe customer/subscription identifiers, checkout events, billing status, current period dates, and payment-event metadata needed to provide paid plans. Stripe handles card details; RoleSift stores subscription status rather than full card numbers.

Chrome extension data

The extension stores authentication session tokens, cached profile/account/credit state, scan preferences, scan identity and handoff state, and privacy-safe failure events in Chrome extension storage. It reads the active tab URL, title, and domain locally to determine whether direct capture is permitted. Job text is read and transmitted only after you initiate an approved direct scan or paste it manually. Restricted or unknown page content is not read. An optional job URL may be submitted with a scan.

Technical and security data

IP address, device/browser information, request logs, error logs, fraud-prevention signals, rate-limit events, authentication events, deployment/security logs, and other technical data needed to operate and secure the service.

Support and early-access contact data

If you contact RoleSift, test the product, or help administer it, we may process your name, email address, message content, issue details, and support history. This product notice covers RoleSift user and support data, not separate workforce or contractor records.

03

Purposes and lawful bases

The lawful basis depends on the feature and purpose. RoleSift uses the bases listed below.

Providing requested services — contract

We use account, profile, job, CV, scan, application, planning, subscription, and usage data because it is necessary to create and operate your account, perform the extraction or scan you request, provide dashboards and account controls, enforce credits, and provide subscription access, or to take steps you request before entering a contract.

Security and reliability — legitimate interests

We use proportionate technical logs, authentication events, rate limits, privacy-safe failure events, cached fingerprints, and credit-ledger records to protect accounts, prevent abuse and duplicate charging, debug faults, and keep the service reliable. Our legitimate interests are protecting users, the service, and allowance integrity.

Payments and records — contract and legal obligation

We use subscription and payment-status data to provide paid plans and manage billing under our contract with you. We keep records required for tax, accounting, dispute, and other applicable legal duties under legal obligation.

Optional communications or storage — consent where stated

Where a feature expressly relies on consent, you may refuse without losing unrelated service access and may withdraw it as easily as you gave it. Withdrawal does not affect earlier lawful processing. The CV extraction and structured-profile save confirmations record the specific action you requested; they do not override your statutory rights.

04

AI processing — OpenAI

RoleSift calls OpenAI from the server side, not directly from the Chrome extension or browser frontend.

What may be sent

For profile extraction, when you request it, RoleSift may send CV/profile text to OpenAI API server-side to extract factual details for a structured JobFitProfile. For a scan, RoleSift sends the job description text you pasted or explicitly scanned, role metadata, the user-entered preferences relevant to that scan, and the reviewed structured profile evidence needed to generate fit scores, risk indicators, questions, recommendations, and application guidance.

What is returned

RoleSift receives structured analysis such as scores, matched strengths, CV gaps, red flags, questions, and suggested next actions. Results may be cached for the authenticated user to avoid duplicate credit charges.

Current storage boundary

OpenAI calls happen from RoleSift's backend, not the browser or extension. RoleSift stores structured job-fit profile fields, scan fingerprints, and structured results. In the current setup flow, RoleSift does not save the original CV text or uploaded CV file to your profile.

Provider data controls

OpenAI states that API content is not used to train its models unless the API customer opts in. Under OpenAI's default API data controls, abuse-monitoring logs may contain prompts and outputs and may be retained for up to 30 days. RoleSift does not opt submitted API content into model training. OpenAI may retain content longer where legally required or for security reasons under its applicable terms.

Provider boundary

OpenAI processes submitted content only for the AI features you request and under RoleSift's provider arrangements. RoleSift does not expose OpenAI API keys to the browser, extension, or support workflows.

05

CV and profile data

RoleSift only needs information that helps judge job fit. A redacted CV or short profile summary is usually enough.

What is useful

For CV extraction, RoleSift needs factual CV details such as education level, degree subject, relevant skills, tools, projects, experience summaries, certifications, and leadership examples. In the preferences step, you can separately add target roles, target industries, target locations, work style, role type preferences, availability, salary expectations, and a short work-authorisation summary where relevant.

What is not needed

Passport numbers, National Insurance numbers, full home address, banking details, medical information, disability information, ethnicity, religion, political opinions, trade union membership, or anything else not needed for job-fit scanning.

What is stored

If you choose to save the profile, RoleSift stores the reviewed structured JobFitProfile, including reviewed CV facts and user-entered job search preferences, plus scan results, feedback, account data, consent records, and credit/subscription records needed to run the service. The original CV/profile text or uploaded file is not saved to your profile in the current setup flow.

Your controls

Signed-in users can use Settings to export account-associated data, delete scan history or profile/preferences data, and request full account deletion. Full account deletion requires the current password and an explicit confirmation. RoleSift is a decision aid, not a guarantee of job success or a replacement for professional careers advice.

06

Who we share information with

We use service providers to run RoleSift. They process personal information for the purposes described below and under their applicable data processing terms.

Supabase

Authentication and database services, including user accounts, profiles, preferences, subscriptions/account status, scan cache metadata, usage events, and app data.

Vercel

Website hosting, backend functions, deployment infrastructure, request handling, logs, and security/operational monitoring.

Stripe

Checkout, card/payment processing, invoices, billing events, customer IDs, subscription IDs, subscription status, and payment-related fraud prevention.

OpenAI

Server-side extraction of CV/profile text into factual CV details after processing consent, plus AI analysis of job description text you pasted or explicitly scanned through an approved direct-scan flow, user-entered job preferences, and structured job-fit profile evidence where you request a scan that uses AI.

Google / Chrome Web Store

The RoleSift Chrome extension is installed from the Chrome Web Store. Google may process extension listing, review, installation, browser, and account-related information under its own terms.

Chrome Web Store Limited Use

RoleSift's use and transfer of Chrome extension user data is limited to providing and improving the user-facing RoleSift job-fit service. RoleSift does not sell extension user data, use it for personalised advertising or creditworthiness/lending, or permit human access except with the user's affirmative agreement for support, for security or abuse investigation, to comply with law, or where aggregated and anonymised for internal operations.

Professional advisers or authorities

Where necessary, we may share limited information with professional advisers, regulators, payment dispute handlers, or law enforcement where legally required or to protect rights and security.

07

Transfers and retention

International transfers

Supabase, Vercel, Stripe, OpenAI, and Google may process data outside the UK, including in the United States or other locations. Where personal information is transferred internationally, RoleSift relies on applicable provider terms, data processing terms, and lawful transfer safeguards where required.

Retention

Account and profile data is kept while your account is active. Scan results and profile/preferences data can be deleted through Settings. Once a full-account request is accepted, RoleSift blocks new purchases, checkpoints billing closure and account-data deletion for safe retry, and removes account-linked application data and the Supabase Auth user when the workflow completes. A minimal deletion audit record containing identifiers, state, timestamps, retry counts, and privacy-safe error codes may remain so interrupted requests can be recovered and completion can be evidenced. Stripe, payment, security, support, dispute, tax, accounting, and legal records may be retained by RoleSift or its providers where reasonably needed or legally required.

Export and deletion controls

Signed-in users can export RoleSift account-associated data, delete scan history, delete profile/preferences data, or delete the full RoleSift account through Settings. The full-account control verifies the current password, accepts and checkpoints the request, closes RoleSift billing, removes non-cascading application records, and then deletes the Supabase Auth user and remaining account-linked rows. If a provider or database step is temporarily unavailable, the response says that deletion is pending and the stored checkpoint supports a safe retry. It does not promise deletion of records Stripe or another provider must retain for legal, tax, accounting, dispute, fraud-prevention, or security purposes. Contact support if a deletion request cannot be completed.

Logs and operational records

Technical, security, support, billing, and immutable credit-ledger records are retained only for as long as reasonably needed for the purpose collected, considering account security, service reliability, dispute and abuse risk, applicable limitation periods, and tax/accounting duties. RoleSift periodically reviews these criteria and deletes or anonymises records when they are no longer needed.

08

Your UK data protection rights

Depending on the lawful basis and any exemptions, you may have the following rights over your personal information.

Access

You can ask for copies of your personal information and supporting information about how it is used.

Rectification

You can ask us to correct personal information you think is inaccurate or incomplete.

Erasure

You can ask us to delete personal information, subject to legal, billing, security, and abuse-prevention limits.

Restriction and objection

You can ask us to restrict certain processing or object to processing in certain circumstances.

Portability

You can ask for certain information you provided to be transferred to you or another organisation where this right applies.

Withdraw consent

Where RoleSift relies on consent, you can withdraw it at any time. This does not affect processing that happened before withdrawal.

To make a rights request, use the contact details above. We will respond without undue delay and within one month where required by law.

09

Complaints

Send a privacy complaint to the configured support address or use the Contact/Support page. Put “Privacy complaint” in the subject and describe the account, issue, relevant dates, and outcome you want, without including passwords, identity numbers, card details, or unnecessary CV data. RoleSift will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, keep you informed about progress, and explain the outcome. If you remain unhappy, or prefer not to contact RoleSift first, you may complain to the Information Commissioner's Office.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113.

ico.org.uk/make-a-complaint

RoleSift

AI job-fit scanner for students and graduates.

Add to Chrome
Cookie Preferences

Product

FeaturesPricingChrome Extension

Company

Our StoryPricingContactTrust & Security

Resources

FAQSample scanDashboard previewRoleTracker previewRolePath previewHelp & Support

Legal

Privacy PolicyTermsCookie PolicyCancellation / Refund
© 2026 RoleSift. All rights reserved.