Skip to content

Your information at RoleRaven

Privacy policy

Your job search can tell a personal story. This policy explains what RoleRaven collects, how it is used, who receives it, and how you can exercise your rights.

Last updated:

1. Who we are

RoleRaven helps people find and research jobs against their own preferences. This policy covers roleraven.com, the RoleRaven workspace, and the RoleRaven browser extension. It also covers professional information about people mentioned in our employer research.

The operator of RoleRaven is responsible for deciding how personal information is used (the “data controller”). The operator’s legal name, country, and privacy contact will be added here once confirmed.

2. Information we collect

  • Account information: your email address, name if supplied, password hash, account dates, and sign-in information.
  • CV and career information: text extracted from a CV you upload or paste, including any contact details, employment history, education, skills, and other information it contains. We process uploaded files to extract text and save that text and the profile information derived from it.
  • Your search brief: desired roles, locations, pay expectations, working arrangements, interests, exclusions, commute starting point and travel preferences, research questions, and notes.
  • Your workspace: selected jobs, saved and archived opportunities, decisions and notes, AI assessments, dossiers, research progress, and notifications. Questions you send in job chat are processed with the relevant job and assessment context.
  • Extension information: page captures, draft imports, selected briefs, and authentication information, as described in the browser-extension section below.
  • Professional information from other sources: job postings and company or people information from employer websites, job boards, professional profiles such as LinkedIn, search results, and data providers. This can include names, job titles, employment, profile links, biographies, and source excerpts.
  • Technical and support information: server requests and errors, activity timestamps, research logs, and information you send when contacting us. Logs can include job or brief identifiers, search queries, commute locations, and uploaded filenames. Hosting providers may also process IP addresses and device or browser information when handling requests.

An email address and password are needed for an account. Other information depends on the features you choose; leaving out relevant career or location information can limit matching or commute research. Please omit unnecessary sensitive details, such as health information, identity-document numbers, or information about other people that is unrelated to your search.

3. How and why we use it

Where UK data protection law applies, our purposes and legal bases are:

  • Providing the service you request (contract): creating your account, interpreting your CV, maintaining briefs, finding and researching roles, analysing extension captures, answering job questions, and delivering service notifications.
  • Operating and protecting RoleRaven (legitimate interests): diagnosing problems, maintaining reliability, preventing misuse, and responding to support enquiries.
  • Researching employers and professional roles (legitimate interests): collecting and reusing relevant company and professional information to help users evaluate opportunities, while taking account of the interests and rights of the people concerned.
  • Meeting legal duties (legal obligation): responding to valid legal requests and handling data-protection rights.

If we ask for consent for a separate optional use, we will explain that use when asking. You may withdraw that consent at any time. Reading this policy or creating an account is not blanket consent to unrelated uses of your information.

4. AI and job research

RoleRaven sends relevant CV text, brief details, research questions, job-chat messages, captured page content, and research evidence to the AI provider used for that feature. AI helps extract information, suggest search criteria, answer questions, and assess jobs against your brief. Personal information included in those inputs may therefore leave RoleRaven for processing.

Automated filters and AI assessments can rank opportunities, decide which roles enter your inbox, and move roles to the archive. These results depend on your criteria and available evidence and can be incomplete or wrong. You can review findings and sources, change your brief, and make your own decisions about roles. RoleRaven does not make employers’ hiring decisions or submit applications for you.

Your account details, CV, personal brief, and decisions are not published to other users. Job details and company and professional facts can be reused across accounts. AI providers may retain inputs and outputs under the terms and retention arrangements applicable to their service.

5. Browser extension

Opening the extension starts reading and analysing the active page. When you are signed in, it sends the capture to RoleRaven to identify a job opening, which may involve AI processing, before you press “Add & research”. A draft import may be saved at this stage. That button then adds the identified role to the brief you choose and queues research.

Captures can contain the page URL and title, visible page or job-panel text, highlighted text, structured job data, and candidate hiring posts with their links. This can include information visible on pages you have signed into and incidental personal information shown on the page. Use the extension on content you intend to send for job research.

  • Active-tab and scripting access let the extension read the page you open it on. It does not run a background browsing-history collector.
  • Cookie access reads your RoleRaven session cookie and passes it to RoleRaven to authenticate requests. It does not read other sites’ cookies or passwords.
  • Browser storage remembers the selected brief and popup state. Details and retention are explained below.

Extension information is used to identify, import, and research opportunities and operate those features. We do not sell it, use it for personalised advertising, or use it to determine creditworthiness or lending eligibility. Uninstalling the extension stops future collection by it; it does not delete records already sent to your RoleRaven account.

6. Who receives information

We use external services to run RoleRaven. The provider used depends on the feature and service configuration. These integrations receive the information needed for their part of the service:

Hosting and database services
Infrastructure providers, including Fly.io for application hosting, process stored account and workspace information and technical requests.
OpenAI or Anthropic — AI processing
Relevant CV and brief content, job and research information, extension captures, and job-chat messages are processed to produce the requested responses and assessments.
Job-search partners — job discovery
Role titles, keywords, location, and search filters are used to retrieve job listings.
Tavily or Microsoft Bing — web research
Search queries and research context are used to locate evidence. Queries can contain details from the questions you ask.
Apollo or Coresignal — professional information
Company names and professional search criteria are used to find people associated with an employer.
Google Maps — commute research
A commute origin, destination, and travel mode are used to estimate travel time and resolve locations.
Resend — service email
When email delivery is enabled, your email address and the notification subject and content are sent to deliver service updates.
PostHog — product analytics and session replay
Page visits, clicks, and similar usage events, together with session recordings of how the site is used, are sent to PostHog's EU cloud so we can understand which pages and campaigns perform and fix usability problems. Recordings mask everything typed into form fields. Account signups are also recorded server-side with the campaign details that brought you here.

Authorised operators may access information to provide support and maintain the service. We may also disclose relevant information where required by law or necessary to protect legal rights or investigate misuse. We do not sell your personal information or share your CV with employers as an application.

If you follow a link to an employer, job board, or other website, that site handles information under its own privacy policy. Research also involves visiting external sources, which receive the requested URL and normal technical request information.

7. Cookies and browser storage

RoleRaven uses cookies for sign-in, request protection, remembering your active brief, and understanding how the site is used. The current website does not include advertising trackers.

  • Analytics cookies and storage: PostHog sets a cookie and uses browser storage to recognise repeat visits, attribute signups to campaigns (such as utm_source), and record anonymised usage sessions with masked form inputs. Analytics records are held in PostHog's EU cloud under its retention arrangements.
  • Authentication cookies: keep you signed in and support the login flow. Sessions normally expire after 30 days and may be renewed while you use the service; signing out ends the current website session.
  • Active-brief cookie: remembers which brief you last selected for up to one year, renewed when the selection is remembered.
  • Search-preview storage: the website saves recent search criteria and preview results in your browser. Results are reused for up to 10 minutes, but stored entries can remain until replaced or you clear site data.
  • Extension storage: your selected brief identifier uses browser sync storage and may sync between browsers signed into the same browser account. Captures and popup results use browser session storage, can be restored for 30 minutes, and are cleared when the browser session ends; the restore limit is not a server-deletion deadline.

You can clear cookies and site data through your browser settings and remove the extension through its extension settings. Blocking authentication cookies can prevent sign-in. Clearing browser storage does not delete information on our servers.

8. Retention and security

We keep account information, CV text, briefs, imports, and research records while needed to provide your workspace. Retention depends on whether the account and research remain in use, whether information is needed to resolve a support or security issue, and any applicable legal duties. You can request account closure and deletion of associated personal information using the privacy contact below.

The service does not currently apply a fixed automatic deletion period to all records. Research caches, brief undo snapshots, and extension drafts may have expiry or reuse limits; these do not guarantee erasure of the underlying records. Deleting a brief or editing its CV does not necessarily remove older cached copies, logs, or previously created research. A deletion request can cover these associated records as well. Archiving a job only changes its workspace status.

Any information retained after a deletion request must have a continuing lawful reason, such as a legal duty or resolving a dispute. Separate copies held by service providers, including operational logs or backups, follow their applicable retention arrangements. Public company and professional research may remain useful independently of your account; people described in that research can also exercise their rights.

Security measures include HTTPS for the production website and provider API requests, hashed account passwords, and account-based access checks. Optional extension access tokens are stored as hashes on the server and can be revoked from the workspace. No system can guarantee absolute security.

9. International processing

Providers may process information outside the United Kingdom, including in the European Economic Area and the United States. Application hosting in a particular region does not mean that all AI, search, email, or support processing stays there.

Where UK transfer rules apply, an overseas transfer must be covered by an applicable adequacy arrangement or another lawful safeguard, such as the UK International Data Transfer Agreement or UK Addendum to standard contractual clauses. Contact us for the destinations and transfer arrangements relevant to your information, or to request a copy of applicable safeguards.

10. Your rights and choices

Subject to applicable law and its exceptions, you can ask to access or receive a copy of your personal information, correct it, delete it, restrict its use, or receive eligible information in a portable format. You can withdraw consent for any processing based on consent without affecting earlier lawful processing.

Your right to object: you can object to processing based on legitimate interests, including professional information used in employer research, by contacting us and explaining your circumstances.

You can edit your brief and CV information in the workspace and review or change decisions about opportunities. For wider requests, use the privacy contact below. We may need information to verify your identity and locate the records concerned. We will respond within the period required by applicable law and explain any lawful extension or limitation.

You can complain to the UK Information Commissioner’s Office through its complaints page, or to your local data-protection authority where applicable. You do not have to contact us first to exercise that right.

11. Contact and updates

Privacy contact details are awaiting confirmation and will appear here before this draft is finalised.

We will update this page when our practices change and revise the date above. Where a change requires additional notice or consent, we will provide it before applying the relevant new use.