Your Career Data is Confidential.

At Careertile, we treat your professional journey with the same level of security as high-stakes industry data. We do not sell your data, we do not use your resumes for training public models, and we prioritize your ownership of everything you build.

1. Data Collection

We collect the information you explicitly provide: resume content, contact details, and account preferences. This data is used solely to facilitate the features of the Careertile Studio, such as the 9-Step Wizard and AI Cover Letter Generator.

2. AI Processing

Our AI features (powered by Groq) process your resume data in a secure environment. Your data is not permanently stored by our AI partners for their model training purposes.

3. Regional Intelligence (GDPR)

For users in the DACH region and EU, we adhere to GDPR standards. You have the right to export or delete your data at any time via the Dashboard.

4. Security

We use Supabase for secure data persistence with Row-Level Security (RLS), ensuring that only you can access your career roadmap.

5. Banned User Data Retention Policy

Accounts banned for abuse or chargebacks will enter a 30-day quarantine. You will retain read-only access to download your existing data for 30 days to comply with GDPR data portability requirements. On Day 30, all your data is permanently hard-deleted, except for minimal identifiers (e.g., email address) which are retained under "Legitimate Interest" strictly to prevent future service abuse.

6. EU AI Act & B2C Status

Careertile operates strictly as a Business-to-Consumer (B2C) platform providing General Purpose AI (GPAI) text-generation assistance. We do not engage in automated biometric identification, emotion recognition, or High-Risk candidate profiling.

7. Infrastructure & Sub-processors

All user data is processed entirely within the European Union to ensure strict GDPR and EU AI Act compliance. Our infrastructure is hosted on Oracle Cloud Infrastructure (OCI) in the Madrid (eu-madrid-3) region, and our database is hosted on Supabase in the Ireland (eu-west-1) region. We utilize Groq as our enterprise AI inference sub-processor under a strict zero-data-retention policy.

8. AI Data Retention

Temporary AI generation usage logs are deleted after 30 days. However, cryptographically hashed audit trails containing no personally identifiable payload data are retained for 6 months strictly to comply with EU AI Act Article 12 regulatory record-keeping requirements.