Privacy Policy

Last updated: 30 September 2026

In short: This policy explains what personal data CareerVerse collects, why, and the rights you have. We use passwordless sign-in — an emailed one-time code, or "Continue with Google" if you choose it (note that Google's sign-in button loads on our home page, so Google sees your visit even if you never use it — Section 2(a1); and if you create your account that way, we start your profile with the name and photo from your Google Account — Section 2(a2)) — store your content to run the Service, and send some text to a third-party AI provider (OpenAI, etc.) to power AI features. If you sit a mock interview, the audio of your spoken answers is sent to a speech-to-text provider so it can be graded, and the text of each question is sent to a speech-synthesis provider so it can be read aloud — Section 4 sets out exactly who receives what, names the provider that transcribes your voice — which processes it in the European Union — together with the browser fallback that takes over when it cannot run, and is blunt about the one localisation promise we cannot make. We also build a Career Twin for you automatically from work you complete here — it shows the skills on your record and the work behind each, gives each skill a standing that your graded results move, and, against a target you choose, shows how far your record reaches it. We never lower a standing because of results that did not pass without asking you first. Those standings and figures decide nothing and never leave the product — we do not send them to employers or anyone else. You can switch off any source of it at any time in your account settings, which also deletes what we derived from that source (Section 4). We use optional third-party analytics (Microsoft Clarity, Google Analytics, etc.) and advertising-measurement (Google Ads and Meta Pixel) tools that load only if you consent, and — again only with your consent — record which channel or campaign brought you to us (Section 2(l)). We also set, without asking, a small cookie that only remembers which of our campaign links your browser has opened, so we count each browser once; it is never linked to your account and never used to credit a sign-up (Section 5). We advertise CareerVerse and measure which ads lead to visits, sign-ups, and free-trial starts — including sharing a hashed (irreversible) version of your email with Google to match those results and page-visit/browser signals with Meta — but we do not sell your data or show third-party ads on CareerVerse. Anything you post in the public Community is visible to anyone and can appear in search engines (see Section 14).

This Privacy Policy explains how ASOasis Tech Private Limited ("ASOasis", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the CareerVerse website and related features (the "Service"). It is designed to meet India's Digital Personal Data Protection Act, 2023 ("DPDP Act") — the statute that will be our primary data-protection law once its main provisions commence in May 2027, and which we are already building towards — as well as the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA), where applicable. The Indian law that binds us today is the Information Technology Act, 2000 and the 2011 Rules made under it. Section 3 sets out both, and is honest about which is which. Read this policy together with our Terms of Service.

The Service is intended only for individuals aged 18 or older (see Section 13).

1. Who we are

ASOasis Tech Private Limited, a company incorporated in India, is responsible for your personal data. We are the Data Fiduciary for the purposes of the DPDP Act, the Controller under the GDPR, and the Business under the CCPA/CPRA.

2. Information we collect

In short: The information you give us, the content you create, and a little technical data to keep you signed in — plus, if you create your account with "Continue with Google", the display name and profile photo Google hands us at that moment — profile data that reached us from a company rather than from you (Section 2(a2)). If you consent, we also collect pseudonymised product-analytics through third-party tools (Microsoft Clarity, Google Analytics, etc.), use advertising tools (Google Ads and Meta Pixel) to measure which ads bring people to CareerVerse, and record which channel or campaign your own sign-up came from. Separately, and regardless of that choice, we keep aggregate counts of how often things happen across the Service with no identifying data attached (Section 2(m)); and every email we send carries open and click tracking added by our email provider, which keeps a per-recipient history we can look up (Section 2(q)).

This section was added to on 26 September 2026, to describe the email saying a mock-interview result is ready, and the one follow-up email after your first mock interview; and on 27 September 2026, to describe the answer timing behind the delivery notes on your mock-interview results; and on 28 September 2026, to describe what we count for our campaign links and what we keep when your sign-up came through one of them; and on 30 September 2026, to name the skill names from your profile that we keep beside a match we made for them.

a. Account and authentication data. Your email address, used for one-time-passcode (OTP) sign-in, and an authentication token kept in a secure session cookie. We do not collect or store passwords. When you request a sign-in code, your IP address may be forwarded to our backend for rate-limiting and abuse prevention.

a1. Sign in with Google (optional). If you choose "Continue with Google", Google confirms your identity to us and sends us a signed assertion containing your email address, whether Google has verified it, a stable identifier for your Google Account, and — in most cases — your Google display name and a link to your Google profile picture. We use that identifier to recognise you on later sign-ins, and we store it alongside your account; what we do with the name and picture is set out in Section 2(a2) below. We never receive your Google password, and we do not request access to your Gmail, Drive, Contacts, or any other Google data — the name and the picture link are simply fields inside the signed assertion, not access to your account. Because CareerVerse issues its own session, signing out of Google does not sign you out of CareerVerse. Google sign-in works only when Google's verified email exactly matches your current CareerVerse sign-in email; if the Google address changes, you must instead use the one-time code sent to your existing CareerVerse email, and Google does not silently change that address for you. If you stop using Google sign-in in your account settings, this does not affect your Google Account: we disable the identifier in CareerVerse, end CareerVerse sessions created through it, and retain the disabled record so ordinary Google sign-in cannot silently restore that access. It does not remove a name or photo that was copied onto your profile when the account was created (Section 2(a2)) — by then they are ordinary profile fields, and yours to change or clear. To enable it again, you must first verify your CareerVerse email with a fresh one-time code and then choose a Google Account with that same email. Active and disabled Google sign-in history is visible in your account settings.

A "Continue with Google" button appears on our home page and on our sign-in screens. It appears in account settings only if you explicitly start re-enabling a disabled Google sign-in method, and only after email verification. Drawing that button loads Google's sign-in code, and when it loads Google receives your IP address, basic device and browser information, the page address, and any Google cookies your browser already holds — so if you are signed in to Google, Google can recognise you at that moment. On the home page this happens as soon as the page loads, whether or not you ever use the button; on a sign-in screen it happens when that screen opens. To us, however, nothing about your Google account is revealed unless you actively choose "Continue with Google" — and we do not use Google's automatic "One Tap" prompt, so no Google sign-in prompt ever appears on its own. (Drawing the button also makes one request to our own backend to mint a single-use security token; as described in 2(a), your IP address may be processed for rate-limiting and abuse prevention.) See Google's Privacy Policy.

a2. Starting your profile from Google (new accounts only). If your CareerVerse account is created by "Continue with Google", we start it with the display name and profile picture from that signed assertion, so you do not begin with an empty profile. Profile information reaches us from a company rather than from you in one other place — a LinkedIn import you start yourself (Section 2(g)). This one is different because you never asked for a profile change at all: it happens as a side effect of creating your account. That is why we set it out on its own. It happens once, at the moment the account is created, and only then:

  • It never runs on a later sign-in, and never when Google is connected to an account that already existed — that is an existing account gaining a sign-in method, and nothing about your profile changes.
  • It never writes over anything already filled in. If a field already has a value, we leave it exactly as it is.
  • It is best-effort. If Google sends no name or picture, or the picture cannot be fetched, that field is simply left empty and your sign-in carries on normally.

For the picture, our server fetches the image from Google once and keeps our own copy, on our storage in India (Section 6). We do not keep Google's link to it on your profile — only our copy — so displaying your photo on CareerVerse makes no request to Google, and a page showing your avatar never tells Google you were there. From that moment it is an ordinary profile photo in every respect: it appears wherever a profile photo appears, and you can replace or remove it in your account settings exactly like one you uploaded yourself.

Because it is a one-time copy, it is a snapshot, not a mirror: changing or deleting the picture on your Google Account later does not change or delete ours, and neither does disconnecting Google sign-in (Section 2(a1)). Editing or clearing the fields yourself is what changes them here. On the one sign-in path that asks you for an emailed code before finishing, we hold the name and the picture link on a server-side record tied to that attempt. It is never sent to your browser, and it expires automatically — though, like our other records, a copy can survive for a while afterwards in routine backups (Section 8).

b. Profile data. Name, headline, summary, phone number, location, profile photo, skills, languages, work experience, education, and LinkedIn/GitHub/portfolio URLs. You give us most of it directly. Two things can arrive another way: on an account created through "Continue with Google", the name and profile photo are filled in from your Google Account at that moment (Section 2(a2)), and a LinkedIn import writes what it fetched into these fields (Section 2(g)). Either way they are ordinary profile fields afterwards, yours to change or clear.

c. Resume. A resume file you upload (e.g. PDF), and information derived from it when you use AI resume features.

d. Job-application records you create in the application tracker — including the status you set on one, which is where an outcome such as an offer or a rejection is recorded if you choose to record it, and, where you paste a job description, the set of skills you accept from it (Section 4).

e. User-generated content. Forum posts, comments, and images; code submissions; system-design canvases; project write-ups; and the text you enter into AI features (including job descriptions and mentor-chat messages). Content you post in the public Community is visible to anyone and may be indexed by search engines — see Section 14.

f. Mock-interview data. Camera video and microphone audio recordings; the transcript of your spoken answers (which is produced by sending that audio to a provider as you speak — Section 4 says who, and what we can and cannot promise about it); and derived proctoring events with timestamps (for example, "face not detected", "multiple faces", "gaze away", tab switch, window blur, full-screen exit, camera or microphone disconnect, or attempted copy/paste), from which an integrity signal is derived. If you switch on the optional composure estimate during an interview, we also store the summary figures it produces — one per answer and one for the session — which are worked out on your device, so that your account page can show you your own trend; we do not use them in grading. We do not receive or store the underlying facial-landmark data, or any video from the composure estimate — that is computed and stays in your browser (see Section 4). For each spoken answer, we also record timing measured in your browser — how long you spoke and how soon you began after the question finished — and show it to you on your results as delivery notes; they are not used in your score. If we finish grading an interview in the background — because grading it took longer than our time limit allows, or because you answered every question but the interview was never submitted — we may send you one email for that interview saying its result is ready, with a link to it. It carries no score, figure, verdict or standing (Section 4). We record against that interview that we sent, or tried to send, that email, so it is never sent twice; the record is deleted with the interview.

g. LinkedIn import data. If you choose to import from LinkedIn, the data fetched from a public LinkedIn profile you specify — name, skills, work experience, and education. Starting the import writes this straight into your profile: there is no separate save step, and it overwrites your existing name, skills, work experience, and education. If you have no headline yet, one is set from your most recent role. From that moment they are ordinary profile fields (Section 2(b)), yours to change or clear at any time.

h. Limited technical data. Information necessary to operate and secure the Service, such as the IP address forwarded for rate-limiting and standard server logs.

i. Billing data. If you purchase a paid plan, your payment is processed by a third-party payment processor acting as the merchant of record (see Section 6). We receive your email address and limited transaction and subscription data (such as plan, amount, currency, status, and renewal dates) needed to provision your access and keep our records. We do not receive or store your full payment-card number — card details are handled by the payment processor.

j. Product-analytics data (only with your consent). If you accept analytics cookies, we use third-party analytics tools (Microsoft Clarity, Google Analytics, etc.) to understand how the Service is used. Clarity captures pseudonymised interaction data — pages viewed, clicks, scrolls, mouse movement, approximate location inferred from IP (not stored by us), and device/browser type — and session replays (a reconstructed playback of your visit). We configure Clarity to mask the text you type and other sensitive input, so it is not recorded. Google Analytics (GA4) measures pseudonymised usage — pages viewed, events (such as starting an interview or completing a lesson), approximate location inferred from IP, device/browser type, and site-performance (Core Web Vitals) and error signals; GA4 does not log or store your IP address, and we do not enable Google Signals, advertising features, or cross-site ad profiling. Neither tool is loaded at all unless you consent, and you can withdraw consent at any time via "Cookie preferences" in the site footer. See Sections 5–7. We may use service providers, including AI tools, to analyse pseudonymised usage data to improve the Service and our marketing; we do not sell this data.

k. Advertising-measurement data (only with your consent). If you accept, we use Google Ads and Meta Pixel to measure and optimise our own advertising. When you arrive from a Google ad, Google adds a click identifier to the URL; we store it in a first-party cookie and later send it to Google to attribute a resulting sign-up, trial, or purchase (a "conversion"). To improve matching we also send Google a hashed (SHA-256, irreversible) version of your email — not your raw email — using Google's "Enhanced Conversions". Meta Pixel sends Meta the pages you view, the page address and referrer, the time of the visit, browser/device and network information (including IP address), and Meta cookie/browser identifiers so Meta can measure and optimise our ads. When you arrive from a Meta ad, Meta adds its own click identifier to the URL; if you accept, we store it and provide it back to Meta (in Meta's _fbc cookie, together with the time of the click) so a resulting sign-up can be matched to the ad you clicked — the purpose that identifier was put on your link for. When a consented visitor creates a new CareerVerse account, or starts a free trial of Premium, the Pixel also sends Meta the corresponding standard event (registration or trial started), carrying at most one opaque event identifier — issued by our systems for a registration, and by our payment processor for a trial — so the same action can be deduplicated if server-side measurement is added later. Those events contain no email, CareerVerse user id, authentication method, plan, amount, profile data, form values, or other custom data. If you create your account or start your trial before answering the cookie banner and then accept, that one event identifier is held in your browser's memory only — never written to your device, never sent anywhere — and the event is sent once you accept, for up to 30 minutes; if you decline, close the tab, or reload the page first, it is discarded and nothing is ever sent. This implementation does not enable Meta Advanced Matching or send your email, profile data, resume, application records, or the text you enter into CareerVerse to Meta. Meta may associate Pixel activity with a Meta account and use it according to its privacy and advertising settings, including for ad personalisation. Neither advertising tag is loaded, and no advertising-measurement cookie is set by us, unless you consent; you can withdraw consent at any time via "Cookie preferences" in the footer. We do not show third-party ads on CareerVerse.

l. Sign-up source (only with your consent). If you accept, we record where your sign-up came from and keep it on your account: the marketing "channel" (for example paid search, organic social, email, or direct), the campaign name or id, the website that linked you (the domain only — never the full address or what you searched for), the page you first landed on, the time, and any advertising click identifier that was on the link. If that source is one of our own campaign links (Section 5), we also record when you later start a free trial and when you first pay, if you do, so we can see which of our campaign links lead to trials and payments. We use this only to understand which of our own channels and campaigns bring people to CareerVerse, and which of our campaign links lead to trials and payments. It is first-party — recorded by us, kept by us, and not shared with any advertising platform for this purpose. (The advertising click identifier is the one exception, and only for a different purpose: it is separately used to measure our advertising, as Section 2(k) describes, which is what the ad platform put it on your link for.) Nothing is recorded unless you consent, the first source we record for you is never overwritten, and withdrawing consent via "Cookie preferences" in the footer permanently deletes it — a later change of mind cannot bring it back.

m. Aggregate activity counts (no identifying data). We keep plain running totals of how often certain things happen across the whole Service — for example how many accounts were created, how many signed-in visitors reached the pricing page or opened checkout, how many free trials began, and how many lessons were completed. These are counts only: each records that something happened once, with no user id, email, device identifier, cookie, or IP address attached, and nothing about you is stored beside them. That includes how many times each of our campaign links is opened, and by how many different browsers; to tell one browser from another we read the campaign-link cookie described in Section 5, which holds only link codes, and nothing from it is stored beside the count. The counts themselves therefore cannot be traced back to you, filtered to you, or used to single you out; they are held in our own cloud infrastructure, and may be copied — still as counts only, with nothing about you attached — to other systems and tools we use to run and report on our business; they are not shared with any advertising platform, and are not sold. To be precise about what that does and does not cover: it is a statement about the counts, not a claim that no record of your request exists anywhere — our ordinary server logs, described in Section 2(h), record requests as they do for the rest of the Service, and are kept and deleted on the same basis. The counts are not derived from those logs and cannot be joined back to them by us. We use them to see whether the Service — and the journey from signing up to upgrading — actually works. Because they contain no personal data, they are not part of the optional cookie consent and are unaffected by withdrawing it; the third-party analytics and advertising tools in Sections 2(j) and 2(k), which do involve personal data, remain consent-only.

One more thing this paragraph is not. Everything above is a statement about these counts — it is not a claim that we never measure anything against your account. Separately from them, and not part of them, we mark which days your account was active, and record which growth lens you chose, and we roll those up into cohort figures to see whether people come back and whether a feature is worth keeping (Section 3). Those markers sit on your account rather than in the counts, are never shared with any advertising platform, and go when your account goes. We also read them for one account at a time for the follow-up email in Section 2(p1): to decide whether to send it, and to record whether you came back.

n. Your Career Twin (what we work out from your own activity). CareerVerse builds a Career Twin for you: a list of the skills on your record — the ones you added or ticked yourself, and the ones your work here evidences — what evidences each one, a standing for each skill, and — once you set a target — how far your record reaches it. We assemble it automatically, from activity you have already carried out — your achievement-journal entries; your profile headline, summary, work history and the skills you have listed; mock interviews you have sat; coding solutions you have submitted; projects you have submitted; system-design sessions you have completed and the notes recorded during them; courses and course exercises you have finished; a résumé you upload; and a profile you import from LinkedIn. A journal entry you write up from a merged public pull request we found for a code-host username you typed reaches it as well, as the journal entry it is (Section 4). Two further sources are treated differently and are named here so the list stays complete: interview transcripts, which need a separate permission you must grant and can withdraw, and a job description you paste, which is held against the application it belongs to and deleted with it, along with the set of skills you accept from it. What we store is mostly pointers and labels: which skill, which piece of your own work supports it, when that work happened, whether the link was chosen by you or worked out by us, and — for graded work — whether that attempt passed, judged by the same pass rule the page that graded it uses. From those we work out each skill's standing. Alongside them we store your answer whenever we asked whether to record a lower standing, together with the attempts that question was about; the figures described in Section 4; and a record of when one of those figures was shown to you. There is free text alongside those pointers, and it is worth being exact about who wrote it: the only prose we generate is a short factual note about a completed session — an observation, never a judgement (Section 4). The rest comes from you: the target role you type in if you set a goal, any comment you add to an item, and the skill names you type — the ones you set as a target's skills, the ones you set against a job description, and a skill name from your profile that we matched to a skill on our list, which we keep beside that match (Section 4). Every entry says where it came from, and you can remove or detach it. Section 4 explains how it works, how to stop it, and how long each part is kept.

o. Email reminder settings. If either the weekly win prompt or the monthly growth digest is — or has been — switched on for your account, we store what those sends need: which of the two you are getting, the day and hour you want the weekly one, your timezone, and, only if you fill it in, the month your performance review falls in. We also count how many prompts in a row drew no journal entry, so that we can ease off automatically rather than keep mailing into silence.

The timezone is the one your browser reports. It reaches us when you sign in, and we record it when either email is switched on for your account — including where we switched them on for you at sign-up (Section 3). We use it for nothing but working out when to send. We keep it after you switch both emails off, so that turning one back on later restores the schedule you had rather than silently resetting it to a default hour you never chose; it is deleted when your account is deleted. We are listing it separately, rather than leaving it unmentioned inside a scheduling setting, because it is a rough indication of where in the world you are. All of it is visible and changeable in your account settings.

Separately from those settings, for each of these emails we send you we keep a record of when it was sent and, for a weekly prompt, whether a journal entry was filed from the link in it. Each of those records is kept for about 180 days from the send. If the weekly win prompt carries a note from your career twin, it is built at send time from your target and the skills on your career twin, and nothing new is stored for it.

p. The one win-back email, and whether it arrived. Separately from the two reminders above, we may send you a single message — once, ever — if you opened an account and never took a paid plan. It is not a stream and there is no switch left on for it: each account may receive one of these for the lifetime of the account, and once it has gone it cannot be sent again. Every copy carries a one-click unsubscribe link; using it stops this message and takes you out of the campaign permanently, and you can ask us to do the same at support@careerverse.tech.

We measure that one send, and it is worth being exact about which parts of it are attached to you and which are not. Against your account, we record that the message was sent and which version of it you got, and afterwards whether you signed back in, started a free trial or took a paid plan, or why you left the campaign — on the same record that enforces the once-ever limit. Separately, if a copy bounces or you report it as spam, we act on that against your account too: it stops any further mail of this kind reaching you.

Whether it was delivered and whether it was opened, we count for the campaign as a whole. We count how many of these messages our email provider delivered, how many were opened, and how many had a link in them clicked — the first two described on this page since 8 September 2026, the third since 17 September 2026. The open count works because the message carries a small tracking image: it loads when you open the message, which is what reports that a copy was opened — and, as any image in any email does, it discloses to the host serving it your network address and basic information about the mail client that fetched it. That image is not special to this message: every email we send carries one, and any web link in it is tracked as well (Section 2(q), which sets out the one exception). Our own databases hold no per-account record of deliveries, opens or clicks. Ours are counted in aggregate only: running totals for the campaign, with no user id, email address or device identifier stored beside them, so that we can tell whether the message arrives and is read at all. Our email provider does keep one, for this message as for every other: a per-recipient history of its delivery and of any open or click, which we can look up (Section 2(q)). The image is served from a host operated by our cloud provider (Section 6) rather than by us. If you would rather it never loads, most mail clients can be set not to load images automatically; the unsubscribe link stops the message itself.

p1. One follow-up email after your first mock interview. About a day after we grade a mock interview that is the only graded mock interview on your account — normally your first — we may send you one email inviting you back for your next one — but only if you have not been back on CareerVerse on a later day, and only while your account is active and its email address is verified. It is sent once, ever: each account can receive it at most once for the lifetime of the account; once it has been sent or held back (below) it is never sent for a later interview, and if the moment to send it passes we do not send it late. It never carries a score, figure, verdict or standing, or anything else about how your interview went (Section 4).

For the first 4 weeks after we start sending it, about half of the accounts that qualify are picked at random and not sent it, so that we can compare whether the people who got it came back more often than the people who did not. Being in that half is final too: an account picked for it is never sent this email later. After those 4 weeks, every account that qualifies is sent it.

Against your account, we record when that interview was graded, and whether you used the unsubscribe link. If we decided not to send it before choosing a group, we record why (for example, that you had already come back), and when. Otherwise we record which of the two groups your account was placed in, and when; when the email was sent, if it was; and whether your account was active on CareerVerse in the 7 days after the day it was graded, and when we checked. To tell whether you came back, we read the markers of which days your account was active, described in Section 2(m); nothing new is collected for that. The record holds no email address and does not say which interview it was. We keep it until your account is deleted, because it is what makes sure this email is only ever sent once. It is included in the copy of your data you can download (Section 10).

Every copy carries an unsubscribe link, and the one-click unsubscribe some mail apps show at the top of a message. The email is sent only once, so it will not come again either way; using the link records that you did not want it. You can object to the record above by writing to support@careerverse.tech. Like every email we send, it carries the open and click tracking set out in Section 2(q); our own databases hold no per-account record of whether it was delivered, opened or clicked. If a copy bounces, or you report it as spam, we keep a note of that against a one-way hash of the address, not your account, so this email is not sent to it again. A copy that bounces because the address does not exist also stops our other reminder emails to that address. That note is not deleted with your account, so that a new account on the same address is not emailed against it.

q. Open and click tracking in every email we send. Every email we send you is delivered by our cloud provider (Section 6), and it adds tracking to each one as it goes out — the tracking is not in the email we write. That covers all of them: sign-in codes; the codes that confirm an account action, and the security notices we send about your account (for example when your other sessions are signed out, or Google sign-in is linked, turned on or removed); a notice that a payment failed; emails about an expert session or a recruiter review; a notice that a mock interview result is ready (Section 2(f)); the weekly win prompt and the monthly growth digest (Section 2(o)); the win-back message (Section 2(p)); and the one mock-interview follow-up email (Section 2(p1)). It works in two ways:

  • An open-tracking image. A tiny, invisible image, unique to that one message, is added to the email. When your mail client loads it, the request tells our provider that this message was opened, and when.
  • Click-tracking links. Each web link in the email is replaced by a link, also unique to that message, to a host our provider operates, which sends you straight on to the page the link was for. Clicking one tells our provider which link in which message was clicked, and when. There is one exception: the sign-in button in an email carrying a sign-in code. We mark that one link so our provider leaves it as it is, and it does not record a click on it.

Both are served from hosts operated by our cloud provider, not by us, and as any image or link fetched over the internet does, each request also discloses to that host the network address and basic mail-client or browser information of the device that made it — yours, or that of a mail service that loads images on your behalf. Only the formatted (HTML) version of an email is tracked: each of these emails also carries a plain-text version, in which nothing is tracked and no link is replaced.

Who holds the result. Our provider keeps a delivery and engagement history for each message and each recipient: your email address, the subject and sender, the mail service that received the message, and when it was sent, delivered, opened or clicked, or bounced or reported as spam. We can look that history up, by recipient address, for messages sent in the last 30 days. The provider's open and click events are not copied into our own databases; separately, if you file a journal entry from the link in a weekly prompt, we note against that send that it led to an entry (Section 2(o)). None of the provider's history goes to any advertising platform, and what reaches our own monitoring from it is totals, with no address or account attached.

Why, and on what basis. We use it to see whether the emails we send arrive and are read, and to catch problems delivering to the mail services our users rely on. The basis is our legitimate interests in that (Section 3). It is not consent, and we do not call it that: nothing asked you to switch it on.

How to object. Set your mail client not to load images automatically, and the tracking image does not report an open unless images are loaded anyway — by you, or by a mail service that fetches them in advance; a link you click in the formatted version is still tracked, so if your mail client can show the plain-text version instead, use that. Where an email carries an unsubscribe link, using it stops that kind of email, and the tracking that comes with it — the link in the formatted version itself passes through a tracking link, while the one in the plain-text version, and the unsubscribe option some mail apps show at the top of a message, do not. You can also write to support@careerverse.tech. We cannot yet switch tracking off for a single recipient, so for emails without an unsubscribe link, such as sign-in codes, turning off image loading and reading the plain-text version are the ways to avoid it.

Until 17 September 2026 this page described only a tracking image, and only in the win-back message; the tracking set out above was already applied to the emails we send, and this paragraph is the correction.

What we do not do. We do not sell your personal data or show third-party ads on CareerVerse. Our advertising is limited to running and measuring our own campaigns on platforms such as Google and Meta (Section 2(k)); those platforms may use the consented advertising signals under their own policies. The third-party tools we use include Microsoft Clarity, Google Analytics, Google Ads, and Meta Pixel, each loaded only with your consent (see Sections 5–7).

3. How and why we use your data, and our legal bases

In short: To run CareerVerse for you, keep it working and honest, and meet our legal duties. Each use below gets its own line, and each answers two separate questions: the basis under the EU and UK GDPR, and the ground we expect to rely on under India's DPDP Act once its main provisions commence. Those are not the same list and we have not pretended they are. Where a line says consent, there is a real switch and we tell you where it is; where there is no switch, we do not call it consent.

A note on how we cite. Everywhere else in this policy, "Section 5" means a section of this document. In the tables below we are citing statutes, so we write those as DPDP s.7(a) or GDPR Art. 6(1)(b). If you see "s." or "Art.", we mean the Act named in that column, not this policy.

Your account, and the Service you asked for

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Sign you in by one-time email code, or with Google if you choose it, and keep your sessionGive you access to your accountPerformance of a contractDPDP s.7(a) — you gave us your email in order to be signed in
Rate-limit sign-in and other sensitive requests, using the network address the request arrived fromStop credential-stuffing and abuse of the sign-in systemLegitimate interests: keeping accounts and the sign-in system safeNothing on the s.7 list squarely fits — see "Security, and a gap we are not papering over" below
Record, when you sign up, the network address the request reached us fromKeep our own sign-up recordsLegitimate interests: keeping accurate records of our own serviceDPDP s.7(a)
Draw the "Continue with Google" button, which loads Google's code and lets Google see your visit even if you never use it (Section 2(a1))Offer you a sign-in methodLegitimate interests: offering a sign-in method. Google and we are jointly responsible for what the button sends as it loads — see belowConsent — a step we have not built yet. This is separate from the cookie banner, which does not cover the sign-in button (Sections 5 and 6)
Start a new account's profile with the display name and photo from the Google Account you signed up with, including fetching that image from Google once and keeping our own copy (Section 2(a2))Give a new account a usable profile instead of an empty oneLegitimate interests: sparing you from re-entering what you have just signed in with. You can object by clearing either field in your profile — we never put them backThe s.7 list does not cover this either: you gave this data to Google, not to us, so it was not "voluntarily provided" to us for this purpose. We will ask properly before those provisions commence
Store and display your profile, resume, job applications, journal entries, notes, bookmarks and other content you createProvide the core ServicePerformance of a contractDPDP s.7(a) — you gave it to us to be stored and shown back to you. For how a name or photo can arrive on your profile without you giving it to us, see the row above
Run and grade the coding problems, projects, system-design sessions and course exercises you submitProvide the practice features you usePerformance of a contractDPDP s.7(a)
Send the text you give us to our AI provider (Section 4) to power resume, interview, mentor, conversation-rehearsal and grading featuresProvide the AI features you ask for, at the moment you askPerformance of a contractDPDP s.7(a) — you supplied the text for exactly this
Meter your usage against the limits of your plan — CVTokens, mentor turns, interviews, code runs, conversation simulations and job-description readings each count separatelyKeep the Service usable and priced fairlyPerformance of a contractDPDP s.7(a)
Take payment and manage your subscription, renewals and refundsBill you for a plan you boughtPerformance of a contractDPDP s.7(a)

Mock interviews

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Record camera video and microphone audio during a mock interviewLet you practise and watch yourself backConsent, taken before recording starts; and performance of a contract for the practice session you asked forConsent (DPDP s.6)
Send the audio of your answers to a speech-to-text provider so it can be turned into the transcript you are graded on, and — where that provider is unavailable — fall back to your browser's own transcription (Section 4)The transcript is the graded artefact; without it there is no mock interviewConsent, taken on the same screen — which names the kinds of recipient (a speech-to-text provider acting for us, or your own browser's vendor) rather than the companies or the countries, and Section 4 of this Policy is where each one is named; and performance of a contract for the practice session you asked for. Section 7 covers the transfer positionConsent (DPDP s.6)
Send the text of each question to a speech-synthesis provider so the interviewer can read it aloud (Section 4)Make the exercise a spoken interview rather than a reading exercise. Your own voice is never sent to itPerformance of a contractDPDP s.7(a)
Capture proctoring events during a mock interview — for example face not detected, multiple faces, looking away, tab switch, window blur, full-screen exit, camera or microphone disconnect, blocked right-click and blocked copy/paste — and derive an integrity signal from themMake the exercise a fair test of you, so the result means somethingConsent, taken on the same screen; and legitimate interests in the exercise being honestConsent (DPDP s.6)
Work out an optional composure estimate on your device from your camera, and store the per-answer and whole-session summary figures it produces (Section 2(f))Give you optional coaching on how you came across. We do not use it in gradingConsent — off unless you turn it on during the interviewConsent (DPDP s.6)
Measure the timing of your spoken answers in your browser and show it back as delivery notes (Section 2(f))Give you feedback on how you spoke; not used in gradingPerformance of a contractDPDP s.7(a)
Finish grading a mock interview in the background, and email you once that its result is ready (Section 2(f))Give you the result of the practice session you asked forPerformance of a contractDPDP s.7(a)

Community, and anything you choose to make public

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Host Community discussions and comments, and publish the ones you choose to make public — to anyone, and to search engines (Section 14)Run the community, and publish what you chose to publishPerformance of a contract — hosting and publishing to the audience you chose are both part of the Community service you signed up for. Where a post contains special-category data, you have manifestly made it public (Art. 9(2)(e))Hosting: DPDP s.7(a). Once it is public, the Act does not apply to data you have yourself made publicly available (DPDP s.3(c)(ii)(A))
See which account posted anonymously, act on reports, and moderate contentKeep the Community safe and enforce our TermsLegitimate interests: safety, moderation, and enforcing our TermsNothing on the s.7 list squarely fits — see below
Publish a public profile at a handle you claim, or a share link for a promotion packet you choose to sharePublish the page you asked us to publishPerformance of a contract, carrying out your instructionDPDP s.7(a); and the Act does not apply to data you have yourself made publicly available (DPDP s.3(c)(ii)(A))

Your Career Twin

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Build your Career Twin automatically from work you complete here, including a standing for each skill worked out from your graded results, and keep a record that a profile import ran (Section 4)Provide the Career Twin featurePerformance of a contractConsent — a step we have not built yet. Today the per-source switches in your account settings are how you stop it
Read a journal entry, or your profile headline or summary, that you select, and suggest skills from itProvide a feature at the moment you ask for itPerformance of a contract, at your requestDPDP s.7(a) — you chose the text and asked us to read it
Read work you completed before the feature existed, so your record is not emptyMake the feature useful from your first visitLegitimate interests: making the feature useful immediatelyConsent — a step we have not built yet

Keeping the Service working, and knowing whether it works

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Keep the Service secure, investigate abuse, keep server logs, and enforce our TermsProtect you, other users, and usLegitimate interests: preventing fraud and abuse, and keeping the Service availableNothing on the s.7 list squarely fits — see below
Keep streaks, mastery points, badges and your activity heatmap from the work you do hereShow you your own progressPerformance of a contract — it is a feature on your account pageDPDP s.7(a)
Count each account's active days, and which growth lens you chose, and report those to ourselves as cohort figuresSee whether people come back, and whether a feature is worth keepingLegitimate interests: understanding whether the Service worksConsent — a step we have not built yet
Maintain, debug and improve CareerVerseFix faults, and decide what to build nextLegitimate interests: keeping the Service running, and deciding what to buildConsent — a step we have not built yet
Keep aggregate, non-identifying counts of product activity (Section 2(m))See whether the Service, and the journey from signing up to upgrading, actually worksThe stored counts are not personal data. But a signed-in request is what increments one, and that observation rests on our legitimate interests in measuring the ServiceThe stored counts are not personal data. For the request that increments one, the position is the same as the line above
Send you the weekly win prompt and the monthly growth digest by emailKeep your achievement journal alive, and show you what it added up toConsent — the switch in your account settings — except where we resolved your sign-up as coming from India or the United States, in which case both may start on and the basis is our legitimate interests in helping you get value from the journal and the career twin you keep with us. You can switch them off at any time, and you have a right to object (see below)Consent — a step we have not built yet, and one we will have to ask for before ss.3–17 commence. Sign-ups we resolve as Indian may start with both already on
Use the same resolved sign-up country to decide which country's rates, currency and payout method apply to you in Refer & Earn, and record that answer against your referral profileWork out what a referral pays you, and in which currency, without asking you for anythingPerformance of a contract — it is what decides the amount and the currency of a commission you are owed under the Refer & Earn Terms. Where we could not resolve it, we ask you instead and record your answerDPDP s.7(a) — it is necessary to work out and pay what we owe you under a programme you chose to take part in

Measurement and marketing

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Measure product usage with third-party analytics tools (Microsoft Clarity, Google Analytics)Understand how the Service is used, and fix problems; analyse that pseudonymised usage data, including with AI tools, to improve the Service and our marketingConsentConsent (DPDP s.6)
Measure our own advertising with Google Ads and Meta Pixel, including sending Google a hashed version of your email (Section 2(k))See which of our ads bring people to CareerVerseConsent. For what those tags collect and send as they load, Google and Meta are each jointly responsible with us — see belowConsent (DPDP s.6)
Record on your account which channel or campaign your sign-up came from, and, for a campaign link, when you started a trial or first paid (Section 2(l))See which of our own channels and campaigns bring people to CareerVerse, and which of our campaign links lead to trials and paymentsConsentConsent (DPDP s.6)
Count how often each of our campaign links is opened, and — using the campaign-link cookie in your browser (Section 5) — by how many different browsers (Section 2(m))See how many people each of our own posts and campaigns reachesLegitimate interests: knowing how many people open our campaign links. This is not consent and we do not call it that — there is no switch you turned on. You have a right to object: delete the cookie in your browser at any time, which makes no difference to using CareerVerse, though opening another of these links while signed out sets it again; to stop that too, block cookies for this site, which also stops you staying signed in. It is never read or set while you are signed inThe counts are not personal data, and the cookie holds only link codes. For reading that cookie: consent — a step we have not built yet
Keep the choice you made at the cookie banner on your account, and — when you are signed in on a device where the cookie recording it is missing — put your own last answer back rather than asking you again (Section 5)Be able to show what you agreed to and when, and honour an answer you have already given — including a refusal — on every device you sign in onLegal obligation to be able to demonstrate the consent you gave (GDPR Art. 7(1)) for keeping it; legitimate interests in not re-asking a question you have answered, for reading it back. This is not a second consent and we do not call it one: it only ever restores a decision you made, it never turns a refusal into an acceptance, and it never restores one you withdrewDPDP s.7(a) — you gave us the answer so that we would act on it
Send you the one win-back email, record against your account that it was sent, which version you got, and whether you then signed back in, started a free trial, took a paid plan or left the campaign, and count deliveries, opens and clicks for the campaign in aggregate — the opens through a tracking image and the clicks through tracked links (Section 2(p))Reach an account that never took a paid plan, once, and know whether that one message arrives and is read at allLegitimate interests: telling our own existing users about our own service, and knowing whether a message we sent them worked. This is not consent and we do not call it that — there is no switch you turned on. You have a right to object: the one-click unsubscribe in the message stops it permanently, or write to support@careerverse.tech. Our own databases hold no per-account record of deliveries, opens or clicks; the per-recipient history our email provider keeps of every email, this one included, is the row after nextConsent — a step we have not built yet, and one we will have to ask for before ss.3–17 commence. The unsubscribe link is how you stop it today
Send you one follow-up email about a day after a mock interview is graded, if it is the only graded one on your account (normally your first) and you have not already come back; for the first 4 weeks, hold about half of the accounts that qualify back at random so the two groups can be compared; and record against your account when that interview was graded and either why it was not sent before a group was chosen, or which group it was in, whether it was sent and whether you were active in the 7 days after it was graded; and whether you unsubscribed (Section 2(p1))Help someone who has just sat their first mock interview carry on practising, once, and know whether that message helpsLegitimate interests: helping an existing user carry on practising, and knowing whether the message helps. This is not consent and we do not call it that — there is no switch you turned on. You have a right to object: use the one-click unsubscribe in the message, or write to support@careerverse.tech. Our own databases hold no per-account record of deliveries, opens or clicks; the per-recipient history our email provider keeps of every email, this one included, is the next rowConsent — a step we have not built yet, and one we will have to ask for before ss.3–17 commence. The unsubscribe link is how you stop it today
Track opens and clicks in every email we send — sign-in codes, account-action codes and security notices, payment-failed notices, expert-session and recruiter-review emails, mock-interview result notices, the weekly win prompt, the monthly growth digest, the win-back message and the one mock-interview follow-up email — through an invisible tracking image and click-tracking links our email provider adds, which leave it a per-message, per-recipient history we can look up (Section 2(q))Know whether the emails we send arrive and are read, and catch problems delivering to the mail services our users rely onLegitimate interests: knowing whether the emails we send you reach you and work. This is not consent and we do not call it that — there is no switch you turned on. You have a right to object: set your mail client not to load images automatically and read the plain-text version, use the unsubscribe link where an email has one, or write to support@careerverse.tech. We cannot yet switch this tracking off for a single recipient, so for emails with no unsubscribe link, such as sign-in codes, those mail-client settings are the way to avoid it todayConsent — a step we have not built yet, and one we will have to ask for, or stop tracking these emails, before ss.3–17 commence. The routes in the previous column are how you object today
Publish our own videos to our YouTube channel, and once a day find recent public YouTube videos about careers, keeping their video IDs, channel IDs, titles and publish dates; titles may be sent to an AI provider to suggest a draft comment that a person reviews (Section 16)Promote CareerVerse on our own channel, confirm our uploads went live, and pick videos our team may watch or comment on by handLegitimate interests: promoting our own service, and taking part by hand in public conversations about careersThe Act does not apply to data a creator has themselves made publicly available (DPDP s.3(c)(ii)(A)); for publishing our own videos, and for anything a title says about someone other than the creator who posted it, nothing on the s.7 list squarely fits

Support, and the law

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Answer support requests, and handle in-product feedback reports including any screenshot you attachHelp you, and fix what you reportPerformance of a contract if you have an account; otherwise legitimate interests in answering people who contact usDPDP s.7(a) — you contacted us for this
Meet legal, tax and regulatory duties, and respond to lawful requests, judgments and court ordersComply with the law we are subject toLegitimate interests in complying with the Indian law that governs us. Art. 6(1)(c) covers only obligations laid down by EU or UK law, so we do not claim it for our Indian duties; where an EU or UK obligation genuinely applies, Art. 6(1)(c)DPDP s.7(d) where Indian law requires us to disclose something to the State, and s.7(e) for a judgment or order. A duty simply to retain records is not squarely covered by either

Two legal systems, two different answers

The two right-hand columns differ because the two laws are not built the same way, and copying one across to the other would be inaccurate.

The EU and UK GDPR offer six lawful bases, two of which — performance of a contract, and legitimate interests — carry most of what a service like ours does.

India's DPDP Act offers only two kinds of ground: your consent (s.6), and a closed list of nine "certain legitimate uses" (s.7). That list is fixed. There is no contract-performance ground and no legitimate-interests ground in the DPDP Act at all — "legitimate uses" looks like the GDPR's "legitimate interests" but works differently, because there is no balancing test and nothing can be added to the list.

  • Where the India column says s.7(a), that is the ground for "the specified purpose for which you voluntarily provided your personal data" and in respect of which you have not told us you do not consent to that use. That second half is part of the ground itself: the data you handed us, used for the thing you handed it over for — and if you tell us you object to a particular use, that ground stops being available to us for it. Write to support@careerverse.tech.
  • Where it says s.7(d) or s.7(e), those are the grounds for a legal duty to disclose something to the State, and for complying with a judgment or order.
  • Where it says consent — a step we have not built yet, we mean it literally: when those provisions commence we will need your consent for that use, and the screen that asks for it does not exist today. We would rather say so than claim a consent we never asked you for.

What governs your data in India today

Most of the DPDP Act is not yet in force. The sections that set out lawful grounds, the notice we must give you, and your rights as a Data Principal (ss.3 to 17) commence eighteen months after the Government's commencement notification of 13 November 2025 — that is, in May 2027. The India column above therefore describes the position from that date. It is not a description of today.

The Data Protection Board of India was established in law by that same notification, but as at the date of this policy no Chairperson or Members have been appointed, so it cannot yet hear anything. We are not going to point you at a redress route that does not yet function.

Until then, the Indian law that actually governs this is the Information Technology Act, 2000 — in particular s.43A — together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("the 2011 Rules"). Those survive precisely because the provision of the DPDP Act that removes them (s.44(2)) sits in the same deferred tranche and does not take effect until May 2027 either. Under those Rules:

  • We treat your mock-interview camera video and microphone audio as sensitive personal data.
  • We ask for your consent before any recording starts, on a screen that lists each item separately, and we use that data only for the purposes stated there. Rule 5(1) speaks of consent "in writing through letter or fax or email"; an in-product consent screen with a versioned record of what you agreed to is the accepted modern reading of that requirement, and it is the reading we rely on.
  • You can withdraw that consent at any time by writing to support@careerverse.tech, and you can delete any interview and its recording yourself. If you withdraw it, we will not be able to offer you recorded mock interviews.
  • We publish this policy, describe the security measures we take (Section 9), and provide a Grievance Officer (Section 12).

We are setting this out now rather than waiting, because it is the law that binds us today.

Security, and a gap we are not papering over

Three lines above — rate-limiting sign-in, moderating the Community and acting on reports, and keeping the Service secure — are things any service has to do. Under the GDPR they rest on our legitimate interests, which you can object to.

The DPDP Act's list of nine legitimate uses contains no general security or fraud-prevention ground. The one clause that mentions protecting against loss or liability applies to employers and their employees, which is not our relationship with you. We could have written "consent" in that column, but we do not ask you to consent to being rate-limited, and it would not be true. So we have written that nothing on the list squarely fits, and we will follow whatever rules the Central Government makes under s.40 of the DPDP Act, and any direction of the Data Protection Board that applies to us, before those sections commence.

Where we say "consent", here is the switch

Consent means nothing without a real way to refuse, so here is every place we rely on it and the control that goes with it. If a use is not on this list, consent is not what we rely on for it.

  • Analytics, advertising measurement, and recording your sign-up source. One banner, one choice, covering all three together — accepting or declining applies to all of them, and there is no separate switch per purpose today. You can change it at any time from "Cookie preferences" in the site footer. Nothing loads and no such cookie is written until you accept.
  • Mock-interview recording, proctoring, event capture, and sending your audio to be transcribed. A consent screen before the interview starts, listing each item separately so you can see exactly what each one covers, and saying who receives your audio — that screen names the kinds of recipient (a speech-to-text provider acting for us, or your own browser's vendor), and this Policy is where each of them is named. All of them are required for a recorded mock interview, so the interview cannot start until each is ticked. The screen is shown every time you start an interview, so you always tick the current wording rather than a remembered one, and we record which version of it you agreed to: the wording changed on 27 August 2026, when transcription moved from your browser to a provider acting for us, and again on 2 September 2026, when a second such provider was switched on.
  • The composure estimate. Off by default, and turned on inside the interview only if you want it. It is genuinely optional: everything else about the interview works identically without it.
  • The weekly win prompt and the monthly growth digest. Both are off unless you switch them on in your account settings — that switch is the consent — except where we resolved your sign-up as coming from India or the United States, in which case both may start on instead, and consent is not what we rely on for them (see Section 3). "May", because that also requires your browser to have told us your timezone at sign-up: where it did not, both stay off, so the only way to know your own setting is to look. We work the location out from the internet connection you signed up on, so it reflects where you were at that moment rather than where you live; if it put you on the wrong side of that line, switching them off in your account settings is the fix, and it sticks. Every one of these emails also carries a one-click unsubscribe link. No existing account was changed by this — nothing that was already off has been switched on.

Withdrawing consent stops that processing going forward; it does not make what we already did unlawful. Where you withdraw a consent you previously gave, we also permanently delete the record of where your sign-up came from (Section 2(l)), so a later change of mind cannot bring it back. That holds even if we have changed what we ask you to consent to in the meantime: if we re-ask and you decline, we treat it as withdrawing the consent you gave before, not merely as a fresh "no".

Where we say "legitimate interests", you have a right to object

You have the right to object, on grounds relating to your particular situation, to processing we base on our legitimate interests, including profiling. We must then stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms. We are setting this out separately from the other rights in Section 10 because the law requires us to bring it to your attention on its own. Where we ever process your data for direct marketing, you can object at any time with no reason needed and we must stop — that one is unconditional.

Your Career Twin is profiling in the GDPR's sense — automated processing that evaluates aspects of how you perform at work — and it now produces figures about you: a readiness figure against a target you accepted, a match percentage against a job description you paste, and a completeness figure for the career twin itself. It also gives each skill on your record a standing, which your graded results move. Section 4 sets out exactly what each one measures.

Profiling is not the same as a decision, and the difference is what matters here. Those figures and standings decide nothing: nothing is withheld from you because of them, no access, price or eligibility turns on them, and no third party — no employer, no recruiter — ever receives them. They are shown to you, to help you choose what to work on. A lower standing because results did not pass is recorded only if you confirm it, and your next pass on that skill lifts it again. On that basis they do not engage the rules on solely automated decisions producing legal or similarly significant effects, and Section 10 sets out the rights that do apply. If that ever changes — if a figure of ours were to drive a decision about you, or travel to someone who makes one — this section changes with it, before it ships.

We give you more than the law requires here. Two of the three Career Twin lines above rest on performance of our contract, which carries no statutory objection right at all. We apply the per-source switches to all three anyway: under "What builds your record" in your account settings there is a switch for each source, you do not need to give a reason, and we do not weigh your objection against our own interests. Section 4 sets out exactly what turning one off deletes, and Section 10 notes that on a large account the deletion takes more than one step.

For anything else we base on legitimate interests, write to support@careerverse.tech and tell us what you object to. You can also ask us how we weighed our interests against your rights for any of those lines, and we will tell you.

One thing those per-source switches are not. They let you stop processing that has already started. They are not a consent step, and we do not present them as one — Career Twin building is on unless you switch a source off. When the DPDP Act's main provisions commence that will no longer be enough, and we will ask you properly.

The one place we do ask first. Reading your interview transcripts is a separate, explicit permission that is off until you grant it, and withdrawable at any time (Section 4). That is a genuine consent step, and we keep it visibly apart from the switches above so the two are never mistaken for each other.

Who else is responsible alongside us

For three things described on this page, another company decides things about the data alongside us rather than simply acting on our instructions. We name them here because you should know who else holds a piece of this; the essence of each arrangement is set out in Section 6.

  • Google, for what its sign-in button collects and sends when it loads on our pages (Section 2(a1)).
  • Google, for the advertising measurement you consent to (Section 2(k)).
  • Meta, for what the Pixel collects and sends once you consent (Section 2(k)).

There is also a third kind of relationship, which the two categories above do not describe. When Google hands us your display name and picture as you create an account (Section 2(a2)), Google is not acting on our instructions and is not deciding jointly with us — it is a separate company disclosing data to us under its own terms, and what happens to that data afterwards is our decision alone.

For everything else, our providers act on our instructions — see Section 6 for who they are and what each receives.

4. AI processing, your Career Twin, and on-device proctoring

In short: To power AI features, we send the relevant text to a third-party AI provider (OpenAI, etc.) through our backend. Your Career Twin is built automatically from work you have already done here and from what you have put on your profile — you can switch off any source of it at any time, and doing so deletes what we derived from that source and does not undo. It gives each skill a standing that your graded results move, and those results never move it lower without your confirmation. It produces figures about how far your record reaches a target you have chosen; those standings and figures decide nothing and never leave the product. Reading your interview transcripts needs a separate permission you must grant. Face proctoring stays on your device.

AI features

When you use an AI feature, the relevant content is sent through our backend to a third-party AI provider (OpenAI, etc.) to generate the output — including your resume text, the job descriptions you provide, your interview answers and transcripts, short-answer submissions, system-design solutions, mentor-chat messages, and — when you ask us to read one for your Career Twin — your achievement-journal entries and your profile headline or summary. We send only the content needed to provide the feature you requested. AI usage is metered as "CVTokens". OpenAI may process this data outside India, including in the United States (see Section 7).

What travels with a mentor message when you open the AI mentor from a page. So that the mentor can answer about what is in front of you, a short description of the page you are on is sent to the AI provider alongside your message. What that description holds depends on the page, and the most it ever carries is this: on a coding problem, the problem and the code in your editor at that moment; on a résumé analysis, the overall score we gave it, the job role and the skills we extracted from your résumé; on a tailored résumé, the fit score; on the community pages, what you searched for and the titles, text and top replies of the discussions on your screen, with the authors' names left out; on a course or a lesson, the titles of the course, the module and the lesson. On your account page and your achievement journal it carries nothing but which page it is — no profile field, no journal entry. The skill labels on your Career Twin are added at the end of that description, and are the smallest part of it. Before it is sent, the description is capped in size and swept for email addresses, phone numbers and long runs of digits, which are replaced. There is no setting that turns this off, but you can leave the page out of any one message. The small cross on the page's label above the message box leaves the page out of your next message, so no description is sent with it and no audit record is made for it; the page is attached again automatically after that. Otherwise, what is sent is what you have on screen and in your editor when you send.

Each time a page description is sent, we also keep an audit record of it, tied to your account. It holds the time it was made, how long the description was, a one-way code computed from it, and a copy of the description after that sweep. The sweep replaces only email addresses, phone numbers and long runs of digits, so the copy can still hold the code in your editor or the discussion text described above. It also notes which of a list of suspicious phrases the description contained, whether the mentor's reply came back normally, and a few technical details of how the request was handled. It does not hold the message you typed. We keep these records so that we can look into attempts to misuse the mentor and check that our safeguards against them work, and each is deleted about 90 days after it was made. They are not part of the copy of your data we put together when you ask for one, but while your account is open you can ask us for these records separately at support@careerverse.tech, and we will send you what they hold about you. If you want them, ask before you close your account. Closing your account or asking us to erase your data does not remove them sooner.

Your Career Twin: automatic processing of your own activity

This subsection was added to this Policy on 15 September 2026, rewritten on 19 September 2026, when the feature it describes was released, added to on 21 September 2026, when combining two entries on the skill list became something that can happen without a person deciding it, and added to again on 22 September 2026, when you gained a control that takes off a lower standing you had confirmed, and when what happens to your record if we retire an entry from the skill list was set out here for the first time. It changed again on 25 September 2026, to say what the weekly win prompt may carry from your career twin, and on 30 September 2026, to say how we may match a skill you listed under a name we do not use, for your record only, and that switching Profile off deletes those matches. Two sentences it carried about proctoring were wrong; the correction is below, under "One correction".

What we do. Your Career Twin (Section 2(n)) fills itself in. As you use CareerVerse, we match the work you complete against a list of skills and record that the work evidences them.

How that skill list is built, and why it is shared. The list is not fixed and not written by hand. When we meet a skill name we do not hold — in a job description you paste, in a résumé or profile you import, in a skill name you type, or in your own work — an AI normalises it into a canonical entry and may add it to the list automatically, so the product is not limited to a vocabulary someone wrote in advance. Our team reviews, merges and retires entries afterwards, not before.

Two consequences we would rather state than have you discover:

  • The list is shared across everyone. An entry created from one person's text becomes an entry every other user's work can be measured against. It holds skill names only — never who supplied a name, and nothing about you. A name on it can start from something a person typed, but only the skill name itself is kept, never the text around it.
  • What you supply can therefore affect what others see. The checks on that are the three stated here and no others: new entries are rate-limited; a proposed name that duplicates or closely resembles an entry we already hold is refused — a near-spelling of one, or the same words in a different order, or those words with one more added — and your text is then left unmatched rather than becoming a second name for one skill; and our team reviews, merges and retires them afterwards. We are not going to tell you that what comes back from that AI is drawn from a fixed, closed set of names, because it is not — that is exactly what "may add it to the list automatically" means.

Two entries that turn out to be the same skill can now be combined without a person deciding it. Because the list is built as described above rather than written by hand, the same skill arriving twice under two spellings is ordinary rather than rare, and leaving the pair apart splits the evidence for it in two. So where the same skill appears twice we may combine the entries automatically — and only where the entry being folded away was created automatically in the first place. An entry our team wrote is never combined away without our team doing it. Every automatic combination can be undone for 14 days, and so that it genuinely can be, we first take a copy of the records of yours the change would touch and keep it for that window (Section 8); if it is not undone in those 14 days it becomes permanent, exactly as a combination our team makes is permanent today. Nothing about you is added or taken away by it: your evidence moves from the entry that goes to the one that stays, and a standing is worked out again from what remains — the case named further down, under how a standing can fall without a question.

Matching a skill you listed, for your record only. A skill on your profile may be listed under a name we do not use — a short form, say, or another spelling. When you save the skills on your profile, or when a new account's skills are checked again once it is a week old (Section 8), our AI may match such a name to a skill on our list, or we may reuse the answer it gave earlier for the same name, whoever listed it then. When the answer is a match, we keep it against your account — your name for the skill and the skill on our list we matched it to — and count that skill on your record as one added automatically from your profile, without asking you first. That match is kept for you alone and counts on your record only. The answer about the name itself holds nothing about who listed it, and can be reused for anyone who lists the same name. Your matches are listed under "Skills we matched from your words" in your account settings. If one is wrong, choose Not what I meant beside it: the skill is withdrawn from your record the next time your record is worked out in full, unless you added or ticked it yourself or something else still supports it, and we keep your answer for as long as the match would have lasted, to stop the same match being made for you again in that time. While Profile is switched off, no match is kept for you, and switching Profile off deletes every match and every Not what I meant answer. A match lasts at most about 180 days (Section 8).

Reading your own words, only when you ask. You can also ask us to read a journal entry, or your profile headline or summary, and suggest skills from what it says. This never happens on its own: you choose the text and press the button, and the text is sent to our AI provider as described above. Anything it produces is marked an unconfirmed suggestion until you accept it, and an unconfirmed suggestion is never turned into prose about you — it is not used to draft, summarise or write anything. Nor does it count towards what your record shows you can evidence, and it does not change what we suggest you practise next: a guess nobody has checked should not be able to talk us out of recommending the very thing that would prove it. It starts counting only when you accept it, or when other evidence lands against the same skill — graded work you complete here, a role on your profile, or a journal entry. From then on it is no longer a guess, and it stops expiring (Section 8); if that other evidence later goes, the 180-day clock starts again.

A look back over your earlier work. So your career twin is not empty on day one, we also read work you completed before this feature existed. Today that covers your journal entries, mock interviews and coding submissions; we do not re-import the same history over and over.

Where other people's words can reach it, so you know. Most of what builds your career twin is your own activity. Two sources are not purely yours, and we say so plainly:

  • Imported documents — a résumé or an imported profile can contain text someone else wrote about you, such as a recommendation. We record who a sentence is about by its grammar rather than assuming that appearing in your document makes it your claim, and anything drawn from prose is marked an unconfirmed suggestion until you accept it.
  • A code host — when you type a username into the journal's recall panel, we look up merged pull requests that username authored in public repositories, and show you each one's title, repository, date and link. A title is text that may have been written by somebody other than you. There is no connection, no install and no stored credential: we hold nothing that could reach a private repository, and there is nothing for you to revoke, because there is nothing connected. The lookup itself stores nothing and files nothing. What can reach your career twin is only a journal entry you wrote and filed from one of those results, and it is governed by the Achievement journal switch like any other entry. We never treat a username as proof of anything: you typed it, and we do not check that it is yours. Your employer never agreed to share your work with us, and you cannot agree on their behalf.

How to stop it — the control, and what it costs. Under "What builds your record" in your account settings there is a switch for each source. Turning one off does two things: we stop reading that source straight away, and we delete what we derived from it — the links, the supporting entries, the passed or not-passed results we kept for its graded attempts, and any notes or suggestions that came from it. Its attempts also stop counting in any decision about a lower standing: a lower standing you confirmed or declined stops citing them, and is deleted once fewer than three pieces of graded work remain behind it. Then we withdraw any skill we had worked out that nothing else still supports. Two things correctly stay: a skill other work still evidences, and a skill you confirmed yourself — that one is your statement rather than ours, so it is yours to remove, not ours.

That deletion is permanent. Turning the source back on later starts again from your new work only; it does not bring back what was removed, including anything we had quoted from your own words. One honest exception: if you turn Profile back on, your work-history entries and the skills listed on your profile reappear — not restored from a copy, but simply re-read from your profile, which still says what it said. Anything we quoted from your headline or summary does not come back, and nor does a skill that counted only because we had matched a name you listed to a skill on our list (above): switching Profile off deleted that match, so that skill comes back only if we match the name again later, for example when you next save the skills on your profile.

Your actual work is never deleted by this. Your journal entries, submissions, interviews and profile stay exactly as they are; only what we made of them is removed. And switching a source off never restricts what you can do — adding, confirming, correcting or removing an entry yourself is your statement, not ours, and is never blocked.

You can correct it yourself, item by item. On the Career Twin page you can remove any skill, detach any piece of evidence from a skill it was linked to, and decide whether a lower standing we propose is recorded. Removing a skill is permanent for that item — a later automatic pass cannot quietly bring it back. Where a model has written a short factual note about one of your sessions, you can mark it wrong, which takes it out of your record immediately, with nobody reviewing that decision. Where two things you have told us appear to disagree, you decide: keep one, or say both are true, which keeps both and closes the question. In either case you can also add your own written comment, which is stored with the item, is never sent to any AI provider, and is included if you ask for a copy of your data.

Each skill's standing, and how it moves. Every skill on your record — one you added or ticked yourself, or one your work evidences — has a standing: one of four named steps, which we show beside the graded results behind it. The four are Not shown yet, Shown, Shown consistently and Working on it. A skill starts at Not shown yet, and a skill we first meet through graded work you did here is added at the step that result earns, never below the starting step, even when that result did not pass. Moving up is automatic: one passed piece of graded work puts a skill on Shown, and three put it on Shown consistently. Each piece of graded work counts once however many times you attempt it, and it counts as passed if any attempt passed — a later attempt that does not pass never undoes that. Whether an attempt passed is decided by the same pass rule the page that graded it uses.

We never lower a standing because of results that did not pass unless you confirm it. If three different pieces of graded work on a skill have not passed within the last 90 days, all of them since your last pass on it, we show you those attempts and ask whether to record the skill at Working on it. No lower standing is recorded unless you confirm. If you decline, the skill stays exactly where it was — and we keep your answer, so that we do not ask you again about those same attempts; we ask again only if a different piece of graded work on that skill does not pass. A lower standing you confirmed is not a mark you have to live with, and you can take it back yourself: the skill's own row on your Career Twin page carries a control that takes it straight off, with nothing to do first and nothing to delete — where that skill stands then follows your graded work again, and we will not ask you about that same work again. It also lifts on your next pass on the skill, and it goes altogether if you remove the skill, or delete, detach or switch off the work it cites.

A standing can still fall without a question, when the evidence behind it goes. That happens when you remove a skill, detach evidence from it, or delete the work itself (a mock interview, for instance); when you turn a source off (above); when we correct which skill a piece of our own content evidences — which can take evidence away from a skill you confirmed; when we merge two entries on the skill list that turn out to be the same skill; or when we retire an entry from that list. None of those records anything against you: the standing is simply worked out again from what remains. Evidence growing old never lowers a standing.

Retiring an entry goes further than the rest of that list, so we set it out on its own. Our team retires an entry when it should never have been on the list at all — most often because it means the wrong thing — and a retirement is not a merge: there is no other entry for it to fold into, so nothing moves across. From then on nothing new is ever worked out against it. The next time your record is worked out — and on a large account that can take more than one pass, because each pass walks only part of your work — a skill of yours that we had worked out and that named the retired entry is withdrawn from your record, without your doing anything, and without our asking you first.

Two kinds of entry are left where they are, and only one of them is yours. A skill you added or ticked yourself is left alone: that one is your statement rather than ours. And a skill we only ever guessed from your own words and you never confirmed is left alone too — that one is our guess about you rather than your statement, nothing withdraws it, and it stays on your record naming the retired entry until it expires or you remove it yourself on your Career Twin page. We would rather say that than let you assume anything still there is something you put there.

Nothing else of yours moves — your work, your journal entries and the evidence behind your other skills all stay exactly as they are, and nothing is recorded against you. A target you have set is not edited either: it still asks for the skills it asked for. But if the retired entry is one of them, or if a withdrawn skill was counting towards it, the figure showing how far your record reaches that target goes down, and where the retired entry itself is on the target it can never be evidenced again, so that part of the figure does not come back. A retirement cannot be undone. Unlike an automatic combination it has no 14-day window: there is no before-and-after copy taken at the moment it runs, and nothing to put the entry back from. What does stay is the entry itself — kept on file, marked as withdrawn, with the date we withdrew it and the reason — and because it is still on file, it is included in a copy of your data if you ask for one, and nothing removes it with the passage of time. It stays withdrawn: the retired name cannot be evidenced again, so a skill that leaves your record this way does not come back on its own.

Mock interviews count per competency. An interview can move the standing of each competency it scores that matches a skill on our list, one competency at a time. A competency counts as passed when it averages 6 or more out of 10 across the answers that scored it, and as not passed below that. Answers where we captured no words at all are left out, so an answer we never heard does not count against you; an answer we captured only in part is scored on what we captured. Interviews graded before 07:23:01 UTC on 24 August 2026 stay on your record as practice but carry no passed or not-passed result at all, so they never move a standing.

The figures it produces, and what they mean. Your Career Twin produces three numbers, and we describe them exactly rather than leaving you to guess:

  • a readiness figure against a target you chose and accepted — how far the skills on your record reach that target, with each skill counted by its standing, so a skill on a higher step counts for more. A suggestion counts for nothing until you accept it or other evidence lands against it, and we show no figure at all until at least three pieces of graded work stand behind the target; below that we tell you what would help instead;
  • a match percentage when you give us a job description — the same measurement against the skills that description asks for;
  • a completeness figure for the career twin itself — how much of what we know how to hold, we hold.

These figures and standings measure our evidence about your work, one skill at a time. None of them is a single rating of you as a person, and none predicts what any employer will decide. A standing reflects the graded work you have done here on that one skill, and any lower step you confirmed. A readiness figure is lower when fewer of the target's skills are on your record, or when little graded work stands behind them — which is often a statement about how much you have done here rather than about what you can do. We say so on the page, and we tell you to apply anyway when the role is right.

The figures and standings are automated, and we do not pretend otherwise. But they decide nothing: nothing is withheld from you because of them, no access or price changes, and no third party sees them. They exist to show you where to put your effort. You can dispute or remove any evidence behind them at any time (below), which can change them, and you decide whether a lower standing is ever recorded (above).

A job description you paste, and the skills you take from it. Against an application, you can have a job description read into a proposed list of skills — that reading is a paid feature and is metered — or you can set the list yourself, which is free, and the match figure works the same either way. The list you accept is stored beside that job description, on that application, and is deleted with the application, exactly as the description itself is. You can also remove the list on its own at any time, which stops us measuring your record against it and leaves the application untouched. The record that a figure was shown to you (Section 8) keeps which application and which version of the description it was measured against — never the text of the description.

We do not send your Career Twin, any of these figures, or any skill's standing to employers, recruiters, or any other third party. They are blocked at the source from every place they could leak: they are stripped from promotion packets and review documents you share with a manager, they are never part of a recruiter review you ask for, they never appear in a résumé we generate for you, on your public profile or behind any share link, and no figure or standing is ever included in any email we send. The one part of your career twin an email may carry is in the weekly win prompt: it may name one skill on your target that your work that week included and one skill your career twin suggests you build next, by name only and never with a figure, a count, a standing or the role you are aiming for; or, if you have not set a target or not finished it, it may ask you to. Standings are never sent to our AI provider either — not to draft a résumé, not to prepare an interview, and not to the AI mentor. One qualification, so the sentence is exact: if you open the AI mentor while looking at a page, the skill labels on your career twin are added to the end of the description of that page which goes to our AI provider, so the mentor can answer usefully — labels only, never your evidence, your figures, your standings, your notes or your comments. The labels are the smallest part of what is sent, and the rest of it — which on some pages includes your own code or a score we gave you — is set out in full at the top of this section rather than left for you to infer from this sentence. A standing is not a stored value at all: we work each one out afresh from the evidence in front of us every time we show it to you. Your own copy of your data (Section 10) therefore carries what a standing is worked out from rather than the standing itself — every graded attempt and whether it passed, every lower-standing decision you made and the attempts it cited, and, on each record of a figure we showed you, the standings that figure counted.

What is excluded from it by design, and what changed. Mock-interview video and audio recordings, the composure signal and any integrity score are never used to build your Career Twin and cannot become part of it. Practice conversations are excluded permanently — nothing you say there is recorded, indexed or readable by us, and that is a property of how it is built rather than a promise we keep by choice.

One correction, because we published the opposite and would rather name it than quietly delete it. From 15 September 2026 this page said that proctoring events — the on-device signals described below — had become one of the sources that build your career twin, and that they had their own switch under "What builds your record". Neither was true. There is no proctoring switch, proctoring is not one of the sources listed there, and since your career twin is built from the sources in that list, it is not built from your proctoring events. The integrity score derived from them stays excluded too, as the paragraph above says. A control we told you about and you never had is worth correcting out loud.

Interview transcripts are different, and are off unless you turn them on. What you said in a mock interview is more personal than the grade you were given for it, so we do not fold it in with everything else: reading your transcripts to work out skills requires a separate, explicit permission that you can withdraw at any time, and it is off until you give it. Without it, interviews still contribute — through the competency scores the grading already produced, judged per competency as described above, not through your words.

Legal bases. Building and showing your Career Twin is performance of our contract with you (GDPR); the look back over earlier work, and maintaining the skill list itself, rest on our legitimate interests in making the feature useful from the first visit. Under the DPDP Act, the grounds are the per-purpose ones set out in Section 3, and they are deliberately not all the same.

On permissions, exactly. For the ordinary sources we do not ask for a separate Career Twin permission — the per-source switches are how you stop that processing, and they are switches you turn off, not ones you must turn on. One source is the exception: reading your interview transcripts is a separate, explicit permission that is off until you grant it and that you can withdraw at any time. We keep the two apart on purpose, so that "on unless you stop it" and "off unless you ask for it" never get confused.

Whichever basis applies, you get the same per-source control — you do not need to give a reason, and we act on it rather than weighing it against our own interests. For the parts that rest on our contract with you, that is more than the law requires: there is no statutory right to object to contract-based processing at all.

On-device proctoring

On-device proctoring (privacy by design). Mock-interview face/attention detection runs entirely in your browser using an on-device vision library (Google MediaPipe, etc.). The detailed facial-landmark data never leaves your device and is never sent to us. Only summarised, derived events (such as "face lost" or "gaze away") and their timestamps are transmitted to and stored on our backend.

Turning your spoken answers into text, and the interviewer's voice

This is not on-device processing, and it is set out separately for that reason. Until 27 August 2026 answer transcription was done by your browser and this paragraph sat under the heading above. It no longer belongs there.

Speech-to-text. Your mock-interview answers are graded from a transcript, not from the recording, so your speech has to be turned into text. One provider does that for us: AssemblyAI, a specialist speech-to-text provider that processes the audio in the European Union. It acts as our processor and returns the text to your browser as you speak. Where it cannot run for a given answer, your own browser transcribes instead — a different recipient, described further down this section.

A second provider used to share this work, and no longer does. Until 3 September 2026 an answer could instead be transcribed by Amazon Web Services (Amazon Transcribe), which we called in the India region, and our server decided per answer which of the two handled it. We retired that arrangement: no mock-interview audio is sent to Amazon Transcribe any more, and the two admissions this page owed for that path — that we could not tell you the audio stayed in India, and that we could not tell you it was never used to improve that provider's own services — came off the page with it. AWS is still the provider that hosts the rest of the Service and stores your recordings, in India (Section 6); it no longer turns them into text.

Two things we are not telling you about your answer audio, because we cannot stand behind them. We are not telling you that this audio stays in India: the provider above transcribes it in the European Union, deliberately and on every session it handles, and where your browser transcribes instead your audio goes to your browser's vendor, in whichever country that vendor chooses. And on that fallback path we cannot tell you that your voice is never used to improve someone else's service — that is the browser vendor's decision, under its policies rather than ours. What we can tell you, on every path here, is what we do with it: we do not sell it, we do not show it to other users, and we do not use it to train our own models.

The specialist provider is switched on, and we named it here before it carried anything. The version of this policy published on 1 September 2026 described AssemblyAI in the conditional, because at that point no session had gone to it. That is no longer the conditional: your answer audio is sent to AssemblyAI on every session our server routes there, and it is transcribed in the European Union. It receives the audio of your spoken answers and nothing else — not your recording, not your profile, not your resume, and not anything you type.

That is a transfer out of India, and we are not going to soften it. Everything else about the Service runs in India (Section 6). We pin the European region rather than letting the session be routed to whichever one is nearest, so it is a named place rather than an unknown one — but a named place outside India is still a cross-border transfer, and Section 7 sets out what we rely on for it.

What had to be true before we switched it on, and still has to be true for it to stay on. We do not route a session to that provider except under a paid plan with its model-improvement option switched off — the arrangement under which streaming audio and the transcripts made from it are not used to train or improve its models and are not retained once the session ends. Those are not that supplier's defaults, which is exactly why the option has to be switched off, and it was switched off before the first session was routed to it. This is the only non-training assurance on this page that we actually hold, it covers that provider alone, and it is not a claim about the browser fallback below. If it ever stops being true, this page changes with it and the date at the top moves, so what you read here always describes where your voice actually goes.

If our own speech-to-text is unavailable, your browser does it instead. Your browser's built-in speech recognition is kept as a fallback, and in some browsers (notably Chrome) it sends your audio to the browser vendor (Google), under that vendor's control and policies rather than ours. That path is used when the provider above cannot run for a given answer — for example on an unsupported browser, or when a limit or an outage means we do not open a stream. You are not told which path a given answer took, because there is nothing you can do about it mid-interview; both are described here so that neither is a surprise.

The interviewer's voice. Each question is read aloud in a synthetic voice produced by Google Cloud Text-to-Speech. We send it the text of the question — which is generated from your profile, your job description and your previous answers — and it returns audio. Your own voice and your own recording are never sent to it. Where that synthesis is unavailable, your browser's own built-in speech synthesis reads the question instead and nothing leaves your device for it. This was previously not described here at all; it is, as of 27 August 2026.

5. Cookies and local storage

In short: Two essential sign-in cookies — one keeps you signed in, the other lasts 15 minutes while you sign in with an emailed code — one that records your cookie choice, plus one set by Google's sign-in button. Analytics cookies (Microsoft Clarity and Google Analytics), advertising-measurement cookies (Google Ads and Meta Pixel), and two that record which channel or campaign brought you here, only if you consent. We also set, without asking, a cookie that holds only the codes of our campaign links your browser has opened, so we count each browser once; it is never linked to your account. Some drafts live only in your browser until you save.

This section was added to on 28 September 2026, to describe the campaign-link cookie.

  • Session cookie (cv_session). A strictly necessary, HttpOnly cookie that keeps you signed in. It is set with SameSite=Lax, marked Secure in production, contains your email and an authentication token, and expires automatically. It is not used for tracking or advertising.
  • Sign-in link cookie (cv_signin). A strictly necessary, HttpOnly cookie we set when you ask for a sign-in code on our website, so that the code, and the sign-in button that may come with it in the email, work only in the browser where you asked for them. It is named __Host-cv_signin in production, set with SameSite=Lax, marked Secure in production, and holds a random value, the email address you are signing in with and, if you were on your way to a particular page, that page. It expires 15 minutes after your latest code request and is deleted once you sign in with the code or the button. It is not used for tracking or advertising.
  • Google sign-in cookie (g_state). Drawing the "Continue with Google" button causes Google's sign-in code to set a first-party g_state cookie on our domain. Google uses it to remember sign-in-prompt state, and it contains a randomly generated identifier for your browser. Because that button is on our home page, this is set for visitors who never use it and never sign in. We treat it as necessary to offering sign-in rather than as analytics or advertising, so it is not covered by the consent banner — see Section 2(a1) — but we list it here so you know it is there. It is not used by us for tracking or advertising, and we do not read it. You can clear it like any other cookie in your browser settings.
  • Campaign-link cookie (cv_go). We put links starting careerverse.tech/go/ in our own posts and campaigns. When a browser that is not signed in opens one, we set a first-party, HttpOnly cookie that remembers which of those links that browser has already opened, so that opening one again is not counted twice in how many people it reached. It holds only those link codes — the 20 most recent at most — and nothing about you. It is set with SameSite=Lax, marked Secure in production, and expires 90 days after the last campaign link it counted. We read it only at the moment such a link is opened, never store what it holds, and never link it to an account; it is not used for advertising, and it is not used to credit a sign-up to a link — that uses the sign-up source cookies below, and only if you consent. It is not covered by the consent banner: we rely on our legitimate interests in knowing how many people open our campaign links (Section 3). To object, delete it in your browser settings at any time — that makes no difference to using CareerVerse, though opening another of these links while signed out sets it again; to stop that too, block cookies for this site, which also stops you staying signed in. It is never read or set while you are signed in, and a browser without it is simply counted as new the next time it opens one of these links.
  • Browser local storage. Some features keep drafts and in-progress work locally in your browser for your convenience (for example, resume-builder and resume-tailoring drafts, application-workspace notes, code-editor contents, and interview progress markers). This data stays on your device unless and until you save or submit it.
  • Analytics cookies — Microsoft Clarity (only with your consent). If you accept, Clarity sets cookies to measure product usage and record pseudonymised session replays — for example _clck (a persistent Clarity user id) and _clsk (per session), plus cookies Clarity sets on its own clarity.ms / Microsoft domains. These are non-essential: Clarity is not loaded and none of these cookies are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They are not used for advertising.
  • Analytics cookies — Google Analytics (only with your consent). If you accept, Google Analytics (GA4) sets cookies to measure product usage — for example _ga and _ga_* (persistent, used to distinguish visitors). These are non-essential: GA is not loaded and none of these cookies are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They are not used for advertising.
  • Advertising-measurement cookies — Google Ads (only with your consent). If you accept, we store the Google click identifier from an ad you clicked in first-party cookies (for example cv_gclid) and load the Google Ads tag (which may set its own _gcl_* cookies), to attribute a later sign-up, trial, or purchase to that ad. These are non-essential: none are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They measure our own ads' results and are not used to show you third-party ads on CareerVerse.
  • Advertising-measurement cookies — Meta Pixel (only with your consent). If you accept, Meta Pixel records page views and a standard event when a genuinely new account is created or a free trial is started — including one that happened earlier in the same browsing session, shortly before you accepted (Section 2(k)) — and may set/read Meta advertising cookies such as _fbp and _fbc to identify a browser and measure or optimise our Meta ad campaigns. _fbc holds the ad-click identifier that was on your link; where the Pixel cannot record it itself — because it only loads once you accept, by which time you may have moved on from the page you arrived on — we write that cookie for it when you accept, from the identifier your own link carried. Both are deleted when you withdraw consent. These are non-essential: the Pixel is not loaded and no Meta Pixel event is sent unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. Meta may use this activity under its own privacy policy and your Meta advertising settings; we do not enable Advanced Matching or send your email to Meta in this implementation.
  • Sign-up source cookies (only with your consent). If you accept, we store how you reached us — channel, campaign, the linking domain, the landing page, and any advertising click identifier, and simply "direct" when you arrive with no marketing link at all — in two first-party cookies (cv_attr for your first visit and cv_attr_last for your most recent). They are read only by us, when you create an account, and are deleted when you withdraw consent. One further cookie (cv_consent) records the choice you made here; it is strictly necessary — without it we cannot tell whether you consented, and it is what stops the cookies above from ever being written. We also keep that choice on your account — what you chose, when, and which version of this notice you were shown — so that we can show what you agreed to. From 11 September 2026 we also read it back, for one purpose: if you are signed in on a device or browser where this cookie is missing, we put your own last answer into it instead of asking you the same question again. Only a decision you actually made is ever restored; a refusal is restored exactly as an acceptance is; a choice you have withdrawn is never restored; and if we cannot find a live answer of yours, or the one we find was made against an older version of this notice, you are simply asked again. Signing out clears this cookie from the browser.
  • We set no non-essential cookie (analytics, advertising, or sign-up source) without your consent, other than the campaign-link cookie above, and we do not use cookies to show you third-party ads on CareerVerse. If you consent to Meta Pixel, Meta may use the resulting activity under its own policy, including for ad personalisation.

6. How we share your data

In short: We share only with the providers needed to run CareerVerse. We never sell your data.

We do not sell your personal data. If you consent, we share limited advertising-measurement data with Google and Meta to measure and optimise our own advertising (Section 2(k)); Meta may use Pixel activity under its own policy, including for ad personalisation. We share data with service providers such as the following:

  • Amazon Web Services (AWS) — cloud hosting, file storage (S3), and compute, in the ap-south-1 (Mumbai, India) region. Your data, including interview recordings, is stored on AWS. AWS also delivers every email we send — sign-in codes, account notices, the reminders in Section 2(o), the win-back message in Section 2(p), the mock-interview follow-up in Section 2(p1) and the rest listed in Section 2(q) — so it receives your email address, and the message itself, in order to send them. It adds open and click tracking to every one of them (Section 2(q), which also names the one link we tell it not to track): the tracking image is fetched from, and every tracked link redirects through, an AWS-operated host, which is where your network address and mail-client or browser information go when a copy is opened or a link in it is clicked. AWS keeps a per-message delivery and engagement history for each recipient, which we can look up, and it reports delivery, open and click totals back to us, with no address attached, across all our email and separately for the reminder emails (together with payment-failed notices, which go out the same way), for the win-back message and for the mock-interview follow-up. AWS does not transcribe your spoken mock-interview answers: it did until 3 September 2026, and that arrangement was retired (Section 4). Hosting, storage and mail delivery are what it does for us now, and the hosting and storage stay in that India region.
  • AssemblyAI — in use. It receives the audio of your spoken mock-interview answers for every session our server routes to it, and returns the transcript your answers are graded from (Section 4), processing that audio in the European Union — a transfer outside India, see Section 7. It receives no other content: not your recording, not your profile, not your resume, and not anything you type. We use it under a paid plan with its model-improvement option switched off, so that streaming audio and the transcripts made from it are not used to train or improve its models and are not retained after the session.
  • OpenAI — receives the content described in Section 4 to generate the AI outputs you request.
  • Microsoft (Clarity) — only if you consent to analytics cookies, the pseudonymised interaction data and session replays described in Section 2(j) are sent to Microsoft, which provides the Clarity product-analytics service and processes that data under the Microsoft Privacy Statement, potentially outside India (including the United States). If you do not opt in, no Clarity data is shared.
  • Google (Sign-in) — a "Continue with Google" button appears on our home page, our sign-in screens and your account settings, and drawing it loads Google's sign-in script, so Google receives your IP address, basic device and browser information, the page address, and any Google cookies your browser already holds at that moment — on the home page this happens on page load, even if you never use the button. If you then choose "Continue with Google", Google confirms your identity to us and sends us your email address, whether Google has verified it, a stable identifier for your Google Account, and — in most cases — your display name and a link to your profile picture (Section 2(a1)). If that request creates your account, our server then fetches that picture from Google's image servers, which tells Google the image was fetched and reveals our server's network address and the time; the image itself comes back to our storage in India (Section 2(a2)). Neither the sign-in nor that fetch is analytics or advertising, so neither is part of the optional cookie consent; Section 3 sets out what we rely on for each. Google processes this under its terms and privacy policy, potentially outside India (including the United States).
  • Google (Analytics) — only if you consent to analytics cookies, the pseudonymised usage and event data described in Section 2(j) are sent to Google, which provides the Google Analytics service and processes that data under Google's terms and privacy policy, potentially outside India (including the United States). GA4 does not store your IP address. If you do not opt in, no Google Analytics data is shared.
  • Google (Ads) — only if you consent to advertising cookies, we send Google the click identifier and a hashed version of your email (Section 2(k)) to measure which of our ads lead to sign-ups, trials, and purchases. Google processes this under its terms and privacy policy, potentially outside India (including the United States). If you do not opt in, no Google Ads data is shared.
  • Meta (Ads / Pixel) — only if you consent to advertising cookies, Meta receives the page-visit, browser/device, network, referrer, and Meta cookie/browser identifier signals described in Section 2(k), plus a standard event with an opaque server-issued event identifier when a new account is created or a free trial is started, to measure and optimise our ads. We do not enable Advanced Matching or send your email, CareerVerse user id, authentication method, plan, amount, or CareerVerse content to Meta in this implementation. Meta processes this under its privacy and cookie policies, potentially outside India (including the United States). If you do not opt in, Meta Pixel is not loaded and no Pixel event is shared.
  • Payment processor (merchant of record) — if you buy a paid plan, a third-party payment processor acts as the merchant of record: it collects your payment and receives your email and transaction/subscription data to bill you and issue any refund. It handles your card details directly; we do not receive or store your full card number. See the billing and refund terms in our Terms of Service.
  • LinkedIn (public fetch) — when you initiate it, our backend fetches the public LinkedIn profile for the username you provide. This is a public-profile fetch, not a LinkedIn OAuth/API login. What it fetches is written into your profile as part of the import itself, overwriting the fields listed in Section 2(g).
  • Google (Cloud Text-to-Speech) — receives the text of each mock-interview question and returns the synthetic voice that reads it aloud (Section 4). It does not receive your voice, your recording, or your transcript. Google processes this under its terms and privacy policy, potentially outside India (including the United States).
  • Browser speech vendor (fallback only) — as described in Section 4, when our own speech-to-text cannot run, transcription falls back to your browser's built-in recognition, which in some browsers routes your audio to the browser vendor (e.g. Google) under that vendor's own policies.
  • Legal and safety — we may disclose data where required by law or legal process, or to protect the rights, safety, or security of our users, the public, or ASOasis.
  • Business transfers — if ASOasis is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this Policy or a successor policy.

We require our service providers to protect personal data and to use it only to provide services to us.

7. International data transfers

In short: We host in India. If your data crosses borders, we use lawful safeguards.

Our primary infrastructure and stored data (including interview recordings) are hosted in India (AWS ap-south-1, Mumbai). Some processing involves transfers outside India — in particular, AI inputs sent to OpenAI, the text of mock-interview questions sent to Google (Cloud Text-to-Speech), authentication data sent to Google (Sign-in) — which includes the connection data described in Section 2(a1), sent when the sign-in button loads rather than only when you use it — and, where you consent, interaction data sent to analytics providers (Microsoft (Clarity) and Google (Analytics)) and advertising-measurement data sent to Google Ads and Meta Pixel — which may be processed in the United States or other countries. Your mock-interview audio is missing from that list on purpose, not by oversight: it is the one transfer we will not summarise in a clause, and it has its own paragraph next.

Your mock-interview audio needs its own paragraph, and this is the honest version of it. One provider transcribes it for us, and your own browser is the fallback when that provider cannot run (Section 4). AssemblyAI processes it in the European Union — not a "may" and not an accident of routing, but a deliberate transfer outside India on every session that takes that path, which is why it was named here before it carried anything rather than after. We pin that European data zone rather than letting the connection be routed to whichever one is nearest, and one honesty point belongs with that claim rather than buried under it: the short-lived credential your browser opens the session with is issued through the provider's global endpoint rather than a European one, so the request for it is not itself EU-resident — it carries no audio and no transcript, only the permission to open a session, and the audio path is the one we pin. Until 3 September 2026 a second provider in the India region took the answers we did not route to the EU one, and this paragraph carried a third leg for it; that provider was retired and the leg went with it, so the EU transfer is now the only one we make for this audio ourselves. On the fallback path — where your browser transcribes instead — your audio goes to your browser's vendor, under that vendor's own policies and outside our control, which is very likely to be outside India. So every path here does or may involve a transfer outside India. If you would rather not have any of that happen, do not start a mock interview: it is the one feature this applies to, and the consent screen before it starts is where we ask.

One flow on this page runs the other way. When we fetch your Google profile picture as your account is created (Section 2(a2)), the image travels into India and comes to rest on our storage there; what leaves is only the request for it, described in Section 6. An inbound copy like that is not a restricted transfer, so the safeguards below are not what protects it — we mention it so the direction is not left to guesswork.

For users in the EEA/UK, where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA, as applicable); you may request a copy via support@careerverse.tech.

For users in India the answer has to be given twice, for the reason Section 3 sets out: the DPDP Act's own provisions do not commence until May 2027, so pointing only at that Act would name no safeguard that is operative today. Today, the law that governs these transfers is the Information Technology Act, 2000 and the 2011 Rules made under it. Rule 7 of those Rules permits a transfer only to a recipient that ensures the same level of data protection the Rules require, and only where the transfer is necessary for the performance of a lawful contract with you or you have consented to it. Both of those limbs are what we rely on for your mock-interview audio — the transcript is the artefact the exercise is graded from, and the consent screen before recording starts is where we ask you — alongside the contractual requirement stated at the end of Section 6 that every provider protect your data and use it only to provide services to us. From May 2027, when ss.3–17 commence, these transfers must additionally comply with the DPDP Act, including any restriction on transfer to a particular country that the Central Government notifies under s.16; we will follow whatever it notifies.

8. How long we keep your data

In short: We keep your data while your account is active, then delete or anonymise it within a reasonable period. Your conversations with the AI mentor are kept while your account is open, are deleted when you close it, and are included in a copy of your data.

This section was added to on 25 September 2026, to say how long we keep a word you told us means a skill, and a company you tag on a practice problem; and on 30 September 2026, to add the reminder to look at skills you typed again once your account is a week old, and how long we keep a match we made for a skill you listed.

Some parts of your Career Twin (Section 4) clear themselves on fixed clocks, whether or not you act:

  • A skill we guessed from your own text and you never confirmed is deleted after about 180 days — unless other evidence lands against that skill first (graded work you complete here, a role on your profile, or a journal entry). Then it is no longer a guess: it stops expiring and stays like any other skill with evidence behind it, and if that evidence later goes, the 180-day clock starts again. A guess that expires is genuinely deleted, not hidden.

  • The record of the sentence we read it in — the "your own words" entry that shows you why we suggested a skill — is deleted after about 180 days as well, and this one runs whether or not you confirmed the skill. Confirming the skill keeps the skill; it does not keep the quotation behind it. Any comment you added to that entry is stored on it and goes when it goes, so if you want to keep what you wrote, keep your own copy.

  • A short factual note a model wrote about one of your sessions is deleted after 12 months.

  • A disagreement between two things you have told us that you never settle lapses after about 365 days, and both statements are released.

  • A lower standing you declined is kept for 90 days after the newest attempt it concerned, so that we do not ask you again about the same attempts. It goes sooner if you delete, detach or switch off the work it cites.

  • A record that a figure was shown to you — what the readiness or match figure was, how much lower it could have been, what it was computed from, including the standing of each skill it counted, and, where the figure was measured against a job description, which application and which version of that description — is deleted after 12 months. We keep it so we can tell whether our figures are any good, and we delete it because a permanent log of every number you were ever shown serves no purpose to you. It never holds the text of a job description.

  • A job description you paste is held against the application it belongs to and is deleted with that application, and so is the set of skills you accept from it. It is a third party's text, and we have no reason to keep it once the application is gone.

  • A copy of your own records, taken so that an automatic combination can be undone (Section 4) is kept until that 14-day window closes, and clears itself within a week after. It is taken before the change is made, it holds your own records and nothing anyone else supplied, and it exists for one purpose: to put your record back exactly as it was if the combination is reversed. It is included if you ask for a copy of your data, and it goes when you close your account.

  • A record that a skill name has been seen by this account is kept for 90 days after the last time that name was seen. We keep it to tell whether three different people have met the same new name — which is one of the ways a name reaches the shared list, the one that lets a name we were not sure enough about on its own get there after several people have used it. A name we are sure enough about is added without it. It holds a one-way code for the name, computed with a secret only we hold so the name cannot be read back out of it — never the name itself — and nothing about where you typed it or what else you were doing.

  • A reminder to look at the skills you typed again, once your account is a week old, is kept for up to 30 days. For a new account's first week we do not send a skill name we do not hold to an AI to be matched to or added to the skill list, so when you save one in that week we note that your account should be looked at again once it is seven days old, and then we check your saved skills a second time in the same way as described above. The reminder holds no skill name and no text — only that your account is due, on which day, and how many times we have tried — and it is deleted when that check is done, after three tries, or when you close your account. It is included if you ask for a copy of your data.

  • A match we made for a skill you listed — your name for the skill from your profile and the skill on our list we matched it to (Section 4) — ends, and is deleted, within about 180 days of when we made it: sooner if it came from an answer our AI had given earlier, because a match lasts only as long as the answer it came from, and sooner still if you switch Profile off or close your account. If you choose Not what I meant for one under "Skills we matched from your words" in your account settings, we keep that answer, which holds the same two names, until the match would have ended; switching Profile off or closing your account deletes it sooner. When a match ends or you turn it down, the skill it added is withdrawn from your record the next time your record is worked out in full, unless you added or ticked it yourself or something else still supports it; the withdrawn entry stays on file, marked as withdrawn. Matches and answers are both included if you ask for a copy of your data.

Three parts of your Career Twin have no clock at all, and are kept until you act. We are naming them here rather than leaving them out, because a retention section that lists only the things with timers is not a complete answer.

  • A lower standing you confirmed is kept until you take it off from that skill's own row (Section 4), your next pass on the skill lifts it, you remove the skill, or you delete, detach or switch off the work it cites. In those last cases it is trimmed to what remains, and deleted once fewer than three pieces of graded work stand behind it.
  • A skill we no longer ask you about — one you asked us to stop suggesting, or one added for you when two entries on the skill list turned out to be the same skill — is kept until you take it off. All of them are listed under "Skills we no longer ask you about" in your account settings, the ones you did not ask for included, and each is removed from there. Being on that list keeps a skill out of our suggestions and nothing more: nothing is deleted from your record by it, and work you do that shows the skill still counts.
  • A word you told us means a skill — one you used that we did not hold by that name, stored with the skill you picked for it so that we read that word your way — is kept until you take it off under "Your own words for skills" in your account settings or close your account, and taking that skill off your record does not remove it.

Three more are kept for as long as the thing they belong to.

  • The result we keep for a graded attempt — passed or not passed — is kept with our record of that attempt, and is deleted when that record is: when you delete the work, turn its source off, or close your account. Detaching the attempt from a skill does not delete it.
  • A copy of your target's skill list, kept alongside the target so we can find it again, goes when a skill leaves the target or when you delete the target.
  • A record that a profile import ran — which provider, when it first ran and when it last ran, and nothing it fetched — is kept until you close your account. It stays when you switch Profile off, because it records something you did rather than something we worked out.

A skill you confirmed yourself does not expire — it is your statement, and it stays until you remove it. As the second bullet says, that is true of the skill itself and not of the quoted sentence we first read it in.

A display name or photo copied from Google when your account was created (Section 2(a2)) is kept like any other profile field: it is a one-time copy that we never refresh, so changing or deleting the picture on your Google Account does not change or delete ours, and disconnecting Google sign-in does not remove it either. Editing or clearing it in your profile is what changes it here.

A company you tag on a practice problem, as one that asks it, is stored against your account and has no clock: it is kept until you remove your tag from that problem, we delete the problem, or you close your account.

We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete specific content (such as an interview recording or forum post), we remove it from active systems, though it may persist briefly in routine backups. When you close your account, we delete or anonymise your personal data within a reasonable period, except where longer retention is required by law. If you would like to know the retention period that applies to a specific category of data, contact us at support@careerverse.tech.

This part of Section 8 was rewritten on 24 September 2026. Until then it said that we could not delete your conversations with the AI mentor at all, and that a copy of your data did not include them. Both have changed, and what follows is the position now.

Your conversations with the AI mentor have no clock of their own, so here is exactly what removes them. Nothing removes them with time: they are kept for as long as your account is open. Closing your account deletes them, and so does asking us to erase your account. That is the only way they go. There is no control anywhere in the Service that deletes one conversation on its own, and we do not delete one for you on request while you keep your account. Like other content we delete, they may persist briefly in routine backups.

What is kept, and what goes, is the exchange itself — what you typed, what the mentor replied, and when — and a running summary of the conversation that the mentor writes as you go, so it can remember what you have already discussed. That summary is our own prose about what you told it. It is kept alongside the exchange, on exactly the same terms, and it goes when the exchange goes. When a conversation goes, all of it goes: your messages, the mentor's replies to them, and the summary. A copy of your data includes every conversation: your messages, the mentor's replies, when each was sent, the summary, and, for a conversation you opened from a page, a short label for that page.

So four of your rights now reach every one of your mentor conversations: access, a copy, taking them elsewhere, and erasure — though erasure reaches them only together with your account. Two rights still stop here for every conversation: correcting what one of them holds, and restricting the processing of one. Section 10 sets out why, where the rights themselves are stated. The plain advice therefore still holds: do not type anything into the mentor that you would later need us to correct, or to delete while you keep your account. Apart from our ordinary server logs (Section 2(h)), two things we keep that are connected with the mentor do not go when your account does. One is the running count of your mentor messages that we keep to apply your plan's limits: it holds how many you have sent in the current day and month and when it was last updated, never anything you wrote, and it clears itself within about six weeks of that last update, which is normally your last message. The other is the audit record kept for each page description, which Section 4 describes: each is deleted about 90 days after it was made, and closing your account does not remove it sooner.

9. How we keep your data safe

In short: We use sensible technical and organisational measures, and a passwordless sign-in.

We take reasonable steps to protect your data, including: passwordless sign-in via email OTP (there is no password to steal); a secure, HttpOnly session cookie that client-side scripts cannot read; server-side handling of your authentication token so it is not exposed to the browser; same-origin protections and per-IP rate-limiting on sensitive endpoints; encrypted transport (HTTPS/TLS); and hosting on AWS with access controls. You can end every other signed-in session from your account settings. Stopping Google sign-in also ends the sessions it created, blocks ordinary Google sign-in from silently restoring it, and requires fresh email verification before it can be enabled again — it does not, however, remove a name or photo copied to your profile at sign-up, which by then are ordinary profile fields you control (Section 2(a2)). Keeping facial-landmark data on your device further reduces what we hold. No system is perfectly secure, so we cannot guarantee absolute security. Because we sign you in through your email, keeping your email account secure is an important part of protecting your CareerVerse account.

In the event of a personal-data breach, we will notify the relevant authorities and affected individuals where and as required by applicable law.

10. Your privacy rights

In short: You have strong rights over your data, and the exact rights depend on where you live. Two of them stop short of your AI mentor conversations: we cannot correct one, or restrict what we do with one. And we delete them only together with your account, not one at a time (Section 8). The audit records of page descriptions, which are connected with the mentor, are not part of the copy of your data we put together, though you can ask us for them separately while your account is open, and neither closing your account nor asking us to erase your data removes them sooner: each is deleted about 90 days after it was made (Section 4).

Some of these you can exercise yourself, without contacting us. Under "What builds your record" in your account settings you can stop us working anything out from any source; and on your Career Twin page you can remove a skill, detach a piece of evidence, decline a lower standing we propose or take off one you already confirmed, or mark a model-written note wrong and add your own comment to it. We stop reading the source straight away and begin deleting immediately; on a large account the deletion may take more than one step, and the page tells you if so and offers you a button to finish it (Section 4). That message lives on the page you started it from. If you close the tab before it finishes, write to support@careerverse.tech and we will complete it — the source stays switched off in the meantime, so nothing further is read from it either way.

You can also get a copy of your data, and delete your account, yourself. Under "Your data" in your account settings, you can request a copy of your data and download it once it is ready, and you can delete your account. Both ask you to confirm with a code we send to your email address. While your account has a subscription you have not cancelled, a free trial included, you cannot delete the account there: cancel the subscription first, or write to support@careerverse.tech.

Whatever your location, contact support@careerverse.tech to exercise your rights (India residents may also contact the Grievance Officer in Section 12). We may verify your identity — usually by confirming control of your account email — before acting, and we will respond within the time the law allows. We will not discriminate against you for exercising your rights.

One limit, stated here rather than left for you to discover: your conversations with the AI mentor. A copy of your data includes every one of them, so your rights to access them and to take them elsewhere reach all of them. Closing your account deletes them, and so does asking us to erase your account. But we do not delete one on its own while you keep your account (Section 8). The audit records of page descriptions have limits of their own, which we set out after the list below. Two more limits apply to every mentor conversation, and we would rather state them here than have you discover them by asking us:

  • We cannot correct one. A message is written once and is never edited afterwards, by you or by us, and the running summary the mentor keeps of a thread is rewritten only by the mentor itself, on a later turn of that same thread. So if the mentor has recorded something about you that is wrong, we have no way to put it right, and telling us it is wrong will not change what is stored.
  • We cannot restrict what we do with one. There is no mark we can put on a conversation that says "keep this but stop using it": every later turn of a thread reads what came before it, and the summary with it, and sends them to our AI provider again. The only things that stop that are your not sending another message in that thread — nothing reads a conversation unless you do — and closing your account, which deletes it.

So wherever the rights below speak of correcting or restricting your personal data, read them as stopping at your mentor conversations. Where they speak of erasing it, read that, for your mentor conversations, as erasing them together with your account. The audit records of page descriptions that Section 4 describes have limits of their own. They are not part of the copy of your data we put together, but while your account is open you can ask us for them separately at support@careerverse.tech, and we will send you what they hold about you. Neither closing your account nor asking us to erase your data removes them sooner: each is deleted about 90 days after it was made. The running count of your mentor messages that Section 8 describes is not in that copy either, and neither closing your account nor an erasure request removes it sooner: it clears itself within about six weeks. The rights that none of this touches are these four: objecting to processing, withdrawing a consent you gave, being told the source of data we did not get from you, and complaining to a regulator. Access and taking your data elsewhere reach every mentor conversation, and for the audit records, access works as just described. Section 8 sets out what is kept and what goes.

India (DPDP Act, 2023)

The DPDP Act's rights provisions commence in May 2027 (Section 3). We are not waiting for that date — everything below is available to you today on request, whether or not the Act yet compels it.

You have the right to: access a summary of the personal data we process about you and related processing; correct, complete, update, and erase your personal data; grievance redressal (Section 12); and nominate another individual to exercise your rights in the event of your death or incapacity. Where we rely on consent, you may withdraw it at any time, as easily as it was given.

Separately, and in force now, section 43A of the Information Technology Act, 2000 and the 2011 Rules give you a route to compensation for a failure to protect sensitive personal data; a claim under it goes to an adjudicating officer under section 46 of that Act. Where CareerVerse acts as an intermediary in respect of content other users post, the Grievance Appellate Committee under the IT Rules 2021 can hear an appeal against our Grievance Officer's decision on such content.

European Union and United Kingdom (GDPR)

You have the right to: access your personal data and obtain a copy; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict or object to certain processing, including processing based on our legitimate interests; data portability; withdraw consent at any time where we rely on it; be told the source of personal data we did not get from you directly — such as the display name and photo Google gives us when an account is created through "Continue with Google" (Section 2(a2)), or what a LinkedIn import fetched (Section 2(g)); and lodge a complaint with your local supervisory authority. We do not use solely automated decision-making that produces legal or similarly significant effects on you. Your Career Twin is assembled automatically and does produce figures about you — a readiness figure, a match percentage and a completeness figure — and a standing for each skill on your record (Section 4) — but those figures and standings decide nothing: nothing is withheld from you because of them, no access, price or eligibility turns on them, and they are never shared with employers, recruiters or any other third party. You can see every piece of evidence behind them, dispute or remove any of it, decline a lower standing we propose, and add your own written comment, which is stored with the item and included if you ask for a copy of your data.

California (CCPA/CPRA)

You have the right to: know what personal information we collect and how we use and disclose it; access and obtain a copy of it; delete it; correct inaccurate information; opt out of sale or sharing for cross-context behavioural advertising; and not be discriminated against for exercising your rights. We do not sell personal information. Meta Pixel activity may constitute "sharing" under California law, but it remains off unless you opt in; declining the banner or choosing "Turn off" under "Cookie preferences" exercises that opt-out.

11. Third-party links

The Service may contain links to third-party websites and services that we do not control (including the LinkedIn, GitHub, and portfolio links you add). This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Please review their policies before providing them your information.

12. Grievance Officer (India)

In short: In India, you can raise privacy concerns with our Grievance Officer.

In accordance with India's DPDP Act and the Information Technology Act, 2000 and rules thereunder, you may contact our Grievance Officer regarding the processing of your personal data:

We will acknowledge and address grievances within the timelines required by applicable law. If your grievance is not satisfactorily resolved, you may approach the Data Protection Board of India.

13. Children

In short: CareerVerse is for adults only.

The Service is intended only for individuals aged 18 or older, and we do not knowingly collect personal data from anyone under 18. We do not direct the Service to children, track or profile children, or target advertising at them. If you believe a person under 18 has provided us personal data, contact support@careerverse.tech and we will take reasonable steps to delete it and close any associated account.

14. Content you post in public areas is public

In short: Discussions and comments you post in the public Community are visible to anyone on the internet and can appear in search engines. Posting anonymously hides your name from other people, but not from us. Don't post anything you need to keep private.

The public Community. CareerVerse includes a public Community. A discussion you post there — and comments on it — is visible to anyone on the internet, whether or not they have a CareerVerse account, and may be crawled, indexed, and displayed by search engines. Along with your title and text, this includes any tags and image, and associated information such as vote counts, the number of comments, and the times you posted or edited; some of this is also published as machine-readable structured data for search engines. It is not private and is not limited to signed-in members. (Replies nested under a comment are, for now, shown only to signed-in members — but you should treat anything you post as capable of becoming public.)

Once it's public, it's out of our hands. Anyone on the internet — including people and companies not bound by our Terms — can copy, screenshot, cache, republish, or use your public Community content to train AI or other systems. We cannot control or prevent that, and deleting a post cannot claw back copies others have already made.

Posting anonymously. If you post anonymously, we hide your name and profile photo from other users and the public. Anonymity protects your identity from other people — not from us: ASOasis and its moderators can still see which account posted (for safety, moderation, legal, and your own edit/delete purposes), and it does not make the content itself private — the text, tags, and images you posted remain public. If you post without choosing anonymity, your profile display name and photo are shown publicly with your post.

Post carefully. Do not include personal, confidential, sensitive, or identifying information — yours or anyone else's — in Community content you do not want to be public. You are responsible for what you post (see our Terms of Service).

What is not public here. Discussions attached to specific learning content (such as a course lesson) are not part of the public Community and stay visible only to signed-in users. This section covers the public Community feed and its discussion pages.

Deleting public content. When you delete a Community post or comment, we remove it from public view on CareerVerse promptly. Copies may persist briefly in routine backups (see Section 8), and — as noted above — search engines and other third parties may keep copies that we cannot remove for you.

Public profile. Separately, you can give yourself a public profile by claiming a handle (your personal URL). Claiming that handle makes the profile public — we tell you so on the form before you confirm — and from then on the sections you have filled in are public and may be indexed by search engines. If your account was created through "Continue with Google", remember that your name and photo were filled in for you (Section 2(a2)) — so check them before you claim a handle, because publishing publishes those too. Accounts have no public profile until you claim a handle, sensitive contact details are always excluded, and you can switch back to private at any time from your account settings.

15. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where the changes are material, provide additional notice through the Service or by email where appropriate. Where the law requires fresh consent, we will obtain it.

16. YouTube

CareerVerse, through its internal tool CareerVerse Social Publisher, uses YouTube API Services to publish CareerVerse's own videos to its official YouTube channel (@CareerVerse_Tech) and to find recent public YouTube videos about careers.

See the Google Privacy Policy: http://www.google.com/policies/privacy.

When our channel owner authorises the tool, we store a Google authorisation token limited to the youtube.upload permission. It lets the tool upload videos to the channel, set their thumbnails, upload a channel banner image and set the channel's watermark; it cannot delete anything. The tool uses it only to upload videos. We send YouTube each video with its title, description, visibility setting and made-for-kids setting. From each upload we keep the video ID YouTube returns, including any copy our tool posts in our team chat, for no longer than 30 days unless we refresh it from YouTube.

Once a day we search YouTube for recent public videos about careers, and we read our own channel's public upload list. From these we keep video IDs, channel IDs, titles and publish dates. We use them only to pick videos our team may watch or comment on by hand, and to confirm that our own uploads went live. The links are shown to our team in our internal workplace chat. Titles may be sent to an AI provider (Google Gemini) to suggest a draft comment that a person reviews. We do not sell this data, use it for advertising, or share it with anyone else. We delete it within 30 days of retrieving it, including the copies of YouTube links our tool posts in our team chat.

To ask us to delete the YouTube data we store, or to withdraw CareerVerse's access through us, email support@careerverse.tech. We revoke our access token with Google right away and delete the stored YouTube data within 7 days. In addition to that procedure, you can revoke CareerVerse's access at any time at https://security.google.com/settings/security/permissions. If you do, we delete the stored YouTube data within 30 days. Deleting the data CareerVerse stores does not affect any data stored by YouTube. To delete data on YouTube itself, use YouTube (for example YouTube Studio) or another authorised app that supports deleting it.

17. Contact us

For any privacy question or to exercise your rights:

  • Email: support@careerverse.tech
  • Company: ASOasis Tech Private Limited, India
  • India DPDP Grievance Officer: see Section 12.