legal
privacy policy
effective 1 July 2026
1. who we are
CareerScore (“we”, “us”, “our”) operates the platform at careerscore.getscore.site. We are the data controller for personal data processed through the Service.
Contact: careerscore@getscore.com
2. what data we collect
2a. data you provide directly
- Basics: Full name, date of birth, and career level — entered manually in the Calculate flow. Used only to compute and personalise your score.
- CV / LinkedIn export: Documents you upload are processed through our OCR and extraction pipeline. Text is extracted, structured facts are parsed by an AI model, and the document is not stored on our servers after the request completes.
- Proof documents: Documents attached to specific claims (offer letters, transcripts, etc.) are processed for cross-checking and are not retained.
- Email & password: If you create a CareerScore account, your credentials are managed by Supabase Auth. We never see your plaintext password.
- Waitlist email: If you join the waitlist, your email is stored to notify you of product updates.
2b. data we collect automatically
- Usage logs: Server logs may include IP address, timestamp, and endpoint accessed. Used for abuse prevention and rate limiting (via Upstash Redis). Logs are rotated regularly.
- Session data: We store your in-progress Calculate state in browser
sessionStorageso you don't lose data on refresh. This is local to your browser and is cleared when you reset or close the tab.
2c. github data (oauth)
- When you connect GitHub, we request access to your public repositories (or public + private if you select that option).
- We inspect repository metadata only: README presence, test file presence, CI config, star counts, language composition, and commit frequency. We do not read source code contents.
- GitHub OAuth tokens are not stored. The inspection happens within the request lifetime.
3. how we use your data
- To compute, display, and store your CareerScore.
- To verify claims against uploaded proof documents (confidence signal only; never used to change the score).
- To personalise scores against your peer cohort (stage, domain).
- To enforce rate limits and prevent abuse.
- To notify you (waitlist only) when relevant product updates are available.
- To comply with legal obligations.
We do not sell your data. We do not use your data to train AI models (extraction models process your documents in real time; your data is not used as training input).
4. third-party processors
We share data with the following processors under contractual data-processing agreements:
- Supabase — database & authentication (EU/US region, SOC 2 compliant).
- Vercel — hosting and edge infrastructure.
- DeepSeek — AI text extraction and university prestige estimation. CV text is sent to DeepSeek; it is not stored by us after extraction.
- Firecrawl — web research for deep-research mode (company / project verification).
- OCR.space — fallback image OCR for scanned CVs.
- Upstash Redis — rate-limit counters (IP-keyed, no PII stored).
- GitHub — OAuth and repository inspection.
5. cookies & local storage
We use a single short-lived cookie (cs_gh) to pass GitHub OAuth results back to the application after a redirect. This cookie expires immediately after processing and contains only encoded GitHub profile data (no auth tokens).
We do not use advertising cookies, tracking pixels, or third-party analytics.
6. data retention
- Uploaded documents: Not retained after request completion.
- Score results: Retained indefinitely while your account is active, or until you delete them.
- Account data: Retained until you request deletion.
- Waitlist emails: Retained until you unsubscribe or the list is closed.
- Server logs: Retained for up to 30 days.
7. your rights (UK/EU GDPR)
If you are in the UK or EU, you have the right to:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion of your data (“right to be forgotten”).
- Portability: Receive your data in a machine-readable format.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: At any time where processing is based on consent.
To exercise any right, email careerscore@getscore.com. We will respond within 30 days.
8. security
All data in transit is encrypted via TLS. Stored scores are protected by Supabase row-level security policies. API access requires signed keys (ECDSA P-256). We apply rate limiting on all cost-bearing endpoints to prevent abuse.
No system is 100% secure. If you discover a vulnerability, please disclose it responsibly to careerscore@getscore.com.
9. children
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have done so, contact us immediately.
10. changes to this policy
We may update this Privacy Policy from time to time. Changes are posted here with an updated effective date. Continued use of the Service after changes constitutes your acceptance of the updated policy.
11. contact
Privacy enquiries: careerscore@getscore.com