This policy explains what personal information Rolefit collects, how we use it, and the third-party processors we rely on. Rolefit is operated by Andrew Malvani, who is the data controller for the personal information described here (“we,” “us”). Your résumé is personal information (PII), so we treat it with care and keep the list of processors below deliberately explicit.
What we collect
Account data (email, authentication credentials managed by our auth provider), your profile (résumé text, instructions, location preferences, contact details, and any voluntary EEO self-identification you choose to provide), the job reviews and application packages we generate for you, and usage counters used to enforce plan limits. Payment is handled by Stripe — we never see or store your card number.
How we use it
We use your profile to review public job postings for fit and to generate tailored résumés and cover letters. To do this, your résumé text and instructions are sent to large-language-model providers for review and generation. We also record LLM traces (for debugging and quality) that may include your résumé text.
Third-party processors
We share data with the following processors, each only as needed to run the Service:
- Supabase — our database, authentication, and file storage. Your profile, reviews, and uploaded résumé files are stored here at rest.
- Vercel — hosts the web application (the dashboard you use).
- Railway — hosts our backend jobs (the reviewer and pollers).
- Stripe — processes subscription payments. Card data goes directly to Stripe and never touches our systems; we store only Stripe identifiers (a customer and subscription id) and your plan, status, and billing-period dates.
- OpenRouter and the downstream AI model providers it routes to — we send your résumé text and instructions to these providers to review jobs and generate résumés and cover letters.
- LangFuse(US cloud) — LLM observability. Traces we send for debugging and quality evaluation may include your résumé text. Traces are retained according to LangFuse’s retention settings.
Storage & retention
Your data is retained for as long as your account is active. Uploaded résumé files live in a storage bucket that is not versioned — when a file is deleted, it is gone permanently and cannot be recovered. We keep usage counters and minimal billing records as long as needed for accounting and abuse prevention.
Your rights: export & deletion
You can download everything we hold about you at any time using Export my data on your profile page. You can also permanently delete your accountfrom the same page: deletion removes your profile, reviews, generated application packages, and archived résumé files from our storage, cancels any active subscription, and deletes your customer record (email, name, saved payment methods) from Stripe. Deletion is irreversible. We keep two minimal traces: a deletion-ledger entry holding a keyed, irreversible hash of your email (proof of erasure and abuse prevention — never the address itself), and internal pipeline run records permanently disassociated from your identity. Note that Stripe retains its own charge and invoice records for tax and accounting compliance, and that LLM traces already sent to LangFuse and data at third-party model providers are governed by those providers’ retention policies.
Security
Access to your data is enforced per-tenant at the database level, so one user’s data is not visible to another. We restrict internal access and avoid exposing internal error details to clients.
Contact
Questions or a data request? Contact support or review our Terms of Service.