Privacy Policy

Effective on public launch · Last updated: 14 July 2026

This is the legal version of our privacy promise, structured to meet India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). The short version: your data exists to serve you, and for nothing else. KNETT IT INFRASTRUCTURE AND SOLUTIONS PRIVATE LIMITED, 79, Shyam Lal Road, Darya Ganj, New Delhi, Delhi, India – 110002 is the Data Fiduciary for personal data processed through Roleora.

1. What we collect, and why

We collect only what the product needs. Each purpose is specific; we don’t reuse data for unrelated purposes (purpose limitation).

DataWhy we collect it
Account data: email, name, login method (email OTP / Google / GitHub)To create and secure your account and send essential service email
Profile data: education, role, skills, career detailsTo build your career profile and personalise generated documents
Work entries and logsThe core product — your career record; the source for every AI-generated document
Journal entriesPrivate reflection. Optionally client-side encrypted (see Section 4)
Uploaded documents: resumes, certificates, and sensitive files you may choose to upload such as ID proofs or salary slipsStored for you, in your document vault, at your choice
Payment status and transaction references (via Razorpay)To manage your subscription and credits. We never receive card/UPI credentials
Usage and technical data: log-ins, feature usage, device/browser basics, error logsSecurity, abuse prevention, metering, and fixing bugs
Community posts (when live)To display them, as you direct, in the Community

We do notcollect data we don’t need, and we do not buy data about you from anyone.

2. Consent, and withdrawing it

We process your personal data on the basis of your consent, given when you sign up and when you turn on optional features, after notice in clear, plain language. You can:

  • withdraw consent anytime — as easily as you gave it — by turning off the relevant feature, or by deleting your account from Settings;
  • request this notice and consent information in English (the language Roleora launches in) or in any language listed in the Eighth Schedule to the Constitution of India — write to privacy@roleora.com and we will provide a translation;

Withdrawing consent stops future processing; it doesn’t make past lawful processing unlawful, and some data may be retained where law requires (e.g., payment records for tax).

3. Our three commitments

  1. No AI training on your data. Your content is never used to train or fine-tune AI models — not by us, and contractually not by our AI processor.
  2. No selling data.We do not sell, rent, or trade personal data. No “anonymized insights” sold sideways either.
  3. No ads. No advertising on Roleora, no ad trackers, no third-party analytics SDKs that ship your data elsewhere.

We charge money for the product so we never have to make money from your data.

4. The encrypted journal — a special note

If you turn on journal encryption, your journal entries are encrypted on your device (AES-256-GCM) with a passphrase only you know. We store ciphertext. We cannot read, recover, or hand over your encrypted journal content — not to you without your passphrase, and not to anyone else. If you lose both the passphrase and your recovery code, that content is permanently unrecoverable. That’s the honest cost of a real lock.

5. Who processes data on our behalf

We use a small set of processors, each bound by contract to process data only on our instructions:

  • Microsoft Azure— hosting, storage, and databases. Application services and email run in Azure’s Central India region; AI document generation runs on Azure OpenAI in Sweden Central (EU) — prompts and outputs are processed there and not retained for training.
  • Azure OpenAI Service (Microsoft) — AI document generation. Under Azure OpenAI terms, your prompts and outputs are not used to train models and are not shared with other customers or with OpenAI.
  • Razorpay — payment processing (an RBI-regulated payment aggregator). Razorpay handles your payment instrument under its own privacy policy; we receive only transaction status and references.
  • Azure Communication Services (Microsoft) — sending OTP and service emails.

We do not use any third-party advertising or analytics processors.

6. Your rights (Data Principal rights under the DPDP Act)

You have the right to:

  • Access — a summary of the personal data we hold about you and how it is processed. Most of this is simply visible in the app; the rest, on request.
  • Correction and updating — fix inaccurate or outdated data, mostly self-serve in the app.
  • Erasure — delete individual items anytime, or delete your whole account from Settings. Deletion is real (see Section 7).
  • Portability — a one-click JSON export of everything you own, free, anytime, from Settings.
  • Grievance redressal — see Section 9.
  • Nominate a person to exercise your rights if you die or are incapacitated (write to privacy@roleora.com to set this up).

To exercise any right the app doesn’t cover self-serve, email privacy@roleora.com. We verify identity via your registered email before acting on requests.

7. Retention and deletion

  • Active accounts:we keep your data as long as your account exists — it’s your record; that’s the product.
  • Account deletion: immediate, irreversible erasure from live systems on confirmation; backup copies expire within their 30-day retention window. Payment and tax records are kept as long as law requires, then deleted.
  • Dormant accounts: after 24 months with zero logins, we send four notice emailsincluding a one-click export offer. If you don’t return, the account and data are deleted. We don’t keep personal data nobody is using.

8. Children’s data

Roleora is for users 18 and older— under-18 signup is blocked at signup via date-of-birth confirmation. We do not knowingly process a child’s personal data. If we learn an account belongs to someone under 18, we delete the account and its data. We do not do targeted advertising for anyone, of any age; features that observe your activity over time (streaks, heatmaps, AI memory) are the reason we restrict signup to adults, since the DPDP Act prohibits behavioural monitoring of children — a dedicated under-18 experience without such tracking is planned separately.

9. Grievance redressal (Grievance Officer)

Under the DPDP Act and the Information Technology Act, our Grievance Officer is:

Aaryash Kansal
Director, KNETT IT INFRASTRUCTURE AND SOLUTIONS PRIVATE LIMITED
grievance@roleora.com
79, Shyam Lal Road, Darya Ganj, New Delhi, Delhi, India – 110002

We acknowledge grievances within 48 hoursand aim to resolve them within the timelines prescribed under applicable law. If you’re unsatisfied with our response, you may approach the Data Protection Board of India.

10. Data breaches

If a personal data breach affects you, we will notify you and the Data Protection Board of Indiaas required by the DPDP Act — promptly, in plain language, with what happened, what data was involved, and what we’re doing about it. No burying it in a changelog.

11. Security

Encryption in transit and at rest; tenant isolation enforced on every database query; short-lived signed URLs for file access; rate limiting, audit logging, and security headers; client-side encryption available for the journal. Payments never touch our servers.

11b. Cookies

We use only first-party cookies strictly necessary to sign you in and keep your session secure. No advertising cookies, no third-party trackers, no cookie banner theatre — there’s nothing to opt out of.

12. Changes to this policy

Material changes are announced by email and in-app notice before they take effect, with the previous version archived. We will never change the three commitments in Section 3 quietly.

Questions: privacy@roleora.com.