Skip to content
RoleframeRoleframe
Legal

Privacy Policy.

Last updated:

We care about your privacy. This page explains what personal data we collect, how and why we use it, who we share it with, where it is processed, and the rights you have under the EU General Data Protection Regulation (GDPR).

We never sell your data. We only use it to provide and improve Roleframe for you.

Who we are & how to contact us

This Privacy Policy explains how Roleframe(" we", "us", or "our") collects, uses, and protects your personal data when you use our website, our web application, and our browser extension (together, the "Service"). Roleframe is the data controller of your personal data.

Controller & privacy contact
Roleframe
Jana Ostroroga, Leszno, Poland
Email: [Email Protected]

This Policy should be read together with our Terms of Use and our Cookie Policy.

1. Data we collect

We collect data you provide to us, data we collect automatically when you use the Service, and limited data from the providers that help us run it.

Information you provide

  • Account data. When you sign up, your name, email address, and authentication details are handled securely through our authentication provider. You may add optional profile information.
  • Career content. The content you create or upload: resumes and resume content (work history, education, skills, certifications), cover letters, job descriptions you save or analyse, notes, and related career materials.
  • Payment data. Card payments are processed by Stripe(Stripe Payments Europe, Ltd.), our payment processor and, via Stripe Managed Payments (Link), the merchant of record for your purchases. Stripe collects your card details directly; we receive only limited information such as your billing country, the last four digits and type of your card, and your subscription/payment status. We do not store your full card number. Stripe's own privacy policy governs how it processes your payment data.
  • Communications. When you contact support, we keep the content of those messages.
  • Extension saves. Job postings and contacts you choose to save with our browser extension, plus your weekly goals. See Section 4 for exactly what the extension reads and sends.

Information we collect automatically

  • Usage data. How you interact with the Service: features used, actions taken, and timing, generally in aggregated, de-identified form.
  • Device & connection. Device type, operating system, browser, IP address, and similar technical identifiers.
  • Cookies. See Section 10 and our Cookie Policy.

2. How we use your data and our legal bases

Under the GDPR we must have a legal basis for each use of your personal data. We use your data:

  • to create your account, provide the Service, and run the AI-powered actions you request: to perform our contract with you (Art. 6(1)(b) GDPR);
  • to secure the Service, prevent fraud and abuse, monitor performance, and improve and develop features using aggregated, de-identified data: our legitimate interests (Art. 6(1)(f) GDPR);
  • to send marketing communications and to set non-essential cookies: with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time;
  • to keep records and meet tax, accounting, and other legal duties: to comply with a legal obligation (Art. 6(1)(c) GDPR).

3. AI features

Roleframe uses artificial intelligence to power features such as resume optimisation, cover-letter generation, role and keyword matching, and document parsing. When you use these features, the content you provide (such as resume text and job descriptions) is processed to generate the outputs you request.

Your content is processed by our AI systems only to deliver the feature you request, under strict security and confidentiality controls. We do not use your personal resumes or other identifiable career documents to train general-purpose AI models, and any providers that help us run these features are contractually prohibited from training their models on your content. We may use aggregated, de-identified patterns to improve our own features.

4. Browser extension

We publish a Roleframe browser extension for Chrome. It saves job postings and contacts to your Roleframe account, shows your weekly goals and lets you change them, and can run one job search across several boards at once. Everything else in this Policy applies to the extension as well. This section adds the detail that is specific to it.

The extension runs on every website you visit, not only on job boards. It has to, because it cannot know in advance which page is a posting. On a page it does not recognise as a posting, it does nothing and sends us nothing.

What it reads on the pages you visit

The extension supports more than 230 job boards, and it can also recognise a posting on other sites. To tell whether the page you are on is one it can save, it looks at that page automatically, as soon as it loads and again if the address changes. You do not have to click anything for this to happen.

All of it happens inside your browser, on the page as it is already loaded. We do not receive your browsing history, and we receive nothing about a page you do not save.

The extension can also see the addresses and titles of your open tabs. That is how it knows which page you are looking at when you open the panel. It stays in your browser too.

When you open the Roleframe side panel on a job posting, the extension reads the posting from the page and fills in the save form for you: job title, company, location, the description, salary, posted date, and employment type. On a site it does not recognise in detail, it may take a larger part of the page's text as the description, which is why you can read and edit it before you save. Everything stays in your browser until you choose to save it.

What it adds to the pages you visit

On a page it recognises as a posting, the extension puts its own "Save to Roleframe" button on the page, and the description editor opens over the page so you have room to read. Neither one sends us anything.

What it sends us when you save

When you save a job, we receive those fields, the address of the posting, the name of the site you saved it from, any notes you wrote, the stage you filed it under (such as bookmarked or applied), and the fact that the save came from the extension. We store it in your job tracker under your account, and we keep the description as plain text. Saving the same posting again updates the job you already have instead of adding a second one.

If a save arrives incomplete, we also record the address of the posting and which details were missing, so we can improve how the extension reads that site. That record carries no account identifier and is not part of your profile. We keep it no longer than 90 days. The basis is our legitimate interest in the extension working (Art. 6(1)(f) GDPR).

When you add a contact, we receive what you typed into the contact form: name, job title, company, email, LinkedIn, and location. The contact form is one you fill in yourself. The extension does not read contact details off a profile page.

Contact details are personal data about someone else. We process them so we can give you the tracker you asked for, which is our legitimate interest and yours in running your job search (Art. 6(1)(f) GDPR). You choose what to add, so please add only what you need. If you are not a Roleframe user and believe one of our users has saved your details, see Section 9.

Your weekly goals are the target job title, weekly saves target and weekly applications target on your account. You can set them in the web app or in the panel, and the panel reads your progress against them from our servers. Nothing about the page you are on is sent with them.

Signing in

The extension signs you in to the same Roleframe account as the web app, through our authentication provider. Your session is kept in your browser, which is what saves you signing in every time you open the panel. There is no separate extension password. So that you do not have to sign in twice, it may read the Roleframe sign-in cookie on our own addresses. It has no access to cookies on any other site, and it never reads cookies to identify you across the web.

What stays on your device

In your browser's own extension storage, the extension keeps a copy of the jobs and contacts you saved, your goals, the job-board detection settings it downloads, the last multi-board search you ran, a note that you have seen the welcome page, and your signed-in session. It also keeps whether the panel is open, for as long as your browser is running. The copies are there so the panel loads instantly and a save you make offline is not lost.

A job save that never reached us is sent again the next time you open the panel. A contact that fails to save stays in the form so you can try again, and it is not sent later on its own.

What the extension does not do

  • It does not track the pages you browse or build a profile of them. It can see them, and it tells us about none of them.
  • It does not send us page content other than the posting you choose to save.
  • It does not run AI on a job at the moment you save it. AI runs later, only when you ask for it. See Section 3.
  • Nothing it collects is used for advertising, and we never sell it.

On Roleframe's own websites, and only there, the extension tells the page that it is installed and which version it is, so the site can skip the install prompt. It reads nothing from those pages.

5. How we share your data

We never sell your data, and we do not share it for third-party advertising. We share personal data only where necessary to run the Service:

  • with the service providers who process data on our behalf, under contracts that require them to protect your data and use it only on our instructions. They are Stripe (payments), Clerk (accounts and sign-in), Vercel and Neon (hosting, storage, and databases), Upstash (rate limiting), Google Cloud and Resend (email delivery), and Sentry and PostHog (error monitoring and product analytics). Separately, Google Forms hosts the optional feedback form your browser opens if you uninstall the extension, described in Section 4;
  • where required by law or in response to a valid request from a competent authority; and
  • in connection with a merger, acquisition, or sale of assets, in which case your data remains protected by this Policy.

6. International transfers

We aim to process your data within the EU/EEA. Where a provider necessarily processes data outside the EEA, we rely on appropriate safeguards, such as a European Commission adequacy decision or the EU Standard Contractual Clauses, to ensure your data receives an equivalent level of protection. You can ask us for more detail or a copy of the relevant safeguards.

7. Data retention

We keep your personal data for as long as your account is active or as needed to provide the Service. When you delete your account, we delete or anonymise your personal data within a reasonable period (normally within 30 days), except where we must keep certain records to meet legal obligations (for example, billing records for tax) or to establish, exercise, or defend legal claims. Because deletion is permanent, please export anything you want to keep beforehand.

Jobs, contacts, and goals saved with the browser extension are part of your account data and are deleted with it. Uninstalling the extension is not the same as deleting your account: it clears what the extension kept in your browser and leaves what you already saved to Roleframe untouched.

The extraction records described in Section 4 carry no account identifier and are not part of your profile, though they are written at the moment you save. We delete them once we have used them to fix the site, and in any case within 90 days. If you ask us to delete your account and want those gone too, tell us and we will remove them.

8. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, and the use of reputable infrastructure providers. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where the law requires.

9. Your GDPR rights

Subject to conditions in the law, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected (rectification);
  • have your data erased (right to be forgotten);
  • restrict or object to certain processing;
  • receive your data in a portable format and have it transferred (data portability); and
  • withdraw consent at any time, without affecting prior use.

You can exercise most of these rights directly in your account settings (including exporting your content and deleting your account), or by contacting [Email Protected]. We will respond within the time limits set by the GDPR.

10. Cookies

We use essential cookies that are required for the Service to function, and, only with your consent, analytics and other non-essential cookies. You can manage your choices at any time. Full details, including the categories of cookies and how to control them, are in our Cookie Policy.

Our browser extension sets no cookies of its own. It keeps what it needs in your browser's extension storage, which we cannot reach into, and only for the things you asked it to do. It can read our own sign-in cookie on Roleframe addresses so that signing in once covers both, and it cannot read cookies on any other site. See Section 4.

11. Children

The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and where changes are material we will give you notice through the Service or by email before they take effect.

13. Contact us

For any privacy question or to exercise your rights, contact us at:

Roleframe
Jana Ostroroga, Leszno, Poland
Email: [Email Protected]