Privacy Notice

Version: 1.1-beta · Effective: 24 July 2026 · Last updated: 10 September 2026 (Autofill beta supplement)

This notice explains how GRADPLAN LTD uses personal data in the UK paid beta, including what is sent to AI providers, how long data is kept and how to exercise your rights.

1. Controller and contact details

GRADPLAN LTD is the controller for GradPlan account, product, support and legal-acceptance data. We are registered in England and Wales under company number 17348755. Registered office: 56 Fremantle Road, Ilford, United Kingdom, IG6 2AZ.

For access, correction, deletion, objection, restriction, portability, withdrawal or a privacy complaint, email hello@gradplan.uk. Please use the email connected to your account where possible. We may need proportionate information to verify identity.

2. Scope and service boundaries

This notice covers the public website, beta application, account and billing journey, support and the five paid-beta product areas: Tracker, Application Studio, Prep Hub, Insights and Improve Hub. Cappy AI, Group Task Simulation and legacy live/video analysis are not part of the paid-beta release described here.

GradPlan is for people aged 18 or over. We record an 18+ declaration and its version/time; we do not ask for a date of birth. If you believe a child has provided data, contact us.

3. Personal data, purposes and lawful bases

DataWhy we use itUK GDPR lawful basis
Account identity: user ID, email, display name, sign-in provider, authentication/security state and 18+ declarationCreate, secure and administer the account; enforce eligibility; communicate essential service informationContract; legitimate interests in security and fraud prevention; legal obligation where applicable
Beta application/invitation, access status, pass dates and entitlement recordsApprove testers, provide the purchased pass and enforce scope and allowancesSteps at your request before contract; contract; legitimate interests in operating a bounded beta
Tracker content: employers, roles, public job URLs/text, recruitment-email text you paste, stages, dates, contacts, interviews, notes, tasks and prioritiesProvide Tracker, Smart Import and role-linked workflowsContract; legitimate interests for security, support and service improvement using minimised operational data
Role & Company Intelligence data: the selected application, confirmed company identity, source references and excerpts, generated role/company brief, private notes, saved talking points and feedbackProvide vacancy-specific interview research, preserve your workspace and avoid regenerating unchanged materialContract for the requested research and storage; legitimate interests in source quality, reliability and cost control
Application Studio documents and text: CVs, cover letters, job descriptions, instructions, working copies, versions and accept/dismiss decisionsStore documents; generate requested drafts/reviews; preserve user-controlled version historyContract
Prep data: assigned questions, draft answers, psychometric answers/scores/history, microphone audio, transcripts, interview questions, feedback and scoresProvide deterministic practice and the requested Offline Audio Interview flowContract; explicit consent only if a special-category element is genuinely required and an approved flow asks for it. The normal product is not designed to require such data.
Improve Hub data: career profile context, self-assessments, feedback, goals, weekly actions and completion stateProvide user-controlled improvement planningContract
Private interview reflections: interview context, questions/topics, optional answer summaries, confidence and performance ratings, follow-up notes, reported interviewer feedback, outcome and generated coachingLet you keep a private learning record, continue drafts and request personalised post-interview feedback. These records are not contributed to community insights.Contract for storage and requested coaching. Any future community contribution would require a separate choice and assessment.
AI request metadata: request IDs, feature/scope, prompt/schema/model version, hashes, token/cost estimates, status, timing, safety and quota events; limited replay/cache content where implementedReturn requested output, avoid duplicate charges, control quotas, troubleshoot, secure the service and manage provider costContract for the requested result; legitimate interests in reliability, security and cost control
Legal acceptance data and payment data: Stripe customer/session/payment IDs, amount, currency, status, billing details returned by Stripe, accepted document versions, immediate-access request, time and sourceTake payment, issue/verify access, handle cancellation/refunds, prove the contract and meet tax/accounting/legal dutiesContract; legal obligation; legitimate interests in legal claims and fraud prevention
Support, feedback and privacy complaintsRespond, investigate, remedy problems and improve the betaContract; legal obligation for rights/complaints; legitimate interests for support and improvement
Newsletter data: email, name, subscription status, confirmation and suppression evidenceSend the optional GradPlan Briefing only after a separate positive marketing choice; honour unsubscribe and prevent re-contactConsent for marketing; legal obligation/legitimate interests for a minimal suppression record
Device/service data: IP/network-derived signals, browser/device information, authentication storage, reCAPTCHA result, request/security logs and service-worker/cache stateDeliver the site, maintain sessions, prevent abuse, diagnose incidents and keep the service secureContract; legitimate interests in secure and reliable operation; legal obligation where applicable

Where we rely on legitimate interests, we use the data because the processing is necessary for a secure, supportable beta and we consider the impact on users. You may object; we will stop unless we have compelling grounds or need the data for legal claims.

Public waitlist — added 6 September 2026

When you ask to join the waitlist, we collect your email, career stage and confirmation that you are 18 or over. Graduation year, broad industry and role interests are optional. We use these details to manage your request for access, understand aggregate demand and plan relevant onboarding. We do not ask for your university, degree, date of birth or documents. The basis for managing your access request is taking steps at your request before a contract; minimised demand analysis supports our legitimate interest in improving the service.

We record the choice and time for optional GradPlan product emails separately. It is not preselected or required to join. We do not treat an unverified email submission as permission to send promotional emails: ownership and consent must be confirmed before a marketing send. You can withdraw your choice or request removal by emailing hello@gradplan.uk. Any future promotional email must offer an unsubscribe option.

We retain a referring hostname and bounded campaign labels when present, not full referrer URLs. reCAPTCHA runs when you submit to prevent abuse. Our waitlist rate limiter keeps a keyed digest of the network address, not the raw address. Waitlist records use our existing Firebase database; the controlled submission function runs in London (europe-west2). Waitlist preferences are not sent to AI providers.

Unconverted waitlist entries expire after 12 months and are targeted by daily deletion. Rate-limit records expire after two days and are also targeted by that cleanup. Copies in provider backups expire under their own recovery policies. You may ask for earlier access, correction or deletion at the email above, subject to proportionate identity checks. Repeating an anonymous submission cannot change an existing entry. If you later create an account, matching must use a verified email and offer you a chance to confirm or change your preferences; this transfer is not automatic in the current release. Linked records are covered by account export and deletion.

4. Special-category, criminal-offence and third-party data

Please minimise sensitive content. Job documents and recordings can reveal health, disability, race or ethnic origin, religion, political opinions, trade-union membership, sexual orientation or criminal-offence information. GradPlan does not need this information for normal use. Remove it unless strictly necessary and do not provide another person’s data without authority.

We do not infer special-category attributes or use them to score employability. If a future workflow intentionally requires special-category or criminal-offence processing, it must have a documented Article 9/10 condition and appropriate safeguards before release. The paid beta does not treat general contract performance alone as authority for such processing.

5. AI and speech processing

AI operates only when you request an enabled feature. Question Cards, psychometric scoring and normal Improve Hub planning are deterministic in this paid-beta scope. Saving an interview-reflection draft does not use AI; submitting it for personalised feedback does.

FlowWhat leaves GradPlanWhat comes back and how it affects you
Tracker Smart ImportThe recruitment email/job-ad text you paste, or text retrieved from a supported public HTTPS job URL, plus limited extraction instructions and contextGoogle Gemini returns structured role fields as an editable draft. You review and change fields before saving. No employer receives it.
Application Studio generation and reviewExtracted CV or cover-letter text, relevant job description/role context and your instruction; not payment dataGemini returns a draft or review suggestions. You can edit, accept or dismiss them. GradPlan does not automatically replace the source document.
Role & Company IntelligenceThe selected vacancy and employer details, source-labelled public evidence retrieved for that employer, bounded profile/CV context, and any existing Tracker company research or Prep Hub company notes, market briefing and research-vault text relevant to your preparation. Notes added inside the Intelligence workspace are not included in later generation. For recent public reporting, NewsData.io receives only a bounded company-name search—not your identity, CV/profile, private notes, vacancy description or role text.Gemini returns a source-attributed role/company brief and candidate-specific preparation suggestions only after you select Generate or confirm Refresh. Existing saved research is treated as private, unverified context rather than an official source. Opening the workspace does not call Gemini or NewsData.io. Source classifications distinguish evidence, GradPlan analysis and items to verify; no employer receives the output. NewsData.io free-tier coverage is delayed, limited and not exhaustive.
Offline Audio Interview transcriptionMicrophone-only audio from the practice session is uploaded to a private temporary Google Cloud Storage object and sent to Google Cloud Speech-to-Text using the EU regional endpoint configured in sourceSpeech-to-Text returns a transcript. No video or facial analysis is used in this paid-beta flow.
Offline Audio Interview feedbackThe transcript, interview question and limited job/application contextGemini returns criterion-level feedback and suggested scores; GradPlan calculates the displayed final score. It is coaching for you, not an employer assessment or hiring prediction.
Post-interview reflection feedbackThe company/role/interview context and reflection content you choose to submit, including recorded questions, answer summaries, self-assessment, reported immediate feedback and outcomeGemini returns private structured coaching, possible answer structures, practice topics and possible follow-up questions. GradPlan stores the result so reopening it does not create another request. The output distinguishes self-assessment and user-recorded/reported information from verified fact; it is not a hiring prediction and is not shared with employers or other users.

Models and provider use

The source defaults currently reference Google Gemini models including gemini-3.5-flash and gemini-3.1-pro-preview; the exact deployed model may be changed through controlled configuration. GradPlan’s release controls require a paid Gemini API service for UK use. Google’s current Paid Services terms say submitted prompts and responses are not used to improve Google products, but Google separately states that prompts, context and output may be retained for up to 55 days for abuse monitoring and that flagged material may receive authorised human review. Do not submit unnecessary sensitive or confidential information.

Google states that Speech-to-Text does not retain input audio for service improvement unless the customer opts into data logging, and that batch/asynchronous transcript results may remain available for approximately five days. GradPlan’s source uses the EU endpoint and does not intentionally opt in to service-improvement logging; the current production-account setting still requires release verification.

No solely automated significant decisions

GradPlan does not make employment decisions, rank you for an employer, submit applications or make a solely automated decision that has a legal or similarly significant effect. You control saving Smart Import data and accepting document suggestions. Employers do not receive AI output from GradPlan.

Optional email application import

Where a provider is available, you can connect Gmail or Google Workspace to look for job applications you have already submitted. Connecting does not start a scan. You choose the account and date range and press Scan my inbox. GradPlan requests read-only mail access; it does not send, delete or modify your messages.

GradPlan first filters messages at the email provider, then checks limited metadata and snippets. For likely recruitment messages, it reads the necessary content, removes unrelated material and contact details where practical, and sends a small extract to the existing Gemini service to suggest application fields. No attachments or complete threads are analysed. Email access and refresh credentials are encrypted and remain on the backend.

You can open, edit, select or ignore suggestions. Only your explicit final approval creates applications in your tracker; email content cannot change existing applications. Full email bodies are not retained by GradPlan. Temporary suggestions, small source excerpts and scan records expire after 30 days; message fingerprints and approval receipts expire after 180 days. Expired data is inaccessible through the importer and is removed by automated database expiry. You can disconnect at any time in Settings → Password & security → Connected email accounts. Previously approved applications remain until you remove them or delete your account.

Gmail handles the mailbox and connection permissions; Google Cloud/Firebase handle processing and storage; Gemini handles limited structured extraction while the existing AI release controls pass. You can also remove provider consent through your Google account. GradPlan does not opt email requests into optional Gemini data sharing or model training. Provider processing remains subject to the AI and international-transfer details in this notice. Provider availability is subject to setup and verification.

6. Files, recordings and local device storage

Supported documents are stored in private Google Cloud Storage and authorised through short-lived access checks. Parsed text and document metadata may also be stored in Firestore to provide the workspace. The implementation applies type, size, ownership and rate checks; a separate malware-scanning service is not currently evidenced, so only upload files you trust.

Offline interview audio is a temporary processing file. Source code requests deletion after successful transcription. If deletion fails, the object is marked for retry and scheduled cleanup runs regularly; stale objects are targeted within 24 hours. Storage soft-delete configuration can keep a recoverable version for about seven further days. Transcripts and feedback remain in the workspace until you or GradPlan delete them under the account lifecycle.

GradPlan uses necessary browser/device storage for Firebase authentication, security, preferences, in-progress forms, rate/idempotency state, PWA caching and service operation. We found no advertising or general behavioural-analytics tracker in the paid-beta source. See the Cookies and Device Storage Notice.

7. Recipients and processors

  • Google Cloud/Firebase – hosting, authentication, Firestore, Cloud Functions/Run, Storage, logging, security and Speech-to-Text.
  • Google Gemini API – only for the user-requested AI flows described above while release controls pass.
  • NewsData.io – recent public company-reporting search for Role & Company Intelligence. It receives a bounded company-name query and server request metadata, not candidate or workspace content.
  • Stripe – checkout, payment, refunds/disputes, receipts and billing portal. Stripe acts as processor for some activities and as an independent controller for certain payment/compliance purposes.
  • Resend or another approved email delivery provider – only where enabled for essential account/transactional messages. Durable post-contract confirmation is a release requirement, not a claim that every email flow is already active.
  • Professional advisers, authorities or courts – when reasonably necessary to comply with law, protect rights or handle a claim.

We do not sell personal data and do not share your workspace with employers. We require providers to use appropriate contractual, security and confidentiality protections.

Optional newsletter

New newsletter signup and confirmation are paused during the current beta. Historical newsletter records remain covered by account export and deletion, and we retain only the minimal suppression evidence needed to honour an earlier unsubscribe or erasure choice. If newsletter signup is reintroduced, its consent will remain separate from requesting or purchasing beta access.

8. International transfers

GradPlan’s core Google Cloud resources identified in the audit are in UK/EU multi-regions and europe-west2, and source uses the EU Speech-to-Text endpoint. However, Google Gemini abuse monitoring/caching, Stripe payment operations and communications support can involve processing outside the UK.

Where restricted transfers occur, we rely on the provider’s applicable UK adequacy route or contractual safeguards, such as the UK International Data Transfer Addendum/recognised standard clauses, together with technical and organisational measures. The executed provider agreements and live account configurations must be verified before payment launch. You can request information about the relevant safeguard from hello@gradplan.uk.

9. Retention and deletion

We keep personal data only as long as needed for the purpose described, legal duties and the establishment, exercise or defence of claims. Current implementation and provider limits are:

DataCurrent retention/deletion behaviour
Account, Tracker, Application Studio, Prep and Improve workspace data, including Role & Company Intelligence, private notes, private interview reflections and stored coachingKept while the account remains open. Deleting an application or account targets its private intelligence record as well as other related records. A reflection can also be deleted individually. Pass expiry does not automatically delete workspace data. Account deletion targets active operational records, subject to recent sign-in, legal-retention configuration and exceptions below.
User-deleted documents and operational dataRemoved from active application storage where deletion succeeds. Cloud Storage soft delete can retain a recoverable version for about seven days; provider backups/recovery systems expire on their own bounded cycles.
Offline interview audioDeletion requested after successful transcription; failed deletion is retried and stale temporary files are targeted within 24 hours. Storage soft delete may add about seven days.
Speech-to-Text batch resultGoogle documents approximately five days for asynchronous/batch transcript-result availability. Input audio is not retained by Speech-to-Text under the non-logging configuration described above.
Gemini prompts, context and responsesGoogle documents up to 55 days for abuse monitoring, including possible authorised review when flagged. GradPlan may hold limited replay/cache content for shorter technical periods where implemented; workspace results remain under the account lifecycle.
Payment, acceptance, refund, fraud, accounting, support and complaint evidenceKept only while necessary for contract, tax/accounting, regulatory and legal-claims purposes. The source does not yet evidence an approved automated expiry period; access is restricted and records are subject to manual/legal review rather than being presented as automatically deleted on a fixed date.
Service and security logsKept under bounded Google Cloud logging settings and security needs. The current live retention setting was not re-verified during the 22 July audit because cloud authentication required interactive renewal; no unsupported fixed period is promised here.

You can download a JSON account export in Settings even without an active paid entitlement. Account deletion is available in Settings after recent authentication, but it may be paused if the legally required retention configuration is not approved; email us if the control is unavailable. We will not retain operational content merely because a pass expired.

10. Security

Controls evidenced in source include Firebase authentication, server-side entitlement checks, UK access controls, least-privilege database/storage rules, private file paths, short-lived access authorisation, reauthentication for deletion, App Check/reCAPTCHA and rate/cost limits. Cloud metadata previously evidenced UK/EU resource regions, uniform bucket access, seven-day soft delete and Firestore point-in-time recovery. No internet service is risk-free; tell us promptly if you suspect unauthorised access.

11. Your UK data-protection rights

Depending on the circumstances, you may ask us to:

  • give you access to personal data and information about its use;
  • correct inaccurate or incomplete data;
  • erase data;
  • restrict processing;
  • provide data you supplied in a portable format;
  • object to legitimate-interests processing or direct marketing;
  • withdraw consent at any time where consent is the basis, without affecting earlier processing; and
  • obtain human review and challenge a qualifying automated decision. GradPlan does not currently make such decisions.

Rights are not absolute. We will explain a lawful refusal or restriction. We normally respond within one month, subject to the UK GDPR rules for complex requests. There is no charge unless a request is manifestly unfounded or excessive.

12. Privacy complaints

Email hello@gradplan.uk with the issue and outcome you want. We will acknowledge a data-protection complaint within 30 days, investigate it, keep you informed where resolution takes longer, and provide the outcome without undue delay.

You may complain at any time to the UK Information Commissioner’s Office (ICO), including through the ICO data-protection complaint service. We would appreciate the chance to address the issue first, but you do not have to contact us before the ICO.

13. Changes to this notice

We may update this notice when features, providers, law or processing changes. We will publish the new version and effective date and give an appropriate in-product or email notice for a material change. New optional processing will not be justified by a historic acceptance where a new choice or consent is required.

Privacy contact: GRADPLAN LTD, 56 Fremantle Road, Ilford, United Kingdom, IG6 2AZ · hello@gradplan.uk

GradPlan Autofill — controlled Chrome beta (10 September 2026)

GradPlan Autofill uses information you explicitly approve in Settings to suggest and populate job-application fields. Existing account and career-profile details are offered as unverified drafts. Each value records its source, approval status and review time. You control permitted categories, can disable Autofill, disconnect extensions and delete the separate Autofill Profile.

The extension scans visible form metadata on the active page only when you choose to scan it. Labels, input types, field identifiers, descriptions and select options are classified locally. Page contents and candidate answers are not sent to AI services or GradPlan for classification. Only selected values are sent to the page when you choose to fill. The receiving website and its scripts can read values once inserted. You should review the website and every answer before continuing.

Equality and special-category fields, highly sensitive identifiers, declarations, signatures and CAPTCHA are excluded. Do not put sensitive information into free-text Autofill fields. Obvious sensitive terms are rejected, but this filter cannot determine every meaning of free text. The extension never submits an application, clicks application navigation or uploads a file. Selected document names and references can be displayed; files are uploaded manually through the existing document workflow.

Connection approval happens in the signed-in GradPlan website using Firebase authentication and App Check. The website keeps the public connection challenge in session storage for up to ten minutes to preserve the request through sign-in; the secret verifier stays in the extension. A one-use connection grant expires after two minutes. The extension keeps a short-lived session credential and account email in Chrome session memory, cleared on browser restart or disconnect. Credentials rotate during active use, expire after 15 minutes without renewal and have an eight-hour absolute lifetime. Complete profiles are not written to Chrome persistent storage. Previous field values for Undo remain in the content script's memory until navigation or browser closure.

Profiles stay in your GradPlan account until deleted or removed under the account-retention process. Session records, pairing grants, rate-limit buckets and optional daily aggregate counts have expiry fields and are scheduled for Firestore TTL deletion; expiry is enforced before physical deletion. Aggregate counts are retained for up to 90 days plus the provider's deletion delay. Profile and linked session records are included in account export and deletion; security credentials are not exported as usable secrets.

Optional anonymous daily counts are off by default. If enabled, they record totals such as scans, detected fields, insertions and undo actions, without names, answers, page domains or form text. A beta diagnostic report is created locally only when requested and contains the domain, detected platform and classification counts. You decide whether to share it with support. The API and hosting providers also process network and operational request metadata under the existing service-security arrangements.

Successful online GradPlan sign-out revokes paired extension access. If a network failure prevents revocation, disconnect the extension locally; server access remains bounded by credential expiry and the eight-hour absolute limit. Disabling Autofill, deleting its profile and account/token revocation also block future access. Already inserted data on an employer website must be edited there.