Privacy Policy
Effective on public launch · Last updated: 14 July 2026
This is the legal version of our privacy promise, structured to meet India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). The short version: your data exists to serve you, and for nothing else. KNETT IT INFRASTRUCTURE AND SOLUTIONS PRIVATE LIMITED, 79, Shyam Lal Road, Darya Ganj, New Delhi, Delhi, India – 110002 is the Data Fiduciary for personal data processed through Roleora.
1. What we collect, and why
We collect only what the product needs. Each purpose is specific; we don’t reuse data for unrelated purposes (purpose limitation).
| Data | Why we collect it |
|---|---|
| Account data: email, name, login method (email OTP / Google / GitHub) | To create and secure your account and send essential service email |
| Profile data: education, role, skills, career details | To build your career profile and personalise generated documents |
| Work entries and logs | The core product — your career record; the source for every AI-generated document |
| Journal entries | Private reflection. Optionally client-side encrypted (see Section 4) |
| Uploaded documents: resumes, certificates, and sensitive files you may choose to upload such as ID proofs or salary slips | Stored for you, in your document vault, at your choice |
| Payment status and transaction references (via Razorpay) | To manage your subscription and credits. We never receive card/UPI credentials |
| Usage and technical data: log-ins, feature usage, device/browser basics, error logs | Security, abuse prevention, metering, and fixing bugs |
| Community posts (when live) | To display them, as you direct, in the Community |
We do notcollect data we don’t need, and we do not buy data about you from anyone.
2. Consent, and withdrawing it
We process your personal data on the basis of your consent, given when you sign up and when you turn on optional features, after notice in clear, plain language. You can:
- withdraw consent anytime — as easily as you gave it — by turning off the relevant feature, or by deleting your account from Settings;
- request this notice and consent information in English (the language Roleora launches in) or in any language listed in the Eighth Schedule to the Constitution of India — write to privacy@roleora.com and we will provide a translation;
Withdrawing consent stops future processing; it doesn’t make past lawful processing unlawful, and some data may be retained where law requires (e.g., payment records for tax).
3. Our three commitments
- No AI training on your data. Your content is never used to train or fine-tune AI models — not by us, and contractually not by our AI processor.
- No selling data.We do not sell, rent, or trade personal data. No “anonymized insights” sold sideways either.
- No ads. No advertising on Roleora, no ad trackers, no third-party analytics SDKs that ship your data elsewhere.
We charge money for the product so we never have to make money from your data.
4. The encrypted journal — a special note
If you turn on journal encryption, your journal entries are encrypted on your device (AES-256-GCM) with a passphrase only you know. We store ciphertext. We cannot read, recover, or hand over your encrypted journal content — not to you without your passphrase, and not to anyone else. If you lose both the passphrase and your recovery code, that content is permanently unrecoverable. That’s the honest cost of a real lock.
5. Who processes data on our behalf
We use a small set of processors, each bound by contract to process data only on our instructions:
- Microsoft Azure— hosting, storage, and databases. Application services and email run in Azure’s Central India region; AI document generation runs on Azure OpenAI in Sweden Central (EU) — prompts and outputs are processed there and not retained for training.
- Azure OpenAI Service (Microsoft) — AI document generation. Under Azure OpenAI terms, your prompts and outputs are not used to train models and are not shared with other customers or with OpenAI.
- Razorpay — payment processing (an RBI-regulated payment aggregator). Razorpay handles your payment instrument under its own privacy policy; we receive only transaction status and references.
- Azure Communication Services (Microsoft) — sending OTP and service emails.
We do not use any third-party advertising or analytics processors.
6. Your rights (Data Principal rights under the DPDP Act)
You have the right to:
- Access — a summary of the personal data we hold about you and how it is processed. Most of this is simply visible in the app; the rest, on request.
- Correction and updating — fix inaccurate or outdated data, mostly self-serve in the app.
- Erasure — delete individual items anytime, or delete your whole account from Settings. Deletion is real (see Section 7).
- Portability — a one-click JSON export of everything you own, free, anytime, from Settings.
- Grievance redressal — see Section 9.
- Nominate a person to exercise your rights if you die or are incapacitated (write to privacy@roleora.com to set this up).
To exercise any right the app doesn’t cover self-serve, email privacy@roleora.com. We verify identity via your registered email before acting on requests.
7. Retention and deletion
- Active accounts:we keep your data as long as your account exists — it’s your record; that’s the product.
- Account deletion: immediate, irreversible erasure from live systems on confirmation; backup copies expire within their 30-day retention window. Payment and tax records are kept as long as law requires, then deleted.
- Dormant accounts: after 24 months with zero logins, we send four notice emailsincluding a one-click export offer. If you don’t return, the account and data are deleted. We don’t keep personal data nobody is using.
8. Children’s data
Roleora is for users 18 and older— under-18 signup is blocked at signup via date-of-birth confirmation. We do not knowingly process a child’s personal data. If we learn an account belongs to someone under 18, we delete the account and its data. We do not do targeted advertising for anyone, of any age; features that observe your activity over time (streaks, heatmaps, AI memory) are the reason we restrict signup to adults, since the DPDP Act prohibits behavioural monitoring of children — a dedicated under-18 experience without such tracking is planned separately.
9. Grievance redressal (Grievance Officer)
Under the DPDP Act and the Information Technology Act, our Grievance Officer is:
Aaryash Kansal
Director, KNETT IT INFRASTRUCTURE AND SOLUTIONS PRIVATE LIMITED
grievance@roleora.com
79, Shyam Lal Road, Darya Ganj, New Delhi, Delhi, India – 110002
We acknowledge grievances within 48 hoursand aim to resolve them within the timelines prescribed under applicable law. If you’re unsatisfied with our response, you may approach the Data Protection Board of India.
10. Data breaches
If a personal data breach affects you, we will notify you and the Data Protection Board of Indiaas required by the DPDP Act — promptly, in plain language, with what happened, what data was involved, and what we’re doing about it. No burying it in a changelog.
11. Security
Encryption in transit and at rest; tenant isolation enforced on every database query; short-lived signed URLs for file access; rate limiting, audit logging, and security headers; client-side encryption available for the journal. Payments never touch our servers.
11b. Cookies
We use only first-party cookies strictly necessary to sign you in and keep your session secure. No advertising cookies, no third-party trackers, no cookie banner theatre — there’s nothing to opt out of.
12. Changes to this policy
Material changes are announced by email and in-app notice before they take effect, with the previous version archived. We will never change the three commitments in Section 3 quietly.
Questions: privacy@roleora.com.