Career CoPilot is an early-stage career service. This policy explains, in plain
language, what limited data the product handles and how it uses cookies.
1. Who We Are
"Career CoPilot" ("we", "us") is an AI-assisted career-coaching application. This
policy applies to your use of this website and its features.
2. Information We Collect
Account information — if you sign in, basic profile details (such as your name and email) needed to provide the service.
Content you provide — resume text, documents, or answers you submit so the AI tools can analyze them and return results.
Preferences — settings such as your chosen interface language, theme, email categories and job-alert frequency. We also retain a limited history of commercial-email consent and unsubscribe changes so those choices can be honoured.
Hiring and application records — job postings, applications, interview scheduling, scorecards, messages, and consented sourcing records created when you use those workflows.
Billing records — plan, credit, checkout, and payment-provider identifiers. We do not receive or store your full payment-card number.
Basic usage data — standard technical information (such as browser type) needed to operate the site.
3. How We Use Cookies
We use a small number of cookies and similar browser storage. Essential storage is used to:
Remember your cookie consent choice (stored in a cookie_consent cookie).
Keep you signed in and maintain your session.
Remember preferences such as your language selection.
Keep local drafts and setup state, including profile fields, job preferences, onboarding progress, and workspace-tour completion, on the device where you entered them.
Optional error monitoring is disabled until you choose "Allow monitoring"
in the consent banner. You can use the core site with essential storage only.
4. Third-Party Services
To provide features you request, the product uses these external services:
Configured AI provider — content you submit to an AI tool is sent only when you run that tool. Shared product routes use Google Gemini; eligible employers may separately configure their own compatible endpoint.
Employer-configured AI endpoint — an employer's raw provider key is stored in a server-only credential record, masked in the product UI, and used only for requests to the endpoint that employer configured.
Firebase (Google) — authentication, account and application data, uploaded files, and server-side functions.
Email delivery provider — your verified account email, the generated notification content, and delivery status are processed by the authenticated SMTP provider connected to Firebase when an enabled notification is queued. Private in-app conversation bodies are not copied into notification email.
Stripe — payment collection after you explicitly start checkout. Stripe handles payment-card details; Career CoPilot stores billing status and provider identifiers.
Sentry — optional error diagnostics only after you allow optional monitoring. It is configured not to send default personal information.
These providers process data under their own terms and privacy policies.
5. Your Choices
Decline optional monitoring via the consent banner.
Use the site without signing in to avoid creating an account.
Clear cookies and site data through your browser at any time.
Choose email categories and job-alert frequency in Account Settings. Subscription and promotional email also includes a no-login unsubscribe link; account security and other messages required to operate your account cannot be disabled while the account remains open.
Ask us to provide, correct, export, or delete account data by contacting the address below. We may need to verify that the request belongs to the account holder.
Clearing browser data removes device-local copies only. It does not remove records already
stored with your signed-in account or with service providers.
6. Retention and Account Deletion
Partner API usage logs use a 90-day expiry field after the documented production backfill and TTL
rollout. Day/month operational counters contain request and error totals without API-key or request
identifiers and use a 120-day expiry after their last update. Both policies delete eventually rather
than at an exact deadline. Apart from these limited policies, a comprehensive
automatic retention schedule and self-service export/deletion flow are not yet available. Account
removal currently removes sign-in access, the parent profile, and private
employer AI credentials after recurring-billing checks. It is not full data erasure:
shared hiring records, financial and audit records, uploaded files, and Stripe records may remain
pending an approved retention/anonymization policy or required external action. Contact us before
relying on account removal for a specific legal or records-management need.
7. Security and International Processing
We use authenticated server functions, access-control rules, private credential storage, and
transport encryption to reduce unauthorized access. No internet service can guarantee absolute
security. Firebase, Stripe, Sentry, and the configured AI provider may process information in
countries where they or their subprocessors operate; their own privacy terms govern that processing.
8. Policy Changes
We may update this notice as the service, providers, or retention practices change. The date at
the top identifies the current version. Material product changes must be reflected here before release.