Plain-language beta policy
Privacy should feel like control.
The beta keeps learning records on your device and now performs résumé extraction, scoring, and revision planning locally. Accounts and live jobs remain disconnected until their production services are provisioned.
What this beta stores
Your career and exam selection, theme, target dates, question results, flashcard review schedule, saved mistakes, seven daily learning-action counts, local calendar dates for your last visit and last learning action, notes, and any Role Proof Studio stories are stored in this browser using local storage. The static beta does not transmit them to a Role by Role server.
Local role-proof stories
The Role Proof Studio stores up to three Situation–Action–Result drafts in this browser only. A story is labeled “ready to rehearse” only when all three sections contain useful detail and you check that you reviewed its truthfulness and removed client or customer names and confidential information. This is self-reviewed status, not employer verification, a hiring score, or an interview or offer prediction.
Do not enter customer names, account numbers, balances, health information, internal credentials, or confidential employer information. Role-proof stories are deliberately excluded from account sync. Clear an individual story in the studio, use the reset control, or clear site data to remove it from this browser.
Local résumé analysis
After a separate unchecked authorization, the browser reads a selected PDF or DOCX using same-origin copies of PDF.js and Mammoth. The file and extracted text exist transiently in the active tab. Common email addresses, US phone-number patterns, Social Security-number patterns, and links are removed from the working text where detected. Role by Role then keeps only a limited editable profile of skills, accomplishment lines, credentials, and non-content parsing signals in memory. The original file reference, filename, and full extracted text are released after extraction; no résumé content is sent to Role by Role, placed in browser storage, logged, used for analytics, or used for model training.
Local pattern removal is not guaranteed to detect every personal or confidential detail. Remove unnecessary sensitive information before choosing a file and inspect the extracted profile. PDF analysis is limited to 30 pages and files are limited to 10 MB. A scanned image-only PDF may not contain enough readable text.
The readiness score is a deterministic advisory writing and role-alignment heuristic under rubric version resume-readiness-local-v1. The learner must review and correct the extracted profile before scoring. The score is not an employer score, screening decision, interview likelihood, or probability of receiving an offer.
Revisions and deletion
Revision suggestions require a second unchecked authorization and use only the reviewed local profile. Suggestions preserve the source line, may contain clearly marked placeholders, and must not invent facts. The learner can edit each suggestion and then accept it or keep the original before downloading a decision record. Nothing changes the source résumé and nothing is sent to an employer.
The résumé workspace exists only in JavaScript memory. Use “Delete résumé workspace,” refresh, navigate away, or close the tab to discard it. A downloaded revision plan is a new local file controlled by the learner and is not deleted by the website.
Data minimization
Do not select files containing Social Security numbers, full birth dates, medical or financial information, government IDs, passwords, photos, confidential employer information, or another person’s information. File-type checks require both an accepted extension/MIME type and a matching PDF or ZIP signature. The analyzer extracts raw text and never renders document HTML or active content.
Passwordless account and progress-sync preview
No email, code, or learning record is submitted while the account API configuration is blank. When the reviewed account service is connected, signing in may store a versioned copy of structured study progress: selected exam, exam dates and whether each was labeled a planning target or self-recorded official appointment, checkpoint flags, securities and MLO route choices, self-recorded credential and MLO milestone booleans, aggregate question statistics, flashcard grades and schedules, seven daily learning-action counts, and local calendar dates for the last visit and last learning action. The interface asks which copy should win and never silently replaces a device with a different saved revision.
Résumé files, extracted profiles, readiness results, revision drafts, field notes, role-proof stories, job-match results, and community content are excluded from progress sync. Account export includes the saved structured snapshot; account deletion removes it with the account. Before accounts go live, this policy must identify the email and hosting processors, final retention, security notices, support contact, and applicable privacy rights.
The implemented but disconnected account service is designed for Cloudflare Workers, D1, and Email Sending. If it is enabled, Cloudflare will process the email, delivery metadata, session data, structured progress, and operational records needed to provide and protect that service. The Role by Role operator may access those records for support, security, export, and deletion. Final production configuration, locations, subprocessors, and access controls still require verification.
Implemented account-retention schedule—not active yet
- One-time codes expire after 10 minutes. A daily cleanup is implemented to remove the related request record after it has been expired for 24 hours; only a keyed code digest—not the code itself—is stored.
- Sessions have a 30-day maximum lifetime. Logout revokes the active session, and scheduled cleanup removes revoked and expired sessions.
- Email addresses and structured progress remain until account deletion; a final inactivity policy has not been approved.
- Security-event records and non-identifying account-deletion receipts are scheduled for removal after 90 days. Abuse-control windows are scheduled for removal after 48 hours.
These are enforced code defaults for the disconnected preview service, not a final public-retention promise. Email-delivery records, Cloudflare operational logs, backups or recovery copies, legal holds, and any legally required retention are outside that D1 cleanup and must be documented and approved before connection.
Cookies, analytics, and advertising
The current version sets no cookies and includes no analytics, advertising pixels, or behavioral trackers. A production account system will require a secure session cookie. Any analytics must be disclosed and designed to avoid collecting résumé text or sensitive career information.
Audience and account eligibility
No account service is active in this beta. Before public account registration is enabled, the operator must publish a qualified-reviewed minimum age and a clear minor-account policy, including any required parent or guardian consent and the related privacy-rights process. Role by Role will not infer or silently choose that policy from a visitor’s career interest.
Website delivery and operational metadata
The preview is delivered through Cloudflare Pages. Like other website hosts and content-delivery networks, Cloudflare processes ordinary technical request data—such as an IP address, requested URL, timestamp, browser or user-agent details, and security signals—to deliver and protect the site. That is separate from product analytics: Role by Role currently adds no analytics SDK, advertising tracker, or behavioral profile. Before production, the operator must verify which Cloudflare logs are enabled, who can access them, their location and retention, and the process for security and privacy requests. Résumé content must never be placed in a URL or operational log.
Job sources and human control
Live job results must come from authorized direct-employer sources and link to the original listing. New sources are disabled by default; the service requires an approved authorization basis, canonical HTTPS source URL, terms-review date, and removal contact before a feed can be enabled. Results expose the source URL and review date. If the jobs API is connected, the browser sends only the target role and optional preferred location—not résumé text or the editable profile—to retrieve listings. The service extracts a bounded vocabulary of job terms from listing descriptions, and the browser ranks those terms against the reviewed profile locally. Matching is guidance for the job seeker, not an employment decision, indication of employer interest, or guarantee of fit.
Opening an application link is a separate user choice. The link goes to the approved employer or recruiting-system host in a new context without opener access or Role by Role referral data. That destination will receive ordinary request metadata and any information the learner later submits under its own privacy terms; Role by Role does not apply or accept those terms for the learner.
Community and optional support
No community posts, public profiles, direct messages, or social graph are active. Optional-support controls remain disabled until one reviewed hosted payment provider is configured. At the decision point, the interface names that provider and links its privacy policy and terms before the learner leaves Role by Role. The provider—not this page—collects payment and transaction information under its policies. Its merchant dashboard may make a receipt record and payer details available to the Role by Role operator for reconciliation, refunds, disputes, and legally required records. No résumé, study history, score, job match, role-proof story, or Role by Role account identifier is attached to checkout. Role by Role never receives card numbers, and contributing does not change access, scores, matches, rankings, response speed, or service quality.
Your control today
Use the reset control or clear site data in your browser to remove locally stored learning information and role-proof stories. Use “Delete résumé workspace,” refresh, or close the tab to discard résumé-derived memory. There is currently no server résumé copy to retrieve.
This draft is not legal advice and must be reviewed for the operator’s actual location, users, vendors, and business model before publication.
Reviewed September 6, 2026 · Applies to the local-first Role by Role beta