Privacy Policy

Last updated: 20 August 2026

In short: This policy explains what personal data CareerVerse collects, why, and the rights you have. We use passwordless sign-in — an emailed one-time code, or "Continue with Google" if you choose it (note that Google's sign-in button loads on our home page, so Google sees your visit even if you never use it — Section 2(a1); and if you create your account that way, we start your profile with the name and photo from your Google Account — Section 2(a2)) — store your content to run the Service, and send some text to a third-party AI provider (OpenAI, etc.) to power AI features. We also build a Track Record for you automatically from work you complete here — it produces no score or verdict, decides nothing, and we do not send it to employers or anyone else; you can switch off any source of it at any time in your account settings, which also deletes what we derived from that source (Section 4). We use optional third-party analytics (Microsoft Clarity, Google Analytics, etc.) and advertising-measurement (Google Ads and Meta Pixel) tools that load only if you consent, and — again only with your consent — record which channel or campaign brought you to us (Section 2(l)). We advertise CareerVerse and measure which ads lead to visits, sign-ups, and free-trial starts — including sharing a hashed (irreversible) version of your email with Google to match those results and page-visit/browser signals with Meta — but we do not sell your data or show third-party ads on CareerVerse. Anything you post in the public Community is visible to anyone and can appear in search engines (see Section 14).

This Privacy Policy explains how ASOasis Tech Private Limited ("ASOasis", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the CareerVerse website and related features (the "Service"). It is designed to meet India's Digital Personal Data Protection Act, 2023 ("DPDP Act") — the statute that will be our primary data-protection law once its main provisions commence in May 2027, and which we are already building towards — as well as the EU and UK GDPR and the California Consumer Privacy Act (CCPA/CPRA), where applicable. The Indian law that binds us today is the Information Technology Act, 2000 and the 2011 Rules made under it. Section 3 sets out both, and is honest about which is which. Read this policy together with our Terms of Service.

The Service is intended only for individuals aged 18 or older (see Section 13).

1. Who we are

ASOasis Tech Private Limited, a company incorporated in India, is responsible for your personal data. We are the Data Fiduciary for the purposes of the DPDP Act, the Controller under the GDPR, and the Business under the CCPA/CPRA.

2. Information we collect

In short: The information you give us, the content you create, and a little technical data to keep you signed in — plus, if you create your account with "Continue with Google", the display name and profile photo Google hands us at that moment — profile data that reached us from a company rather than from you (Section 2(a2)). If you consent, we also collect pseudonymised product-analytics through third-party tools (Microsoft Clarity, Google Analytics, etc.), use advertising tools (Google Ads and Meta Pixel) to measure which ads bring people to CareerVerse, and record which channel or campaign your own sign-up came from. Separately, and regardless of that choice, we keep aggregate counts of how often things happen across the Service with no identifying data attached (Section 2(m)).

a. Account and authentication data. Your email address, used for one-time-passcode (OTP) sign-in, and an authentication token kept in a secure session cookie. We do not collect or store passwords. When you request a sign-in code, your IP address may be forwarded to our backend for rate-limiting and abuse prevention.

a1. Sign in with Google (optional). If you choose "Continue with Google", Google confirms your identity to us and sends us a signed assertion containing your email address, whether Google has verified it, a stable identifier for your Google Account, and — in most cases — your Google display name and a link to your Google profile picture. We use that identifier to recognise you on later sign-ins, and we store it alongside your account; what we do with the name and picture is set out in Section 2(a2) below. We never receive your Google password, and we do not request access to your Gmail, Drive, Contacts, or any other Google data — the name and the picture link are simply fields inside the signed assertion, not access to your account. Because CareerVerse issues its own session, signing out of Google does not sign you out of CareerVerse. Google sign-in works only when Google's verified email exactly matches your current CareerVerse sign-in email; if the Google address changes, you must instead use the one-time code sent to your existing CareerVerse email, and Google does not silently change that address for you. If you stop using Google sign-in in your account settings, this does not affect your Google Account: we disable the identifier in CareerVerse, end CareerVerse sessions created through it, and retain the disabled record so ordinary Google sign-in cannot silently restore that access. It does not remove a name or photo that was copied onto your profile when the account was created (Section 2(a2)) — by then they are ordinary profile fields, and yours to change or clear. To enable it again, you must first verify your CareerVerse email with a fresh one-time code and then choose a Google Account with that same email. Active and disabled Google sign-in history is visible in your account settings.

A "Continue with Google" button appears on our home page and on our sign-in screens. It appears in account settings only if you explicitly start re-enabling a disabled Google sign-in method, and only after email verification. Drawing that button loads Google's sign-in code, and when it loads Google receives your IP address, basic device and browser information, the page address, and any Google cookies your browser already holds — so if you are signed in to Google, Google can recognise you at that moment. On the home page this happens as soon as the page loads, whether or not you ever use the button; on a sign-in screen it happens when that screen opens. To us, however, nothing about your Google account is revealed unless you actively choose "Continue with Google" — and we do not use Google's automatic "One Tap" prompt, so no Google sign-in prompt ever appears on its own. (Drawing the button also makes one request to our own backend to mint a single-use security token; as described in 2(a), your IP address may be processed for rate-limiting and abuse prevention.) See Google's Privacy Policy.

a2. Starting your profile from Google (new accounts only). If your CareerVerse account is created by "Continue with Google", we start it with the display name and profile picture from that signed assertion, so you do not begin with an empty profile. Profile information reaches us from a company rather than from you in one other place — a LinkedIn import you start yourself (Section 2(g)). This one is different because you never asked for a profile change at all: it happens as a side effect of creating your account. That is why we set it out on its own. It happens once, at the moment the account is created, and only then:

  • It never runs on a later sign-in, and never when Google is connected to an account that already existed — that is an existing account gaining a sign-in method, and nothing about your profile changes.
  • It never writes over anything already filled in. If a field already has a value, we leave it exactly as it is.
  • It is best-effort. If Google sends no name or picture, or the picture cannot be fetched, that field is simply left empty and your sign-in carries on normally.

For the picture, our server fetches the image from Google once and keeps our own copy, on our storage in India (Section 6). We do not keep Google's link to it on your profile — only our copy — so displaying your photo on CareerVerse makes no request to Google, and a page showing your avatar never tells Google you were there. From that moment it is an ordinary profile photo in every respect: it appears wherever a profile photo appears, and you can replace or remove it in your account settings exactly like one you uploaded yourself.

Because it is a one-time copy, it is a snapshot, not a mirror: changing or deleting the picture on your Google Account later does not change or delete ours, and neither does disconnecting Google sign-in (Section 2(a1)). Editing or clearing the fields yourself is what changes them here. On the one sign-in path that asks you for an emailed code before finishing, we hold the name and the picture link on a server-side record tied to that attempt. It is never sent to your browser, and it expires automatically — though, like our other records, a copy can survive for a while afterwards in routine backups (Section 8).

b. Profile data. Name, headline, summary, phone number, location, profile photo, skills, languages, work experience, education, and LinkedIn/GitHub/portfolio URLs. You give us most of it directly. Two things can arrive another way: on an account created through "Continue with Google", the name and profile photo are filled in from your Google Account at that moment (Section 2(a2)), and a LinkedIn import writes what it fetched into these fields (Section 2(g)). Either way they are ordinary profile fields afterwards, yours to change or clear.

c. Resume. A resume file you upload (e.g. PDF), and information derived from it when you use AI resume features.

d. Job-application records you create in the application tracker.

e. User-generated content. Forum posts, comments, and images; code submissions; system-design canvases; project write-ups; and the text you enter into AI features (including job descriptions and mentor-chat messages). Content you post in the public Community is visible to anyone and may be indexed by search engines — see Section 14.

f. Mock-interview data. Camera video and microphone audio recordings; the transcript of your spoken answers; and derived proctoring events with timestamps (for example, "face not detected", "multiple faces", "gaze away", tab switch, window blur, full-screen exit, camera or microphone disconnect, or attempted copy/paste), from which an integrity signal is derived. If you switch on the optional composure estimate during an interview, we also store the summary figures it produces — one per answer and one for the session — which are worked out on your device, so that your account page can show you your own trend; we do not use them in grading. We do not receive or store the underlying facial-landmark data, or any video from the composure estimate — that is computed and stays in your browser (see Section 4).

g. LinkedIn import data. If you choose to import from LinkedIn, the data fetched from a public LinkedIn profile you specify (such as name, skills, and experience), shown to you as suggestions. This is not stored on our servers unless you save it to your profile.

h. Limited technical data. Information necessary to operate and secure the Service, such as the IP address forwarded for rate-limiting and standard server logs.

i. Billing data. If you purchase a paid plan, your payment is processed by a third-party payment processor acting as the merchant of record (see Section 6). We receive your email address and limited transaction and subscription data (such as plan, amount, currency, status, and renewal dates) needed to provision your access and keep our records. We do not receive or store your full payment-card number — card details are handled by the payment processor.

j. Product-analytics data (only with your consent). If you accept analytics cookies, we use third-party analytics tools (Microsoft Clarity, Google Analytics, etc.) to understand how the Service is used. Clarity captures pseudonymised interaction data — pages viewed, clicks, scrolls, mouse movement, approximate location inferred from IP (not stored by us), and device/browser type — and session replays (a reconstructed playback of your visit). We configure Clarity to mask the text you type and other sensitive input, so it is not recorded. Google Analytics (GA4) measures pseudonymised usage — pages viewed, events (such as starting an interview or completing a lesson), approximate location inferred from IP, device/browser type, and site-performance (Core Web Vitals) and error signals; GA4 does not log or store your IP address, and we do not enable Google Signals, advertising features, or cross-site ad profiling. Neither tool is loaded at all unless you consent, and you can withdraw consent at any time via "Cookie preferences" in the site footer. See Sections 5–7.

k. Advertising-measurement data (only with your consent). If you accept, we use Google Ads and Meta Pixel to measure and optimise our own advertising. When you arrive from a Google ad, Google adds a click identifier to the URL; we store it in a first-party cookie and later send it to Google to attribute a resulting sign-up, trial, or purchase (a "conversion"). To improve matching we also send Google a hashed (SHA-256, irreversible) version of your email — not your raw email — using Google's "Enhanced Conversions". Meta Pixel sends Meta the pages you view, the page address and referrer, the time of the visit, browser/device and network information (including IP address), and Meta cookie/browser identifiers so Meta can measure and optimise our ads. When you arrive from a Meta ad, Meta adds its own click identifier to the URL; if you accept, we store it and provide it back to Meta (in Meta's _fbc cookie, together with the time of the click) so a resulting sign-up can be matched to the ad you clicked — the purpose that identifier was put on your link for. When a consented visitor creates a new CareerVerse account, or starts a free trial of Premium, the Pixel also sends Meta the corresponding standard event (registration or trial started), carrying at most one opaque event identifier — issued by our systems for a registration, and by our payment processor for a trial — so the same action can be deduplicated if server-side measurement is added later. Those events contain no email, CareerVerse user id, authentication method, plan, amount, profile data, form values, or other custom data. If you create your account or start your trial before answering the cookie banner and then accept, that one event identifier is held in your browser's memory only — never written to your device, never sent anywhere — and the event is sent once you accept, for up to 30 minutes; if you decline, close the tab, or reload the page first, it is discarded and nothing is ever sent. This implementation does not enable Meta Advanced Matching or send your email, profile data, resume, application records, or the text you enter into CareerVerse to Meta. Meta may associate Pixel activity with a Meta account and use it according to its privacy and advertising settings, including for ad personalisation. Neither advertising tag is loaded, and no advertising-measurement cookie is set by us, unless you consent; you can withdraw consent at any time via "Cookie preferences" in the footer. We do not show third-party ads on CareerVerse.

l. Sign-up source (only with your consent). If you accept, we record where your sign-up came from and keep it on your account: the marketing "channel" (for example paid search, organic social, email, or direct), the campaign name or id, the website that linked you (the domain only — never the full address or what you searched for), the page you first landed on, the time, and any advertising click identifier that was on the link. We use this only to understand which of our own channels and campaigns bring people to CareerVerse. It is first-party — recorded by us, kept by us, and not shared with any advertising platform for this purpose. (The advertising click identifier is the one exception, and only for a different purpose: it is separately used to measure our advertising, as Section 2(k) describes, which is what the ad platform put it on your link for.) Nothing is recorded unless you consent, the first source we record for you is never overwritten, and withdrawing consent via "Cookie preferences" in the footer permanently deletes it — a later change of mind cannot bring it back.

m. Aggregate activity counts (no identifying data). We keep plain running totals of how often certain things happen across the whole Service — for example how many accounts were created, how many signed-in visitors reached the pricing page or opened checkout, how many free trials began, and how many lessons were completed. These are counts only: each records that something happened once, with no user id, email, device identifier, cookie, or IP address attached, and nothing about you is stored beside them. The counts themselves therefore cannot be traced back to you, filtered to you, or used to single you out; they are held in our own cloud infrastructure, are not shared with any advertising platform, and are not sold. To be precise about what that does and does not cover: it is a statement about the counts, not a claim that no record of your request exists anywhere — our ordinary server logs, described in Section 2(h), record requests as they do for the rest of the Service, and are kept and deleted on the same basis. The counts are not derived from those logs and cannot be joined back to them by us. We use them to see whether the Service — and the journey from signing up to upgrading — actually works. Because they contain no personal data, they are not part of the optional cookie consent and are unaffected by withdrawing it; the third-party analytics and advertising tools in Sections 2(j) and 2(k), which do involve personal data, remain consent-only.

One more thing this paragraph is not. Everything above is a statement about these counts — it is not a claim that we never measure anything against your account. Separately from them, and not part of them, we mark which days your account was active, and record which growth lens you chose, and we roll those up into cohort figures to see whether people come back and whether a feature is worth keeping (Section 3). Those markers sit on your account rather than in the counts, are never shared with any advertising platform, and go when your account goes.

n. Your Track Record (what we work out from your own activity). CareerVerse builds a Track Record for you: a list of the capabilities your work here can evidence, and what evidences each one. We assemble it automatically, from activity you have already carried out — your achievement-journal entries; your profile headline, summary, work history and the skills you have listed; mock interviews you have sat; coding solutions you have submitted; projects you have submitted; system-design sessions you have completed and the notes recorded during them; and courses and course exercises you have finished. What we store is mostly pointers and labels: which capability, which piece of your own work supports it, when that work happened, and whether the link was chosen by you or worked out by us. There is free text alongside those pointers, and it is worth being exact about who wrote it: the only prose we generate is a short factual note about a completed session — an observation, never a judgement (Section 4). The rest is yours: the target role you type in if you set a goal, and any comment you add to an item. Every entry says where it came from, and you can remove or detach it. Section 4 explains how it works, how to stop it, and how long each part is kept.

What we do not do. We do not sell your personal data or show third-party ads on CareerVerse. Our advertising is limited to running and measuring our own campaigns on platforms such as Google and Meta (Section 2(k)); those platforms may use the consented advertising signals under their own policies. The third-party tools we use include Microsoft Clarity, Google Analytics, Google Ads, and Meta Pixel, each loaded only with your consent (see Sections 5–7).

3. How and why we use your data, and our legal bases

In short: To run CareerVerse for you, keep it working and honest, and meet our legal duties. Each use below gets its own line, and each answers two separate questions: the basis under the EU and UK GDPR, and the ground we expect to rely on under India's DPDP Act once its main provisions commence. Those are not the same list and we have not pretended they are. Where a line says consent, there is a real switch and we tell you where it is; where there is no switch, we do not call it consent.

A note on how we cite. Everywhere else in this policy, "Section 5" means a section of this document. In the tables below we are citing statutes, so we write those as DPDP s.7(a) or GDPR Art. 6(1)(b). If you see "s." or "Art.", we mean the Act named in that column, not this policy.

Your account, and the Service you asked for

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Sign you in by one-time email code, or with Google if you choose it, and keep your sessionGive you access to your accountPerformance of a contractDPDP s.7(a) — you gave us your email in order to be signed in
Rate-limit sign-in and other sensitive requests, using the network address the request arrived fromStop credential-stuffing and abuse of the sign-in systemLegitimate interests: keeping accounts and the sign-in system safeNothing on the s.7 list squarely fits — see "Security, and a gap we are not papering over" below
Record, when you sign up, the network address the request reached us fromKeep our own sign-up recordsLegitimate interests: keeping accurate records of our own serviceDPDP s.7(a)
Draw the "Continue with Google" button, which loads Google's code and lets Google see your visit even if you never use it (Section 2(a1))Offer you a sign-in methodLegitimate interests: offering a sign-in method. Google and we are jointly responsible for what the button sends as it loads — see belowConsent — a step we have not built yet. This is separate from the cookie banner, which does not cover the sign-in button (Sections 5 and 6)
Start a new account's profile with the display name and photo from the Google Account you signed up with, including fetching that image from Google once and keeping our own copy (Section 2(a2))Give a new account a usable profile instead of an empty oneLegitimate interests: sparing you from re-entering what you have just signed in with. You can object by clearing either field in your profile — we never put them backThe s.7 list does not cover this either: you gave this data to Google, not to us, so it was not "voluntarily provided" to us for this purpose. We will ask properly before those provisions commence
Store and display your profile, resume, job applications, journal entries, notes, bookmarks and other content you createProvide the core ServicePerformance of a contractDPDP s.7(a) — you gave it to us to be stored and shown back to you. For how a name or photo can arrive on your profile without you giving it to us, see the row above
Run and grade the coding problems, projects, system-design sessions and course exercises you submitProvide the practice features you usePerformance of a contractDPDP s.7(a)
Send the text you give us to our AI provider (Section 4) to power resume, interview, mentor, conversation-rehearsal and grading featuresProvide the AI features you ask for, at the moment you askPerformance of a contractDPDP s.7(a) — you supplied the text for exactly this
Meter your usage against the limits of your plan — AI credits, mentor turns, interviews, code runs and conversation simulations each count separatelyKeep the Service usable and priced fairlyPerformance of a contractDPDP s.7(a)
Take payment and manage your subscription, renewals and refundsBill you for a plan you boughtPerformance of a contractDPDP s.7(a)

Mock interviews

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Record camera video and microphone audio during a mock interview, and transcribe your answersLet you practise, watch yourself back, and be graded on what you saidConsent, taken before recording starts; and performance of a contract for the practice session you asked forConsent (DPDP s.6)
Capture proctoring events during a mock interview — for example face not detected, multiple faces, looking away, tab switch, window blur, full-screen exit, camera or microphone disconnect, blocked right-click and blocked copy/paste — and derive an integrity signal from themMake the exercise a fair test of you, so the result means somethingConsent, taken on the same screen; and legitimate interests in the exercise being honestConsent (DPDP s.6)
Work out an optional composure estimate on your device from your camera, and store the per-answer and whole-session summary figures it produces (Section 2(f))Give you optional coaching on how you came across. We do not use it in gradingConsent — off unless you turn it on during the interviewConsent (DPDP s.6)

Community, and anything you choose to make public

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Host Community discussions and comments, and publish the ones you choose to make public — to anyone, and to search engines (Section 14)Run the community, and publish what you chose to publishPerformance of a contract — hosting and publishing to the audience you chose are both part of the Community service you signed up for. Where a post contains special-category data, you have manifestly made it public (Art. 9(2)(e))Hosting: DPDP s.7(a). Once it is public, the Act does not apply to data you have yourself made publicly available (DPDP s.3(c)(ii)(A))
See which account posted anonymously, act on reports, and moderate contentKeep the Community safe and enforce our TermsLegitimate interests: safety, moderation, and enforcing our TermsNothing on the s.7 list squarely fits — see below
Publish a public profile at a handle you claim, or a share link for a promotion packet you choose to sharePublish the page you asked us to publishPerformance of a contract, carrying out your instructionDPDP s.7(a); and the Act does not apply to data you have yourself made publicly available (DPDP s.3(c)(ii)(A))

Your Track Record

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Build your Track Record automatically from work you complete here (Section 4)Provide the Track Record featurePerformance of a contractConsent — a step we have not built yet. Today the per-source switches in your account settings are how you stop it
Read a journal entry, or your profile headline or summary, that you select, and suggest capabilities from itProvide a feature at the moment you ask for itPerformance of a contract, at your requestDPDP s.7(a) — you chose the text and asked us to read it
Read work you completed before the feature existed, so your record is not emptyMake the feature useful from your first visitLegitimate interests: making the feature useful immediatelyConsent — a step we have not built yet

Keeping the Service working, and knowing whether it works

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Keep the Service secure, investigate abuse, keep server logs, and enforce our TermsProtect you, other users, and usLegitimate interests: preventing fraud and abuse, and keeping the Service availableNothing on the s.7 list squarely fits — see below
Keep streaks, mastery points, badges and your activity heatmap from the work you do hereShow you your own progressPerformance of a contract — it is a feature on your account pageDPDP s.7(a)
Count each account's active days, and which growth lens you chose, and report those to ourselves as cohort figuresSee whether people come back, and whether a feature is worth keepingLegitimate interests: understanding whether the Service worksConsent — a step we have not built yet
Maintain, debug and improve CareerVerseFix faults, and decide what to build nextLegitimate interests: keeping the Service running, and deciding what to buildConsent — a step we have not built yet
Keep aggregate, non-identifying counts of product activity (Section 2(m))See whether the Service, and the journey from signing up to upgrading, actually worksThe stored counts are not personal data. But a signed-in request is what increments one, and that observation rests on our legitimate interests in measuring the ServiceThe stored counts are not personal data. For the request that increments one, the position is the same as the line above
Send you the weekly win prompt and the monthly growth digest by emailSend you the emails you asked us forConsent — both are off unless you switch them onConsent (DPDP s.6)

Measurement and marketing

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Measure product usage with third-party analytics tools (Microsoft Clarity, Google Analytics)Understand how the Service is used, and fix problemsConsentConsent (DPDP s.6)
Measure our own advertising with Google Ads and Meta Pixel, including sending Google a hashed version of your email (Section 2(k))See which of our ads bring people to CareerVerseConsent. For what those tags collect and send as they load, Google and Meta are each jointly responsible with us — see belowConsent (DPDP s.6)
Record on your account which channel or campaign your sign-up came from (Section 2(l))See which of our own channels and campaigns bring people to CareerVerseConsentConsent (DPDP s.6)

Support, and the law

What we doWhyEU/UK GDPR basisIndia — DPDP ground (from May 2027)
Answer support requests, and handle in-product feedback reports including any screenshot you attachHelp you, and fix what you reportPerformance of a contract if you have an account; otherwise legitimate interests in answering people who contact usDPDP s.7(a) — you contacted us for this
Meet legal, tax and regulatory duties, and respond to lawful requests, judgments and court ordersComply with the law we are subject toLegitimate interests in complying with the Indian law that governs us. Art. 6(1)(c) covers only obligations laid down by EU or UK law, so we do not claim it for our Indian duties; where an EU or UK obligation genuinely applies, Art. 6(1)(c)DPDP s.7(d) where Indian law requires us to disclose something to the State, and s.7(e) for a judgment or order. A duty simply to retain records is not squarely covered by either

Two legal systems, two different answers

The two right-hand columns differ because the two laws are not built the same way, and copying one across to the other would be inaccurate.

The EU and UK GDPR offer six lawful bases, two of which — performance of a contract, and legitimate interests — carry most of what a service like ours does.

India's DPDP Act offers only two kinds of ground: your consent (s.6), and a closed list of nine "certain legitimate uses" (s.7). That list is fixed. There is no contract-performance ground and no legitimate-interests ground in the DPDP Act at all — "legitimate uses" looks like the GDPR's "legitimate interests" but works differently, because there is no balancing test and nothing can be added to the list.

  • Where the India column says s.7(a), that is the ground for "the specified purpose for which you voluntarily provided your personal data" and in respect of which you have not told us you do not consent to that use. That second half is part of the ground itself: the data you handed us, used for the thing you handed it over for — and if you tell us you object to a particular use, that ground stops being available to us for it. Write to support@careerverse.tech.
  • Where it says s.7(d) or s.7(e), those are the grounds for a legal duty to disclose something to the State, and for complying with a judgment or order.
  • Where it says consent — a step we have not built yet, we mean it literally: when those provisions commence we will need your consent for that use, and the screen that asks for it does not exist today. We would rather say so than claim a consent we never asked you for.

What governs your data in India today

Most of the DPDP Act is not yet in force. The sections that set out lawful grounds, the notice we must give you, and your rights as a Data Principal (ss.3 to 17) commence eighteen months after the Government's commencement notification of 13 November 2025 — that is, in May 2027. The India column above therefore describes the position from that date. It is not a description of today.

The Data Protection Board of India was established in law by that same notification, but as at the date of this policy no Chairperson or Members have been appointed, so it cannot yet hear anything. We are not going to point you at a redress route that does not yet function.

Until then, the Indian law that actually governs this is the Information Technology Act, 2000 — in particular s.43A — together with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("the 2011 Rules"). Those survive precisely because the provision of the DPDP Act that removes them (s.44(2)) sits in the same deferred tranche and does not take effect until May 2027 either. Under those Rules:

  • We treat your mock-interview camera video and microphone audio as sensitive personal data.
  • We ask for your consent before any recording starts, on a screen that lists each item separately, and we use that data only for the purposes stated there. Rule 5(1) speaks of consent "in writing through letter or fax or email"; an in-product consent screen with a versioned record of what you agreed to is the accepted modern reading of that requirement, and it is the reading we rely on.
  • You can withdraw that consent at any time by writing to support@careerverse.tech, and you can delete any interview and its recording yourself. If you withdraw it, we will not be able to offer you recorded mock interviews.
  • We publish this policy, describe the security measures we take (Section 9), and provide a Grievance Officer (Section 12).

We are setting this out now rather than waiting, because it is the law that binds us today.

Security, and a gap we are not papering over

Three lines above — rate-limiting sign-in, moderating the Community and acting on reports, and keeping the Service secure — are things any service has to do. Under the GDPR they rest on our legitimate interests, which you can object to.

The DPDP Act's list of nine legitimate uses contains no general security or fraud-prevention ground. The one clause that mentions protecting against loss or liability applies to employers and their employees, which is not our relationship with you. We could have written "consent" in that column, but we do not ask you to consent to being rate-limited, and it would not be true. So we have written that nothing on the list squarely fits, and we will follow whatever rules the Central Government makes under s.40 of the DPDP Act, and any direction of the Data Protection Board that applies to us, before those sections commence.

Where we say "consent", here is the switch

Consent means nothing without a real way to refuse, so here is every place we rely on it and the control that goes with it. If a use is not on this list, consent is not what we rely on for it.

  • Analytics, advertising measurement, and recording your sign-up source. One banner, one choice, covering all three together — accepting or declining applies to all of them, and there is no separate switch per purpose today. You can change it at any time from "Cookie preferences" in the site footer. Nothing loads and no such cookie is written until you accept.
  • Mock-interview recording, proctoring, and event capture. A consent screen before the interview starts, listing each item separately so you can see exactly what each one covers. All of them are required for a recorded mock interview, so the interview cannot start until each is ticked. We record which version of that screen you agreed to, and ask again when it changes.
  • The composure estimate. Off by default, and turned on inside the interview only if you want it. It is genuinely optional: everything else about the interview works identically without it.
  • The weekly win prompt and the monthly growth digest. Both off unless you switch them on in your account settings, and every one of those emails carries a one-click unsubscribe link.

Withdrawing consent stops that processing going forward; it does not make what we already did unlawful. Where you withdraw a consent you previously gave, we also permanently delete the record of where your sign-up came from (Section 2(l)), so a later change of mind cannot bring it back. That holds even if we have changed what we ask you to consent to in the meantime: if we re-ask and you decline, we treat it as withdrawing the consent you gave before, not merely as a fresh "no".

Where we say "legitimate interests", you have a right to object

You have the right to object, on grounds relating to your particular situation, to processing we base on our legitimate interests, including profiling. We must then stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms. We are setting this out separately from the other rights in Section 10 because the law requires us to bring it to your attention on its own. Where we ever process your data for direct marketing, you can object at any time with no reason needed and we must stop — that one is unconditional.

Your Track Record is profiling in the GDPR's sense — automated processing that evaluates aspects of how you perform at work — which is not the same as automated decision-making. It decides nothing about you; Section 4 sets out in full what it does and does not produce, and Section 10 explains why it does not engage the rules on solely automated decisions.

We give you more than the law requires here. Two of the three Track Record lines above rest on performance of our contract, which carries no statutory objection right at all. We apply the per-source switches to all three anyway: under "What builds your record" in your account settings there is a switch for each source, you do not need to give a reason, and we do not weigh your objection against our own interests. Section 4 sets out exactly what turning one off deletes, and Section 10 notes that on a large account the deletion takes more than one step.

For anything else we base on legitimate interests, write to support@careerverse.tech and tell us what you object to. You can also ask us how we weighed our interests against your rights for any of those lines, and we will tell you.

One thing those per-source switches are not. They let you stop processing that has already started. They are not a consent step, and we do not present them as one — Track Record building is on unless you switch a source off. When the DPDP Act's main provisions commence that will no longer be enough, and we will ask you properly.

Who else is responsible alongside us

For three things described on this page, another company decides things about the data alongside us rather than simply acting on our instructions. We name them here because you should know who else holds a piece of this; the essence of each arrangement is set out in Section 6.

  • Google, for what its sign-in button collects and sends when it loads on our pages (Section 2(a1)).
  • Google, for the advertising measurement you consent to (Section 2(k)).
  • Meta, for what the Pixel collects and sends once you consent (Section 2(k)).

There is also a third kind of relationship, which the two categories above do not describe. When Google hands us your display name and picture as you create an account (Section 2(a2)), Google is not acting on our instructions and is not deciding jointly with us — it is a separate company disclosing data to us under its own terms, and what happens to that data afterwards is our decision alone.

For everything else, our providers act on our instructions — see Section 6 for who they are and what each receives.

4. AI processing, your Track Record, and on-device proctoring

In short: To power AI features, we send the relevant text to a third-party AI provider (OpenAI, etc.) through our backend. Your Track Record is built automatically from work you have already done here — you can switch off any source of it at any time, and doing so deletes what we derived from that source and does not undo. Nothing here decides anything about you. Face proctoring stays on your device.

AI features

When you use an AI feature, the relevant content is sent through our backend to a third-party AI provider (OpenAI, etc.) to generate the output — including your resume text, the job descriptions you provide, your interview answers and transcripts, short-answer submissions, system-design solutions, mentor-chat messages, and — when you ask us to read one for your Track Record — your achievement-journal entries and your profile headline or summary. We send only the content needed to provide the feature you requested. AI usage is metered as "AI credits". OpenAI may process this data outside India, including in the United States (see Section 7).

Your Track Record: automatic processing of your own activity

What we do. Your Track Record (Section 2(n)) fills itself in. As you use CareerVerse, we match the work you complete against a capability list our team maintains centrally — it is not written per person — and record that the work evidences those capabilities.

Reading your own words, only when you ask. You can also ask us to read a journal entry, or your profile headline or summary, and suggest capabilities from what it says. This never happens on its own: you choose the text and press the button, and the text is sent to our AI provider as described above. Anything it produces is marked an unconfirmed suggestion until you accept it, and an unconfirmed suggestion is never turned into prose about you — it is not used to draft, summarise or write anything. Nor does it count towards what your record shows you can evidence, and it does not change what we suggest you practise next: a guess nobody has checked should not be able to talk us out of recommending the very thing that would prove it. It starts counting only when you accept it, or when other evidence lands against the same capability — graded work you complete here, a role on your profile, or a journal entry.

A look back over your earlier work. So your record is not empty on day one, we also read work you completed before this feature existed. Today that covers your journal entries, mock interviews and coding submissions; we do not re-import the same history over and over. It reads only your own activity — there is no path in it to anyone else's.

How to stop it — the control, and what it costs. Under "What builds your record" in your account settings there is a switch for each of the seven sources. Turning one off does two things: we stop reading that source straight away, and we delete what we derived from it — the links, the supporting entries, and any notes or suggestions that came from it — then withdraw any capability we had worked out that nothing else still supports. Two things correctly stay: a capability other work still evidences, and a capability you confirmed yourself — that one is your statement rather than ours, so it is yours to remove, not ours.

That deletion is permanent. Turning the source back on later starts again from your new work only; it does not bring back what was removed, including anything we had quoted from your own words. One honest exception: if you turn Profile back on, your work-history entries reappear — not restored from a copy, but simply re-read from your profile, which still says what it said.

Your actual work is never deleted by this. Your journal entries, submissions, interviews and profile stay exactly as they are; only what we made of them is removed. And switching a source off never restricts what you can do — adding, confirming, correcting or removing an entry yourself is your statement, not ours, and is never blocked.

You can correct it yourself, item by item. On the Track Record page you can remove any capability, and detach any piece of evidence from a capability it was linked to. Removing a capability is permanent for that item — a later automatic pass cannot quietly bring it back. Where a model has written a short factual note about one of your sessions, you can mark it wrong, which takes it out of your record immediately, with nobody reviewing that decision. Where two things you have told us appear to disagree, you decide: keep one, or say both are true, which keeps both and closes the question. In either case you can also add your own written comment, which is stored with the item, is never sent to any AI provider, and is included if you ask for a copy of your data.

Nothing here decides anything about you. Your Track Record produces no score, rating, ranking, readiness percentage, or verdict, and there is no field in which one could be recorded. It counts and dates evidence; it does not grade you and does not predict what any employer will decide. Accordingly this is not automated decision-making producing legal or similarly significant effects (Section 10). We do not send it to employers, recruiters, or any other third party. It is yours to read, and it is used to suggest what to practise next. One qualification, so the sentence is exact: if you open the AI mentor while looking at a page, the capability labels on your record are included in the context sent to our AI provider (as described at the top of this section) so the mentor can answer usefully — labels only, never your evidence, notes or comments.

What is excluded from it by design. Mock-interview video and audio recordings, the composure signal, proctoring events and any integrity score are never used to build your Track Record and cannot become part of it. Practice conversations are excluded too.

Legal bases. Building and showing your Track Record is performance of our contract with you (GDPR); the look back over earlier work, and maintaining the capability list itself, rest on our legitimate interests in making the feature useful from the first visit. Under the DPDP Act, the grounds are the per-purpose ones set out in Section 3, and they are deliberately not all the same — we do not ask for a separate Track Record permission, and the per-source control above is how you stop this processing. Whichever basis applies, you get the same per-source control — you do not need to give a reason, and we act on it rather than weighing it against our own interests. For the parts that rest on our contract with you, that is more than the law requires: there is no statutory right to object to contract-based processing at all.

On-device proctoring

On-device proctoring (privacy by design). Mock-interview face/attention detection runs entirely in your browser using an on-device vision library (Google MediaPipe, etc.). The detailed facial-landmark data never leaves your device and is never sent to us. Only summarised, derived events (such as "face lost" or "gaze away") and their timestamps are transmitted to and stored on our backend.

Browser speech-to-text. Answer transcription may use your browser's built-in Web Speech API. In some browsers (notably Chrome), your audio is sent to the browser vendor (Google) for transcription, under that vendor's control and policies, not ours. Where unavailable or not permitted, transcription is simply turned off.

5. Cookies and local storage

In short: One essential sign-in cookie, one that records your cookie choice, plus one set by Google's sign-in button. Analytics cookies (Microsoft Clarity and Google Analytics), advertising-measurement cookies (Google Ads and Meta Pixel), and two that record which channel or campaign brought you here, only if you consent. Some drafts live only in your browser until you save.

  • Session cookie (cv_session). A strictly necessary, HttpOnly cookie that keeps you signed in. It is set with SameSite=Lax, marked Secure in production, contains your email and an authentication token, and expires automatically. It is not used for tracking or advertising.
  • Google sign-in cookie (g_state). Drawing the "Continue with Google" button causes Google's sign-in code to set a first-party g_state cookie on our domain. Google uses it to remember sign-in-prompt state, and it contains a randomly generated identifier for your browser. Because that button is on our home page, this is set for visitors who never use it and never sign in. We treat it as necessary to offering sign-in rather than as analytics or advertising, so it is not covered by the consent banner — see Section 2(a1) — but we list it here so you know it is there. It is not used by us for tracking or advertising, and we do not read it. You can clear it like any other cookie in your browser settings.
  • Browser local storage. Some features keep drafts and in-progress work locally in your browser for your convenience (for example, resume-builder and resume-tailoring drafts, application-workspace notes, code-editor contents, and interview progress markers). This data stays on your device unless and until you save or submit it.
  • Analytics cookies — Microsoft Clarity (only with your consent). If you accept, Clarity sets cookies to measure product usage and record pseudonymised session replays — for example _clck (a persistent Clarity user id) and _clsk (per session), plus cookies Clarity sets on its own clarity.ms / Microsoft domains. These are non-essential: Clarity is not loaded and none of these cookies are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They are not used for advertising.
  • Analytics cookies — Google Analytics (only with your consent). If you accept, Google Analytics (GA4) sets cookies to measure product usage — for example _ga and _ga_* (persistent, used to distinguish visitors). These are non-essential: GA is not loaded and none of these cookies are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They are not used for advertising.
  • Advertising-measurement cookies — Google Ads (only with your consent). If you accept, we store the Google click identifier from an ad you clicked in first-party cookies (for example cv_gclid) and load the Google Ads tag (which may set its own _gcl_* cookies), to attribute a later sign-up, trial, or purchase to that ad. These are non-essential: none are set unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. They measure our own ads' results and are not used to show you third-party ads on CareerVerse.
  • Advertising-measurement cookies — Meta Pixel (only with your consent). If you accept, Meta Pixel records page views and a standard event when a genuinely new account is created or a free trial is started — including one that happened earlier in the same browsing session, shortly before you accepted (Section 2(k)) — and may set/read Meta advertising cookies such as _fbp and _fbc to identify a browser and measure or optimise our Meta ad campaigns. _fbc holds the ad-click identifier that was on your link; where the Pixel cannot record it itself — because it only loads once you accept, by which time you may have moved on from the page you arrived on — we write that cookie for it when you accept, from the identifier your own link carried. Both are deleted when you withdraw consent. These are non-essential: the Pixel is not loaded and no Meta Pixel event is sent unless you opt in, and you can withdraw consent at any time via "Cookie preferences" in the footer. Meta may use this activity under its own privacy policy and your Meta advertising settings; we do not enable Advanced Matching or send your email to Meta in this implementation.
  • Sign-up source cookies (only with your consent). If you accept, we store how you reached us — channel, campaign, the linking domain, the landing page, and any advertising click identifier, and simply "direct" when you arrive with no marketing link at all — in two first-party cookies (cv_attr for your first visit and cv_attr_last for your most recent). They are read only by us, when you create an account, and are deleted when you withdraw consent. One further cookie (cv_consent) records the choice you made here; it is strictly necessary — without it we cannot tell whether you consented, and it is what stops the cookies above from ever being written.
  • We set no non-essential cookie (analytics, advertising, or sign-up source) without your consent, and we do not use cookies to show you third-party ads on CareerVerse. If you consent to Meta Pixel, Meta may use the resulting activity under its own policy, including for ad personalisation.

6. How we share your data

In short: We share only with the providers needed to run CareerVerse. We never sell your data.

We do not sell your personal data. If you consent, we share limited advertising-measurement data with Google and Meta to measure and optimise our own advertising (Section 2(k)); Meta may use Pixel activity under its own policy, including for ad personalisation. We share data with service providers such as the following:

  • Amazon Web Services (AWS) — cloud hosting, file storage (S3), and compute, in the ap-south-1 (Mumbai, India) region. Your data, including interview recordings, is stored on AWS.
  • OpenAI — receives the content described in Section 4 to generate the AI outputs you request.
  • Microsoft (Clarity)only if you consent to analytics cookies, the pseudonymised interaction data and session replays described in Section 2(j) are sent to Microsoft, which provides the Clarity product-analytics service and processes that data under the Microsoft Privacy Statement, potentially outside India (including the United States). If you do not opt in, no Clarity data is shared.
  • Google (Sign-in) — a "Continue with Google" button appears on our home page, our sign-in screens and your account settings, and drawing it loads Google's sign-in script, so Google receives your IP address, basic device and browser information, the page address, and any Google cookies your browser already holds at that moment — on the home page this happens on page load, even if you never use the button. If you then choose "Continue with Google", Google confirms your identity to us and sends us your email address, whether Google has verified it, a stable identifier for your Google Account, and — in most cases — your display name and a link to your profile picture (Section 2(a1)). If that request creates your account, our server then fetches that picture from Google's image servers, which tells Google the image was fetched and reveals our server's network address and the time; the image itself comes back to our storage in India (Section 2(a2)). Neither the sign-in nor that fetch is analytics or advertising, so neither is part of the optional cookie consent; Section 3 sets out what we rely on for each. Google processes this under its terms and privacy policy, potentially outside India (including the United States).
  • Google (Analytics)only if you consent to analytics cookies, the pseudonymised usage and event data described in Section 2(j) are sent to Google, which provides the Google Analytics service and processes that data under Google's terms and privacy policy, potentially outside India (including the United States). GA4 does not store your IP address. If you do not opt in, no Google Analytics data is shared.
  • Google (Ads)only if you consent to advertising cookies, we send Google the click identifier and a hashed version of your email (Section 2(k)) to measure which of our ads lead to sign-ups, trials, and purchases. Google processes this under its terms and privacy policy, potentially outside India (including the United States). If you do not opt in, no Google Ads data is shared.
  • Meta (Ads / Pixel)only if you consent to advertising cookies, Meta receives the page-visit, browser/device, network, referrer, and Meta cookie/browser identifier signals described in Section 2(k), plus a standard event with an opaque server-issued event identifier when a new account is created or a free trial is started, to measure and optimise our ads. We do not enable Advanced Matching or send your email, CareerVerse user id, authentication method, plan, amount, or CareerVerse content to Meta in this implementation. Meta processes this under its privacy and cookie policies, potentially outside India (including the United States). If you do not opt in, Meta Pixel is not loaded and no Pixel event is shared.
  • Payment processor (merchant of record) — if you buy a paid plan, a third-party payment processor acts as the merchant of record: it collects your payment and receives your email and transaction/subscription data to bill you and issue any refund. It handles your card details directly; we do not receive or store your full card number. See the billing and refund terms in our Terms of Service.
  • LinkedIn (public fetch) — when you initiate it, our backend fetches the public LinkedIn profile for the username you provide. This is a public-profile fetch, not a LinkedIn OAuth/API login, and nothing is saved unless you choose to save it.
  • Browser speech vendor — as described in Section 4, transcription in some browsers routes audio to the browser vendor (e.g. Google).
  • Legal and safety — we may disclose data where required by law or legal process, or to protect the rights, safety, or security of our users, the public, or ASOasis.
  • Business transfers — if ASOasis is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this Policy or a successor policy.

We require our service providers to protect personal data and to use it only to provide services to us.

7. International data transfers

In short: We host in India. If your data crosses borders, we use lawful safeguards.

Our primary infrastructure and stored data (including interview recordings) are hosted in India (AWS ap-south-1, Mumbai). Some processing involves transfers outside India — in particular, AI inputs sent to OpenAI, audio sent to your browser's speech-recognition vendor, authentication data sent to Google (Sign-in) — which includes the connection data described in Section 2(a1), sent when the sign-in button loads rather than only when you use it — and, where you consent, interaction data sent to analytics providers (Microsoft (Clarity) and Google (Analytics)) and advertising-measurement data sent to Google Ads and Meta Pixel — which may be processed in the United States or other countries.

One flow on this page runs the other way. When we fetch your Google profile picture as your account is created (Section 2(a2)), the image travels into India and comes to rest on our storage there; what leaves is only the request for it, described in Section 6. An inbound copy like that is not a restricted transfer, so the safeguards below are not what protects it — we mention it so the direction is not left to guesswork.

For users in the EEA/UK, where we transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA, as applicable); you may request a copy via support@careerverse.tech. For users in India, transfers are made in accordance with the DPDP Act and any restrictions the Central Government may notify.

8. How long we keep your data

In short: We keep your data while your account is active, then delete or anonymise it within a reasonable period.

Some parts of your Track Record (Section 4) clear themselves on fixed clocks, whether or not you act:

  • A capability we guessed from your own text and you never confirmed is deleted after about 180 days. It is genuinely deleted, not hidden.
  • The record of the sentence we read it in — the "your own words" entry that shows you why we suggested a capability — is deleted after about 180 days as well, and this one runs whether or not you confirmed the capability. Confirming the capability keeps the capability; it does not keep the quotation behind it. Any comment you added to that entry is stored on it and goes when it goes, so if you want to keep what you wrote, keep your own copy.
  • A short factual note a model wrote about one of your sessions is deleted after 12 months.
  • A disagreement between two things you have told us that you never settle lapses after about 365 days, and both statements are released.

A capability you confirmed yourself does not expire — it is your statement, and it stays until you remove it. As the second bullet says, that is true of the capability itself and not of the quoted sentence we first read it in.

A display name or photo copied from Google when your account was created (Section 2(a2)) is kept like any other profile field: it is a one-time copy that we never refresh, so changing or deleting the picture on your Google Account does not change or delete ours, and disconnecting Google sign-in does not remove it either. Editing or clearing it in your profile is what changes it here.

We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete specific content (such as an interview recording or forum post), we remove it from active systems, though it may persist briefly in routine backups. When you close your account, we delete or anonymise your personal data within a reasonable period, except where longer retention is required by law. If you would like to know the retention period that applies to a specific category of data, contact us at support@careerverse.tech.

9. How we keep your data safe

In short: We use sensible technical and organisational measures, and a passwordless sign-in.

We take reasonable steps to protect your data, including: passwordless sign-in via email OTP (there is no password to steal); a secure, HttpOnly session cookie that client-side scripts cannot read; server-side handling of your authentication token so it is not exposed to the browser; same-origin protections and per-IP rate-limiting on sensitive endpoints; encrypted transport (HTTPS/TLS); and hosting on AWS with access controls. You can end every other signed-in session from your account settings. Stopping Google sign-in also ends the sessions it created, blocks ordinary Google sign-in from silently restoring it, and requires fresh email verification before it can be enabled again — it does not, however, remove a name or photo copied to your profile at sign-up, which by then are ordinary profile fields you control (Section 2(a2)). Keeping facial-landmark data on your device further reduces what we hold. No system is perfectly secure, so we cannot guarantee absolute security. Because we sign you in through your email, keeping your email account secure is an important part of protecting your CareerVerse account.

In the event of a personal-data breach, we will notify the relevant authorities and affected individuals where and as required by applicable law.

10. Your privacy rights

In short: You have strong rights over your data. The exact rights depend on where you live.

Two of these you can exercise yourself, without contacting us. Under "What builds your record" in your account settings you can stop us working anything out from any source; and on your Track Record page you can remove a capability, detach a piece of evidence, or mark a model-written note wrong and add your own comment to it. We stop reading the source straight away and begin deleting immediately; on a large account the deletion may take more than one step, and the page tells you if so and offers you a button to finish it (Section 4). That message lives on the page you started it from. If you close the tab before it finishes, write to support@careerverse.tech and we will complete it — the source stays switched off in the meantime, so nothing further is read from it either way.

Whatever your location, contact support@careerverse.tech to exercise your rights (India residents may also contact the Grievance Officer in Section 12). We may verify your identity — usually by confirming control of your account email — before acting, and we will respond within the time the law allows. We will not discriminate against you for exercising your rights.

India (DPDP Act, 2023)

The DPDP Act's rights provisions commence in May 2027 (Section 3). We are not waiting for that date — everything below is available to you today on request, whether or not the Act yet compels it.

You have the right to: access a summary of the personal data we process about you and related processing; correct, complete, update, and erase your personal data; grievance redressal (Section 12); and nominate another individual to exercise your rights in the event of your death or incapacity. Where we rely on consent, you may withdraw it at any time, as easily as it was given.

Separately, and in force now, section 43A of the Information Technology Act, 2000 and the 2011 Rules give you a route to compensation for a failure to protect sensitive personal data; a claim under it goes to an adjudicating officer under section 46 of that Act. Where CareerVerse acts as an intermediary in respect of content other users post, the Grievance Appellate Committee under the IT Rules 2021 can hear an appeal against our Grievance Officer's decision on such content.

European Union and United Kingdom (GDPR)

You have the right to: access your personal data and obtain a copy; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict or object to certain processing, including processing based on our legitimate interests; data portability; withdraw consent at any time where we rely on it; be told the source of personal data we did not get from you directly — such as the display name and photo Google gives us when an account is created through "Continue with Google" (Section 2(a2)), or what a LinkedIn import fetched (Section 2(g)); and lodge a complaint with your local supervisory authority. We do not use solely automated decision-making that produces legal or similarly significant effects on you — your Track Record is assembled automatically, but it produces no score, rating or verdict, decides nothing, and is not shared with employers (Section 4).

California (CCPA/CPRA)

You have the right to: know what personal information we collect and how we use and disclose it; access and obtain a copy of it; delete it; correct inaccurate information; opt out of sale or sharing for cross-context behavioural advertising; and not be discriminated against for exercising your rights. We do not sell personal information. Meta Pixel activity may constitute "sharing" under California law, but it remains off unless you opt in; declining the banner or choosing "Turn off" under "Cookie preferences" exercises that opt-out.

11. Third-party links

The Service may contain links to third-party websites and services that we do not control (including the LinkedIn, GitHub, and portfolio links you add). This Policy does not apply to those third parties, and we are not responsible for their content or privacy practices. Please review their policies before providing them your information.

12. Grievance Officer (India)

In short: In India, you can raise privacy concerns with our Grievance Officer.

In accordance with India's DPDP Act and the Information Technology Act, 2000 and rules thereunder, you may contact our Grievance Officer regarding the processing of your personal data:

We will acknowledge and address grievances within the timelines required by applicable law. If your grievance is not satisfactorily resolved, you may approach the Data Protection Board of India.

13. Children

In short: CareerVerse is for adults only.

The Service is intended only for individuals aged 18 or older, and we do not knowingly collect personal data from anyone under 18. We do not direct the Service to children, track or profile children, or target advertising at them. If you believe a person under 18 has provided us personal data, contact support@careerverse.tech and we will take reasonable steps to delete it and close any associated account.

14. Content you post in public areas is public

In short: Discussions and comments you post in the public Community are visible to anyone on the internet and can appear in search engines. Posting anonymously hides your name from other people, but not from us. Don't post anything you need to keep private.

The public Community. CareerVerse includes a public Community. A discussion you post there — and comments on it — is visible to anyone on the internet, whether or not they have a CareerVerse account, and may be crawled, indexed, and displayed by search engines. Along with your title and text, this includes any tags and image, and associated information such as vote counts, the number of comments, and the times you posted or edited; some of this is also published as machine-readable structured data for search engines. It is not private and is not limited to signed-in members. (Replies nested under a comment are, for now, shown only to signed-in members — but you should treat anything you post as capable of becoming public.)

Once it's public, it's out of our hands. Anyone on the internet — including people and companies not bound by our Terms — can copy, screenshot, cache, republish, or use your public Community content to train AI or other systems. We cannot control or prevent that, and deleting a post cannot claw back copies others have already made.

Posting anonymously. If you post anonymously, we hide your name and profile photo from other users and the public. Anonymity protects your identity from other people — not from us: ASOasis and its moderators can still see which account posted (for safety, moderation, legal, and your own edit/delete purposes), and it does not make the content itself private — the text, tags, and images you posted remain public. If you post without choosing anonymity, your profile display name and photo are shown publicly with your post.

Post carefully. Do not include personal, confidential, sensitive, or identifying information — yours or anyone else's — in Community content you do not want to be public. You are responsible for what you post (see our Terms of Service).

What is not public here. Discussions attached to specific learning content (such as a course lesson) are not part of the public Community and stay visible only to signed-in users. This section covers the public Community feed and its discussion pages.

Deleting public content. When you delete a Community post or comment, we remove it from public view on CareerVerse promptly. Copies may persist briefly in routine backups (see Section 8), and — as noted above — search engines and other third parties may keep copies that we cannot remove for you.

Public profile. Separately, you can give yourself a public profile by claiming a handle (your personal URL). Claiming that handle makes the profile public — we tell you so on the form before you confirm — and from then on the sections you have filled in are public and may be indexed by search engines. If your account was created through "Continue with Google", remember that your name and photo were filled in for you (Section 2(a2)) — so check them before you claim a handle, because publishing publishes those too. Accounts have no public profile until you claim a handle, sensitive contact details are always excluded, and you can switch back to private at any time from your account settings.

15. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where the changes are material, provide additional notice through the Service or by email where appropriate. Where the law requires fresh consent, we will obtain it.

16. Contact us

For any privacy question or to exercise your rights:

  • Email: support@careerverse.tech
  • Company: ASOasis Tech Private Limited, India
  • India DPDP Grievance Officer: see Section 12.