Published: August 12, 2026. Change classification: Baseline or non-material change.
Information we process
RoleSharp processes account email and authentication data, resume and profile content, uploaded-file text extraction, target roles and companies, job descriptions, generated documents, product activity, subscriptions, payment metadata, support records, security logs, job-workflow records, and user choices.
Purposes and legal bases
We use data to provide requested services, secure accounts, prevent abuse, administer purchases and offers, respond to support and legal requests, improve reliability, and comply with applicable obligations. Depending on context and jurisdiction, processing may rely on contract, consent, legitimate interests, or legal obligation.
Providers and international processing
Infrastructure, email, payment, analytics, and AI providers receive only data needed for the relevant operation under their applicable terms. Processing locations may differ from your location and may involve lawful international transfers. RoleSharp does not sell personal data or intentionally train RoleSharp-owned models on resume content.
Resume uploads and generated content
Uploaded files are used to extract text for scoring and generation. Saved profiles, generated resumes, application packages, and exports remain associated with the account until deleted under the applicable retention process.
Jobs workflows and connected mailboxes
Daily Matches processes confirmed career-profile versions, campaign rules, job snapshots, fit evidence, and verified account-email versions. RoleSharp Apply stores immutable reviewed packages, posting-backed recipients, tailored attachments, approval receipts, attempt states, quota reservations, and redacted provider receipts.
Gmail and Microsoft connections are separate from login and use send-oriented delegated scopes. Gmail requests openid, email, offline access, and https://www.googleapis.com/auth/gmail.send. Microsoft requests delegated openid, profile, email, offline_access, User.Read, and Mail.Send; User.Read is used only to confirm basic account identity through Microsoft Graph /me. RoleSharp does not request inbox-read, mailbox-modify, contacts, application-wide tenant mail permissions, or mailbox passwords.
Connected refresh tokens are encrypted with a dedicated authenticated key and retained only while the connection remains enabled. Access tokens and authorization codes are transient and are not written to queue payloads or application logs. Disconnect first disables sending and erases the local refresh credential even if the provider is unavailable. RoleSharp then makes a best-effort Google token-revocation request; Microsoft users receive the Microsoft My Apps consent-removal path. Account deletion also disables every connection and erases local credentials.
Notifications, campaigns, cookies, and analytics
RoleSharp may provide service, security, legal, account, and product notices in-app or by email. Promotional communications must respect applicable consent, preference, unsubscribe, bounce, and suppression controls. Essential cookies support authentication and security; analytics should be privacy-bounded and used for product and operational measurement.
Retention and deletion
Retention depends on the record category and operational, security, accounting, fraud-prevention, or legal need. Active-account data is retained to provide the service. Terminal notification-outbox transport metadata is purged after 30 days. Pending OAuth transactions last no more than ten minutes, and consumed or expired state replay tombstones last exactly 24 hours. Account deletion removes user-linked profiles, matches, application packages, mailbox credentials, applications, calibration events, support records, internship reports and evidence, comments, votes, verification records, and processing reservations, subject only to narrowly justified legal, security, fraud, or accounting retention. The original checker upload is not intentionally saved, and temporary parser copies are cleaned up after processing.
Security
Passwords are hashed, high-risk credentials are encrypted, administrative access is separated and audited, and operational logs should avoid secrets and unnecessary personal data. No system can guarantee absolute security.
Your rights and choices
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on consent. Product controls support account updates, exports, privacy choices, mailbox disconnection, and deletion where available.
Children and minimum age
RoleSharp is not directed to children who cannot lawfully consent to use of the service. Do not create an account if you are below the applicable minimum age without valid authorization.
Contact and legal notices
For privacy questions, rights requests, escalation, or legal-notice handling, contact support@rolesharp.com or use the support form. Material policy changes require a new exact-version acceptance before high-impact actions while basic account and privacy controls remain available.
Questions about this document can be sent to support@rolesharp.com or through the support form.