Privacy Policy
Last updated: March 29, 2026
1. Introduction
Profile Roaster (“profileroaster.in”, “the Service”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our Service.
By using the Service, you consent to the data practices described in this policy. If you do not agree with any part of this policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Email address: Required for order creation and delivery of results
- LinkedIn headline: Submitted for free teaser analysis
- LinkedIn profile data: Raw text pasted from your LinkedIn profile page including headline, about section, experience, education, skills, and certifications
- Job description: Optionally submitted by Pro plan users for job matching analysis
- Feedback and ratings: Optional feedback you provide after receiving results
2.2 Information Collected Automatically
- Order metadata: Order ID, plan type, payment status, timestamps
- Payment information: Razorpay order ID and payment ID (we do NOT store card numbers, UPI IDs, or banking credentials)
- Referral data: Referral codes and conversion tracking
- Usage data: Page views, teaser attempts, and conversion events for analytics
2.3 Information We Do NOT Collect
- We do NOT access your LinkedIn account directly
- We do NOT require LinkedIn login or OAuth authentication
- We do NOT scrape or crawl LinkedIn profiles
- We do NOT store credit card, debit card, or banking credentials
- We do NOT use cookies for advertising or third-party tracking
- We do NOT collect your IP address for profiling purposes
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To parse, analyze, roast, rewrite, and score your LinkedIn profile
- Result delivery: To send you a unique results URL and optional email notifications
- Card generation: To create a shareable roast card image from your scores and top roast
- Payment processing: To create and verify Razorpay payment orders
- Quality improvement: To monitor AI output quality and improve our prompts and scoring algorithms
- Customer support: To respond to your inquiries, feedback, or refund requests
- Fraud prevention: To detect and prevent fraudulent orders or abuse of the referral program
- Analytics: To understand usage patterns, conversion rates, and improve the Service (aggregated, non-personal data)
4. Data Processing by AI
Your LinkedIn profile data is processed by the following AI services to generate your results:
- Google Gemini: Used for initial profile parsing (Stage 1) to extract structured data from raw text
- Anthropic Claude: Used for profile analysis (Stage 2), roast generation (Stage 3), profile rewrite (Stage 4), and quality checking (Stage 5)
Your profile data is sent to these AI providers via their APIs for processing. Both Anthropic and Google have data processing agreements in place. Your data is used solely for generating your results and is not used to train AI models, as per the API terms of both providers.
We do not send any identifying information (such as your name or email) to AI providers. Only the profile text content is transmitted for analysis.
5. Data Storage and Security
5.1 Where Your Data is Stored
- Database: Supabase (PostgreSQL) hosted on AWS ap-south-1 (Mumbai, India)
- Card images: Supabase Storage (S3-compatible object storage)
- Queue system: Upstash Redis for job processing
5.2 Security Measures
- All data is transmitted over HTTPS/TLS encryption
- Database connections use SSL encryption
- Payment processing is handled by PCI-DSS compliant Razorpay
- API keys and secrets are stored as environment variables, never in source code
- Error monitoring via Sentry with personal data scrubbing enabled
- No human reads your profile data during normal operations — processing is fully automated by AI
5.3 Data Retention
- Profile data (raw paste): Deleted after 30 days via automated daily cleanup
- Parsed profile data: Deleted after 30 days
- Results (roast, rewrite, scores): Retained for up to 90 days to allow user access
- Card images: Retained indefinitely (public shareable images)
- Email addresses: Retained for customer support and communication purposes
- Payment records: Retained as required by Indian tax and accounting regulations (minimum 7 years for financial records)
- Teaser data (headline only): Deleted after 30 days for non-converted users
- Result recovery: Profile analysis results are stored for 30 days to allow result recovery. Users can delete their results at any time by visiting profileroaster.in/recover and clicking Delete My Results.
6. Data Sharing
We do NOT sell, rent, or trade your personal information. We share data only with:
- Razorpay: Email address and order amount for payment processing
- Anthropic: Profile text content (anonymized) for AI analysis and generation
- Google: Profile text content (anonymized) for AI parsing
- Supabase: All order data for database storage
- Sentry: Error data with personal information scrubbed
- Upstash: Order IDs for job queue processing
We may disclose your information if required by law, court order, or government request, or to protect the rights, property, or safety of Profile Roaster, its users, or the public.
7. Your Rights
You have the following rights regarding your personal data:
- Right to access: Request a copy of all personal data we hold about you
- Right to correction: Request correction of inaccurate personal data
- Right to deletion: Request deletion of your personal data (subject to legal retention requirements)
- Right to data portability: Request your data in a structured, machine-readable format
- Right to withdraw consent: Withdraw your consent for data processing at any time
- Right to object: Object to the processing of your personal data for specific purposes
To exercise any of these rights, contact us at support@profileroaster.in with your email address and order ID. We will respond within 30 business days.
8. Cookies and Tracking
The Service uses minimal cookies and does not use third-party advertising trackers.
- Essential cookies: Used by Next.js framework for page routing and session management
- Razorpay cookies: Set by Razorpay during payment processing for security and fraud prevention
- No advertising cookies: We do not use Google Analytics, Facebook Pixel, or any ad tracking cookies
- No cross-site tracking: We do not track your activity on other websites
9. Children’s Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.
10. International Data Transfers
Your data is primarily stored and processed in India (AWS Mumbai region). However, AI processing may involve data transfer to servers operated by Anthropic (United States) and Google (global infrastructure) via their APIs.
These transfers are necessary for the performance of the Service. Both providers maintain appropriate data protection measures and comply with applicable data protection regulations.
11. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users via email within 72 hours of becoming aware of the breach
- Provide details about the nature of the breach, the data affected, and steps taken to mitigate it
- Report the breach to relevant authorities as required by applicable law
- Take immediate steps to contain and remediate the breach
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting a notice on the website and updating the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
13. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Profile Roaster
Email: support@profileroaster.in
Website: profileroaster.in
If you are not satisfied with our response, you may lodge a complaint with the relevant data protection authority in your jurisdiction.