Privacy Policy

Last updated: 23 August 2026

Who we are

Rolepath is operated by Kaj Aleksander Kulik, a sole trader in Australia, ABN 76 899 516 534. This policy explains what personal information Rolepath collects, why it is collected, who else handles it, and how you can reach us about it. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

What Rolepath does

Rolepath is a web dashboard paired with a Chrome extension. It stores your resume and search preferences, collects SEEK job ads, screens them against your profile using AI, and drafts cover letters and suggested screener answers for you to review.

With the extension installed and your account signed in, opening a job ad on seek.com.au saves that listing to your account automatically, without you clicking anything. On SEEK application pages the extension fills in your cover letter and shows suggested screener answers for you to review and copy in yourself.

You can also run a search from the dashboard instead of browsing SEEK yourself. That is described under “When you run a search” below.

What we collect

  • Account email. Used to sign you in with a one-time link sent to your address. There are no passwords to store.
  • Profile and resume details. Your name, contact details, location, availability, key achievements, your answers to the optional “How you like to work” questions, and the resume you paste or upload. Resume text or page images are sent to one of our AI providers to be read into a structured form, and we store that structured result on your profile. We do not keep the original file.
  • Search preferences. The job titles, location, distance, work types and classifications you save as your search config.
  • Job listings. Title, company, location, work type, salary, apply type, ad text and screener questions from SEEK ads captured by the extension or returned by a search you run, along with the ad’s web address and the time it was captured, stored in your own private rows. An ad captured by the extension also includes SEEK’s “How you match” summary where the ad shows one. SEEK builds that summary from your own SEEK profile, so it describes you rather than the job.
  • AI output. Screening verdicts and scores, draft cover letters, suggested screener answers, and the stage you set on each job.
  • Sign-in tokens. The browser extension keeps a session token and a refresh token in its own extension storage so it can save captured jobs to your account. It sends them only to our servers and to Supabase, our authentication provider, to keep your session signed in. They are never shared with anyone else.

When you run a search

When you run a search from the dashboard, your saved search criteria, meaning your job titles, location, distance, work types and classifications, go to Rolepath’s servers, and Rolepath retrieves matching listings on your behalf. The listings that come back are saved to your account so you can screen them, and they are covered by the rest of this policy in the same way as listings captured by the extension.

How we use your information

  • Screen job ads against your profile and score them for fit.
  • Draft cover letters and suggested screener answers for a job you choose.
  • Fill in your cover letter and show suggested screener answers on SEEK when you start an application.
  • Retrieve listings that match your saved search criteria.
  • Run and support your account, including counting AI actions against the usage limits on your plan.

We do not sell your information, and we do not use it for advertising or disclose it for anyone else’s marketing.

Where your information is stored, and who else handles it

Your data is stored in a Supabase Postgres database with row level security, so an account can only read its own rows. Traffic between the extension, the web app and the database uses HTTPS.

Some of the providers Rolepath relies on handle information outside Australia. Under Australian Privacy Principle 8 we tell you who they are and where that happens:

  • AI providers: Anthropic, OpenRouter, DeepInfra and Novita AI. Process the AI requests. The job ad, the relevant parts of your profile or resume, and your instructions are sent to one of these providers to produce the output. Anthropic, OpenRouter and DeepInfra process these requests in the United States. Novita AI is based in San Francisco, United States, and its privacy policy, read on 8 September 2026, names the United States as a country it may transfer personal information to. See Anthropic's privacy policy, OpenRouter's privacy policy, DeepInfra's privacy policy and Novita AI's privacy policy.
  • Supabase. Hosts the database and the authentication service. The database runs in Sydney, Australia (ap-southeast-2), confirmed from the project dashboard on 9 August 2026.
  • Resend. Delivers the sign-in emails. Sending runs in Resend’s Tokyo, Japan region (ap-northeast-1), so your email address is handled there for that purpose.
  • SMTP2GO. The backup sender for the same sign-in emails, used only when Resend cannot send one.
  • ImprovMX. Forwards mail sent to our support address on to the operator’s mailbox, so anything you write to us, including an access or deletion request, passes through it. ImprovMX Incorporated is based in the United States, and its privacy policy states that it may process information on computers in the United States and Europe, read from its published policy on 9 August 2026.
  • Stripe. Will process subscription payments once subscriptions launch. Until then, Rolepath takes no payments and does not collect or store card details.

Analytics and tracking

Rolepath does not run third-party analytics or tracking scripts, and it does not use advertising cookies. The providers that host and serve the app keep their own operational request logs, as any web host does, and those logs are governed by their policies rather than by our code.

Information kept in your browser

The dashboard keeps some information in your browser so it loads quickly and keeps you signed in: your sign-in session, your theme and view preferences, and a cached copy of your jobs and AI answers. These local copies stay until that browser storage is cleared, which is separate from deleting data from our servers.

The extension keeps a separate set of its own: your sign-in token and refresh token, your account email and account id, the address of the dashboard it sends requests to, and a copy of your drafted cover letters and screener answers so they can be shown back to you on a SEEK application form. It does not keep captured job ads. Everything except the dashboard address is removed from the extension when you sign out, and when your session is rejected.

How long we keep your information

  • Your account data is kept for as long as your account is active.
  • Removing a job from your list marks it as dismissed rather than deleting it, and dismissed jobs are kept indefinitely so a later search does not suggest them to you again.
  • “Clear all” on the Jobs tab deletes your captured jobs from our servers, and their AI answers go with them.
  • If you ask us to delete your account, we remove the data we hold for you on our servers, including dismissed jobs.

Your choices and your rights

You can view and edit your profile and search preferences at any time in the dashboard, remove individual jobs, or use “Clear all” on the Jobs tab to delete every captured job and its AI answers.

There is no self-serve account deletion yet. To request access to the personal information we hold about you, to have it corrected, or to have your account and its data deleted, email support@rolepath.com.au.

If you are not satisfied with how we handle a privacy matter, you can raise it with the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

If this policy changes, the updated version is published on this page and the date at the top is changed with it.

Contact

Privacy questions, access requests and deletion requests go to support@rolepath.com.au.