Career Story LogoCareer Story
Back to HomeDoc: privacy-policy
Legal & Governance

Career Story Privacy Policy

Effective Date: September 5, 2026

Career Story Privacy Policy

Last Updated: September 5, 2026

This Privacy Policy explains how Career Story ("Career Story," "we," "us," or "our") collects, uses, stores, and discloses information when you use our website, applications, and services (collectively, the "Service").

We designed Career Story to help individuals organize their careers, analyze job opportunities, create resumes and cover letters, and manage job applications with calm, security, and predictability.

1. Information We Collect

A. Account and Identity Information

When you create or manage an account, we may collect:

  • Full name
  • Email address
  • User ID (user_id)
  • Authentication provider (email vs. google)
  • Email-verification status
  • Password-related security hashes (plain text passwords are never stored)
  • Login and account-security timestamps
  • Account status

Google OAuth Sign-In: If you authenticate through Google, we receive information made available through Google's OAuth flow, such as your Google user ID, verified email address, profile name, and profile picture URL.

Temporary verification information, such as OTP codes and related timestamps, is processed for account verification and authentication and is deleted after verification.

B. Career and Professional Information (Master Career Profile)

Career Story allows you to build an immutable Master Career Profile. Depending on what you choose to provide, this may include:

  • Contact Details: Phone number, city, state, country, profile photo.
  • Professional Overview: Headline, current role title, career summary bio, career stage, total years of experience.
  • Social & Web Links: Portfolio, LinkedIn, GitHub, X/Twitter, LeetCode, Medium, and custom links.
  • Work History: Companies/organizations, job titles, employment types (full-time, internship, freelance, contract, consulting, research, volunteer), work locations, employment dates, achievement bullets, skills used.
  • Projects: Project names, project types (personal, academic, open-source, hackathon, client, startup, research), organizations, dates, URLs, achievement bullets, associated skills.
  • Education: Institution names, degrees, fields of study, dates, locations, grades/GPA, achievements, skills.
  • Certifications & Publications: Certification names, issuing organizations, issue/expiration dates, credential URLs, publication titles, publishers, URLs.
  • Career Preferences: Target roles, target industries, preferred locations, and work arrangement preferences (remote, hybrid, onsite, flexible).

C. Job Search and Application Information

When you analyze or track a job, we process:

  • Raw job description text (rawJDText), job title, company name, job URL, job location, target salary range.
  • Extracted ATS target keywords (high, medium, and low priority), qualification requirements, and skill matrices.
  • Application status (Saved, Applied, Interviewing, Offer, Rejected, Archived), application dates, stage history, notes, linked resume snapshot ID, and linked cover letter ID.

D. Resumes and Cover Letters

When you create or tailor application materials, we process:

  • Resumes: Resume titles, resume type (base vs. job-tailored snapshot), target company & role, selected career-profile entries, modified achievement bullets, resume styling preferences (template, font, size, line height, primary color), and calculated ATS match scores.
  • Cover Letters: Cover letter titles, company and role information, custom user instructions, generated cover letter content, and tone preferences (professional, enthusiastic, executive, concise, creative).

E. Technical and Usage Information

We automatically collect standard technical information necessary for operating and securing Career Story:

  • IP address (used for rate limiting and security)
  • Browser type and operating system details (contained in the User-Agent header)
  • Login session information
  • Product telemetry events (e.g., homepage_view, signup_started, signup_completed, job_analyzed) to measure feature usage and improve user experience.

F. Preferences and Local Storage

  • User Preferences: Theme preference (light, dark, system), notification preferences, product updates, default template selections.
  • Browser Local Storage & HTTP-Only Cookies: Authentication session tokens are maintained securely via HTTP-Only cookies or browser LocalStorage. Transient app state (e.g., active tabs, modal toggles) may be stored in browser LocalStorage.

2. How We Use Information

We process your information for the following specific purposes:

  • Providing & Operating the Service: To create and manage your account, store your Master Career Profile, analyze job descriptions, extract ATS keywords, generate/tailor resumes and cover letters, and maintain application snapshots.
  • AI-Powered Processing: Relevant job descriptions, career profile sections, or custom instructions are transmitted securely to enterprise AI providers (OpenAI, Google Gemini, Anthropic) solely to generate the requested output.
  • Security & Fraud Prevention: IP addresses and session logs are used to secure accounts, enforce rate limits, detect abuse, and prevent unauthorized access.
  • Analytics & Improvements: Usage telemetry is analyzed to improve product features, resolve user experience friction, and optimize system performance.
  • Communications: Contact information is used to send transactional notices, security alerts, password resets, and account updates.

3. How We Share Information

We DO NOT sell your personal information, resumes, or career history to recruiters, data brokers, or third parties.

We may disclose information strictly to the following categories of service providers:

  • Infrastructure & Hosting: Cloud databases, hosting platforms, and security monitoring vendors.
  • AI Processing Providers: OpenAI, Google Gemini, and Anthropic for real-time AI deconstruction and text generation.
  • Legal Compliance: Where required by law, subpoena, court order, or to protect the safety and security of Career Story users.

4. AI Provider Privacy & Data Training Policies

Career Story uses enterprise/API access for AI service providers (OpenAI, Google Gemini, Anthropic). Under these enterprise terms:

  • No Public AI Training: Your private career data, resumes, and job details sent via API calls are NOT used to train or refine public AI models.
  • Data Isolation: Information transmitted is processed strictly in real-time to generate your requested resume or cover letter output.

5. Data Isolation & Candidate Authority

Career Story is designed so that your Master Career Profile remains immutable and separate from your application snapshots:

  • Snapshot Autonomy: Editing a resume or cover letter for a specific job application modifies that application snapshot only.
  • Master Profile Safety: Application edits will never overwrite your core Master Career Profile unless you explicitly choose to update your base profile.

6. Data Security & Retention

  • Security Measures: We implement industry-standard encryption, password hashing (bcrypt/Argon2), secure HTTPS/TLS data transmission, strict authentication checks, and rate-limiting controls.
  • Retention: We retain personal information for as long as your account remains active. Upon account deletion, we purge your career profile, resumes, cover letters, and application records from active databases.

7. Your Privacy Rights

Depending on your jurisdiction, you have the right to:

  • Access, review, or request a copy of your personal data.
  • Correct or update any incomplete or inaccurate career records.
  • Delete your account and associated career data at any time.
  • Export your resumes, cover letters, and Master Profile records.

8. Contact Us

If you have any questions or concerns regarding this Privacy Policy or your data, please contact us through the support channel on the Career Story website.