Privacy Policy

Last Updated: 31/05/2026

At Personal Job Coach ("we", "us", "our"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share your data when you use our website, CV analysis, and career tools.

1. Data Controller

Personal Job Coach is the data controller responsible for your personal data. We operate as a sole trader (autónoma) registered in Spain. Business name: Sophie Polani Adam. NIF: Y3672237W. Registered address: C/ Lepant 270, Bajos, 08013, Barcelona, Spain. For any privacy-related enquiries or requests, contact us at privacy@personaljobcoach.com. We are registered with the UK Information Commissioner's Office (ICO). ICO Registration Reference: ZC109604.

2. Information We Collect

We may collect the following types of information:

  • Identity Data: Name, username, or similar identifier (including from social logins like Google or LinkedIn).
  • Contact Data: Email address.
  • Technical Data: IP address, browser type, operating system, and cookie data.
  • Usage Data: Information about how you use our tools (e.g., CVs uploaded for analysis, job descriptions analysed).

3. How We Use Your Data

We use your personal data to:

  • Provide and maintain our Service (e.g., generating CV insights and career coaching).
  • Manage your account and authentication.
  • Improve our tools and user experience.
  • Send you transactional emails (e.g., welcome, account updates) via our provider, Brevo.

4. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR and GDPR Article 6:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the service, including account creation, authentication, CV analysis, and career tools.
  • Consent (Art. 6(1)(a)): Analytics data is only processed with your prior, freely given consent via the cookie banner. You can withdraw this consent at any time.
  • Legitimate interests (Art. 6(1)(f)): Transactional emails to registered users (account confirmations, service updates). You can unsubscribe at any time.

5. Data Retention & Deletion

We retain your personal data for the following periods:

  • Account data (profile, CV, job tracker): retained while your account is active. You can delete your account and all associated data at any time via Settings. Data is permanently deleted within 30 days of a deletion request.
  • Payment records: retained for 7 years to comply with applicable tax law obligations.
  • Analytics data: retained for up to 26 months by Google Analytics, subject to your consent.
  • Email records: retained for 3 years from last interaction, or until you unsubscribe.

6. Service Providers & Data Transfers

We use trusted third-party processors to deliver our service: Vercel (Hosting), Supabase (Database), Brevo (Email), Stripe (Payments), and Google/OpenAI (AI analysis). For international data transfers to US-based processors, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and recognised under UK adequacy frameworks. We do not sell your personal data.

7. AI-Generated Content

Personal Job Coach uses AI (including Google Gemini and OpenAI models) to generate CV analyses, career coaching responses, interview feedback, and job application documents. These outputs are advisory only and do not constitute automated decisions with legal or similarly significant effects under UK GDPR Article 22. All AI-generated content should be reviewed for accuracy before use. If you have questions about AI processing in relation to your data, contact us at privacy@personaljobcoach.com.

8. Gmail Data and the Job Radar Feature

When you use the Job Radar feature, you can optionally connect a Gmail account so that Personal Job Coach can read job alert emails on your behalf. If you grant this access:

  • What data we access: We read the subject line, sender address, and body content of emails that match job alert criteria (for example, emails from LinkedIn, Indeed, or similar platforms). We do not access, read, or store any other emails.
  • Why we access it: To extract job listings from job alert emails and display them in your Job Radar inbox automatically, without you needing to copy and paste each listing manually.
  • How it is stored: Extracted job data (title, company, description, and source URL) is stored in our database (Supabase), hosted on servers within the EU/EEA. Raw email content is processed in memory only and is not stored permanently.
  • How long it is retained: Extracted job listings are retained for as long as they remain in your Job Radar inbox. You can delete individual listings or disconnect your Gmail account at any time via Settings. On account deletion, all data is permanently removed within 30 days.
  • Who it is shared with: Gmail data is not shared with any third party for advertising or profiling purposes. Job listing text is processed by Google Gemini solely to extract job information. Google's handling of data submitted through the Gmail API is governed by Google's API Services User Data Policy.
  • Security measures: All data in transit is protected by TLS 1.2 or higher. Data at rest is encrypted by Supabase (AES-256). Access to your Gmail data requires your explicit OAuth authorisation and is limited to read-only scope. You can revoke this access at any time via your Google Account settings at myaccount.google.com/permissions, or from Settings within the app.
  • Revoking access: To disconnect Gmail from Personal Job Coach, go to Settings within the app. To remove Personal Job Coach from your Google account entirely, visit myaccount.google.com/permissions.

9. Your Legal Rights (UK GDPR)

Under UK GDPR, you have the right to access, correct, erase, or export your personal data, and to withdraw consent at any time. To exercise any right, email privacy@personaljobcoach.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate data.
  • Right to erasure: Request deletion of your data ("Right to be Forgotten").
  • Right to data portability: Export your data as a JSON file via Settings.
  • Right to withdraw consent: Withdraw analytics consent at any time via Cookie Policy.