Privacy policy
RoleWake is operated by an individual maintainer (“we”), who decides how your personal data is used. This page says what we collect, which AI features see it, who else handles it, how long we keep it, and how to download or delete it.
What we collect
- Account. Your email address and a password, stored only as a bcrypt hash — or, if you sign in with Google, the name, email address and profile picture Google shares. Whether your email is confirmed, the security data that keeps sign-in safe (a session version, and a hash of any password-reset link), your language and time zone, and when you were last active.
- Your profile. Your name, headline, contact details (email, phone, address, profile links), education, work experience, skills and languages — entered by you or copied from a CV you import — and any proof points or stories saved to your account.
- Your search. Countries and cities, job functions, experience level, job type, work model, keywords and excluded keywords, compensation target, salary floor, blocked locations, and the companies you follow or dismiss.
- CVs. The text and structure of each CV, the original file you uploaded (PDF or DOCX, up to 4 MB) and each CV’s AI review. A CV’s text includes whatever is written on it, such as your contact details.
- Jobs and documents. The postings in your feed (from job boards and from links you paste), their fit scores, what you did with them (saved, applied, dismissed, follow-up dates), the documents generated for them, your questions to the agent with its answers, and a record of each scan (counts, not content).
- Email preferences. Which RoleWake emails you receive and how often, when you agreed to them, and your unsubscribe link.
- Billing. Your Stripe customer id and subscription status. Card details go to Stripe and never reach our servers.
- Operational data. Rate-limit counters keyed to your IP address, email address or account; Stripe event ids; and security and error logs. Our logs never contain CV text, job descriptions, AI prompts or answers, passwords or access tokens. Our hosting provider also keeps standard request logs, such as IP address, time and page.
How RoleWake uses AI
AI features call models through OpenRouter, a service that routes each request to a model provider (currently OpenAI). Each use below is a single request, made only when the table says; RoleWake makes no other AI requests. Requests carry an internal account id, not your email address. The OpenRouter account RoleWake uses is set to route only to endpoints with zero data retention and to exclude providers that collect prompts. We do not use your content to train AI models.
| Feature | When it runs | What is sent |
|---|---|---|
| Importing a CV | When you upload a CV during onboarding or add one on the CV page — every plan. | The text extracted from your file (never the file itself), to suggest your profile and split the CV into sections. |
| Company suggestions | On the Companies step of onboarding — every plan. | Your job functions, keywords and countries. The model only names companies; RoleWake checks each one’s public job board itself. |
| Fit scores | On every scan (manual and nightly) and for every job you add by link — every plan. | Your search filters (job functions, keywords, countries, level, job type, work model, salary floor) and each new posting’s title, company, location, stated facts and the start of its description. Not your CV or your name. |
| CV review | Automatically when a CV is added, and when you ask for a fresh review — every plan. | The CV’s text and your profile summary (described below). |
| Tailored documents | When you generate them, and in the nightly run for your best new matches — Pro. | Your profile summary, your primary CV’s text, any saved stories or writing sample, and the job posting. |
| Questions about a job | When you ask one — Pro. | Your question, the job posting, your profile summary and the job’s evaluation if it has one. |
| Agent chat | When you send a message — Pro, for accounts in the preview. | Your message, your profile summary, your primary CV’s text and a summary of your search (job counts, top matches, the last scan). |
Your profile summary is your name, headline, target countries and cities, languages, compensation target, job functions, experience level, job type, keywords and excluded keywords, and any proof points — not your email address, phone number or home address.
Fit scores decide the order of your own feed and keep weak matches out of it. They are not shared with employers and decide nothing about you; a job you saved, applied to or added yourself stays visible whatever it scores. The AI’s output can be wrong — you review every suggestion and document before it is used.
Where job searches go
Scans run on our servers. To search job boards, RoleWake sends the search terms and places from your filters (job functions, keywords, countries, cities) to the job-search services it queries, such as Adzuna, Jooble, Careerjet and the German Federal Employment Agency’s job search — never your name, email address or CV. Company career pages are read the same way. A job link you paste is fetched by our servers, not by your browser.
Who else handles your data
These services process personal data on our behalf, only to run RoleWake:
| Service | What it does | What it receives |
|---|---|---|
| Vercel | Hosts the app and runs its code. | Everything the app processes while handling your requests, and request logs. |
| Neon (through Vercel) | The database. | The account data listed above. |
| OpenRouter, and the model providers it routes to | Runs the AI features. | Only the text each AI feature sends (see the table above). |
| Stripe | Payments and subscriptions. | Your email address, your customer record and the payment details you give Stripe directly. |
| Resend | Sends RoleWake’s emails. | Your email address and each email’s content — for example, the job titles and companies in a job alert. |
| Inngest | Schedules background work: the nightly run, emails, clean-ups. | Internal account ids and run counts — not your CV or profile. |
| Google (optional) | Sign in with Google. | The fact that you signed in to RoleWake; we receive your name, email address and profile picture. |
Several of these services are based in the United States, so your data may be processed there. We do not sell your data, show ads, or share it with employers or recruiters.
Why we process it
- To provide the service you signed up for (GDPR Art. 6(1)(b)): your account, profile, CVs, searches, fit scores, documents, job alerts, the emails you need (confirmations, password resets) and billing.
- With your consent (Art. 6(1)(a)): marketing emails, which stay off unless you switch them on. You can withdraw consent at any time.
- For our legitimate interests (Art. 6(1)(f)): keeping RoleWake secure and working — rate limits, logs, abuse prevention — and product-update emails, which you can switch off.
- To meet legal obligations (Art. 6(1)(c)): keeping billing records.
How long we keep it
- Your account and everything in it: for as long as the account exists.
- After you delete your account: you are signed out everywhere at once, your email address is replaced and your password removed, and any open Stripe subscription is cancelled. Everything else is permanently deleted by a daily clean-up once 30 days have passed; until then you can ask us to restore the account.
- Scan records: 30 days after the scan finished.
- Rate-limit counters: those keyed to your IP or email address expire within an hour, those keyed to your account within 7 days; expired counters are swept daily.
- Links we email you: password-reset links work once, for one hour; email-confirmation links for 24 hours.
- Sign-in: the session cookie lasts up to 7 days (see Cookies).
- The shared job-posting inventory — public postings read from company job boards, not tied to any account — drops a posting 30 days after it was last seen.
- Billing records are kept by Stripe under its own legal obligations, and logs by our hosting provider for its log-retention period.
Your rights and choices
- Download your data (access and portability): Settings → Login & Security → Download my data gives you a JSON file of your account, profile, CVs, jobs with their documents and questions, agent chat, followed companies, email preferences, scan records and usage counters. Password hashes and billing identifiers are left out. The original file of each CV can be downloaded from that CV’s page.
- Correct it: edit your details on the Profile, CV and Settings pages, or write to us about anything else.
- Delete it: Settings → Login & Security → Delete my account. It needs an ended subscription, your password and a typed confirmation.
- Stop emails: switch streams off in Settings → Alerts Preferences, or use the one-click unsubscribe link in every email.
- Object or restrict processing: write to privacy@rolewake.com.
- Complain: you can lodge a complaint with the data-protection authority where you live or work.
Cookies
Only the cookies needed to sign you in and keep sign-in secure. No analytics, no ads, no tracking pixels. See Cookies for the full list.
Changes
When this notice changes we update it here with a new “Last reviewed” date. If a change affects how your data is used in a way you would not expect, we will email you first.
Contact
Questions about your data: privacy@rolewake.com.