Privacy Policy
Last updated: July 23, 2026
Dieses Dokument wird nur auf Englisch bereitgestellt; die englische Fassung ist der rechtlich bindende Text.
1. Who we are
RoleRamp is operated by Corvidae Limited (New Zealand)
("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, store, and
protect personal information when you use our website and services (the "Service").
This policy is written for a global English-speaking audience. Because we are based in New
Zealand, we align our practices with the New Zealand Privacy Act 2020
and the Privacy Principles.
2. What we collect
2.1 Information you provide
We collect information you provide directly when you use the Service:
- Account details: Name, email address, and (if you sign in with a social account) authentication via Google or Microsoft. You can also register with an email address and password.
- CV/resume content: Work experience, education, skills, projects, and other professional information you choose to input
- Uploaded files: If you upload an existing CV (PDF, image, or Word document), we store a copy of that file and extract its text so we can populate your CV (see section 4). Uploaded files are automatically scanned for malware before we process them further.
- Referee information: Names, contact details, and professional relationships of referees you add to your CV (stored securely and excluded from AI processing by default)
- Job information: Job descriptions and notes you add for roles you are targeting
- Inbound emails (Job Inbox): If you use the Job Inbox feature, you can forward job-alert emails (for example, from LinkedIn or SEEK) to a private RoleRamp forwarding address we generate for your account. When you do, we receive and process the sender's email address, the subject line, and the body content of each forwarded message so we can extract individual job postings for your Inbox, or, if the message is personal correspondence from a recruiter you have already saved as a contact, so we can file it to that recruiter's timeline instead (see section 4). Because forwarding is under your control (or your email provider's auto-forward rule), a forwarded or misdirected email may incidentally include personal information about other people, for example another person's name, email address, or earlier messages included in a forwarded email chain. We process that incidental information only as part of handling the email you forwarded; we do not use it for any other purpose, and we do not use the Job Inbox feature to build a profile of anyone other than you. You are responsible for only forwarding emails to your RoleRamp address in a manner consistent with your own email provider's terms and any applicable law.
- Recruiter contacts (optional): Name, agency, email, phone number, and notes for recruiters you choose to save in your personal address book. We use this information only to provide the address-book feature to you; we do not share it with the recruiters themselves, use it for outreach on your behalf, or disclose it to anyone else.
- Call recordings (optional): If you record a job-search call (for example, with a recruiter or interviewer) and upload it to a job's activity timeline, we store the audio file, transcribe it, and may generate AI coaching feedback from the transcript (see section 4). You are solely responsible for ensuring you have any consent required by law in your jurisdiction before recording or uploading a call.
- Contact details (optional): Phone number, location/address, and profile links you choose to store
- Payment information: If you purchase a paid plan, your payment is processed by Stripe. We receive limited billing details (such as your plan, subscription status, and the last four digits of your card) but we do not store your full card number
- Communications: Messages you send via contact forms or support channels
2.2 Information collected automatically
- Usage Data: Pages visited, features used, time spent on the platform
- Device Information: IP address, browser type, operating system
- Cookies and similar technologies: See section 10
2.3 Sensitive information
Please avoid entering sensitive information (for example: health information, biometrics, or
government identifiers) unless it is necessary for your CV and you are comfortable doing so.
If you include this information, you consent to us processing it to provide the Service.
3. How we use your information
We use personal information to operate, maintain, and improve the Service, including to:
- Provide, maintain, and improve our CV tailoring and application tracking services
- Generate role-specific CV suggestions based on your CV content and job descriptions
- Personalize your experience and preserve your preferred writing style
- Process your applications and track their status
- Send you service updates, notifications, and support messages
- Respond to your inquiries and provide customer support
- Analyze usage patterns to improve our services
- Detect, prevent, and address technical issues or fraudulent activity
- Comply with legal obligations
Where required by applicable law, we will obtain your consent for certain processing (for
example, non-essential cookies) and you can withdraw consent at any time.
4. AI and document processing
The Service uses AI features powered by Amazon Bedrock. Most AI
features — tailoring CV wording, parsing uploaded CVs into structured sections, and generating
suggestions — run on Anthropic's Claude models. Some features,
currently the AI call-feedback coach described below, run on
OpenAI's GPT-series models, which are also served through Amazon
Bedrock rather than directly through OpenAI. When you choose to use these features, you are asking us
to process certain content you provide.
- Document text extraction: When you upload a CV as a PDF or image, we use Amazon Textract to extract the text from the file. Word documents are read directly. The extracted text is then processed by Amazon Bedrock to structure your CV
- Malware scanning: Files you upload are automatically scanned for malware before we process them further
- You choose what gets sent: Only the content needed for the drafting action you request is submitted for AI processing
- PII minimisation: We aim to exclude obvious contact details and referee details from AI prompts where feasible
- Bedrock processing: Your selected content is sent to Amazon Bedrock for processing, whichever model provider handles the request. Amazon Web Services' Bedrock terms mean that neither AWS nor the underlying model provider (Anthropic or OpenAI) uses content submitted through Bedrock to train their models, and that content is not retained by the model provider after your request is processed
- Call recording transcription: If you upload a call recording, the audio file is stored in Amazon S3 in Sydney, Australia, and transcribed using Whisper, a speech-to-text model we run ourselves on our own servers — the audio is not sent to any external transcription provider. The resulting transcript may then be processed by AI (including the OpenAI models described above, processed in the United States) to generate coaching feedback for you. You are solely responsible for ensuring you have any consent required by law before recording or uploading a call — see section 2.1
- Job Inbox email parsing: If you use the Job Inbox feature, the text content of emails you forward to your RoleRamp address is processed by Amazon Bedrock to identify and extract individual job postings (title, company, location, and similar details) for display in your Inbox. The same Bedrock protections described above apply: content is not used to train the underlying models and is not retained by the model provider after your request is processed. We do not use inbound email content for any purpose other than extracting job postings for you.
- Recruiter correspondence filing: If a forwarded email is personal correspondence from a recruiter contact you have already saved in your Recruiters section, rather than a job alert, we file it automatically to that recruiter's timeline in your account instead of adding it to your Inbox. The email content is processed by Amazon Bedrock to classify it as correspondence and to generate a short title and summary of it. The same Bedrock protections described above apply: this content is not used to train the underlying models. See section 8 for how long we keep the raw email and the resulting timeline entry.
- Referee protection: Referee names and contact details are excluded from AI processing by default to protect their privacy
- No training on your content: We do not use your personal information to train our own models
- Human review: You review and approve all AI-generated suggestions before you export or use them
Important: AI output can be inaccurate or inappropriate. You are responsible for verifying
content, ensuring it is truthful, and deciding what you submit to employers.
5. Browser extension
We offer an optional Chrome (and Chromium-based browser) extension,
"RoleRamp — Save Jobs", that lets you save a job posting
you are viewing into your RoleRamp account. The extension is deliberately narrow in scope:
- Only when you click "Save": The extension reads the current tab's title, address (URL), and visible page text only at the moment you click Save in its popup. It does not run in the background and does not monitor, record, or track the pages you browse or your browsing history.
- Website content: The job posting you save (its text, title, and URL) is sent to our servers to create a Saved Job you can review and tailor a CV against. A saved posting may incidentally contain personal information about other people (for example a recruiter's name); we process it only as part of that saved job.
- Authentication information: The extension uses your existing signed-in RoleRamp session by reading your RoleRamp session cookie on roleramp.com and sending it to authenticate its requests. It stores no separate password or credential of its own, and signing out of RoleRamp immediately revokes its access.
- Account email: The extension may retrieve your account email address from our API to show which account you are signed in to. It is displayed to you in the popup and is not shared with anyone else.
- First-party only: The extension communicates only with RoleRamp's own services (roleramp.com). It does not send your data to any third party, does not sell or transfer your data, and is used solely for the Saved Jobs feature described here.
- Your control: You can remove saved jobs at any time in your account, and you can disable or uninstall the extension from your browser at any time.
The browser permissions the extension requests (access to the active tab on click, script
injection to read that page, cookie access on roleramp.com, and network access to roleramp.com)
exist only to provide this save-a-job functionality.
6. When we share information
We do not sell your personal information. We may disclose personal information only in the
situations below:
- With Your Consent: When you explicitly authorize us to share information
- Service providers: We work with trusted third-party service providers including:
- Amazon Web Services (AWS) - Hosting, database, and file storage (Amazon S3)
- Amazon Bedrock - AI processing for CV tailoring, parsing, and call-feedback coaching, using Anthropic Claude models and, for some features (currently the AI call-feedback coach), OpenAI GPT-series models
- Amazon Textract - Text extraction from uploaded CV files
- Amazon SES - Sending account, verification, and notification emails
- Stripe - Payment processing for paid plans
- Cloudflare Turnstile - Bot and abuse protection on sign-up and sign-in
- Google (Google Analytics and Google OAuth sign-in)
- Microsoft (Microsoft OAuth sign-in and Microsoft Clarity analytics)
All service providers are bound by confidentiality and security obligations.
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
- Protection: To protect our rights, property, or safety, or that of our users
Data location: We host the Service on Amazon Web Services (AWS) in the
Asia-Pacific region. Your account, CV, and application data, along with uploaded CV files (Amazon S3),
document text extraction (Amazon Textract), call recording storage and transcription (self-hosted
Whisper), forwarded Job Inbox emails and their extraction results (Amazon S3), and outgoing email
(Amazon SES), are processed in
Sydney, Australia. AI processing on Amazon Bedrock using Anthropic
Claude models is carried out in Auckland, New Zealand. For some
features — currently the AI call-feedback coach — Amazon Bedrock routes processing to
OpenAI GPT-series models hosted in the United States (us-east-1).
Some other providers operate outside Australia and New Zealand (for example, Stripe, Google, and
Microsoft process data in the United States and other regions). When we disclose personal information
overseas, we take reasonable steps to ensure it is protected in a manner consistent with this policy and
applicable laws.
7. Security
We implement appropriate technical and organizational measures to protect your personal
information:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication requirements
- Secure data centers with physical security measures
- Employee training on data protection
However, no method of transmission over the Internet is 100% secure. While we strive to
protect your information, we cannot guarantee absolute security.
8. Retention
We retain your personal information for as long as necessary to provide our services and
fulfill the purposes described in this policy. You can delete your account and data at any
time through your account settings. After deletion, we may retain certain information as
required by law or for legitimate business purposes (e.g., fraud prevention, legal
compliance).
Job Inbox emails: Raw forwarded email messages (including
attachments, which we do not currently process) are stored in Amazon S3 in Sydney, Australia, for
90 days, after which they are automatically and permanently
deleted. We keep metadata about processed emails, for example when an email was received, its
processing status, and the job postings extracted from it, for as long as your account remains
active, or until you delete the associated Inbox items yourself. If you delete your account,
delete an Inbox item, or disable or regenerate your forwarding address, we make best efforts to
promptly delete the associated stored email content ahead of the 90-day window.
Recruiter correspondence filing: When a forwarded email is
filed to a recruiter's timeline rather than extracted as a job posting (see section 4), the same
90-day raw email retention described above applies. The resulting timeline entry itself is not
deleted after 90 days: it remains in your account until you edit or delete it yourself, and
deleting your account deletes it.
9. Your rights
Depending on where you live, privacy laws may give you rights in relation to your personal
information. In New Zealand, you generally have the right to request access to and
correction of your personal information.
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Receive your data in a structured, commonly used format
- Opt-Out: Unsubscribe from marketing communications
- Object: Object to certain processing activities
- Withdraw Consent: Where processing is based on consent
To exercise these rights, contact us at
[email protected].
If you are not satisfied with our response, you may be able to complain to your local data
protection authority. In New Zealand, this is the Office of the Privacy Commissioner.
10. Cookies and analytics
We use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for the platform to function, including authentication and session management
- Analytics (Google Analytics): We use Google Analytics to understand how users interact with our Service. It collects information such as page views, session duration, and user behavior. IP addresses are anonymized.
- Analytics (Microsoft Clarity): We use Microsoft Clarity to capture aggregated usage analytics such as heatmaps and session recordings of how visitors interact with our pages. This helps us improve usability. Clarity may mask page content where configured.
- Authentication Cookies: When you sign in via Google or Microsoft, or with your email and password, authentication tokens are stored to maintain your session
- Bot protection (Cloudflare Turnstile): We use Cloudflare Turnstile on sign-up and sign-in to detect automated abuse; it may set tokens needed to verify the request
- Preference Cookies: Remember your settings and preferences
If you visit from the European Economic Area or the United Kingdom, we ask for your consent
before setting non-essential (analytics and advertising) cookies, and they remain disabled
until you agree. We use Google Consent Mode so these technologies are withheld until consent.
You can change or withdraw your choice at any time using the
"Cookie settings" link in the footer.
You can also control cookies through your browser settings and opt out of Google Analytics using the
Google Analytics Opt-out Browser Add-on.
However, disabling essential cookies may affect functionality.
11. International users
If you access the Service from outside New Zealand, you understand that your information may
be processed in New Zealand and in other jurisdictions where our service providers operate.
We take reasonable steps to protect information transferred internationally.
12. Children's privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly
collect personal information from children. If you believe we have collected information
from a child, please contact us immediately.
13. ChatGPT and AI assistant integrations
RoleRamp offers an optional integration that lets you connect your RoleRamp account to ChatGPT,
Claude, and other AI assistants that support the Model Context Protocol (MCP), through a server
we operate at api.roleramp.com/mcp. This section explains
how that integration handles personal information. It supplements, and does not replace, the
rest of this Privacy Policy.
- You choose to connect it: The integration is off until you explicitly connect it from within the AI assistant or from RoleRamp's Settings page. We do not enable it on your behalf.
- OAuth account linking: Connecting uses the OAuth standard with a consent screen we host. You sign in with your existing RoleRamp account and approve the specific access requested. RoleRamp never sees your AI assistant's credentials, and the AI assistant never sees your RoleRamp password.
- Data categories processed: Depending on what you ask the assistant to do, the integration can read or update your profile and CV content, saved jobs, applications, generated CV and cover letter drafts, referees, and recruiter contacts, in the same way you could through the RoleRamp website. See sections 2 and 3 above for what each category is and why we process it.
- Task-relevant data only: We return only the data needed to answer the specific request the assistant made, not your full account in one response. Full contact details, referee information, and dates of birth are left out unless the request specifically needs them.
- No chat history access: We do not receive or store your conversation history with the AI assistant. We only receive the specific inputs a tool call sends us and the data we return in response.
- Disconnecting: You can disconnect at any time from RoleRamp's Settings > Connected AI apps, or from the AI assistant's own connector settings. Disconnecting revokes the connection's access immediately.
- Disconnecting does not delete your account: Removing the connection does not delete your RoleRamp account or any data in it. Your saved jobs, applications, CV, and drafts remain exactly as they were; the AI assistant simply loses access until you reconnect.
Drafts, not outcomes: Any CV or cover letter content the
integration generates is a draft for your review, in the same way as CV drafts generated on the
website (see section 4). RoleRamp does not guarantee interviews, offers, employment, or salary
outcomes, and you remain responsible for the accuracy of information in your account. The
integration must not be used to fabricate qualifications, work history, identity, location,
work rights, or certifications, and requests to do so are declined. The integration does not
submit applications to employers or third-party sites; creating an application record in
RoleRamp is a private tracking entry only.
Do not submit passwords, API keys, authentication codes, payment-card details, government
identifiers, or protected health information through this integration.
For more detail, see Using RoleRamp with ChatGPT.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant
changes by posting the new policy on this page and updating the "Last Updated" date. Your
continued use of our services after changes indicates acceptance of the updated policy.
15. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or our data
practices, please contact us: