Back to Home

Privacy Policy

Last Updated: February 2026

Privacy Policy

Effective Date: February 2026

This Privacy Policy explains how CareerDad processes personal information in accordance with the General Data Protection Regulation ("GDPR").

1. Information We Collect

We collect the following personal information to provide our services:

  • Identity Data: Name, Google User ID.
  • Contact Data: Email address.
  • Career Data: Information contained in the CVs you upload (Work history, education, skills), voice data (for interview simulations), and career goals.
  • Transaction Data: Payment reference numbers. Note: We do NOT collect or store full credit card numbers.
  • Partner Attribution Data: Referral code, optional campaign tag, landing path, click time, attribution expiry, and fraud-prevention hashes.

2. Purpose of Processing

We process your data to:

  • Generate optimized CVs, cover letters, and interview questions using Artificial Intelligence (AI).
  • Analyze voice responses for confidence and clarity during interview simulations.
  • Manage your account, authentication, and credit balance.
  • Process payments securely.
  • Operate the CareerDad Partner Program, including 90-day last-click attribution, manual payout review, and fraud prevention.
  • Improve our AI prompts and algorithms (using anonymized data only).

3. Partner Program Attribution

If you arrive through a CareerDad partner link, we may store a first-party cookie and localStorage record for up to 90 days. This record can include the partner referral code, optional campaign parameter, click ID, capture time, expiry time, and landing path. We use this to attribute eligible SaaS and premium service purchases under a last-click model.

For fraud prevention, we may store hashed IP address and hashed user-agent values linked to the referral click. We do not store raw IP addresses for partner attribution. If a purchase converts, we may use the purchased package and transaction amount to calculate commission. Partners do not receive buyer CVs, resumes, job descriptions, profile details, interview content, email addresses, or private account data.

Partner payouts are reviewed manually. We may review referral metadata, conversion status, refund/reversal status, and fraud flags before approving or paying commission.

4. Sharing of Personal Information

We share your data with the following Operator(s) to facilitate the Service:

  • Google Gemini (Google LLC - USA/EU): To generate text, analyze CVs, and simulate interview conversations. Data sent via the Gemini API is subject to Google's rigorous data privacy standards and is not used to train their public models by default.
  • Google Firebase & Google Cloud (USA/EU): For secure database hosting, file storage, authentication, and serverless computing functions.
  • Yoco (South Africa): For secure payment processing.

Cross-Border Transfer: Some of our third-party service providers (specifically Google) are located outside South Africa. We ensure that these providers are subject to laws or agreements (such as GDPR) that uphold principles for reasonable processing of information substantially similar to POPIA.

5. AI Network Outreach (Accelerator Exclusive — R247)

AI Network Outreach is an Accelerator-tier feature (R247 once-off) that helps you bypass ATS black holes by messaging decision-makers directly via your personal Gmail. It is governed by strict Accelerator-only access and requires your explicit human approval before any email is dispatched.

  • CV Value-Prop Parsing: When you upload a CV (PDF, DOCX, TXT), your browser extracts text locally via extractTextFromFile. We keep a client-side value-prop slice (up to 3,500 chars) and a server-side excerpt (up to 4,000 chars) solely to generate a sharp, peer-to-peer outreach draft. The excerpt is sent to Vertex AI (Gemini 2.5 Flash) for that generation request and is not used to train public models. No legacy company-hunting fields or manual bio inputs are required — your CV is the single source of truth, and manual entry is not stored beyond the draft.
  • Isolated OAuth Token Management for Personal Gmail Dispatch: Gmail dispatch uses OAuth 2.0 with the minimal gmail.send scope only — we cannot read your inbox. Refresh/access tokens are written only to users/{uid}/secure_tokens/google (and mirrored to gmail for dispatch), encrypted server-side via decryptToken/AES-GCM with keys in Google Secret Manager. Tokens are never exposed to the client except via getGmailConnectionStatus (which returns only hasRefreshToken boolean, email, and daily quota). You can revoke at any time via Disconnect — which deletes the token doc and clears outreach.gmail* flags. Firestore rules deny client reads/writes to secure_tokens.
  • Outreach Log Storage: Every generated draft and sent message is logged under your private subcollections: users/{uid}/outreach_logs (drafts/sent, subject, body, recipient, provider=gmail, messageId), users/{uid}/outreach_daily_counters/{YYYY-MM-DD} (counts for gamified 20/day per Accelerator, 0/day otherwise), and users/{uid}/outreach_drafts. Logs are readable only by you (owner) and written only via callable functions (generateOutreach, sendOutreachEmail) — client writes are denied by security rules. Logs are retained while your account is active and deleted within 30 days of account deletion, same as career data.

Gating & control: researchProspect / generateOutreach / sendOutreachEmail all verify resolveAccessState.isAcceleratorActive. Non-Accelerator tiers receive a permission-denied error and an upgrade prompt (R247). No outreach is auto-sent — every email requires your explicit “Approve & Send via Gmail” action.

6. Security

We implement industry-standard security measures to protect your data, including encryption in transit and at rest provided by Google Cloud Platform. However, no digital transmission is completely secure.

7. Your Rights

Under POPIA, you have the right to:

  • Request access to the personal information we hold about you.
  • Request the correction or deletion of your personal information.
  • Object to the processing of your personal information.

To exercise these rights, email our Information Officer at support@careerdad.co.za.

8. Retention

We retain your personal information only for as long as your account is active. Upon account deletion, your career data is permanently removed from our active databases within 30 days.

Partner attribution cookies and localStorage records are set to expire after 90 days. Server-side partner click, conversion, and payout records may be retained for accounting, fraud prevention, legal, and dispute-resolution purposes.

9. Information Officer

Name: Donovan Tiemie
Email: support@careerdad.co.za
Address: Oudtshoorn, South Africa

Questions? Contact us at support@careerdad.co.za