Your career data stays yours.

This policy explains what Rolecrate processes, why it is needed, and the controls available to you.

Data we process

When you create an account, Rolecrate stores account details and the career information you choose to add, such as profile fields, experience, education, projects, role preferences, opportunities, notes, resume variants, and application workflow states. Billing records and security logs are stored when relevant.

Connected AI services

Rolecrate only shares account-scoped data with ChatGPT or another agent after you initiate OAuth authorization or create a developer token. The public ChatGPT connection is limited to job-seeker profile, opportunity, application-bundle, and resume-variant tools. It cannot access another user's workspace. You can revoke OAuth access immediately from Settings.

How we use data

We use data to provide the workspace, generate user-requested resumes, maintain the opportunity pipeline, enforce plan limits, secure accounts, troubleshoot errors, and improve reliability. Rolecrate does not sell personal data or use private career records for advertising.

Service providers

Rolecrate uses Supabase for database, authentication, and file storage; Cloudflare for delivery and the public MCP service; Polar for billing; Google Analytics and Leadso analytics for website usage; and OpenAI only when you choose to connect ChatGPT. Each provider processes the minimum data needed for its role.

Retention and security

New, Reviewing, Rejected, and Closed opportunity findings are automatically removed 60 days after creation. Applied and Interview findings are retained so active applications do not disappear mid-process. Account and billing records may be retained as needed for service, security, legal, and accounting obligations. Access is protected with row-level authorization, scoped OAuth tokens, encrypted transport, rate limits, and audit events.

Your choices

You can edit supported workspace records, revoke connected apps in Settings, and cancel billing at any time. To request an account export, correction, or deletion, use the protected contact option on the support page. We may verify account ownership before completing a request.

Contact

Send privacy questions through the Rolecrate support page.