Privacy Policy

Effective: August 2, 2026 - Version 1.7

1. Who We Are

Career Compass is a career intelligence platform operated by:

CodeTech

Wroclaw, Poland

NIP: 7631936648

Email: support@careercompass.pl

Website: https://careercompass.pl

We are the data controller responsible for your personal data. This means we determine how and why your personal data is processed.

Given the current scale of our operations, we have not appointed a Data Protection Officer under Article 37 GDPR. All data protection inquiries can be directed to support@careercompass.pl. We will appoint a DPO if our processing activities require it.

Career Compass helps EU-based IT professionals, project managers, product owners, and delivery managers understand their career strengths through resume scoring and job matching.

2. What Data We Collect

We collect and process the following categories of personal data:

Providing your resume and professional information is necessary to use Career Compass's core features. If you choose not to provide this data, we cannot deliver resume scoring, job matching, or AI-generated career content. Account registration requires only an email address and password (or Google OAuth).

2.1 Identity Information

DataPurposeSource
Full nameAccount identification, CV displayResume upload, manual entry
Email addressAccount access, communicationsRegistration form, OAuth
Phone numberContact information on CVResume extraction
Location (city/country)Job matching, CV displayResume extraction, manual entry
LinkedIn profile URLProfessional profile linkingResume extraction, manual entry

2.2 Professional Information

DataPurposeSource
Current job titleResume scoring, job matchingResume extraction
Work historyExperience scoring, industry classificationResume extraction
Years of experienceCareer depth analysisCalculated from work history
Companies worked forIndustry breadth scoringResume extraction
IndustriesIndustry diversity scoringAI classification
Education historyPresentation scoringResume extraction
Professional summaryContent quality analysisResume extraction

2.3 Skills and Credentials

DataPurposeSource
Technical skillsCompetencies scoring, job matchingResume extraction, keyword matching
Soft skillsCompetencies scoringResume extraction, keyword matching
CertificationsCompetencies scoring, job matchingResume extraction, curated matching
Tools and methodologiesCompetencies scoringResume extraction, keyword matching
LanguagesPresentation scoringResume extraction

2.4 Job Search Preferences

DataPurposeSource
Target rolesJob matching, keyword coverageOnboarding selection
Work location preferenceJob matching (remote/hybrid/on-site)Settings
Employment typeJob matching (full-time/contract/part-time)Settings
Notice periodJob matching availabilitySettings
Job search statusFeature personalizationOnboarding selection

2.5 Usage Data

DataPurposeSource
Job match historyMatch history feature, service improvementAutomatic logging
Profile score historyProgress trackingAutomatic calculation
Login timestampsSecurity, fraud preventionAutomatic logging
Feature usageService improvementAutomatic logging

2.6 Technical Data

DataPurposeSource
IP addressSecurity, fraud preventionAutomatic collection
Browser typeTechnical support, compatibilityAutomatic collection
Device informationTechnical supportAutomatic collection

2.7 Payment Information

DataPurposeSource
Billing emailPayment receipts and invoicingStripe checkout
Payment method type (last 4 digits only)Transaction identificationStripe
Transaction historyPurchase records, supportAutomatic logging
Token balance and purchase timestampsService delivery, usage trackingAutomatic logging

We never store full credit card numbers. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor.

2.8 AI-Generated Content

DataPurposeSource
Cover lettersCareer application supportAI generation from profile + job match
Elevator pitchesNetworking preparationAI generation from profile + job match
Interview prep questionsInterview preparationAI generation from profile + job match
Professional summariesProfile enhancementAI generation from profile data
Polished achievementsAchievement improvementAI generation from user input
Score history snapshotsProgress tracking over timeAutomatic calculation

3. How We Collect Your Data

We collect data through the following methods:

3.1 Direct Collection

  • Registration forms: When you create an account using email/password
  • Resume upload: When you upload your CV in PDF format
  • Manual entry: When you edit or add information to your profile
  • Settings updates: When you configure your job preferences

3.2 Automated Collection

  • AI extraction: We use artificial intelligence to extract structured data from your uploaded resume
  • Keyword matching: We identify skills, certifications, and tools using curated dictionaries
  • Industry classification: We classify your work experience into industry categories using AI analysis
  • Usage logging: We automatically record your interactions with the platform for security and service improvement

3.3 Third-Party Collection

  • Google OAuth: If you sign up or log in with Google, we receive your name and email address from Google
  • Job posting analysis: When you analyze a job posting URL, we extract information from that public job listing

5. How We Use Your Data

5.1 Resume Scoring

We analyze your resume using our Three Pillars Model:

  • Experience Pillar: Evaluates career depth, industry breadth, and achievement impact
  • Competencies Pillar: Assesses certifications, technical skills, soft skills, and tools
  • Presentation Pillar: Reviews contact completeness, content structure, data quality, and language proficiency

This scoring helps you understand your CV's strengths and areas for improvement.

5.2 Job Matching

When you submit a job posting URL, we:

  1. Extract job requirements from the posting
  2. Compare your profile against job requirements
  3. Calculate a match score across Role Fit, Skills Fit, and Preferences Fit
  4. Identify skill gaps and provide actionable insights

5.3 Keyword Coverage Analysis

We analyze how well your resume keywords align with expected keywords for your target roles, helping you optimize your CV for specific career paths.

5.4 Account Management

We use your data to:

  • Create and maintain your account
  • Authenticate your identity
  • Send important service communications
  • Respond to your support requests

5.5 Service Improvement

We use aggregated, anonymized data to:

  • Improve our scoring algorithms
  • Develop new features

5.6 Automated Profiling

Career Compass performs automated profiling under Art. 4(4) GDPR through the following mechanisms:

  • Resume scoring: The Three Pillars Model (Experience, Competencies, Presentation) produces a 0-100 score for each pillar
  • Job matching: Weighted comparison across Role Fit (35%), Skills Fit (35%), and Preferences Fit (30%)

These scores are informational only and do not result in any employment decisions. No decisions producing "legal effects or similarly significant effects" under Art. 22 GDPR are made based on this profiling.

You can review the scoring methodology on the platform. If you have concerns about any automated assessment, contact support@careercompass.pl for human review.

5.7 AI Job Finder (Scheduled Job Matching)

If you turn on the AI Job Finder (an opt-in feature for paid plans), we run the job matching described in 5.2 on a schedule you choose. On your selected day(s) of the week, we search the job boards you picked for fresh public postings, score them against your profile using the same automated processing as manual job matching, and save the best matches as a digest you can review in the app. If you also enable the digest email, we send the results to your account email address.

  • This processing runs only after you explicitly turn it on and stops as soon as you turn it off in Settings
  • The results are recommendations for you only. No decision producing legal or similarly significant effects under Art. 22 GDPR is made; you decide whether to view or apply to any job
  • Digest history is retained for 90 days (see Section 7) and is included in your data export

6. Data Sharing and Third Parties

6.1 Service Providers (Data Processors)

We share data with the following third-party processors who help us operate our platform:

ProviderPurposeData SharedLocation
SupabaseDatabase hosting, authentication, file storageAll user data, resume filesEU (Paris)
Anthropic (Claude API)AI-powered resume extraction and analysisResume text content (identity data redacted before transmission)USA*
Anthropic MCP clients (optional)Third-party AI clients you choose to connect (Claude Desktop, Claude Code, Claude Web, Claude Cowork) read your Career Compass data via our Model Context Protocol (MCP) endpointOnly what you consent to per connection: profile, matches, generated cover letters / interview prep / elevator pitches / LinkedIn headlines, per the read/write scopes you approveUSA*
TavilyJob posting search and content extractionJob posting URLs, and for AI Job Finder searches your target job titles, location and remote preferenceUSA*
VercelApplication hostingTechnical/usage dataEU (Paris)
StripePayment processingBilling email, payment method info, transaction dataUSA*
Landing.aiPDF document parsing (resume extraction)Resume PDF content (the whole file, before identity data is removed); retained by the provider for up to 7 years - see Section 10.2EU (Ireland)
ResendTransactional emails (verification, notifications)Email addressUSA*
LangfuseLLM prompt management and observabilityAI processing metadata only (prompt name, model, token counts) - no resume or job content; retained for a maximum of 30 daysEU (Germany)
CookieYesCookie consent managementCookie preferences and consent records (consent ID, your choice, and timestamp)EU
Google AnalyticsWebsite usage analyticsAnonymized usage data (only after consent)USA*
Solid.jobsJob posting data source (solid.jobs listings via public API)Campaign attribution parameter only (no user PII)EU (Poland)

*For US-based processors, we rely on Standard Contractual Clauses (SCCs) and their additional safeguards. See Section 10 for details.

The processors above may in turn use their own sub-processors, each under a written agreement that gives your data the same protection. Each processor publishes its current sub-processor list, and we are notified in advance of any change.

6.2 What We Do NOT Do

We never:

  • Sell your personal data to third parties
  • Share your resume with recruiters without your explicit consent
  • Use your data for advertising or marketing by third parties
  • Share your data with other users of the platform

6.3 Legal Requirements

We may disclose your data if required by law, court order, or government request, or to protect our legal rights.

6.4 Third-party AI clients (Model Context Protocol)

Career Compass offers an optional integration via the Model Context Protocol (MCP) so you can use AI clients like Claude Desktop, Claude Code, Claude Web, or Claude Cowork to query and act on your Career Compass data from within those clients. This integration is off by default. You must explicitly connect each client, and each connection is a separate consent event.

  • Per-connection consent: every time you authorize an MCP client (new connection or reconnect), you must tick the GDPR checkbox on our consent screen. A previous connection does not cover a new one.
  • Scope: you approve Read and/or Write access. Read lets the client view your profile and matches. Write lets it create cover letters, interview prep, elevator pitches, and job-match analyses on your behalf. Each paid action uses one of your daily AI action allowances on your Career Compass plan.
  • Withdrawal: disconnect any MCP client from Claude's side or from Settings → Connections in Career Compass. Disconnecting immediately revokes the client's tokens and grant.
  • Audit trail: every consent event is recorded with the specific application and grant it authorized; every tool call is audit-logged with a hashed (never plaintext) input fingerprint.
  • Anthropic as sub-processor: when you connect one of Anthropic's Claude clients, data served to that client is processed by Anthropic under their privacy policy. See the sub-processors table above.

You can see your active MCP connections and disconnect them anytime at Settings → Connections.

7. Data Retention

We retain your data only as long as necessary for the purposes described in this policy.

7.1 Retention Periods

Data CategoryRetention PeriodReason
Account dataUntil account deletionService provision
Resume file (our systems)Until account deletionDeleted immediately with account
Resume file (copy held by our PDF parser)Up to 7 yearsHeld by Landing.ai (EU) under its own retention policy; not removed when you delete your account. See Section 10.2
Extracted profile dataUntil account deletionService provision
Job match historyUntil user deletes or account deletionUser feature
AI Job Finder digests and run history90 daysWeekly digests are refreshed content; deleted automatically after 90 days
Login activity logsManaged by Supabase (our authentication provider)Security monitoring
AI processing telemetry (Langfuse traces)30 days rollingLLM observability and debugging; deleted automatically after 30 days
Account deletion audit3 years from deletionLegal compliance

7.2 After Account Deletion

When you delete your account:

  1. Immediate: All personal data, including resume files, is deleted from our systems
  2. Retained for 3 years: Anonymized audit record (SHA-256 hash of email only, no plain text) for GDPR compliance documentation
  3. Retained by our PDF parser: The copy of your resume file held by Landing.ai (EU) is kept under its own retention policy, up to 7 years, and is not deleted with your account. See Sections 7.1 and 10.2

8. Your Rights Under GDPR

As an EU resident, you have the following rights regarding your personal data:

8.1 Right of Access (Article 15)

You can request a copy of all personal data we hold about you.

How to exercise: Email support@careercompass.pl with subject "Data Access Request"

8.2 Right to Rectification (Article 16)

You can correct inaccurate or incomplete personal data.

How to exercise: Edit your profile directly in the platform, or contact us for assistance.

8.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data.

Deletion removes your data from our systems immediately. There is one exception: the copy of your resume file held by our PDF parser (Landing.ai, EU) is kept under that provider's own retention policy, and we have no self-service way to delete it. If you want that copy removed, email us and we will pass your request to the provider, but we cannot guarantee the outcome.

How to exercise:Use the "Delete Account" function in Settings, or email us.

8.4 Right to Data Portability (Article 20)

You can request a copy of all your data in a structured, machine-readable format (JSON/ZIP). This includes:

  • Profile information and preferences
  • Identity data (name, contact details)
  • Extracted skills, certifications, and work history
  • Job match results and history
  • Cover letters, elevator pitches, and interview preparations
  • Original uploaded resume file

How to exercise: Email support@careercompass.pl with subject "Data Export Request". We will fulfill your request within 30 days.

8.5 Right to Restriction of Processing (Article 18)

You can request we limit how we use your data in certain circumstances.

How to exercise: Contact us explaining the specific restriction you're requesting.

8.6 Right to Object (Article 21)

You can object to processing based on legitimate interests.

How to exercise: Contact us with your objection. We will stop processing unless we have compelling legitimate grounds.

8.7 Right to Withdraw Consent (Article 7)

Where processing is based on consent, you can withdraw it at any time through these specific channels:

  • Cookie consent: Use the CookieYes preference center (cookie icon in the footer) to change your cookie preferences at any time
  • Marketing communications: Use the one-click unsubscribe link in any marketing email (when applicable)

Core service features (resume scoring, job matching, AI content) operate under Contract Performance basis (Art. 6.1.b), not consent. These features are part of the service you signed up for.

Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8 Right to Lodge a Complaint

You have the right to complain to a supervisory authority. In Poland, this is:

Urząd Ochrony Danych Osobowych (UODO)

ul. Stawki 2

00-193 Warszawa

Website: https://uodo.gov.pl

Email: kancelaria@uodo.gov.pl

Response Timeline

We will respond to all rights requests within 30 days. If a request is complex, we may extend this by an additional 60 days, but we will inform you of any extension within the initial 30-day period.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

9.1 Technical Measures

  • Encryption in transit: All data transmitted using TLS 1.3
  • Encryption at rest: Database and file storage encrypted
  • Secure authentication: Password hashing, OAuth 2.0 support
  • Access controls: Role-based access, principle of least privilege

9.2 Organizational Measures

  • Data minimization: We only collect data necessary for our services
  • Access limitation: Only authorized personnel can access personal data
  • Incident response: Procedures for detecting and responding to data breaches

9.3 Data Breach Notification

In the event of a data breach that poses a risk to your rights:

  • We will notify the supervisory authority within 72 hours
  • We will notify affected users without undue delay if high risk
  • We will document all breaches and remediation actions

10. International Data Transfers

Your data is primarily stored in the European Union (Supabase EU - Paris).

When we transfer data to processors outside the EU (specifically to the USA for AI processing), we rely on:

10.1 EU-US Data Privacy Framework (DPF)

Stripe and Google are certified under the EU-US Data Privacy Framework, which provides an adequate level of data protection for transfers to the United States. Transfers to our other US processors, including Anthropic, Vercel, Tavily and Resend, rely on the European Commission's Standard Contractual Clauses (Modules Two and Three) as described in Section 10.2.

10.2 Additional Safeguards for AI Processors

  • Anthropic (Claude) does not use your prompts or outputs to train its models, and automatically deletes inputs and outputs within 30 days of receipt. Transfers are covered by Standard Contractual Clauses (Modules Two and Three)
  • Landing.ai (PDF parsing, EU-hosted in Ireland) receives the original resume file, before any identity data is removed. This provider does not operate under zero data retention for our account: it stores the file on its own systems for up to 7 years under its published privacy policy, and its standard terms permit it to use customer materials to operate and improve its services. Your data stays in the EU. We keep this arrangement under review and will move to a zero-retention or contractually time-limited arrangement if one becomes available to us
  • Tavily (job posting search) may use query data to improve its own service
  • Apart from the resume file sent to Landing.ai, only professional data reaches AI processors (skills, experience, education, job descriptions), with identity data removed first
  • We do not ask for special categories of personal data. A resume you upload may contain such data if you chose to include it (for example health, ethnic origin, religious belief or trade union membership), and that file is processed as a whole by our PDF parser

10.3 EU Data Storage

Supabase stores all persistent user data in the EU (Paris region). Langfuse (LLM observability) is hosted in the EU (Germany); observability traces are automatically deleted after 30 days.

10.4 AI Processing Specifics

When your resume is processed by AI services:

  • Identity data (name, email, phone number, LinkedIn URL) is extracted locally on our servers using pattern matching - no AI is involved in processing your personal identifiers
  • Our PDF parser (Landing.ai, EU-hosted) receives the original resume file - including identity data - because it must read the whole document to convert it to text. It only parses the file; it does not classify or profile you
  • Identity data is then stripped from the parsed text before it is sent to Anthropic (Claude), our LLM provider. Only professional content (skills, experience, education) reaches the model
  • Anthropic does not train on this data and deletes inputs and outputs within 30 days. Landing.ai keeps its copy of the original file for up to 7 years under its own policy, and that copy is not removed when you delete your account with us
  • Results are immediately returned and stored in our EU database

11. Cookies

We use cookies and similar technologies to operate our platform. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

Summary:

  • Essential cookies: Required for authentication and security (no consent needed)
  • Functional cookies: Not currently used. May be introduced for preferences in the future (consent will be required)
  • Analytics cookies: We use Google Analytics 4 to understand how visitors interact with our website and which features are most useful. Analytics cookies are only set after you provide consent via our cookie banner

12. Children's Privacy

Career Compass is designed for professionals and is not intended for anyone under 18 years of age.

We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at support@careercompass.pl, and we will delete such data.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

13.1 Notification Process

  • Minor changes: Updated policy posted on this page with new "Last Updated" date
  • Material changes: Email notification to registered users before the changes take effect

13.2 Continued Use

Your continued use of Career Compass after changes take effect constitutes acceptance of the updated policy. If you do not agree with changes, you may delete your account.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email: support@careercompass.pl

General Inquiries: hello@careercompass.pl

Company Information:

CodeTech

NIP: 7631936648

Wroclaw, Poland

We aim to respond to all inquiries within 5 business days, and to formal rights requests within 30 days.

This Privacy Policy was drafted in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applies to users of Career Compass in the European Union.