Privacy Policy

Last updated 30 June 2026

Rolevera is operated by Nicholas Mahon operating as Rolevera Technologies ("Rolevera", "we", "us"), the data controller for the personal information described here.

This policy explains what we collect, why, who we share it with, and the choices you have. We have written it in plain language. If anything is unclear, contact us using the address at the end.

Rolevera will never sell your career data to recruiters or employers.

Information we collect

We collect the information you give us and a small amount generated as you use the product:

  • Account details: your name, email address, a password (stored only in hashed form by our authentication provider), and the sign-in identifier if you use Google or LinkedIn.
  • Career materials you provide: resumes, cover letters, writing samples, profile answers, and any text you paste or upload.
  • Job and application data: job descriptions you import, fit assessments, generated documents, and the status of roles you track.
  • Billing details: your plan and payment status. Card numbers are handled by Stripe and are never stored on our systems.
  • Usage and diagnostics: basic event counts used for fair-use limits and product analytics, and error reports when something goes wrong.

How we use your information

We use the information you give us to:

  • Run fit assessments and generate resumes, cover letters, and interview preparation.
  • Save your profile and your work so you can return to it.
  • Enforce fair-use limits and prevent abuse.
  • Process payments and manage your subscription.
  • Send service email such as verification, receipts, and account notices.
  • Monitor and fix errors, and understand which features are used so we can improve the product.

We do not use your career materials for advertising, and we do not sell them.

How AI processing works

Fit assessments and document drafts are produced using models provided by Anthropic. When you run an assessment or generate a document, we send the relevant parts of your profile and the job description to Anthropic so it can return the result.

Under our commercial agreement with Anthropic, your content is processed only to produce your output and is not used to train Anthropic's models.

Every AI-generated claim is linked back to something in your own profile through the Evidence Map, and AI changes to your content are shown to you and can be reversed before you export.

Who we share data with

We use a small set of processors to run the service. They act on our instructions under data-processing agreements:

  • Supabase: hosting of your account, database, and uploaded files.
  • Anthropic: AI processing for assessments and document generation.
  • Stripe: payment processing.
  • Resend: delivery of transactional email.
  • PostHog: product analytics, active only if you accept analytics cookies.
  • Google Ads and Reddit: advertising measurement, active only if you accept Advertising cookies in the banner. They measure marketing performance only; they never receive your resume, assessments, or generated documents.
  • Crisp: in-app support chat for signed-in users.
  • Sentry: error monitoring, configured not to send personal data by default.
  • Vercel: application hosting, content delivery, and anonymized Web Analytics (cookieless page-view counts for service reliability; no cross-site tracking).

If you choose to import documents from Google Drive or Microsoft 365, we access only the files you select, and only at the moment you import them.

Some processors are located outside the UK and EU. Where that is the case, transfers rely on appropriate safeguards such as standard contractual clauses.

We may add or change processors as the product evolves. We will keep this list current and update the date above when we do.

Cookies and analytics

We use essential cookies needed to sign you in and keep the product working, including a first-party cookie that stores ad click identifiers (such as gclid) for attribution when you later purchase. This does not share your career content with ad networks.

We run anonymized, cookieless Web Analytics through our hosting provider (Vercel) to measure overall traffic and keep the service reliable. We send route patterns (for example `/documents/[jobId]`) rather than record identifiers in URLs, and we strip sign-in tokens and job identifiers from query strings before transmission. It does not use marketing cookies, does not identify you across websites, and is not controlled by the cookie banner.

Analytics cookies (PostHog) are optional and load only if you accept them in the cookie banner.

Advertising cookies (Google Ads and Reddit pixels) are optional and load only if you accept the Advertising category. We store your Advertising choice in a first-party cookie so purchase attribution to ad networks respects that choice. They measure marketing performance only; they never receive your resume, assessments, or generated documents.

Crisp support chat uses functional cookies to keep your conversation when you are signed in.

How long we keep your data

We keep your information while your account is open. You can export a full copy of your data, or delete your account, at any time from Settings.

Deleting your account removes your profile, documents, writing samples, job records, and assessments. A limited set of records required for legal, tax, or fraud-prevention reasons may be retained for a short period.

Your rights

You can access, correct, export, or delete your data from Settings, or by contacting us.

If you are in the UK or EU, you also have the right to access a copy of your data, correct inaccurate data, erase your data, restrict or object to processing, request data portability, and withdraw consent at any time. You may lodge a complaint with your local data protection authority. In the UK, that is the Information Commissioner's Office.

How we protect your data

We use encryption in transit, row-level access controls so each user can reach only their own data, and server-side validation of uploads. No system is completely secure, but we work to protect your information and will notify you of a breach where the law requires.

Children

Rolevera is intended for working professionals and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes to this policy

We may update this policy as the product changes. We will post the new version here and update the date above. For significant changes we will notify you by email.

Who is responsible, and how to reach us

The data controller is Nicholas Mahon operating as Rolevera Technologies. This will be updated to the incorporated entity after incorporation, and we will notify existing users of the change.

Questions? hello@rolevera.ai