RoleerityAI-powered career intelligence

Privacy operations

Data Retention and Deletion Policy

Effective and last updated August 24, 2026

This policy explains how long RoleVerity keeps different categories of information, the criteria used when a fixed period is not appropriate, and what happens when you delete information or your account. It supplements our Privacy Policy.

Our retention principles

RoleVerity keeps personal information only for as long as reasonably necessary and proportionate to provide the service, fulfill the purpose described when it was collected, protect the service, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, or regulatory obligations.

When no fixed period applies, we consider whether your account is active, whether you still need the information in your workspace, the sensitivity and volume of the information, operational and security risks, legal obligations, and whether the information can be deleted or de-identified.

Retention schedule

Account and authentication data

Display name, email address, account settings, authentication metadata, and current sessions are kept while your account is active. They are removed from RoleVerity's active systems when permanent account deletion completes, subject to the limited exceptions below.

Career workspace and user-created records

Career profiles, saved searches, job records, notes, applications, activities, fit analyses, ATS scans, generated résumés, usage records, and entitlement records are kept while your account is active or until you delete or replace the applicable item. User-owned database records are removed when permanent account deletion completes.

Résumé files and upload staging

Your active private résumé file and extracted text are kept until you replace the résumé, use the résumé-deletion control, or permanently delete your account. A pending résumé upload expires after two hours. Rejected, canceled, abandoned, or expired upload files are removed promptly when possible, with a protected cleanup process retrying eligible removals.

Recoverable browser drafts

Recoverable in-progress form drafts are stored in your browser, not in the RoleVerity database. They expire after 24 hours and are cleared sooner after successful completion or sign-out when the applicable control runs. You may also clear your browser storage.

Billing and subscription information

RoleVerity keeps plan status, subscription dates, and the Stripe identifiers needed to provide billing and entitlements while your account is active and, when necessary, for billing reconciliation, disputes, fraud prevention, accounting, or legal compliance. RoleVerity does not store full card numbers or card security codes. Stripe separately retains payment and transaction records under its own policies and legal obligations.

Security, reliability, and cost-control records

  • Operation abuse-control records older than seven days are removed when the system next evaluates the same protected operation for that user.
  • Privacy-limited operational alert records older than 90 days are removed when the alert ledger next records an eligible monitor event.
  • External-service spending-control records older than 400 days are removed when the relevant budget is next evaluated. If your account is deleted sooner, its user identifier is removed from records retained for operational accounting.
  • Detailed Vercel application runtime logs are currently kept for up to 30 days under RoleVerity's configured hosting plan.
  • Stripe webhook event identifiers and limited processing status are kept under restricted access for as long as reasonably necessary to prevent duplicate processing, investigate failures, and reconcile billing. The ledger does not contain full card details.

Support and provider records

Support communications and records held by service providers are retained only as needed to respond, maintain security, satisfy contractual or legal obligations, and resolve disputes. Providers may maintain their own security, transaction, or compliance records under their published terms.

Your deletion controls

In your Profile, you can delete your active résumé without deleting the rest of your account. This removes the private file and clears its stored résumé metadata and extracted text. You can also edit or delete other workspace information through the available product controls.

Before deletion, you can download a private JSON export of your account data. The export is generated on demand and returned directly as a download; RoleVerity does not keep a separate server-side copy of that export. PDF and DOCX résumé exports are likewise generated on demand and returned directly.

What permanent account deletion does

Permanent account deletion requires a fresh verification step and an explicit confirmation phrase. Once confirmed, RoleVerity performs the following protected sequence:

  1. cancels or deletes linked active Stripe billing resources when present and safe to do so;
  2. finds and removes private résumé files owned by the account;
  3. deletes the Supabase authentication identity, which cascades deletion through user-owned RoleVerity database records; and
  4. removes current authentication sessions and clears local recoverable drafts from the browser.

If a required billing, file-storage, or identity step fails, RoleVerity stops and reports that deletion could not be completed so you can retry. Some linked billing data or files may already have been removed before a later step fails. Previously issued access tokens cannot be refreshed after identity deletion and expire according to their normal short lifetime.

Permanent account deletion is irreversible and ends access immediately. It also cancels active paid access without creating a refund or credit, as described in the Refund and Cancellation Policy.

Backups, service providers, and delayed erasure

Deletion removes information from RoleVerity's active systems. If encrypted database backups or disaster-recovery copies exist, deleted database records may remain temporarily in those copies until the applicable backup is overwritten or expires. Backups are not used to restore deleted account data except when required for disaster recovery, and restored data remains subject to this policy.

Supabase database backups do not include the underlying private Storage object files. RoleVerity removes owned résumé objects separately during account deletion. A provider may retain limited security, fraud-prevention, billing, transaction, or compliance records under its own legal obligations even after RoleVerity submits a deletion or cancellation request.

When limited information may be retained

We may retain the minimum information necessary when deletion is restricted or an exception applies, including to comply with law, respond to valid legal process, complete a transaction you requested, maintain financial records, detect or prevent fraud and security incidents, debug errors, exercise or defend legal claims, enforce our agreements, or protect rights and safety.

Information retained for one of these reasons is access-restricted, not used for unrelated product or marketing purposes, and deleted or de-identified when the reason no longer applies.

Requests and questions

Use the controls in your Profile or email support@roleverity.com. We may verify that you control the account before completing a request. Where applicable, an authorized agent may submit a request with proof of authority.

For broader information practices and contractual terms, review the Privacy Policy and Terms of Service.

Policy changes

We may update this policy as RoleVerity's services, providers, or legal obligations change. We will post the updated policy here, revise the effective date, and provide additional notice when required by law.