CareerCaptain Legal & compliance

CAREERCAPTAIN · LEGAL

Privacy Notice

How CareerCaptain handles account, career, AI and service-usage data under UK data-protection law.

Last updated · 14 September 2026

1. Controller and contact

The Better Growth Company Ltd (company no. 12585000) is the controller of personal data processed through CareerCaptain, except where another organisation acts as controller for its own independent processing.

Data-protection correspondence may be sent to: Data Protection, The Better Growth Company Ltd, Apartment 1107, 9 Churchyard Row, London, SE11 4FF.

2. Data we process

  • Account data: email address, display name, authentication and session information.
  • Career records you choose to add: jobs, projects, achievements, people, interactions, skills, goals, learning, feedback, institutions, compensation, events, content and relationships.
  • Imported and document data: information contained in supported files you choose to import or add, including supported LinkedIn CSV exports and documents such as PDFs, DOCX and text files. For documents we may store source-file metadata, a server-computed SHA-256 receipt, extracted text, derived retrieval chunks and embeddings.
  • AI inputs and outputs: prompts, selected career context, query-relevant document excerpts and generated responses when you use Genie, meeting briefs, career narratives or the Weekly Career Brief.
  • Security and service data: login attempts, sessions, request metadata and information needed to protect and operate the service.
  • Billing data: subscription plan, billing interval, subscription status, Stripe customer and subscription identifiers, payment-event records and limited billing metadata. CareerCaptain does not store your full card number.
  • Product-usage and AI operational events: limited first-party metadata about high-value actions such as generating a brief, using Capture, importing or exporting. For AI requests this can include the model/intelligence class, reasoning level, prompt version, token counts, context size/truncation, latency and output-validity status. This operational measurement is designed not to record prompt bodies, generated answer bodies, document passages or the substantive content of your career records.

3. Why we use personal data

Provide CareerCaptain

We process account and career data to provide the service you request, including saving records, searching, generating timelines, producing exports and delivering authenticated features.

Provide AI-assisted features

When you deliberately invoke an AI feature, CareerCaptain assembles relevant context for that request and may send it to an AI service provider so that the requested output can be generated. AI output is treated as interpretation, not as a silent replacement for your source records.

Security, reliability and abuse prevention

We process technical and authentication data to secure accounts, investigate failures, limit abuse and protect the service.

Improve the product

We use limited first-party product-event data to understand whether key workflows are useful and where users encounter friction.

Process subscriptions and payments

Where you choose a paid plan, we process the billing and subscription information needed to establish, administer and enforce that subscription, reconcile payment events and provide customer billing controls.

4. Lawful bases

Depending on the processing, we rely on performance of a contract (providing the service you ask for), legitimate interests (for proportionate security, service improvement and fraud prevention), legal obligations, and consent where the law specifically requires it.

We do not treat agreement to this Privacy Notice as consent. Where consent is the required lawful basis, it must be requested separately and can be withdrawn.

5. AI and document processing

CareerCaptain currently uses the OpenAI API for selected AI features. Document processing also uses Floot-managed AI infrastructure where needed for tasks such as OCR and semantic embeddings, which may route the relevant document material to configured OpenAI or Google models. Relevant prompts, contextual data or document material are transmitted only when needed to perform the feature you have requested or enabled.

OpenAI states that, by default, inputs and outputs submitted through its API and business services are not used to train its models unless the API customer explicitly opts in. Provider retention, security and legal exceptions remain governed by the applicable provider terms and policies and may change independently of CareerCaptain.

CareerCaptain applies request-level data minimisation before AI use. General AI context does not include compensation records merely because compensation exists in your account; compensation context is included only when the request or selected focus explicitly concerns pay, remuneration or related financial context. Genie document retrieval is query-specific rather than automatically sending every stored document to the model.

Digital text is extracted deterministically where practical. Image-only PDFs may require machine OCR. Extracted text, OCR and embeddings are treated as derived processing artefacts rather than as a replacement for the original source document.

Where you record the outcome of an action after using an AI feature, CareerCaptain may make that outcome available to later AI requests as self-reported context. It is kept distinct from the earlier AI interpretation and is not treated as independent verification or proof that the action caused the outcome.

You should avoid entering information about other people that is unnecessary for your purpose, particularly sensitive or confidential information you are not entitled to process.

6. Human judgement and automated processing

Genie, briefs, narratives, drafting and situation-analysis features are decision-support tools. CareerCaptain does not use those AI outputs to make a solely automated decision about you that itself produces legal or similarly significant effects. You choose whether to request an output, whether to rely on it, whether to record a follow-through action and how to act on it.

CareerCaptain is designed to expose material context limitations where practical. A context summary may show which categories of your record were supplied to the model and whether eligible context was omitted to fit the request. That provenance is an aid to review, not a guarantee that generated output is correct.

7. Service providers and disclosures

We use service providers to host and operate CareerCaptain, including Floot-managed application infrastructure and database services, OpenAI for AI functionality, and Stripe for payment processing and subscription administration. Stripe processes payment information under its own security and privacy arrangements. We may also disclose information where required by law, to protect legal rights, or in connection with a legitimate corporate transaction subject to appropriate safeguards.

We do not sell personal data.

8. International processing

Some service providers may process data outside the United Kingdom. Where UK data-protection law requires safeguards for restricted transfers, we expect the relevant transfer mechanism or recognised safeguard to be used by the controller or processor responsible for that transfer.

9. Retention

Career records are generally retained while your account remains active so that the product can provide longitudinal professional memory. Authentication sessions currently expire after up to 30 days. Other operational and security records are retained only for as long as reasonably required for the purpose for which they were created, subject to legal, dispute and security needs.

For documents, you can choose to retain the original source until you delete it or use the privacy-minimising option that removes the original after successful extraction and indexing. When you delete a document normally, it moves to Recently deleted for 30 days so it can be restored; after that recovery period the retained source, extracted chunks and document-specific lifecycle data are permanently purged. A source already removed under the privacy-minimising option cannot be restored as an original file.

10. Your rights

Depending on the circumstances, UK data-protection law gives you rights to access, correct, erase, restrict or object to processing, receive certain data in portable form, and withdraw consent where processing is based on consent. Some rights are qualified and may not apply in every case.

The product provides record-level deletion and export controls for relevant data. Account-level erasure requests may require us to reconcile subscription, payment-event, security and audit records that can be subject to separate legal or operational retention requirements; exercising a right to erasure does not mean every record must or can always be deleted immediately where an applicable exception or legal obligation applies.

You also have the right to complain to the Information Commissioner's Office (ICO). We encourage you to contact us first so that we can try to resolve the issue.

11. Changes to this notice

We will update this notice when material data uses, service providers or legal requirements change. Material changes should be brought to users' attention before or when the new processing begins where required.