Legal

Privacy Policy

Effective date: March 10, 2026

BestRole ("we", "our", or "us") is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, and how you can control it.

1. Information We Collect

1.1 Account Information

When you create a BestRole account, we collect your email address and, optionally, your name and profile picture via OAuth (Google).

1.2 Resume & Career Data

You may upload or create resumes, add job applications, set job goals, and record interview notes inside BestRole. All of this content belongs to you and is processed solely to deliver our services.

1.3 Usage Data

We automatically collect technical information including IP address, browser type, operating system, pages visited, time spent, and referring URLs. This data helps us improve performance and fix bugs.

1.4 Payment Information

Subscription payments are processed by Stripe. We never store your full card number or CVV. We receive only non-sensitive billing metadata (last 4 digits, billing country, subscription status).


2. How We Use Your Information

We use your data to:

  • Provide, operate, and improve the BestRole platform
  • Personalize AI-generated resume suggestions, job matches, and outreach messages
  • Send transactional emails (account confirmation, password reset, job reminders)
  • Respond to support requests
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal data. We do not use your resume content to train AI models shared across users.


3. How We Share Your Information

We share your data only with trusted service providers necessary to run BestRole:

ProviderPurposeData shared
SupabaseDatabase & authenticationAll user data
GeminiAI features (resume, outreach)Resume content, job context
ResendTransactional emailEmail address
StripePayment processingBilling details
VercelHosting & analyticsUsage data

We may disclose information if required by law, court order, or to protect the rights, property, or safety of BestRole or its users.


4. Data Retention

We retain your personal data for as long as your account is active or as needed to provide our services. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or legitimate business interests (e.g. fraud prevention, dispute resolution).

Aggregated, anonymised usage statistics may be retained indefinitely.


5. Security

We implement industry-standard safeguards including TLS encryption in transit, encryption at rest, access controls, and regular security reviews. However, no system is completely secure. We encourage you to use a strong, unique password and enable two-factor authentication where available.

In the event of a data breach that affects your personal data, we will notify you and the relevant authorities as required by applicable law.


6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • AccessRequest a copy of the personal data we hold about you.
  • CorrectionRequest that we correct inaccurate or incomplete data.
  • DeletionRequest deletion of your data ("right to be forgotten").
  • PortabilityReceive your data in a structured, machine-readable format.
  • ObjectionObject to processing of your data for direct marketing.
  • RestrictionRequest that we limit how we use your data in certain circumstances.

To exercise any of these rights, email us at support@bestroleai.com. We will respond within 30 days.


7. Cookies & Tracking

BestRole uses the following types of cookies:

  • Essential cookies: Required for authentication and secure session management. Cannot be disabled.
  • Analytics cookies: Vercel Analytics collects anonymous page-view data to help us understand usage. No cross-site tracking.

We do not use advertising or third-party tracking cookies.


8. Third-Party Services

BestRole may contain links to third-party websites or integrate with services (e.g. LinkedIn, job boards). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you use.


9. Children's Privacy

BestRole is not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly. If you believe a child has used our service, please contact us.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and, for material changes, notify you by email or a prominent notice in the app. Continued use of BestRole after the effective date constitutes acceptance of the updated policy.


11. Contact Us

If you have questions or concerns about this Privacy Policy or how we handle your data, please contact us: