Skip to content

What we store, and who sees it

Version dated 2026-09-14. A plain-English description of what this service does with your CV and your account. If anything here stops being true of the product, the page is wrong and we fix it.

Who is responsible for your data

Who runs this: still to be filled in

RoleRelief is a private preview run by its founder in Ireland. The company behind it is not formed yet, so we do not publish the legal name of the company, its registration number, its registered office address: we would rather say that than invent them. Until then, reply to any email you have had from us and a person will answer. The preview will not open to people we do not know until this box has been replaced with the real details.

Your CV is never shown to an employer or a recruiter

There is no employer product, no recruiter product and no searchable database of candidates. Nobody can look you up here. We do not sell, rent, publish or share your CV, your profile or your email address, and we never send them to an employer.

Jobs come to us, not the other way round: we read employers’ own public job feeds and two job APIs. Before a match is sent we check the posting is still open by re-reading that feed or fetching the posting page with a plain request that names our service. That check carries nothing about you.

We never apply for a job on your behalf and we never rewrite or tailor your CV. You apply yourself, on the employer’s site.

What we use your data for, and the legal basis

  • Signing you in, reading your CV, matching you and emailing the matches: this is the service you asked for, so the basis is the contract between us (GDPR Article 6(1)(b)).
  • Anything in your CV about your health, disability, religion, ethnicity, sexuality, politics or union membership: we ask you to leave it out. If you leave it in, we process it only with the explicit consent you give on the upload form (Article 9(2)(a)), which you withdraw by uploading a CV without those details or by deleting your account.
  • Using your “not for me” answers to score later postings, and reading them to find out why a match was wrong: our legitimate interest in making the matching precise (Article 6(1)(f)). You can object by not giving a reason, or by writing to us.
  • Keeping the copy of each email and the record of each run: our legitimate interest in never sending the same thing twice and in being able to show our work (Article 6(1)(f)).
  • The sign-in cookie and server logs: needed to run the site securely, which is both the contract and a legitimate interest. The cookies page lists every cookie.

We do not use your data for advertising, for profiling anyone else, or for training models.

The matching is automated, and here is how it works

A model reads your CV into a profile you correct. Your filters are applied as a plain database query: a posting outside them is removed before anything is scored. The rest are shortlisted by similarity between your profile and each posting, then a model scores the shortlist against your profile, your filters and your past “not for me” answers, writing a breakdown and reasons that must quote your profile and the posting word for word. Anything the model says that it cannot quote is thrown away, and a match with no checkable reason is not sent. A posting is sent only if it scores above our threshold and was confirmed open in the previous 24 hours, and never more than your weekly number.

This is automated processing that decides what we show you. It makes no decision about you for anyone else: no employer sees a score or knows you exist. You can see the logic behind every match on its card, correct the profile it was based on, tell us when it is wrong, and ask a person to look at any match or any empty week by writing to us. If you are in the UK, those are also your rights under UK data protection law for automated decisions: to be told, to make representations, and to have a person review the outcome.

Your “not for me” reasons are private to you

When you turn a match down, the reason and any note you add belong to your account. No employer or recruiter sees them, they are never attached to an application, and no other user can read them: every read is scoped to your own account, and there is no public or employer-facing way into the database at all.

Two things do happen with them, and you should know both.

  • They go into the scoring of later postings, so a role that resembles one you rejected scores lower. That means the reason and your note are sent to Google (Gemini) as part of the scoring request, along with your profile and the posting.
  • We can read them on an internal page while working out why a match was sent, and we count them in aggregate to see how often matches are wrong and why. That page shows us your email address, your filters, the lines quoted from your profile and your notes, and it is limited to our own admin accounts. A second internal page lists the emails we tried to send you — when, to which address, the subject line and whether it arrived — so that an email that silently failed can be found. It does not show what the emails said.

What we store

  • The CV file you uploaded, in a private bucket, in a folder named after your account. There is no public link to it, and only our own server, acting for your account, reads that folder: the parser reads the file to build your profile, and nothing else in the product reads it. Uploading a new CV removes the previous file; if that removal ever fails, the file is picked up when the account is deleted.
  • The profile we read out of it: a headline, your level and the line of the CV that shows it, roles with their highlights, skills, qualifications, domains, languages, where the CV says you are based, and a short summary, plus any correction you make to it on the profile page.
  • One embedding of that profile: a list of 1024 numbers, built from the profile rather than from the file, used to pick a shortlist of postings to score.
  • Your filters: place and radius, work modes, levels, any salary floor, employment types, employers you excluded, title words you excluded, and your softer preferences.
  • Your account settings: the email address on your Google account, how often we email, your weekly cap, whether you are paused or have unsubscribed from email, which plan your account is on, whether you have asked for a run to start now, whether we have opened your account and when, and when you agreed to the terms and gave the consent above.
  • Whether we opened your account, and when. We approve accounts by hand, so a new sign-up waits until one of us decides. While it waits, the only things we hold about you are the email address Google gave us and the fact that you signed in — there is no CV, nothing has been read, and no matching has run. If we decide not to open the account we keep that decision and the email address, so the same address does not come round again unnoticed, and the email we send you carries a link that deletes both without signing in. That link is always there; you never have to ask us.
  • The matches we sent you: which posting, the score and its breakdown, the quoted rationale, what you tapped, any “not for me” reason and note, and anything you told us about applying.
  • A record of each run: how many postings passed your filters, which were shortlisted and scored, what each scored, and whether the posting was still live. It is what lets us show our work and explain a week that sent you nothing.
  • A copy of each email we sent you, and a hashed form of the links in it. The copy is how we make sure nothing is sent twice; the hash is what lets a link be checked, expired or revoked without the link itself being stored in our database.
  • Server logs: the hosting platform records each request with your IP address, the page and the time, as any web host does, and keeps them for 30 days. Our own log lines refer to your account by its id, never by your email address or anything from your CV.

The only cookie we set is the one that keeps you signed in, plus three that last for the minutes a Google sign-in takes. There is no analytics code, no tracking pixel and no advertising code, in the app or in our emails.

How long we keep it

While your account exists, we keep your CV, profile, filters and matches. Your profile is the product, so we do not quietly expire it, and your match history is what stops us sending you the same role twice. Replacing your CV removes the old file.

Three things are trimmed on a timer, because nothing reads them after a while: the text of each email we sent you is emptied 90 days after sending (the record that it was sent stays), the scoring trace behind each run is emptied 90 days after the run, and a link token is deleted a week after it expires. Everything else stays until you delete your account; we would rather say that than imply a retention period the code does not enforce. If an account sits unused for a long time we may email you and, if you do not answer, delete it the same way; we will say so here before we start doing that.

Deleting everything

You can delete your account from Settings, or from the footer of any email we send you, without signing in. An emailed link only opens a page that says what is about to happen and asks you to confirm. Nothing is deleted by opening a link.

The moment you confirm, matching stops and nothing more is sent. We then delete:

  • the CV file you uploaded
  • the profile we read from it and the embedding made from that profile
  • your filters
  • every match we sent you and every answer you gave
  • our record of each run we made for you
  • our copy of each email we sent you and the links in it
  • your email address and your account

All of it is removed within 24 hours, and we email you once when it is done (if that email fails, the deletion still happens). That email is the last one you get from us. This cannot be undone. Copies in our database backups and in the email provider’s delivery logs fall out of their own retention windows after that.

Pausing instead

If you only want the emails to stop, pause instead. Pausing stops every run and every email and changes nothing else: your CV, profile and filters stay exactly as they are, and you resume when you want. Pause from Settings or from the footer of any email, again without signing in.

Who else handles your data

These are the companies your data reaches. Each of them works on our instructions, and none of them is paid in data.

  • Google runs the database that holds everything listed above (Cloud SQL, in London), the servers the app runs on (Cloud Run, in Belgium), the timer that starts each background job, and the Gemini models that read your CV and score postings, through Google’s EU location, under terms that do not allow your data to be used to train its models. For reading, Gemini receives the text of your CV, or the PDF itself when the text does not come out cleanly, so it receives whatever your CV contains, including your name and contact details. For scoring, it receives your profile, your filters, your past “not for me” reasons and notes, and the posting being scored. The shortlist embedding is made from your profile summary (headline, level, job titles, domains, skills, summary), not from the file, your email address or your feedback. Google also handles sign-in: when you press “Continue with Google”, Google tells us the verified email address on your account and nothing else, and Google itself knows you signed in here, under its own privacy policy.
  • Supabase runs the private bucket your CV file sits in, in its London region on Amazon Web Services. It holds the file and nothing else.
  • Resend sends our emails. It receives your email address and what is in the email: the roles we matched, links to them, and your pause, delete and unsubscribe links.

The job aggregators we read (Adzuna and Reed) and the employers whose feeds we read receive nothing about you from us. If a role came from Adzuna, its “open the posting” link goes through Adzuna’s own link first, which records the click before sending you on to the employer; the card says so. Anthropic and Voyage AI, two other model providers, exist in our code for comparing matchers on a labelled test set; they are not used on live accounts, and if that changed this page would say so first.

Resend is a US company. Where your data leaves the EU or the UK we rely on the safeguards the law provides for that (an adequacy decision or standard contractual clauses in the provider’s data-processing terms). The signed terms with each provider are listed here once the company is formed.

Your rights

You can, at any time and for free:

  • see what we hold about you, and get a copy of it;
  • correct it: your profile and filters are editable on the site, and we correct anything else on request;
  • delete it, from Settings or any email, without asking us;
  • ask us to restrict or stop a use of it, including the feedback-informed scoring above;
  • withdraw the consent you gave for sensitive details, by uploading a CV without them or by deleting your account;
  • take your data with you in a machine-readable form: Settings has a one-click download of everything we hold, as JSON.

Write to us and we answer within a month. If you think we have got something wrong, you can complain to a data protection authority: in Ireland and the rest of the EU, the Data Protection Commission; in the UK, the Information Commissioner's Office.

Age

The service is for adults looking for work. If you are under 18, do not upload a CV; if we learn that an account belongs to someone under 18, we delete it.

Changes

When this notice changes in a way that matters, we email you before the change and update the version date at the top. The previous wording is in our source history.

Back to the front pageCookiesTerms