Privacy Policy
Last updated: 18 August 2026RoleSage processes personal data to provide hiring and candidate workflows, strengthen trust in hiring, and deliver AI-assisted insights. We aim to collect only what is necessary and use it responsibly. If we contacted you about your business and you do not use RoleSage, see If we contacted you about your business .
Data we collect
Depending on how you use the service, this may include account details, profile data (such as skills, activities, and experience), role and application data, uploaded content, usage events, audit logs, and support messages.
Google User Data
If you choose to connect Gmail, RoleSage accesses your Google Account email address and display name, OAuth access and refresh tokens, and the permissions you grant. When RoleSage sends an email through Gmail, Google also returns message and thread identifiers used to show and maintain the communication in your authorized RoleSage timeline.
RoleSage requests the gmail.send permission only to send hiring-related emails from your connected Gmail account on your behalf. RoleSage does not request permission to read Gmail and does not read, download, or synchronize messages or replies from your Gmail inbox.
We use Google User Data only to connect the Gmail account, identify the sending mailbox, send emails that you initiate or authorize through RoleSage, and maintain user-visible communication and delivery records. Email content is disclosed to Google for delivery and to the intended recipients. Service providers may process Google User Data only where necessary to operate and secure this feature.
We do not sell Google User Data, use it for advertising, transfer it to advertising platforms, data brokers, or information resellers, use it to determine creditworthiness, or use it to develop, improve, or train generalized or non-personalized AI or machine-learning models. Human access is limited to cases where you give explicit permission for support, access is necessary for security, or access is required by law.
OAuth credentials are encrypted at rest and Google User Data is transmitted using secure protocols. We retain connection credentials only while Gmail remains connected. Disconnecting Gmail stops further access, attempts to revoke RoleSage's Google authorization, and permanently deletes the stored OAuth tokens, granted permissions, Google email address, and display name from the mailbox connection. Historical outbound communications and their delivery identifiers may remain in the authorized RoleSage timeline under the retention terms below.
You can manage or disconnect Gmail in Account Settings. To request deletion of other Google User Data or associated communication records held by RoleSage, contact support@rolesage.com. Deletion requests may be subject to limited security, legal, or dispute-resolution retention obligations.
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
How we use it
We use personal data to operate RoleSage, authenticate users, process candidate and role workflows, generate insights and match signals, maintain security, improve the service, and meet legal obligations.
AI-assisted features
RoleSage uses AI to analyze profiles, suggest improvements, and support matching. These outputs are assistive and not authoritative. You remain responsible for reviewing your data, and hiring decisions are made by humans.
Sharing
Your data is shared with hirers only when relevant (such as when you apply for a role). We may also share data with trusted service providers that help us operate the platform, such as hosting, authentication, analytics, and support tools. We do not sell personal data.
Cookies and storage
Necessary storage supports security and sign-in. Preference, analytics, and marketing storage remain disabled unless you opt in, and you can change these choices at any time. With marketing consent, RoleSage may record restricted campaign parameters and advertising click identifiers for up to 30 days so that a later demo request, onboarding completion, or real opening milestone can be attributed to the campaign. Direct visits do not overwrite an existing permitted paid-campaign touch.
When Meta measurement is enabled, RoleSage may send Meta a standard Lead event with a stable event ID, event time, RoleSage page URL, and the permitted Meta click identifier. RoleSage does not include your name, email, phone number, resume, candidate information, application content, or opening content in that event. Browser and server copies use the same event ID for deduplication.
Retention and security
We retain data only as long as necessary to provide the service, meet legal obligations, resolve disputes, and protect the platform. Raw campaign and provider identifiers are retained for up to 30 days. If a permitted journey produces a server-confirmed outcome, a contact-detail-free campaign snapshot may be retained for up to 24 months for experiment measurement. Human demo request details are retained for up to 180 days unless they must be kept longer for an active relationship or legal reason. We apply reasonable technical and organizational safeguards to protect your data.
Your rights
You may request access, correction, or deletion of your data, or raise privacy concerns via our support contact. Where consent applies, you can withdraw it at any time.
If we contacted you about your business
This section is for people we have approached directly, rather than people who use RoleSage. If we emailed you about your work and you have never signed up, this is the part that applies to you.
What we hold. Your name, your work email address, your job title or role, the company you work for, and where applicable a link to your public professional profile. We do not hold your personal contact details, your home address, or anything about you outside your professional role.
Where we got it. From public sources: company websites and team pages, published professional profiles, public investment and portfolio listings, and similar published material. We did not buy it from a data broker or a contact list vendor. The first message we send you names the specific source we found you in, and we keep a record of that source against your details so we can always answer the question.
Why we hold it, and our lawful basis. To contact you about RoleSage in connection with your professional role. Our lawful basis is legitimate interests: reaching a named person in a relevant role at a company we have a genuine business reason to approach. We do not use these details for automated decision-making or profiling, we do not use them to train AI models, and we do not sell or share them with anyone outside our own service providers.
How long we keep it. If we never make contact, up to 24 months from when we collected it. If we contact you and you do not respond, up to 36 months from our last message. If we end up in an active conversation, for as long as that conversation is live, and up to 36 months after it closes. After that we remove the details that identify you and keep only the business record, which no longer names you. If you ask us to stop contacting you, we keep the minimum needed to honour that indefinitely, because otherwise we would find you again and contact you again.
Your rights. You can ask what we hold, correct it, have it deleted, or object to our holding it at all. Reply to any message from us, or write to support@rolesage.com, and we will action it within 30 days. Asking us to stop takes effect regardless of anything else, and you do not have to give a reason. If you are in the EU or UK you may also complain to your local data protection authority; in Australia, to the Office of the Australian Information Commissioner.
Contact
For privacy questions or requests, contact us at support@rolesage.com.