Privacy notice
Effective 20 September 2026 · version 2026-09
This notice explains what findmycareer.ai does with your information. It is written to be read, not to be survived. If anything here doesn’t match what you see in the product, tell us and we’ll fix one or the other.
Who we are
findmycareer.ai is operated by [legal entity name], [registered address], India. For privacy questions, including any request under the Digital Personal Data Protection Act 2023, write to privacy@findmycareer.ai. Our grievance officer is [name], reachable at the same address.
What we collect, and why
| Data | Why we hold it |
|---|---|
| Account: name, email, country, time zone, sign-in provider | To give you an account and keep it secure. Passwords and social sign-in are handled by our identity provider; we never see a password. |
| Profile: headline, city, target roles, preferred locations and work modes, salary floor, visa and relocation answers | To rank jobs for you and to explain each score. |
| Résumés you import or write: experience, projects, education, skills, and the file’s hash | To build your master résumé and tailor versions per job. Tailoring only reuses your own content. |
| Applications you track: company, role, stage, events, reminders, notes | To keep your pipeline and remind you before something goes quiet. |
| Mailbox, if you connect one: sender, recipient, subject, a short snippet, the date and our classification of job-related emails only | To keep your tracker current without manual entry. We do not store the body of your emails. Full text is fetched from your mailbox at the moment you open a message, and is not retained. |
| Emails you approve and send through us | To send them from your own mailbox, exactly once, and record what was sent on the application. |
| AI usage records: which feature, which model, token counts, latency, cost, and whether it failed | To run the service, control cost and abuse, and meet AI transparency and logging obligations. Prompts and answers are not kept in these records. |
| Career Pilot conversations and anything you ask it to remember | To answer using your own data. You can view and delete what it remembers in Settings. |
| Technical: IP address, device and browser, pages and actions, error reports | Security, abuse prevention, and fixing what breaks. |
We collect only what a feature needs. Declining something specific (connecting a mailbox, importing a résumé) turns off that feature and nothing else.
Google user data
If you connect Gmail, we request read access to your mail and permission to send the emails you approve. We use that access only to find job-related email for your tracker and to send messages you explicitly approve. We keep the sender, subject, a short snippet and our classification of job-related messages; everything else is discarded in memory after classification and never stored.
findmycareer.ai’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, do not allow humans to read it except with your explicit permission for support or where required by law, and do not use it to train generative AI models.
Disconnecting Gmail in Settings revokes our access at Google immediately and deletes the stored credential. Emails already synced stay on your applications until you delete them or your account.
How AI is used
- Models are used to classify job emails, draft emails and résumé wording, and answer your questions from your own data.
- Your content is not used to train any model. Our model providers process it to answer the request and do not train on it.
- Matching is a transparent score, not a black box: every point has a reason you can read, and nothing is decided about you automatically.
- Anything that leaves the platform — an email, an application — waits for your approval first.
Who else processes your data
We use a small number of providers, each for one job:
- WorkOS — sign-in, social login and enterprise SSO
- Anthropic — the language model behind Career Pilot, classification and drafting
- Voyage AI — embeddings used to retrieve relevant jobs
- Google — only if you connect Gmail
- Resend — transactional email (reminders, notifications)
- Vercel and Amazon Web Services (Mumbai) — hosting, database and background workers
- Sentry — error reporting (scrubbed of tokens, cookies, emails and phone numbers)
We do not sell your data, and we do not share your profile with employers unless you ask us to. Where a provider processes data outside India, we rely on contractual safeguards with that provider.
How long we keep it
- While your account is open: your profile, résumés, applications and synced email metadata stay until you delete them.
- After you delete your account: we mark it deleted immediately, stop all processing, and purge the data within 30 days.
- Logs and audit records: up to 12 months, because we need them for security and to answer disputes.
- Records we must keep by law (for example invoices): as long as the law requires.
Your rights
You can, at any time and without giving a reason:
- See everything we hold — Settings → Privacy & data → Download my data gives you one JSON file, including your consent history.
- Correct anything — your profile, résumé and applications are editable in the product.
- Delete your account — Settings → Privacy & data. This is irreversible.
- Withdraw consent — Settings → Privacy & data lists every purpose you have agreed to, what withdrawing it stops, and when you agreed. Withdrawing takes effect immediately: matching stops scoring, your Career ID’s public page stops resolving, mailbox reading stops. We keep a record that you agreed and that you changed your mind, which is the only way either of us can show what happened.
- Complain — write to our grievance officer, and if we don’t resolve it, to the Data Protection Board of India.
Children
findmycareer.ai is for people aged 18 and over. We do not knowingly create accounts for children, and we do not profile or advertise to them. If you believe a child has an account, write to us and we will remove it.
Security
Your data is encrypted in transit and at rest. Every request runs under database row-level security scoped to you, access to third-party credentials is held in an encrypted vault the application role cannot read, and sensitive changes are recorded in an audit log. More detail is on our security page.
Changes
If we change this notice in a way that affects you, we’ll tell you in the product before it takes effect and, where the law requires it, ask for consent again. Each version is numbered; this is version 2026-09.