Privacy Policy

Last updated: July 23, 2026

Este documento se ofrece únicamente en inglés; la versión en inglés es el texto legalmente vinculante.

1. Who we are

RoleRamp is operated by Corvidae Limited (New Zealand) ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use our website and services (the "Service").

This policy is written for a global English-speaking audience. Because we are based in New Zealand, we align our practices with the New Zealand Privacy Act 2020 and the Privacy Principles.

2. What we collect

2.1 Information you provide

We collect information you provide directly when you use the Service:

  • Account details: Name, email address, and (if you sign in with a social account) authentication via Google or Microsoft. You can also register with an email address and password.
  • CV/resume content: Work experience, education, skills, projects, and other professional information you choose to input
  • Uploaded files: If you upload an existing CV (PDF, image, or Word document), we store a copy of that file and extract its text so we can populate your CV (see section 4). Uploaded files are automatically scanned for malware before we process them further.
  • Referee information: Names, contact details, and professional relationships of referees you add to your CV (stored securely and excluded from AI processing by default)
  • Job information: Job descriptions and notes you add for roles you are targeting
  • Inbound emails (Job Inbox): If you use the Job Inbox feature, you can forward job-alert emails (for example, from LinkedIn or SEEK) to a private RoleRamp forwarding address we generate for your account. When you do, we receive and process the sender's email address, the subject line, and the body content of each forwarded message so we can extract individual job postings for your Inbox, or, if the message is personal correspondence from a recruiter you have already saved as a contact, so we can file it to that recruiter's timeline instead (see section 4). Because forwarding is under your control (or your email provider's auto-forward rule), a forwarded or misdirected email may incidentally include personal information about other people, for example another person's name, email address, or earlier messages included in a forwarded email chain. We process that incidental information only as part of handling the email you forwarded; we do not use it for any other purpose, and we do not use the Job Inbox feature to build a profile of anyone other than you. You are responsible for only forwarding emails to your RoleRamp address in a manner consistent with your own email provider's terms and any applicable law.
  • Recruiter contacts (optional): Name, agency, email, phone number, and notes for recruiters you choose to save in your personal address book. We use this information only to provide the address-book feature to you; we do not share it with the recruiters themselves, use it for outreach on your behalf, or disclose it to anyone else.
  • Call recordings (optional): If you record a job-search call (for example, with a recruiter or interviewer) and upload it to a job's activity timeline, we store the audio file, transcribe it, and may generate AI coaching feedback from the transcript (see section 4). You are solely responsible for ensuring you have any consent required by law in your jurisdiction before recording or uploading a call.
  • Contact details (optional): Phone number, location/address, and profile links you choose to store
  • Payment information: If you purchase a paid plan, your payment is processed by Stripe. We receive limited billing details (such as your plan, subscription status, and the last four digits of your card) but we do not store your full card number
  • Communications: Messages you send via contact forms or support channels

2.2 Information collected automatically

  • Usage Data: Pages visited, features used, time spent on the platform
  • Device Information: IP address, browser type, operating system
  • Cookies and similar technologies: See section 10

2.3 Sensitive information

Please avoid entering sensitive information (for example: health information, biometrics, or government identifiers) unless it is necessary for your CV and you are comfortable doing so. If you include this information, you consent to us processing it to provide the Service.

3. How we use your information

We use personal information to operate, maintain, and improve the Service, including to:

  • Provide, maintain, and improve our CV tailoring and application tracking services
  • Generate role-specific CV suggestions based on your CV content and job descriptions
  • Personalize your experience and preserve your preferred writing style
  • Process your applications and track their status
  • Send you service updates, notifications, and support messages
  • Respond to your inquiries and provide customer support
  • Analyze usage patterns to improve our services
  • Detect, prevent, and address technical issues or fraudulent activity
  • Comply with legal obligations

Where required by applicable law, we will obtain your consent for certain processing (for example, non-essential cookies) and you can withdraw consent at any time.

4. AI and document processing

The Service uses AI features powered by Amazon Bedrock. Most AI features — tailoring CV wording, parsing uploaded CVs into structured sections, and generating suggestions — run on Anthropic's Claude models. Some features, currently the AI call-feedback coach described below, run on OpenAI's GPT-series models, which are also served through Amazon Bedrock rather than directly through OpenAI. When you choose to use these features, you are asking us to process certain content you provide.

  • Document text extraction: When you upload a CV as a PDF or image, we use Amazon Textract to extract the text from the file. Word documents are read directly. The extracted text is then processed by Amazon Bedrock to structure your CV
  • Malware scanning: Files you upload are automatically scanned for malware before we process them further
  • You choose what gets sent: Only the content needed for the drafting action you request is submitted for AI processing
  • PII minimisation: We aim to exclude obvious contact details and referee details from AI prompts where feasible
  • Bedrock processing: Your selected content is sent to Amazon Bedrock for processing, whichever model provider handles the request. Amazon Web Services' Bedrock terms mean that neither AWS nor the underlying model provider (Anthropic or OpenAI) uses content submitted through Bedrock to train their models, and that content is not retained by the model provider after your request is processed
  • Call recording transcription: If you upload a call recording, the audio file is stored in Amazon S3 in Sydney, Australia, and transcribed using Whisper, a speech-to-text model we run ourselves on our own servers — the audio is not sent to any external transcription provider. The resulting transcript may then be processed by AI (including the OpenAI models described above, processed in the United States) to generate coaching feedback for you. You are solely responsible for ensuring you have any consent required by law before recording or uploading a call — see section 2.1
  • Job Inbox email parsing: If you use the Job Inbox feature, the text content of emails you forward to your RoleRamp address is processed by Amazon Bedrock to identify and extract individual job postings (title, company, location, and similar details) for display in your Inbox. The same Bedrock protections described above apply: content is not used to train the underlying models and is not retained by the model provider after your request is processed. We do not use inbound email content for any purpose other than extracting job postings for you.
  • Recruiter correspondence filing: If a forwarded email is personal correspondence from a recruiter contact you have already saved in your Recruiters section, rather than a job alert, we file it automatically to that recruiter's timeline in your account instead of adding it to your Inbox. The email content is processed by Amazon Bedrock to classify it as correspondence and to generate a short title and summary of it. The same Bedrock protections described above apply: this content is not used to train the underlying models. See section 8 for how long we keep the raw email and the resulting timeline entry.
  • Referee protection: Referee names and contact details are excluded from AI processing by default to protect their privacy
  • No training on your content: We do not use your personal information to train our own models
  • Human review: You review and approve all AI-generated suggestions before you export or use them

Important: AI output can be inaccurate or inappropriate. You are responsible for verifying content, ensuring it is truthful, and deciding what you submit to employers.

5. Browser extension

We offer an optional Chrome (and Chromium-based browser) extension, "RoleRamp — Save Jobs", that lets you save a job posting you are viewing into your RoleRamp account. The extension is deliberately narrow in scope:

  • Only when you click "Save": The extension reads the current tab's title, address (URL), and visible page text only at the moment you click Save in its popup. It does not run in the background and does not monitor, record, or track the pages you browse or your browsing history.
  • Website content: The job posting you save (its text, title, and URL) is sent to our servers to create a Saved Job you can review and tailor a CV against. A saved posting may incidentally contain personal information about other people (for example a recruiter's name); we process it only as part of that saved job.
  • Authentication information: The extension uses your existing signed-in RoleRamp session by reading your RoleRamp session cookie on roleramp.com and sending it to authenticate its requests. It stores no separate password or credential of its own, and signing out of RoleRamp immediately revokes its access.
  • Account email: The extension may retrieve your account email address from our API to show which account you are signed in to. It is displayed to you in the popup and is not shared with anyone else.
  • First-party only: The extension communicates only with RoleRamp's own services (roleramp.com). It does not send your data to any third party, does not sell or transfer your data, and is used solely for the Saved Jobs feature described here.
  • Your control: You can remove saved jobs at any time in your account, and you can disable or uninstall the extension from your browser at any time.

The browser permissions the extension requests (access to the active tab on click, script injection to read that page, cookie access on roleramp.com, and network access to roleramp.com) exist only to provide this save-a-job functionality.

6. When we share information

We do not sell your personal information. We may disclose personal information only in the situations below:

  • With Your Consent: When you explicitly authorize us to share information
  • Service providers: We work with trusted third-party service providers including:
    • Amazon Web Services (AWS) - Hosting, database, and file storage (Amazon S3)
    • Amazon Bedrock - AI processing for CV tailoring, parsing, and call-feedback coaching, using Anthropic Claude models and, for some features (currently the AI call-feedback coach), OpenAI GPT-series models
    • Amazon Textract - Text extraction from uploaded CV files
    • Amazon SES - Sending account, verification, and notification emails
    • Stripe - Payment processing for paid plans
    • Cloudflare Turnstile - Bot and abuse protection on sign-up and sign-in
    • Google (Google Analytics and Google OAuth sign-in)
    • Microsoft (Microsoft OAuth sign-in and Microsoft Clarity analytics)
    All service providers are bound by confidentiality and security obligations.
  • Legal Requirements: When required by law, court order, or governmental authority
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
  • Protection: To protect our rights, property, or safety, or that of our users

Data location: We host the Service on Amazon Web Services (AWS) in the Asia-Pacific region. Your account, CV, and application data, along with uploaded CV files (Amazon S3), document text extraction (Amazon Textract), call recording storage and transcription (self-hosted Whisper), forwarded Job Inbox emails and their extraction results (Amazon S3), and outgoing email (Amazon SES), are processed in Sydney, Australia. AI processing on Amazon Bedrock using Anthropic Claude models is carried out in Auckland, New Zealand. For some features — currently the AI call-feedback coach — Amazon Bedrock routes processing to OpenAI GPT-series models hosted in the United States (us-east-1). Some other providers operate outside Australia and New Zealand (for example, Stripe, Google, and Microsoft process data in the United States and other regions). When we disclose personal information overseas, we take reasonable steps to ensure it is protected in a manner consistent with this policy and applicable laws.

7. Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Secure data centers with physical security measures
  • Employee training on data protection

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy. You can delete your account and data at any time through your account settings. After deletion, we may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).

Job Inbox emails: Raw forwarded email messages (including attachments, which we do not currently process) are stored in Amazon S3 in Sydney, Australia, for 90 days, after which they are automatically and permanently deleted. We keep metadata about processed emails, for example when an email was received, its processing status, and the job postings extracted from it, for as long as your account remains active, or until you delete the associated Inbox items yourself. If you delete your account, delete an Inbox item, or disable or regenerate your forwarding address, we make best efforts to promptly delete the associated stored email content ahead of the 90-day window.

Recruiter correspondence filing: When a forwarded email is filed to a recruiter's timeline rather than extracted as a job posting (see section 4), the same 90-day raw email retention described above applies. The resulting timeline entry itself is not deleted after 90 days: it remains in your account until you edit or delete it yourself, and deleting your account deletes it.

9. Your rights

Depending on where you live, privacy laws may give you rights in relation to your personal information. In New Zealand, you generally have the right to request access to and correction of your personal information.

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Receive your data in a structured, commonly used format
  • Opt-Out: Unsubscribe from marketing communications
  • Object: Object to certain processing activities
  • Withdraw Consent: Where processing is based on consent

To exercise these rights, contact us at [email protected].

If you are not satisfied with our response, you may be able to complain to your local data protection authority. In New Zealand, this is the Office of the Privacy Commissioner.

10. Cookies and analytics

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for the platform to function, including authentication and session management
  • Analytics (Google Analytics): We use Google Analytics to understand how users interact with our Service. It collects information such as page views, session duration, and user behavior. IP addresses are anonymized.
  • Analytics (Microsoft Clarity): We use Microsoft Clarity to capture aggregated usage analytics such as heatmaps and session recordings of how visitors interact with our pages. This helps us improve usability. Clarity may mask page content where configured.
  • Authentication Cookies: When you sign in via Google or Microsoft, or with your email and password, authentication tokens are stored to maintain your session
  • Bot protection (Cloudflare Turnstile): We use Cloudflare Turnstile on sign-up and sign-in to detect automated abuse; it may set tokens needed to verify the request
  • Preference Cookies: Remember your settings and preferences

If you visit from the European Economic Area or the United Kingdom, we ask for your consent before setting non-essential (analytics and advertising) cookies, and they remain disabled until you agree. We use Google Consent Mode so these technologies are withheld until consent. You can change or withdraw your choice at any time using the "Cookie settings" link in the footer.

You can also control cookies through your browser settings and opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on. However, disabling essential cookies may affect functionality.

11. International users

If you access the Service from outside New Zealand, you understand that your information may be processed in New Zealand and in other jurisdictions where our service providers operate. We take reasonable steps to protect information transferred internationally.

12. Children's privacy

Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

13. ChatGPT and AI assistant integrations

RoleRamp offers an optional integration that lets you connect your RoleRamp account to ChatGPT, Claude, and other AI assistants that support the Model Context Protocol (MCP), through a server we operate at api.roleramp.com/mcp. This section explains how that integration handles personal information. It supplements, and does not replace, the rest of this Privacy Policy.

  • You choose to connect it: The integration is off until you explicitly connect it from within the AI assistant or from RoleRamp's Settings page. We do not enable it on your behalf.
  • OAuth account linking: Connecting uses the OAuth standard with a consent screen we host. You sign in with your existing RoleRamp account and approve the specific access requested. RoleRamp never sees your AI assistant's credentials, and the AI assistant never sees your RoleRamp password.
  • Data categories processed: Depending on what you ask the assistant to do, the integration can read or update your profile and CV content, saved jobs, applications, generated CV and cover letter drafts, referees, and recruiter contacts, in the same way you could through the RoleRamp website. See sections 2 and 3 above for what each category is and why we process it.
  • Task-relevant data only: We return only the data needed to answer the specific request the assistant made, not your full account in one response. Full contact details, referee information, and dates of birth are left out unless the request specifically needs them.
  • No chat history access: We do not receive or store your conversation history with the AI assistant. We only receive the specific inputs a tool call sends us and the data we return in response.
  • Disconnecting: You can disconnect at any time from RoleRamp's Settings > Connected AI apps, or from the AI assistant's own connector settings. Disconnecting revokes the connection's access immediately.
  • Disconnecting does not delete your account: Removing the connection does not delete your RoleRamp account or any data in it. Your saved jobs, applications, CV, and drafts remain exactly as they were; the AI assistant simply loses access until you reconnect.

Drafts, not outcomes: Any CV or cover letter content the integration generates is a draft for your review, in the same way as CV drafts generated on the website (see section 4). RoleRamp does not guarantee interviews, offers, employment, or salary outcomes, and you remain responsible for the accuracy of information in your account. The integration must not be used to fabricate qualifications, work history, identity, location, work rights, or certifications, and requests to do so are declined. The integration does not submit applications to employers or third-party sites; creating an application record in RoleRamp is a private tracking entry only.

Do not submit passwords, API keys, authentication codes, payment-card details, government identifiers, or protected health information through this integration.

For more detail, see Using RoleRamp with ChatGPT.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of our services after changes indicates acceptance of the updated policy.

15. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Corvidae Limited (RoleRamp)

Email: [email protected]

Contact Form: Contact Us