Last updated: 22 July 2026

Privacy Policy

Your job search is personal. You tell Avery things you would not put on a résumé — why you want to leave, what you are afraid of, what you are paid. This page explains exactly what we do with all of it, in the order you would actually ask: who we are, what we hold, why, who else sees it, how long we keep it, and how to make us stop.

1. Who is responsible for your data

The data controller for the personal data described in this policy is Career Love, operated by Brick30 Technologies LLC(“Career Love”, “we”, “us”). Career Love Builder is the product; Brick30 Technologies LLC is the company that operates it.

  • Privacy contact: [email protected] — use this address for every request under this policy, including access, deletion and complaints.
  • Postal address: 3120 Viking Blvd NE, East Bethel, MN 55092, United States
  • Data protection officer: we have not appointed a DPO. We are not required to under GDPR art.37 on our current processing; the privacy contact above reaches the people who make these decisions.
  • EU / UK representative (GDPR art.27): not currently appointed. If you are in the EEA or UK you can raise anything directly with the privacy contact above, and you always retain the right to complain to your own supervisory authority (see section 10).

This policy was last updated on 2026-07-22 and describes the service as it behaves on that date.

2. What personal data we hold

In plain English: Everything you type into the product, everything you upload, and the technical records our servers need to run it. We do not buy data about you from anyone, and we do not run advertising trackers or third-party analytics. If you opt in, we keep a first-party log of which features you use — described honestly below.

Account data

Email address, a bcrypt hash of your password (never the password itself), your display name, an optional avatar image reference, and the timestamps and versions of the consents you have given. If you sign in with LinkedIn we also receive your LinkedIn identifier, first and last name, headline, profile picture URL, vanity URL and email address.

Career profile

The substance of your coaching: current title, employer, industry, city, years of experience, work arrangement, current and target salary, target role, level, industry and city, relocation willingness, skills, what makes your background unusual, what triggered the jump, your timeline, your description of an ideal day, the barriers in your way, what you have already tried, and your satisfaction score.

Résumés and CVs

The original file you upload (PDF, DOC or DOCX, up to 5 MB) and the plain text extracted from it. Extraction happens on our own servers with local libraries — your file is not sent to a document-parsing service. The original binary is stored in our self-hosted object storage; the extracted text is stored in our database and is what gets used for scoring and tailoring.

Job applications and opportunities

Job listings you save or that our sourcing agents surface for you, match scores and the reasoning behind them, application status and dates, company briefs, interview preparation notes, offer details and negotiation notes, and any free-text notes you write.

Outreach messages and contacts

Draft emails, LinkedIn messages and call scripts prepared for you; the sequence and scheduling state around them; and the details of the people you are trying to reach — name, job title, employer, LinkedIn URL, and email address or inferred email pattern. Your do-not-contact list also lives here.

A note on other people’s data. Contact records are personal data about third parties who never signed up for our service. We hold them only as part of delivering your job search, we collect them from public and professional sources, we never use them for our own marketing, and we honour your do-not-contact list. If you are one of those contacts and want your record removed, email [email protected].

AI conversation history

Your full chat history with Avery, interview practice sessions and your answers, generated coaching insights, search journals, reflections and strategy reports.

Technical and operational data

IP address and user-agent string captured at the moment you give or withdraw consent (that is the art.7 proof that the consent was yours); audit events recording security-relevant actions; agent-run logs; and per-AI-call metadata (provider, model, token counts, latency, estimated cost).

Usage analytics — only if you opt in

If, and only if, you switch on the analytics toggle in the cookie banner or in Settings, we keep a first-party log of how you use the product: a named event (for example page_view or marked_sent), a small set of coarse properties (things like which kind of item, or a bucketed message length — never the message), the path of the page you were on, and a random session identifier that exists only for that browser tab. It is recorded on our own servers, in our own database, and goes nowhere else.

What that log deliberately does not contain: no IP address, no user-agent string, no free text of any kind — nothing you typed, no résumé content, no message content, no names or email addresses of your contacts. It is never sold, never shared with any third party, and never used for advertising. We use it to see where the product works and where people get stuck, so we can fix the product. Rows are deleted automatically after 180 days, and the whole log is off by default — with the toggle off, nothing is recorded at all.

3. Why we process it, and our lawful basis (GDPR art.6)

In plain English: Most of what we do, we do because you asked us to coach you — that is the contract. Optional email — the weekly digest, goal check-ins, opportunity alerts and anything promotional — and optional cookies rely on consent instead. If you have not switched optional email on, we do not send it; if you switch it off, we stop. Either way you keep the product, and you still get the small number of transactional messages about your account and about deadlines you would otherwise miss.

PurposeData usedLawful basis
Create and run your account; authenticate youAccount dataContract — art.6(1)(b)
Deliver coaching, résumé analysis, job matching, interview prep and outreach draftingCareer profile, résumés, conversations, applicationsContract — art.6(1)(b)
Find and rank opportunities; research target companies and contactsCareer profile, target criteria, contact recordsContract — art.6(1)(b); legitimate interests for third-party contact data — art.6(1)(f)
Transactional email: messages about your account, security, and something already in flight — for example a reminder that an offer you are holding has a decision deadlineAccount data, applicationsContract — art.6(1)(b)
Optional update email: the weekly digest, goal check-ins, and new-opportunity alertsAccount data, applications, goalsConsent — art.6(1)(a)
Marketing email about new features and offersEmail address, nameConsent — art.6(1)(a)
Optional usage analytics (the first-party event log in section 2)Event names, coarse properties, page paths, a per-tab session idConsent — art.6(1)(a) (and PECR / ePrivacy)
Security, abuse prevention, rate limiting, audit logging, backupsIP, user-agent, audit events, account dataLegitimate interests — art.6(1)(f)
Debugging, capacity planning, AI cost controlAgent-run logs, AI call metadataLegitimate interests — art.6(1)(f)
Complying with law; establishing or defending legal claimsWhatever is strictly relevantLegal obligation — art.6(1)(c); legitimate interests — art.6(1)(f)

Our legitimate-interests balancing

Where we rely on legitimate interests we have weighed our interest against your rights and freedoms, as art.6(1)(f) requires. For security and abuse prevention: our interest is keeping accounts and other people’s job-search data safe; the data used is minimal (IP, user-agent, action records), it is not used to profile you commercially, retention is capped, and a user would reasonably expect a service holding their résumé to keep security logs. For third-party contact research: our interest is delivering the service you asked for; the data is professional-context information about people in a hiring role, sourced from public and professional channels, it is never sold or used for our own marketing, it is deletable on request, and the do-not-contact list gives an immediate opt-out. On both, we consider the balance to fall in favour of processing. If you disagree in your particular situation, you can object — see section 10.

We do not deliberately collect special-category data (GDPR art.9). Free-text fields — conversations with Avery, résumé content, notes — can contain it if you choose to write it there (health, religion, trade-union membership, and so on). Please only share what you want processed.

4. AI and automated processing (GDPR art.22)

In plain English: AI does the drafting and the ranking. It never sends anything. Nothing leaves the app for a recruiter, hiring manager or employer until you have looked at it and tapped send yourself.

What is automated, concretely:

  • Opportunity scoring and ranking. Language models score how well a job matches your profile and thesis, and order your queue accordingly. The score is advice. You decide what to apply to.
  • Résumé analysis and tailoring. Models score your résumé against a job description and suggest edits. You keep the original and choose what to change.
  • Contact discovery and classification. Models read publicly available search results and classify whether a person looks like a relevant recruiter or hiring manager.
  • Outreach drafting. Models write first drafts of emails, LinkedIn notes and call scripts in your voice, from your profile.
  • Coaching, interview prep and the story of your search. Models generate guidance, practice questions and written summaries of your search.

The human gate

Every outbound message passes through an explicit approval step in the product before it can be marked ready, and the app itself never transmits outreach to a recipient. When you are ready to send, the product hands you a pre-filled link that opens your ownemail client, or the recipient’s LinkedIn page, plus copy-to-clipboard blocks — and the message only counts as sent when you say it was. In other words: the human is the transport. The only email our servers send is service email to you (reminders, alerts, digests).

Article 22

GDPR art.22 concerns decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Our position, honestly stated: this product is decision-support, not automated decision-making in that sense. No score we produce grants or denies you anything — we are not an employer, we do not screen you for a job, and we make no eligibility, credit or employment decision about you. Every consequential action (apply, send, accept, decline) is taken by you. We do not use AI to profile you for advertising, pricing or eligibility.

That said, ranking shapes attention: an opportunity our models score poorly is one you are less likely to see first. Models are wrong sometimes, and their training data carries bias. So the product always shows the reasoning behind a score, always lets you search and apply outside the ranking, and never hides an opportunity from you outright. If you believe an automated output has affected you unfairly, email [email protected] — you can ask for a human to look at it, express your point of view, and contest the result.

5. Who else sees your data

In plain English: A lot of this stack runs on our own hardware, and we would rather tell you which parts do not. We never sell your data, and we never share it with your current employer.

Self-hosted — your data stays on infrastructure we operate

  • PostgreSQL — the primary database: account, profile, applications, conversations, contacts.
  • MinIO object storage — the original résumé files you upload and rendered document artefacts.
  • Redis — the background job queue (scheduling, not long-term storage).
  • Local language models — an Ollama server and a self-hosted model gateway on our own network handle a large share of AI work. Where the gateway forwards a request to an upstream free model, that upstream is a third party.
  • SearXNG — a self-hosted metasearch instance, used for web and news search when configured (which is the deployment default we run).

Third parties — data does leave our infrastructure

RecipientWhat they receiveWhen
Anthropic (Claude API, US)Prompt content: résumé text, career profile, chat history, job descriptions, outreach contextWhen an administrator has enabled the Anthropic provider or unlocked it for a high-quality tier
Qwen (chat.qwenlm.ai, operated by Alibaba)The same prompt contentAs a fallback step on every quality tier when the local gateway is unavailable — so this can happen in normal operation
Brave Search API (US)Search queries — typically company names and role/people-finding phrases, not your profileOnly when the self-hosted SearXNG instance is not configured
scrape.do (proxy fetching service)The URLs of job postings and career pages being fetchedWhen a scraping token is configured; some paths can be redirected to a self-hosted equivalent
Greenhouse, Lever, Ashby, IndeedNothing about you — outbound reads of public job boards onlyDuring opportunity sourcing
LinkedInOAuth exchange; we receive your name, email, headline and picture and store the access tokenOnly if you connect your LinkedIn account
Our email relayYour email address and the content of service emailsWhenever we send you a reminder, alert or digest

What we do not do. We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not run advertising, session replay or fingerprinting tools, and no third-party analytics service — there are none in the codebase. The only analytics is the opt-in, first-party event log described in section 2, which runs on our own servers and is shared with no one. We do not disclose your job search to your current or prospective employer. We may disclose data to professional advisers, or to authorities where we are legally compelled, and would notify you unless legally barred from doing so.

6. International transfers

Our own infrastructure is self-hosted. However, several of the third parties in section 5 — Anthropic, Brave Search and LinkedIn — are US-based, and Qwen and scrape.do are operated from outside the EEA and UK. When one of those services is used, the relevant content leaves the EEA/UK.

Where we transfer personal data outside the EEA or UK we rely on the transfer safeguards published by each provider, such as EU Standard Contractual Clauses (with the UK Addendum where applicable) or the provider’s certification under the EU–US Data Privacy Framework, incorporated through that provider’s terms. We will not overstate this: we are documenting the exact mechanism in place for each provider, and if you want the current position for a specific one, email [email protected] and we will tell you what it is rather than what it ought to be.

7. How long we keep things

In plain English: Your account content stays until you delete it. The operational logs behind the scenes expire on a timer, whether you ask or not.

DataRetention
Account, profile, résumés, applications, conversations, contactsUntil you delete the item or your account. On account deletion we remove your records from our database and the résumé files you uploaded from our file storage
Per-AI-call metadata (provider, model, tokens, cost)30 days, then automatically deleted
Agent run logs90 days (failed runs are kept longer for diagnosis)
Security audit events180 days
Usage analytics events (only ever recorded if you opted in)180 days, then automatically deleted. Deleting your account removes them immediately
System backupsAt most 30 days. Nightly snapshots are deleted 30 days after they are taken — we keep no longer-term archive of any kind. A deletion request removes you from the live system immediately; snapshots taken before that request still contain your records, and every one of them is deleted within 30 days of your request
Consent records (GDPR art.7 proof)Kept for the life of the account, so we can demonstrate what you agreed to and when. They are deleted together with the account — we keep no consent record about you after you are gone
Temporary download links for your résumé filesSigned links expire after 1 hour

8. How we protect it

Measures actually implemented in the product today:

  • Passwords are hashed with bcrypt at cost factor 12. We never store or log the password itself, and we cannot recover it for you.
  • Sessions use signed, encrypted JWT cookies that are HttpOnly, SameSite=Lax and marked Secure over HTTPS, so browser JavaScript cannot read them. Sign-in and sign-out are CSRF-protected.
  • Every API route except a small allow-list (auth, health check, version, and the cron-dispatch endpoint which enforces its own bearer secret) is behind a server-side session check in middleware.
  • Data access is scoped to your user ID at the query layer, so one account cannot read another’s records.
  • Rate limiting on authentication, AI and other sensitive endpoints, to blunt brute-force and abuse.
  • Résumé downloads use short-lived signed URLs (1 hour) rather than public file links.
  • Uploads are constrained by type and size (PDF/DOC/DOCX, 5 MB), and text-bearing inputs are sanitised before storage.
  • The database, object storage and model servers run on infrastructure we operate, not on shared third-party SaaS.
  • If you connect LinkedIn, the access token we receive is encrypted before it is written to the database, using AES-256-GCM with a key held in the deployment environment rather than in the database. This applies to tokens stored from 19 July 2026 onward; if you connected LinkedIn before that date your token was stored unencrypted and is being migrated — until that migration is complete for your account, a copy of the database would yield a working LinkedIn credential. Reconnecting LinkedIn replaces the stored token with an encrypted one straight away. That token is also redacted from the data export described in section 9.

The limits of that, so you are not misled: the LinkedIn access token is the only column we encrypt field-by-field, and passwords are stored as bcrypt hashes rather than encrypted. Everything else — your profile, résumé text, conversations and contacts — is stored in the database without per-field encryption, protected instead by encryption in transit (HTTPS/TLS), by access control, and by the physical and operating system security of the servers we run. We are not going to claim full-disk encryption on every host as a blanket guarantee; if you need to know the exact posture of a specific system, ask us and we will tell you what it actually is. No system is perfectly secure, and we cannot guarantee absolute security.

Email in transit.The emails we send you carry job-search content, so the connection to our outbound mail server is encrypted too: in production the app either connects over TLS directly or upgrades the connection with STARTTLS, and it refuses to send at all if that upgrade fails. Unencrypted sending is possible only against a local mail catcher on a developer’s own machine, never on the live service. What we cannot promise is the leg after that: once your provider accepts the message, delivery onward to your inbox and the storage of it there are governed by your own email provider, not by us.

Breach notification. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware (GDPR art.33). Where the breach is likely to result in a high risk to you, we will tell you directly and without undue delay (art.34), describing what happened, what data was involved, and what to do about it. We will also comply with applicable US state breach notification laws.

9. Your controls in the app

You do not need to email us to exercise the two most common rights. In Settings → Privacy & your data you can:

  • Export your data — download a machine-readable copy of your account, profile, résumés, applications, conversations and contacts.
  • Delete your account — request erasure of your account and its associated records.
  • Change your consents — turn marketing email off or on, and update your cookie preferences, at any time.

Everything else — rectification, restriction, objection, or a question about any of the above — goes to [email protected].

10. Your rights if you are in the EEA, UK or Switzerland

In plain English: You can see it, fix it, take it with you, tell us to stop, or make us delete it. Asking costs nothing and we will not treat you differently for asking.

  • Access (art.15) — confirmation of whether we process your data, a copy of it, and the details in this policy.
  • Rectification (art.16) — correction of inaccurate data and completion of incomplete data. Most profile fields you can edit yourself.
  • Erasure (art.17) — deletion where the data is no longer needed, you withdraw the consent it relied on, or you successfully object.
  • Restriction (art.18) — a freeze on processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability (art.20) — the data you gave us, in a structured, commonly-used, machine-readable format, for the processing based on consent or contract. The export in Settings is built for exactly this.
  • Objection (art.21) — you may object at any time to processing based on legitimate interests, on grounds relating to your particular situation. Objection to direct marketing is absolute: we stop, no balancing.
  • Withdraw consent (art.7(3)) — at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew, and does not affect the parts of the service that run on contract rather than consent.
  • Rights relating to automated decisions (art.22) — see section 4.

How to exercise them. Use Settings where the control exists, or email [email protected]. We respond within one month (art.12(3)), extendable by two further months for complex or numerous requests — we will tell you if that happens and why. We may need to verify your identity, usually by confirming control of the account email.

Complaints. If you think we have got this wrong, please tell us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority (art.77), specifically the one in your country of residence, place of work, or where the alleged infringement happened. In the UKthat is the Information Commissioner’s Office (ICO), ico.org.uk, helpline 0303 123 1113. In the EEA it is your national data protection authority; the European Data Protection Board publishes the current list of members at edpb.europa.eu. In Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC).

11. Your US state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another state with a comprehensive consumer privacy law (including Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and others as they take effect), you have the rights below. Terms such as “personal information”, “sale”, “share” and “sensitive personal information” have the meanings given in the applicable state statute.

  • Right to know / access — the categories and specific pieces of personal information we have collected, the categories of sources, our business purposes, and the categories of third parties we disclose to. Sections 2, 3 and 5 above are that disclosure; the export in Settings gives you the specific pieces.
  • Right to delete — deletion of the personal information we collected from you, subject to statutory exceptions (for example security, legal compliance, or completing a transaction you requested).
  • Right to correct — correction of inaccurate personal information.
  • Right to data portability — a copy in a portable, readily usable format.
  • Right to opt out of sale or sharing, and of targeted / cross-context behavioural advertising.
  • Right to limit use and disclosure of sensitive personal information.
  • Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects. As explained in section 4, we do not make such decisions about you.
  • Right to non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We offer no financial incentives for personal information.
  • Right to appeal — where your state provides it (Virginia, Colorado, Connecticut and others), you may appeal a refusal by replying to our decision email. We will respond in writing within the statutory period, and if we deny the appeal we will tell you how to contact your state attorney general.

Do Not Sell or Share My Personal Information

Career Love does not sell your personal information, and does not share it for cross-context behavioural advertising. We have never done so. There are no advertising networks, no third-party analytics or marketing trackers, no data brokers and no ad-tech pixels in this product — we checked the codebase rather than assuming. The only usage measurement is our own first-party, opt-in event log (section 2), which lives on our servers and is disclosed to nobody, so it is not a “sale” or “share” under any state statute. Because there is no sale or sharing, there is nothing to opt out of, which is why you will not find an opt-out toggle: it would be a switch wired to nothing. We honour Global Privacy Control (GPC) signals in the sense that there is no selling or sharing for such a signal to stop. If that ever changes, we will update this policy before the change takes effect and provide a working opt-out.

Sensitive personal information

Depending on what you choose to write, your profile and conversations may include information a state law treats as sensitive (for example precise employment details or content you volunteer in free text). We use it only to provide the coaching service you asked for and for the security purposes described above — never to infer characteristics about you for advertising. We do not disclose it for any purpose that would trigger the “limit use” right; you can still ask us to limit it.

Making a request

Use Settings for export and deletion, or email [email protected]. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days with notice. An authorised agent may submit a request on your behalf with written permission; we may still ask you to verify your identity directly.

California “Shine the Light” (Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing purposes.

12. Children

Career Love Builder is a service for working adults and is not directed to children. You must be at least 16 to create an account (or 18 where your local law requires it for the contract to be valid). We do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete the account and its data promptly. If you believe a child has given us data, email [email protected] and we will act on it.

13. Cookies and local storage

We use a small number of strictly necessary cookies and one cookie that remembers your cookie choice. Nothing non-essential is stored or run before you opt in; the analytics session identifier (clb_analytics_session) is only ever written after you have said yes. The full, itemised list — real cookie and storage names, purposes and durations — is in our Cookie Policy.

14. Changes to this policy

If we change how we handle your data we will update this page and move the “last updated” date. For material changes — a new category of data, a new purpose, or a new third-party recipient — we will notify you in the app or by email before the change takes effect, and where the change relies on consent we will ask you again rather than assume the old answer still stands. Previous consent versions are retained so both of us can tell what applied when.

In practice that means the next time you sign in after a material change, a notice covers the app with the updated documents linked, and the rest of the interface stays behind it until you tick the box yourself. The box is never pre-ticked, and we do not record you as having accepted anything just because you kept the tab open. You can always sign out, read both documents while signed out, and email us instead. The same notice appears for accounts created before these documents were published, because we had never asked those people at all.

We want to be straight with you about the limit of that pause, because it is narrower than it looks. What stops is your own use of the app interface. What does not stop is the background work you already asked us to do under our contract with you — the scheduled agents that search for roles, score them against your profile, look up contacts and draft outreach for your approval keep running on their normal schedule while the notice is up. That processing rests on performing the contract, not on consent, so a pending acknowledgement does not switch it off. Nothing is sent to anyone on your behalf without your explicit approval, and nothing is deleted or frozen. If you want the background work stopped as well, sign out and email us at [email protected] and we will pause or close the account; you can also use the objection and opt-out rights in sections 10 and 11.

15. Contact

Career Love, operated by Brick30 Technologies LLC
Privacy contact: [email protected]
3120 Viking Blvd NE
East Bethel, MN 55092
United States