Privacy Policy

Effective date: May 30, 2026  ·  Last updated: June 6, 2026

The short version: We collect only what you give us. We use it only to help you find jobs. Your accessibility information is never shared with employers, never put on your resume, and never sold. You control your data and can delete it at any time.

1. Who We Are

CandyBabble Careers is an AI-powered job search and resume tailoring platform operated by CandyBabble LLC. We are headquartered in the United States. You can reach us at jerome7207@gmail.com.

This policy explains what information we collect, how we use it, and what rights you have over it.

2. What We Collect

Account Information

When you create an account we collect your email address. We use Supabase Auth to manage authentication via magic link. We do not store your password — there is no password.

Resume Information

When you use the My Resume feature, you paste your resume text. We extract structured information from that text — name, contact details, skills, work history, and education. You review and confirm every field before anything is saved. This information is stored in your personal account and used only to generate tailored resume versions for you.

Accessibility Preferences (sensitive data — explicit consent required)

You may optionally tell us about your accessibility needs — for example, that you use a wheelchair, have one arm, have dyslexia, or any other need. This information is used for one purpose only: to help filter and prioritize job listings based on your stated preferences.

Disability and accessibility information is a special category of personal data under the EU General Data Protection Regulation (GDPR Article 9) and sensitive personal information under the California Privacy Rights Act (CPRA). We collect it only with your explicit, opt-in consent, only for the filtering purpose stated above, and you may withdraw consent and erase this data at any time from the Accessibility tab in your account, with no impact on your ability to use the rest of the platform.

Your accessibility information is NEVER:

You remain in control. Accessibility preferences are optional. You can update, change, or delete your preferences at any time. Filtering suggestions may be imperfect — you can always override any recommendation the system makes.

Job Search Activity

When you use the job matching and rewriter features, we store the tailored resume versions you generate so you can access them again. We do not share your generated resumes with any third party.

Usage Data

We may collect basic technical information such as browser type and general usage patterns to help us improve the platform. We do not use third-party advertising trackers.

3. How We Use Your Information

We do not sell your data. We do not use your data to train AI models. We do not show you advertising.

4. How We Store and Protect Your Data

Your data is stored in Supabase, a managed database platform that provides encryption at rest and in transit. We use Supabase Row Level Security (RLS) so that each user's data is accessible only under their own authenticated session — other users and unauthenticated requests cannot access your records.

Accessibility preference data is stored in a dedicated table with the strictest access controls. No application code reads this data for any purpose other than filtering job listings for your account.

No security system is perfect. If we become aware of a breach affecting your data, we will notify you promptly.

5. Third-Party Services (Subprocessors)

We use a small number of third-party services (“subprocessors”) to operate the platform. Each is named below with the data they receive and a link to their own privacy policy.

We do not use Facebook Pixel, Google Analytics, advertising networks, retargeting pixels, or session-replay tools.

AI training carve-out. We do not train AI models on your data, and our OpenAI usage is configured to opt out of provider training. We do not sell or share your data with AI companies, advertisers, recruiters, or employers for any training, profiling, or marketing purpose.

6. Your Rights

You have the right to:

To exercise any of these rights, email us at jerome7207@gmail.com. We will respond within 30 days.

California residents (CCPA / CPRA)

If you are a California resident, you have the rights listed above plus the right to know the categories and specific pieces of personal information we collect, the right to limit use and disclosure of sensitive personal information (including disability and accessibility data), and the right to opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioral advertising, and we have no “Do Not Sell or Share My Personal Information” link because there is nothing to opt out of — we do not engage in those activities. California residents may also designate an authorized agent to submit requests on their behalf.

EU and UK residents (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing are: (a) contract — to deliver the service you signed up for; (b) explicit consent — for accessibility preferences and any optional features; (c) legitimate interest — for security, fraud prevention, and basic usage analytics. You have the right to lodge a complaint with your local data-protection authority. International transfers to U.S.-based subprocessors (Supabase, OpenAI, Stripe, GitHub, Cloudflare) are made under Standard Contractual Clauses.

Other U.S. state residents

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have substantially the same rights listed above (access, correct, delete, port, opt out of targeted advertising and sale). To exercise any state-law right, email jerome7207@gmail.com.

7. Data Retention

We keep your data for as long as your account is active. Accessibility preferences are retained only while your account is active and are deleted immediately when you remove them from the Accessibility tab or close your account. If you request account deletion, we will permanently delete all your personal data, resume information, accessibility preferences, and generated resume versions within 30 days. Backups are purged on a rolling 90-day schedule.

8. Children's Privacy

CandyBabble Careers is intended for users 18 years of age and older. We do not knowingly collect information from children under 18. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

9. Changes to This Policy

If we make material changes to this policy, we will update the effective date at the top and notify active users by email at least 14 days before the changes take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.

10. Contact Us

CandyBabble LLC

Privacy questions and data requests: jerome7207@gmail.com

Accessibility barriers or accommodation requests: jerome7207@gmail.com · Accessibility Statement

We aim to respond to all privacy and accessibility inquiries within 30 days.

This policy is provided for informational purposes and reflects our current practices in plain language. It is not legal advice. For binding interpretation of your rights under any specific law, consult a qualified attorney in your jurisdiction.

Back to CandyBabble Careers