Who we are
Rolefit is a job-search preparation platform that helps you assess your skills, track job applications, and prepare for interviews using AI-assisted tools. References to "we", "us", or "our" mean Rolefit.
Questions or data requests: contact us.
What data we collect
We collect only what is necessary to provide the service:
- Account data — name and email address, obtained via OAuth sign-in (Google, GitHub, Microsoft, LinkedIn, or Apple). We never see your provider password.
- Profile data — your target job role, seniority level, and CV content if you upload one.
- Job descriptions — text or URLs you paste into the pipeline feature. These may contain company and role information.
- Skill assessments — your test answers, scores, and skill progress over time.
- Behavioral stories — STAR stories you write for interview prep. These are stored against your account.
- Application data — companies, roles, status, interview notes, and AI coaching chat history that you enter.
- Usage data — anonymised product analytics (pages visited, features used, test completion rates) via PostHog. No message content is captured.
- Error data — technical error reports via Sentry, which may include browser type and the page where an error occurred.
How we use your data
We use your data solely to operate and improve the service:
- Authenticating you and maintaining your session
- Generating personalised skill gap analysis and match scores against job descriptions
- Powering AI-assisted coaching, story evaluation, and practice test generation (via the Anthropic Claude API)
- Tracking your skill progress and application pipeline over time
- Understanding how features are used so we can improve the product
- Diagnosing and fixing technical errors
We do not use your data for advertising, sell it to third parties, or use it to train AI models.
Legal basis for processing
For users in the EU/EEA, our legal bases under GDPR are:
- Contractual necessity — processing your account data, skill scores, stories, and application data to deliver the service you signed up for.
- Legitimate interest — anonymised product analytics and error tracking to maintain and improve the service, balanced against your privacy interests.
- Consent — where required (e.g. session replay). You may withdraw consent at any time.
Third-party processors
We share data with the following processors, each bound by a Data Processing Agreement:
- Anthropic — your job descriptions, skill context, story text, and coaching messages are sent to the Claude API to generate AI responses. Anthropic does not use this data to train models by default. See Anthropic's privacy policy.
- Railway — our cloud hosting provider. Your data is stored on Railway infrastructure.
- PostHog — anonymised product analytics. No personally identifiable content (message text, story text) is included in analytics events.
- Sentry — error monitoring. May capture browser metadata and stack traces when errors occur.
We do not use any OAuth provider beyond authentication — we do not access your Google Drive, GitHub repos, LinkedIn connections, or any other provider data beyond your name and email.
Data retention
- Active accounts — data is retained for as long as your account exists.
- Deleted accounts — personal data is deleted within 30 days of account deletion, except where retention is required by law.
- Analytics data — PostHog event data is retained for 12 months.
- Error logs — Sentry error data is retained for 90 days.
Cookies and tracking
We use the following cookies:
- Session cookie — HTTP-only, secure, used to keep you logged in. Strictly necessary; no consent required.
- PostHog analytics — used to track feature usage in aggregate. Contains a randomly generated anonymous ID, not tied to your email unless you are signed in.
We do not use advertising cookies or tracking pixels.
Your rights
You have the right to:
- Access — request a copy of the data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — request deletion of your account and personal data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdrawal of consent — where processing is consent-based, you may withdraw at any time
To exercise any of these rights, contact us. We will respond within 30 days.
California residents have additional rights under CCPA, including the right to know what personal information is sold (we do not sell it) and the right to opt out of sale.
AI and automated processing
Rolefit uses Claude (by Anthropic) to generate skill assessments, story evaluations, match scores, and coaching responses. These outputs are informational and intended to support your own judgement — they are not employment decisions and should not be treated as guarantees of job-search outcomes.
Under GDPR Article 22, you have rights regarding solely automated decision-making that produces legal or similarly significant effects. Our AI outputs are advisory; no hiring decision is made by Rolefit. You retain full control over whether and how to act on any AI-generated content.
Data security
We use HTTPS for all data in transit, HTTP-only secure cookies for session management, and access controls to limit who can query the database. No system is perfectly secure — if you believe your account has been compromised, contact us immediately.
Changes to this policy
We will update this policy if our data practices change materially. When we do, we will update the date at the top of this page. Continued use of the service after a change constitutes acceptance of the updated policy.