Privacy Policy
Last updated August 12, 2026
This is a plain-language summary of how we handle your data while we finalize our full policy. We wrote it to match how the product actually works. If anything here is unclear, email us — we will answer.
Who we are
The service is operated by the team behind MyCareer.Rocks. We are forming MyCareer.Rocks LLC in North Carolina, United States, and will update this page with the registered legal name and contact details when formation is complete. Privacy questions go to [email protected].
What we collect
You give us: account details (name, email, a hashed password, and when you accept the Terms and this policy); career profile information (work history, education, skills, goals, personality and contact fields you choose to add, optional profile photo); imports (text, PDFs, Word files, or LinkedIn exports you upload, plus an import history we keep for limits and support); job context for a resume (job description, optional source URL, application notes and status if you use the tracker); content you generate or save (tailored resumes, cover letters, interview prep packs, email signature preferences, and similar tool outputs); reference contacts (see below); a handwritten signature image if you draw or upload one; messages you send us (for example through the contact form); and optional Gmail connection data (see below).
We and our providers generate: technical and security data (IP address, browser or user agent, session metadata, security events such as sign-ins and failed attempts); billing metadata needed to run your plan and credits (subscription status, credit balance and lots, transaction history — we do not store full card numbers); usage analytics events when analytics is configured; and error diagnostics so we can fix bugs.
From Google (if you use Google sign-in): your Google account email, name, and a stable subject identifier so we can create or link your account. That is separate from the optional Gmail signature connection.
Details about other people
The References tool keeps a list of people you can name as references — their name, job title, employer, how they know you, and the email address or phone number you were given. You add it, so you should have their permission first.
We keep it only to build your references materials. We never contact them, and it is never shown on any public page. It is deleted with your account, included when you download your data, and removable by you at any time from the tool — which deletes their details for good.
Handwritten signature and public media
If you capture a handwritten signature, we store the image so we can put it on email signatures and cover letters you generate. That image is served from a public web address on our media CDN: email apps cannot sign in to fetch a private image. Anyone who receives an email that includes the image can open the image URL itself. We keep the handwritten image off your shareable signature page. Removing it from your profile clears our pointer to it; copies already sent in email still live with the recipient.
Other media we store for you (for example a profile photo) is also served from that public media address. Removing media from your account clears our pointer and we attempt to delete the object we still control; copies already delivered or cached elsewhere can remain.
Shareable signature link
You can turn on a shareable signature page at a personal link (/signature/…). It is off by default. When on, anyone with the link can open the full rendered signature without signing in. That can include your name, job title, company, email, phone, location, profile photo, and any links you put on the signature (such as LinkedIn, website, or booking). The handwritten signature image is not shown on this page.
Search engines are asked not to list the page, but the link itself is not private. Turning the page off or generating a new link stops new access as soon as our cache refreshes (usually within a few hours).
If you connect Gmail
The one-click Gmail install replaces the signature currently set on your Gmail account. So that you can undo that, we keep a copy of the signature that was there before — which usually contains your name, job title, and the phone or email you had listed.
When you disconnect, we restore that previous signature. When you delete your account, we try to restore it before we revoke the Google grant; if Google is unavailable, local erasure still continues.
We request Gmail settings access and use it only to read and write your signature setting. We never read your mail. The connection (including an encrypted refresh token) is stored encrypted, is deleted with your account, and you can disconnect at any time from the signature tool.
Google sign-in
“Continue with Google” is a separate connection from Gmail signature install. It uses standard sign-in access so we receive your email and basic profile to authenticate you. You can disconnect Google sign-in from account settings after a password confirmation. Disconnect is not permanent: signing in again with Google on the same verified email can re-link the account.
How we use it
We use your information to:
- Provide and improve the service (profile, imports, generation, tools, downloads).
- Run AI generation and helpers: when you run generation or AI helpers, the content needed for that request (for example your profile snapshot, a job description, import text, or other content you supply) is sent to Anthropic's Claude models through Cloudflare AI Gateway so the model can respond. We use those providers to run the feature you asked for. We do not sell that content.
- Operate accounts, sessions, security, rate limits, and abuse prevention.
- Bill subscriptions and credits, prevent fraud, and keep an audit trail of payment events.
- Send transactional email (verification, password reset, security, and product notices you have not turned off). Promotional referral email, if enabled, respects your opt-out.
- Answer support requests.
- Understand product usage with privacy-friendly analytics.
- Diagnose errors.
We do not sell your personal information.
Public profiles (not enabled yet)
We do not publish public career profiles today. There is currently no way to publish one at /u/… . The shareable signature link above is a separate, optional feature.
If we enable public profiles later, it will be off by default and only go live if you choose to publish. A published page would show your display name, profile photo, a career story composed from your profile, and channel links you add — never your account email. It would be public to anyone with the link and, by default, could be found by search engines unless you hide it from search. We would generate a social-preview image. You could unpublish at any time. We will update this policy before or when that ships if details change.
Cookies, local storage, and analytics
Essential cookies keep you signed in (session) and support secure flows such as multi-step sign-in or OAuth state. Without them, signed-in use cannot work.
Analytics: when configured, we use Plausible, which is designed to be cookieless. It records page views and a small set of product events (for example signup completed or resume generated) without advertising cookies.
Error monitoring: when configured, Sentry receives technical error reports (stack traces and technical request context such as URLs). We do not use it for advertising, and Session Replay is off.
Local storage: we remember that you dismissed the cookie notice, and we remember your theme preference (light/dark) in your browser.
We do not use advertising pixels or cross-site behavioral advertising cookies on the service.
Who we share it with
We share data with service providers that help us run MyCareer.Rocks, only as needed for their role:
- Anthropic (via Cloudflare AI Gateway) — AI model inference
- Cloudflare — AI Gateway, object storage (R2 / media CDN), optional email delivery, and bot protection (Turnstile)
- Railway — application hosting, database, background jobs, and document render services that compile PDFs from your content
- Polar — payments and subscriptions (Merchant of Record; see below)
- Google — sign-in (if used) and optional Gmail signature API
- Resend or Cloudflare Email — transactional email, depending on configuration
- Upstash — durable rate limiting, when configured
- Plausible — cookieless product analytics
- Sentry — error monitoring
- Logo helpers (for example Brandfetch, Wikidata / Wikimedia, and a domain favicon lookup via Google) — optional company or school logo lookup from names or domains you enter
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition, with notice where required.
We do not sell your personal data.
Payments
Subscriptions and credit packs are billed through Polar, which acts as Merchant of Record. Polar processes payment instruments and holds invoices and tax records under its own policies. We receive subscription and order metadata (for example customer id, plan, amounts, and status) so we can unlock the product and grant credits. After account deletion we may keep redacted payment-event records (without your name or email) so webhooks stay idempotent and we can prevent double grants.
How long we keep it
We keep the data in your account for as long as the account exists. When you delete your account we schedule the erasure, give you 14 days to change your mind, then remove it according to our erasure process (profile, resumes, media we still control, references, Gmail connection after revoke, and related records).
Sign-in records and IP or browser logs we keep to secure the service — including any that were never linked to an account — are kept for up to about 12 months, then deleted automatically.
Exceptions: redacted payment-event rows may remain for the reasons above; IP-based rate-limit records are not tied to your user id and may remain until that 12-month purge; Polar may retain its own billing records; recipients of emails you sent still have what they received. Deletion of files in our object storage is attempted when account media is removed; a storage failure can leave an orphan object, and any copy already fetched from a public URL can remain outside our systems.
Your choices and rights
From your account you can:
- View and edit your profile and tool data.
- Download a portable copy of personal data we hold for you, including account and profile records, resume content we store (including cover letters and interview packs), references, email-signature preferences, import history, billing projections we keep (subscription, credits, credit history), security and session history, connected Gmail metadata (tokens removed), support messages we stored, and media files we can fetch (photo and signature images). The export does not include password hashes or live security secrets, raw payment webhook payloads, IP-only rate-limit rows, or the generated PDF files in private storage, or Word files we build on demand — re-download those from the product while the account is active. Payment receipts live with Polar.
- Delete your account (14-day cool-off, then erasure).
- Disconnect Gmail, manage notification preferences, and disconnect Google sign-in under the conditions described above.
- Turn off the shareable signature link; remove references and your handwritten signature.
Prefer that we handle a request for you? Email [email protected].
These tools are available to everyone with an account — not only residents of particular places.
If you are in the EEA or UK, you may also have rights under GDPR / UK GDPR to access, correct, erase, restrict, object, request portability, withdraw consent where processing is consent-based, and complain to a supervisory authority. We will respond as required by law.
If you are a California resident, you may have rights under the CCPA / CPRA to know, delete, correct, and opt out of “sale” or “sharing” of personal information as those terms are defined there. We do not sell personal information and we do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising privacy rights.
Children
The service is for people 18 or older. We do not knowingly collect personal information from children under 18. We do not collect date of birth; this is a stated eligibility rule, not an age-gate check.
Security
We protect accounts with HTTPS in transit, hashed passwords, encrypted storage for sensitive secrets such as multi-factor authentication material and Gmail refresh tokens where those features are used, access controls that keep generated resume files private, and operational monitoring. No method of transmission or storage is perfectly secure. If we become aware of a breach that requires notice under applicable law, we will notify affected people and regulators as required, without unreasonable delay.
International processing
We and many of our providers process data in the United States. If you use the service from elsewhere, your information may be processed in the US and other countries where our providers operate. Where required, we rely on appropriate transfer mechanisms under applicable law.
Changes
We may update this policy as the product evolves. We will post the new version on this page with an updated date. The version in force when you accepted the Terms and Privacy Policy at signup is also recorded on your account. If a change needs a fresh acceptance, we will explain that in the product.
Contact
Privacy questions? Email [email protected].
MyCareer.Rocks — North Carolina, United States (LLC formation in progress).