Privacy Policy
Last updated 31 August 2026
This policy explains what ReachRole collects, why, who we share it with, and how long we keep it. It covers reachrole.com and the ReachRole application.
Who is responsible
ReachRole is the data controller for the personal data described here. For any privacy request, contact privacy@reachrole.com.
What we collect
- Account data — your email address, a hashed password, and email confirmation status. We never store your password in readable form.
- Career data you provide — uploaded CVs, employment history, career facts and achievements, target roles and preferences, and your conversations with the in-app copilots.
- Work product — evaluations, fit scores, tailored CVs and cover letters, interview prep packs, generated PDFs, and your application pipeline.
- Usage and billing records — which metered actions you used and when (to enforce plan quotas), your plan and subscription status, and a Stripe customer identifier. We never receive or store your card details.
- Technical logs — request metadata, timestamps, and error diagnostics, used to operate and secure the Service.
Why we process it (legal bases)
- To perform our contract with you — running evaluations, generating documents, scanning boards, maintaining your account and subscription.
- Our legitimate interests — securing the Service, preventing abuse of free allowances, and diagnosing faults.
- Legal obligation — retaining billing records where tax law requires it.
We do not sell your data, we do not serve advertising, and we do not use your career data to train AI models.
Who we share it with
We use a small number of processors, each bound by contract:
- Anthropic — receives the portions of your profile, CV, and the job posting needed to produce the output you asked for. Anthropic does not use API inputs to train its models.
- Stripe — payment processing and subscription management. Stripe is the controller of your payment details.
- Our email provider — delivers account confirmation, password reset, and scan digest messages.
- Our hosting provider — operates the server and database where your data is stored.
When we scan a company job board we fetch public pages from that employer or its applicant tracking system. We do not send your personal data to those employers; applying to a role remains something you do yourself.
International transfers
Some processors are based in the United States. Where personal data leaves the European Economic Area, transfers rely on Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
- Account and career data — for as long as your account exists.
- Email confirmation and password reset links — 24 hours and 1 hour respectively, then they expire and are single-use.
- Sessions — up to 30 days, and revoked on password reset.
- After account deletion — your content is deleted or anonymised within 30 days, except billing records kept as long as tax law requires.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. Email privacy@reachrole.com and we will respond within 30 days. If you are in the EEA or UK you may also complain to your local data protection authority.
Cookies
We set one strictly necessary cookie, rr_session, which keeps you signed in. It is HttpOnly, restricted to this site, and expires after 30 days or when you log out. We use no advertising or third-party analytics cookies, so there is nothing to consent to or opt out of.
Security
Traffic is encrypted with TLS. Passwords are hashed. The database and internal services are not exposed to the public internet. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
Changes
If we make a material change to this policy we will notify account holders by email before it takes effect. The date at the top always reflects the current version.