← Back to CareerForge

Privacy Policy

Last updated 6 September 2026.

CareerForge is a job-search product run by NanoCorp. This page describes what we actually store, why, who else processes it, and how to get it removed. If something here does not match what you see in the product, tell us and we will fix the page or the product.

We do not sell your resume data, and we do not use it to train models of our own.

What we collect

  • Account: your email address, your name if you give one, a hashed password, and — if you set one — a security question with a hashed answer. We never store your password itself.
  • What you put into the tools: resume text, job descriptions, generated cover letters and tailored resumes, interview questions and your practice answers, saved jobs, tracker entries, achievement notes and networking drafts. Uploaded PDF or DOCX files are read in memory to extract the text; the file itself is not kept, the extracted text is stored with your account so you can carry on where you left off.
  • The free ATS checker: if you use it without an account, the resume you paste or upload is checked and returned in the response. It is not written to our database.
  • Plan and payment records:your plan, the Stripe customer and checkout identifiers, the amount, currency and product of each payment. Card numbers are entered on Stripe’s own checkout page and never reach us.
  • Support messages: what you write to the in-product chat, so we can answer it.
  • Usage measurement: which steps of the product were used and where the visit came from (for example a campaign link). This is the only category that depends on your cookie choice — see below.

Why we process it

  • To run the tool you asked for, and to keep your work so it is still there on your next visit (performance of our contract with you).
  • To keep your account, plan and sign-in working, and to keep the service secure (contract and our legitimate interest).
  • To take payment and to reconcile a completed checkout with the right account (contract).
  • To answer your support messages (contract and legitimate interest).
  • To measure how the product is used so we can fix what does not work (consent, where consent is required — otherwise legitimate interest, and you can opt out at any time).

Who else processes it

These are the providers actually involved in running CareerForge:

  • Vercel — hosting and serving the application.
  • Cloudflare — the network edge in front of the site.
  • Neon — the managed Postgres database where your account and documents are stored.
  • NanoCorp — the platform that runs this company: it provides the hosted checkout link, the model gateway below, the usage measurement described below, and the support tooling.
  • A large-language-model provider, reached through NanoCorp’s model gateway — the text you submit for analysis, tailoring, cover letters or interview questions is sent to the model to produce the result. It is sent to generate your output, not to train the model.
  • Stripe — payment processing and card data, on Stripe’s own pages.
  • Public job boards and job APIs — when you search jobs, your search terms (not your resume) are sent to the job sources we query. Job cards no longer load company logos from a third-party service, so browsing jobs does not hand your IP address to anyone else.

Cookies and measurement

Necessary cookies. These are always on, because the product cannot work without them:

  • Sign-in session cookies set by our authentication layer, so you stay logged in.
  • careerforge_region — records whether cookie consent is required for your region, so we know whether to wait for your choice. Kept one day.
  • careerforge_consent — remembers the choice you made below. Kept 180 days.

Measurement, only with your agreement. If you accept, we load NanoCorp’s analytics script and store:

  • careerforge_first_touch and a matching entry in your browser’s local storage — where your first visit came from, kept 180 days.
  • Events for the steps you complete in the product, sent to NanoCorp’s analytics service, with an identifier for your account or browser.

In the EU, EEA, UK and Switzerland nothing in that second group runs until you accept. Elsewhere it runs unless you reject it. Rejecting removes what was already stored on this device. We do not use advertising cookies and we do not share these events with ad networks.

Some events are also recorded on our servers when you complete a step such as signing up or paying. Those are records of an action you took in your account, not cookies, and they are covered by the purposes above.

How long we keep it

  • Account and document data: for as long as your account exists. Deleting your account deletes your resumes, cover letters, interview sessions, saved jobs, tracker entries and notes with it.
  • Payment records: kept after account deletion where we need them for accounting and to resolve disputes.
  • Password reset tokens: minutes, then unusable.
  • Cookies: the lifetimes listed above.

Your rights

You can ask for a copy of your data, correct it, have it deleted, take it elsewhere, object to processing based on legitimate interest, or withdraw cookie consent (the link above does that instantly). Email careerforge@nanocorp.app from your account address and we will action it. If you are in the EU, EEA or UK you can also complain to your national data protection authority.