Privacy Policy
Last updated: 9 May 2026
1. Introduction
CareerCoach Pakistan ("we", "us", "our") operates the website and application at careercoach.pk. This Privacy Policy explains what personal information we collect, how we use it, and what rights you have over it. By using our service you agree to the practices described here.
2. Information We Collect
We collect the following categories of information:
- Account information — your name and email address, obtained via Google OAuth when you sign in. We never see your Google password.
- Profile data — your Google profile photo URL (optional, used to display your avatar in the app).
- Interview content — job descriptions you paste, your text and voice answers, and the AI-generated questions and feedback produced during your sessions.
- Billing information — if you subscribe, Stripe collects and stores your payment details. We receive only a customer ID and subscription status — we never see your card number.
- Usage data — pages visited, features used, session counts, and performance metrics (Core Web Vitals), collected via PostHog and Vercel Analytics.
3. How We Use Your Information
- To create and manage your account.
- To generate tailored interview questions and AI feedback using your session content.
- To enforce your 7-day free trial and paid subscription access.
- To send transactional emails (welcome email, trial-expiry reminder) via Resend.
- To analyse product usage in aggregate so we can improve the service.
- To comply with legal obligations.
We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
4. Data Storage and Security
Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure in the US region. All data in transit is encrypted with TLS 1.2+. Row-Level Security (RLS) is enforced at the database level so that each user can access only their own records.
We retain your account data for as long as your account is active. Interview sessions and answers are retained indefinitely unless you request deletion (see Section 7).
5. Third-Party Services
We use the following third-party services. Each has its own privacy policy.
| Service | Purpose |
|---|---|
| Google OAuth | Authentication |
| Supabase | Database and auth session storage |
| Groq / LLaMA | AI question generation and feedback |
| Stripe | Payment processing |
| Resend | Transactional email delivery |
| PostHog | Product analytics |
| Vercel | Hosting and performance analytics |
6. Cookies and Tracking
We use cookies to maintain your login session (set by Supabase). We also use PostHog, which sets a first-party analytics cookie to distinguish returning visitors. We do not use advertising cookies or cross-site tracking.
7. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — request that we delete your account and all associated data.
- Portability — request your session and answer data in JSON format.
To exercise any of these rights, email us at safdarayub@gmail.com. We will respond within 30 days.
8. Children
Our service is intended for users aged 16 and above. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with their data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.
10. Contact
Questions about this policy? Email us at safdarayub@gmail.com.