Legal

Privacy Policy

How RoleSharp handles account data, uploaded resume text, generated content, payments, and admin operations.

Information we process

We process account email, authentication details, resume text, uploaded file text extraction, target company/role data, job descriptions, generated resumes, subscription status, and payment metadata.

How we use service providers

We use infrastructure, email, payment, and AI providers to operate the service. They receive only the data needed for the requested operation under their applicable terms. RoleSharp does not sell personal data or intentionally train RoleSharp-owned models on resume content.

Resume uploads

Uploaded files are used to extract text for resume scoring. The checker response uses extracted text, country, company, role, and optional job description data.

Jobs workflows and connected mailboxes

Daily Matches processes your confirmed career profile, campaign rules, job snapshots, fit and evidence-confidence breakdowns, and your verified RoleSharp account-email version. RoleSharp Apply additionally stores an immutable application-email package, selected posting-backed recipient, tailored resume PDF, approval receipt, attempt state, and a redacted provider receipt. Emailing a CV is not an ATS submission, and provider acceptance does not prove delivery.

Mailbox connection is separate from RoleSharp login. Gmail requests openid, email, offline access, and https://www.googleapis.com/auth/gmail.send. Microsoft requests delegated openid, profile, email, offline_access, User.Read, and Mail.Send. User.Read is used only to confirm basic account identity through Microsoft Graph /me. RoleSharp does not request inbox-read, mailbox-modify, contacts, or application-wide tenant mail permissions and does not collect mailbox passwords.

Mailbox tokens and revocation

Connected refresh tokens are encrypted with a dedicated authenticated key and retained only while that connection remains enabled. Access tokens and authorization codes are transient and are not written to queue payloads or application logs. Disconnect first disables sending and erases the local refresh credential even if the provider is unavailable. RoleSharp then makes a best-effort Google token-revocation request; Microsoft users are shown the Microsoft My Apps consent-removal path because Microsoft does not provide the same granular revocation contract. Deleting the RoleSharp account also disables every connection and erases local credentials.

Internship safety reports

Verified users may submit internship safety reports, optional source links, and evidence files for moderator review. Reporter email and evidence are restricted to authorized administrators and are not displayed on the public safety board. Approved report text, company, location, risk category, aggregate votes, and anonymous community comments may be displayed publicly. Do not upload passwords, government identification numbers, banking details, or unrelated personal data.

Retention and deletion

We keep account data, career-profile versions, saved resumes, application packages, digest snapshots, and redacted attempt history while your account is active so you can inspect the workflow ledger. Terminal notification-outbox transport metadata is purged after 30 days. Pending OAuth transactions last no more than ten minutes, and consumed/expired state replay tombstones last exactly 24 hours. Account deletion removes user-owned profiles, matches, packages, mailbox credentials, applications, calibration events, support tickets, internship reports and evidence, comments, votes, verification records, and processing reservations. Only non-linkable aggregates and records required for legal, fraud-prevention, security, or accounting purposes may remain. The original checker upload is not intentionally saved, and temporary parser copies are cleaned up after processing.

Your choices

You may access, update, export, or delete your account data through the product where those controls are available. You may also contact us to ask about access, correction, deletion, or a privacy concern.

Payments

Payments are handled through configured crypto payment providers. RoleSharp stores payment status and plan metadata needed to activate Premium.

Security

Passwords are hashed. Admin access is separate from user login. Production operators should keep server environment variables and payment keys private.

Contact

For privacy questions, contact support@rolesharp.com or use the support form.