Privacy policy
Last updated: 21 July 2026.
RoleWake is operated by an individual maintainer. This page tells you what data we collect, why, and how to get it back or delete it.
Data we collect
- Account. Email address. Optional name, profile picture if you sign in with Google.
- Career profile. Name, headline, target countries, languages, role archetypes, keywords, compensation target, and the CV Markdown you review and save.
- CV uploads. A PDF or DOCX you choose during onboarding. We extract its text locally, then send only that text through OpenRouter to an AI model for profile suggestions — the file itself is never sent to the AI provider. When you finish onboarding, the original file (max 4 MB) is stored with your CV so you can download it again; it is deleted with your account. Unsaved model responses are not retained.
- Workspace record. The status, runtime identifier, region, endpoint, and lifecycle metadata for your dedicated private workspace (in development). Job-search records created inside that workspace stay in its external runtime.
- Operational data. Rate-limit counters, Stripe webhook event identifiers, session metadata, and security or error logs. CV text, passwords, access tokens, and AI prompts or outputs are not written to application logs.
- Billing. Stripe customer id and subscription status. Card details never touch our servers — Stripe holds them.
CV and AI processing
Onboarding extracts PDF and DOCX text locally, then sends the extracted CV text to OpenRouter for schema-validated, editable profile suggestions. Requests require zero-data-retention endpoints and exclude providers that collect prompt data. OpenRouter and the selected model provider process the text only to return the suggestions. If you later run an AI command inside your dedicated private workspace, that separate runtime uses its own configured AI provider and terms. Passwords, Stripe data, and other users' data are never included.
Your rights
- Export. Write to privacy@rolewake.comfrom the email address on your account and ask for a data export. We reply with a JSON export of the account and control-plane records tied to you, within the GDPR's one-month window. Data created inside the external workspace is exported through that runtime instead.
- Erasure. Delete your account from the Settings page. It requires an ended subscription, your password, and a typed confirmation; the account is soft-deleted immediately and hard-deleted 30 days later by a daily cron. The 30-day window lets you reverse the delete on request before then.
- Correction. Edit supported fields on the Profile and Settings pages, or contact us about any other inaccurate account data.
Cookies
Only first-party session cookies (Auth.js) and a CSRF token. No analytics, no ads, no tracking pixels. See /cookies for the full list.
Where data lives
Account, profile, CV Markdown, the stored original CV file, and workspace metadata live in the configured managed Postgres database. Workspace files live in your dedicated external runtime. Extracted CV text is transmitted transiently through OpenRouter and its selected ZDR model endpoint. Service logs contain operational metadata such as model and token counts, not CV text, prompts, model output, passwords, or access tokens.
Contact
Questions about your data: privacy@rolewake.com.