Privacy Policy
Effective date: September 5, 2026 · Last updated: September 5, 2026
This policy explains what information Rolestead collects, how it's used, and how it's shared — across the Rolestead web application and the Rolestead browser extension for Chrome. “Rolestead,” “we,” “us,” and “our” refer to the operator of the Rolestead product.
Who We Are
Rolestead is a personal job-search workspace: a web application for saving job postings, scoring how well they fit your resume, tracking applications through a pipeline, and generating tailored application materials, paired with a Chrome browser extension that lets you save a job listing to your Rolestead workspace directly from the job board you're looking at. Rolestead does not currently operate as a separately registered company under a different legal name — this policy governs the Rolestead product as a whole, web app and extension alike.
Information We Collect
Account information
When you create a Rolestead account, we collect your email address and, if you sign in with Google, your name and profile picture as supplied by Google. Your password is never seen or stored by Rolestead's own application code — it is handled entirely by our authentication provider, Supabase, which stores only a salted hash. If you fill in optional autofill fields on your Account page (phone number, location, LinkedIn/portfolio/GitHub links, work-authorization and sponsorship-need answers), we store those to identify you and to pre-fill job application forms when you use the extension's autofill feature — never to auto-answer voluntary demographic questions (see the Browser Extension section below).
Job search and workspace data
As you use Rolestead, we store the data you create and the data the product generates on your behalf, including:
- Saved job postings — title, company, description, location, salary, employment type, benefits, visa-sponsorship info, application deadline, and the job's source URL and platform (e.g. Greenhouse, Lever, a job board, or a page you saved via the extension).
- Match scores and tags our AI computes for a job against your resume/profile.
- Applications — pipeline status, notes, generated cover letters, apply messages, and tailored resumes, plus a history of status changes.
- Interview records you log — round details, your notes, and AI-generated feedback.
- Messages you send in a job's AI chat, and the assistant's replies.
- Job-source configurations you set up for automated syncing (e.g. a saved search on a supported job board).
- If you opt into forwarded-email employer-reply detection: the sender, subject, and body text of emails you personally forward to your Rolestead inbound address.
Resume and profile data
Rolestead stores your resume content in a work profile, plus any number of named “personas” (search-strategy variants — target roles, locations, salary expectations, and a persona-specific standing resume) and the tailored resume versions generated for specific applications. This is the data our AI features read to score jobs and draft application materials — see AI Processing below.
Technical and usage data
Rolestead's own application code does not run any analytics, advertising, session-recording, or crash-telemetry service, in the web app or the extension. Our infrastructure providers (Supabase, and whichever service hosts the web app) necessarily process standard technical data — such as IP address, request timestamps, and browser/device information found in HTTP request headers — as an ordinary part of serving web traffic and operating their platforms.
Communications
Supabase, our authentication provider, sends transactional account emails on our behalf (sign-up confirmation, password reset). If you email us directly, we keep that correspondence to respond to you and improve the product.
Browser Extension
The Rolestead extension's only purpose is to let you save a job listing to your Rolestead workspace, check its match score, generate application materials, and track it through your pipeline — all without leaving the job board you're on.
The extension reads the current page only when you explicitly invoke it — opening the extension popup and clicking an action such as “Import this page,” “Recalculate match,” or “Autofill this application.” It has no background service worker, no content script running on pages you haven't acted on, and no <all_urls> permission — it uses Chrome's activeTab and scriptingpermissions, which only grant access to the one tab you're currently viewing, and only once you click the extension icon.
When you import a job, the extension reads the visible text of that page and its URL, and sends them to Rolestead to extract structured job details — title, company, description, location, salary (when listed), employment type, benefits, visa sponsorship, application deadline, source platform, and an external job identifier when the page provides one. When you use “Autofill this application,” a second, separate action, the extension reads the current page's form fields to fill them with the contact and work-authorization information you saved on your Account page — it never autofills voluntary self-identification questions (gender, race/ethnicity, veteran status, disability) and never touches file/resume upload fields.
Data the extension reads is sent only to Rolestead's own backend, at the API address configured in the extension's Settings page — never to any other third party, and the extension itself contains no analytics or error-monitoring code.
Authentication and Local Storage
The web app authenticates you with a session cookie issued by Supabase Auth, refreshed automatically while you're signed in. The extension has no browser session of its own; instead, it stores your personal API token and the configured API address in Chrome's chrome.storage.local — deliberately local-only storage, not chrome.storage.sync, so the token isn't copied to other devices via your Google account. Nothing else is kept in extension storage: no browsing history, no cache of pages you've visited, no analytics identifiers. You can revoke that token at any time from your Rolestead Account page, which immediately invalidates it.
How We Use Information
- Operating the core product: saving and organizing jobs, and tracking applications through your pipeline.
- Computing match/fit scores between a job posting and your resume or a persona.
- Generating application materials — cover letters, apply messages, and tailored resumes — when you request them.
- Pre-filling job application forms with your saved contact details, when you use the extension's autofill feature.
- Detecting and suggesting status updates from employer replies you forward, if you've opted into that feature.
- Creating and securing your account, including authenticating extension requests.
- Maintaining and improving the reliability of the service and responding to support requests.
We do not use your data for advertising, do not build advertising profiles, and do not use it for any purpose unrelated to the product features above.
AI Processing
Rolestead uses Google's Gemini API to power its AI features: extracting structured fields from a job posting, scoring how well a job matches your resume, drafting cover letters/apply messages/tailored resumes, running the per-job chat assistant, and (if you use the forwarded-email feature) classifying a forwarded employer reply. Depending on the feature, this can send job posting text, your resume/profile content, persona details, prior chat messages, or forwarded-email text to Google as the processor of that request. Google receives this data as our service provider, solely to generate the response Rolestead requested — we have not independently verified, and this policy does not represent, whether Google uses this data to train its own models; consult Google's own API terms for their data-handling and retention practices.
How We Share Information
We share information only with the service providers that operate Rolestead on our behalf, and only the information each needs to do its job:
- Supabase — our database and authentication provider. Hosts essentially all account and workspace data described above, and sends transactional account emails.
- Google — provides the Gemini AI models described above, and Google Sign-In if you choose to authenticate with your Google account.
- SendGrid — only if you opt into forwarded-email employer-reply detection, receives the emails you forward to your personal Rolestead inbound address so we can parse and store them.
- Apify— only if you configure the optional Wellfound job-source integration, receives the job-board search URL you provide so it can fetch that board's public listings on our behalf. It does not receive your account, resume, or any other personal information.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, or property of Rolestead or our users. We do not sell your information to anyone, and sharing with the service providers above is not a sale — see the next section.
Sale of Personal Data
Rolestead does not sell personal data.
Chrome Web Store Limited Use
Rolestead's use of information obtained through the Chrome extension adheres to the Chrome Web Store User Data Policy's Limited Use requirements: that data is used only to provide or improve the extension's user-facing functionality — saving jobs, scoring matches, generating materials, and autofilling applications. It is not sold, not used for advertising, not used to determine creditworthiness or for lending purposes, and not transferred for any purpose unrelated to operating that functionality, except to the service providers described above or where required by law.
Cookies and Similar Technologies
The web app uses one essential cookie set: your Supabase authentication session, which keeps you signed in and is required for the app to function. We do not use analytics, advertising, or tracking cookies, and the site has no cookie-consent banner because it sets no non-essential cookies.
Data Retention
We retain your account and workspace data for as long as your account is active, plus any additional time needed to comply with legal obligations, resolve disputes, and enforce our agreements. Removing an individual item (dismissing a job, deleting a persona, an application, an interview, a tracked source, or revoking an API token) removes or deactivates that item going forward, per the controls described in Data Deletion below. Deleting your account, as described next, removes your data outright rather than retaining it further.
Data Deletion
You can delete most things you create in Rolestead directly from the product — jobs, applications, personas, resume versions, interviews, tracked sources, and API tokens all have a delete or revoke action where they're managed.
To delete your entire account, go to Accountin Rolestead and use the “Delete account” control at the bottom of the page. This permanently and immediately deletes your account and every piece of data tied to it — jobs, applications, personas, resume/profile content, interviews, API tokens, and forwarded-email history — and cannot be undone. If you can't access your account, email deimdevelop@gmail.com and we will delete it for you.
Data Security
We use industry-standard measures appropriate to the data we hold: connections to Rolestead are encrypted in transit over HTTPS, your workspace data is isolated at the database level so it's only accessible to your own account, the extension's API tokens are stored as one-way hashes (never the raw token, and never shown again after creation) and can be revoked instantly, and the extension itself requests the minimum Chrome permissions its features need. No system is completely secure, and we cannot guarantee absolute security of your information.
International Data Transfers
Our service providers — Supabase and Google — operate infrastructure that may process or store data outside your own country, including in the United States. By using Rolestead, you understand that your information may be transferred to and processed in countries other than the one in which you live.
Your Privacy Rights
Wherever you're located, you can ask us to access, correct, or delete your personal data, or object to or restrict certain processing. Many of these are self-service in the product (see Data Deletion above); for anything else, email deimdevelop@gmail.com. Depending on where you live, you may have additional rights under local law, and we'll do our best to honor requests consistent with those laws.
Children's Privacy
Rolestead is a tool for job seekers and is not directed to, or intended for use by, children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at deimdevelop@gmail.com and we will delete it.
Changes to This Policy
We may update this policy as Rolestead's features change. If we make a material change, we'll update the “Last updated” date at the top of this page; we don't currently send a separate notification when this policy changes, so check back here periodically.
Contact
Questions about this policy, or a privacy request of any kind, can go to deimdevelop@gmail.com.