At CareerCard ("we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use careercard.ai and the CareerCard mobile application (collectively, the "Service"). This policy applies to users worldwide, including those protected by the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
WSM Enterprises LLC, doing business as CareerCard, is the data controller for the personal data processed through the Service. For privacy-related inquiries, contact us at: support@careercard.ai
We process your personal data under the following legal bases:
CareerCard uses artificial intelligence as a core component of the service to provide personalized career insights. We process your career data (professional history, skills, goals, and documents) through AI models to generate recommendations, optimize resumes, and provide career guidance.
store: false to prevent provider-side storage for training or evaluationCareerCard uses two separate frameworks for managing data processing preferences:
The following categories are managed via the cookie consent banner on web and require your explicit opt-in consent under the ePrivacy Directive:
You may withdraw consent for any cookie category at any time via the cookie banner or your account privacy settings. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal (GDPR Art. 7(3)).
AI processing is a core component of the CareerCard service, performed under contractual necessity (GDPR Art. 6(1)(b)) as described in our Terms of Service. AI features are enabled by default when you use the service. You may opt out of AI processing at any time in your account settings or on the mobile app. Opting out will disable AI-powered features such as career suggestions, performance review generation, and resume optimization.
The AI opt-out is a contractual preference, not a withdrawal of consent. It takes effect immediately and does not affect other aspects of the service.
We use the following third-party services to operate CareerCard. Each processes data only as necessary for its stated purpose:
| Service | Purpose | Data Processed |
|---|---|---|
| OpenAI | AI model inference | Career data (PII-scrubbed), prompts, embeddings |
| Portkey | AI gateway and routing | AI requests (pass-through, not stored) |
| Azure Content Safety | Prompt injection detection | AI prompts (analyzed, not stored) |
| Convex | Backend database and functions | All application data |
| WorkOS | Authentication and user management | Email, name, auth credentials, MFA status |
| Stripe | Payment processing | Billing information, subscription status |
| Cloudflare (R2 & Workers) | File storage, web hosting, CDN | Uploaded documents, web traffic |
| Sentry | Error monitoring & crash diagnosis | Error reports, device info (PII-scrubbed); opt-in session replays with all text & images masked. Email masked and IP not stored. 90-day retention. |
| PostHog | Product analytics | Usage events, feature interactions (anonymized) |
| Resend | Transactional email | Email address, email content |
| Expo Push | Mobile push notifications | Push tokens, notification content |
When you delete your account, all personal data is cascade-deleted across all tables. Consent audit logs and data subject request records are retained for regulatory compliance.
Under GDPR and other applicable data protection laws, you have the right to:
Automated decision-making (Art. 22): CareerCard's AI features are assistive tools that generate suggestions and drafts for your review. No decision with legal or similarly significant effect is made solely by automated means. All AI outputs are advisory and require your review before use.
California residents (CCPA): You have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell your personal information.
To exercise any of these rights, use the in-app settings or contact us at support@careercard.ai. We will respond within 30 days (or sooner if required by law).
We use the following types of cookies and tracking technologies:
You can manage analytics and error reporting consent through the in-app privacy settings. Essential cookies cannot be disabled as they are required for the Service to function.
Your data may be processed in the United States and other countries where our sub-processors operate. For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions as appropriate. Our sub-processors maintain their own data transfer mechanisms as required by applicable law.
You must be 13 years of age or older to use CareerCard. We ask for self-attestation at signup and do not knowingly collect personal information from anyone under 13. If you believe a user under 13 has created an account, email support@careercard.ai and we will delete it.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the date below. For significant changes, we may also notify you via email or in-app notification.
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
If you are in the EU and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
Last updated: June 2026
May 2026 — Clarified that performance/error monitoring includes opt-in, privacy-masked session replay (Sentry) on web and mobile, with a 90-day retention period. No change to default settings; session replay remains off unless you enable it.