Beta legal notice
Privacy Notice
Last updated: 16 July 2026
This notice explains how GradPlan handles personal data while providing the beta career-preparation platform.
1. Who We Are
GradPlan is a beta career-preparation platform operated by Aranda T Tuduwage. For privacy questions or requests, contact: aranda.tuduwage2003@gmail.com.
For the purposes of UK data protection law, the GradPlan operator is the controller of personal data collected through the beta service.
GradPlan is restricted to people aged 18 or over. The beta is not directed to children.
2. What Data We Collect
Depending on how you use GradPlan, we may collect and store:
- Account information, such as your name, email address, unique user identifier, login provider, and beta approval status.
- Age-assurance information: your 18-or-over declaration, its policy version, method, and time. GradPlan does not ask for or store your date of birth for this purpose.
- Job application data, including company names, roles, links, salaries, contacts, deadlines, notes, job descriptions, interview dates, and assessment dates.
- CV and document data, including uploaded CV and cover-letter files, parsed text, generated drafts, annotations, templates, and LinkedIn-exported CV content you choose to import.
- Career-profile and portfolio data, including your headline, introduction, skills, experience, education, projects, links, profile photo, publication settings, and the separate employer-facing snapshot you choose to publish.
- Preparation data, such as interview questions, answer notes, psychometric-style practice results, transcripts, scores, feedback, and progress records. Offline interviews request only your microphone. Accepted audio is uploaded privately for Google Cloud Speech-to-Text transcription, deleted after the transcript is saved, and otherwise removed by temporary-storage cleanup within 24 hours.
- AI prompt data for the enabled beta tools, such as recruitment emails, supported job-ad text, CV or cover-letter text, role context, and offline interview transcripts that you explicitly submit for feedback. Interview audio is sent to Speech-to-Text, not Gemini.
- Payment and access data, such as secure payment processor identifiers, payment status, amount paid, billing status, and the date your 30-day beta access expires.
- Legal acceptance data, including the Terms and Conditions and Privacy Notice versions you confirmed, the confirmation time, and the related checkout session identifier.
- Technical data, such as basic logs, device/browser information, timestamps, error messages, and security events.
- Beta feedback and support data, including the product area, page, message, status, and correspondence needed to respond.
- Privacy complaint data, including your complaint, acknowledgement, review dates, investigation status, outcome, and related correspondence.
- Newsletter data, including your email address, optional first name, signup source, consent wording version, confirmation and unsubscribe times, delivery status, and bounded campaign attribution.
- Newsletter engagement data provided by our email service, such as delivery, bounce, complaint, unsubscribe, and link-click events. Email-open information, where available, is treated as approximate.
- Operational access and AI-usage data, including entitlement changes, bounded usage counts, model identifiers, token counts, estimated cost, and administrative audit facts. These records do not intentionally include CV text, prompts, audio, or video.
3. How We Use Your Data
We use personal data to:
- consider your beta request, confirm the 18+ restriction, create and secure your account;
- manage invite-only beta access and 30-day paid beta access;
- save and display your job applications, CVs, preparation sessions, and progress;
- extract reviewable application fields, generate or review CV and cover-letter drafts, and transcribe and score an offline interview recording when you explicitly request an enabled AI tool;
- extract an editable career-profile draft from a recognised LinkedIn PDF locally in your browser, and publish or remove the employer-facing portfolio you control;
- process payments and prevent billing abuse;
- monitor, debug, secure, and improve the beta service;
- respond to support, privacy, rights requests and data-protection complaints;
- send the GradPlan Briefing when you separately opt in, manage your email preferences, measure bounded campaign attribution, and protect email deliverability; and
- comply with legal, accounting, tax, and security obligations.
4. Lawful Bases
We use the basis attached to each purpose; uploading optional content is not treated as consent merely because it is optional.
| Purpose | UK GDPR basis |
|---|---|
| Beta request, account, workspace, saved documents, support and user-requested tools | Steps at your request before contract and performance of the beta contract. |
| Enabled AI assistance that you request | Performance of the beta contract. AI is also subject to the separate approval gates described below. |
| Payment, entitlement, receipt, refund and dispute handling | Contract; legal obligation for required tax/accounting records; legitimate interests in fraud prevention and legal claims. |
| Authentication, reCAPTCHA, App Check, abuse prevention, debugging, availability and security | Legitimate interests in operating a secure, reliable service and protecting users; legal obligation where applicable. |
| Product feedback and bounded service improvement | Legitimate interests in understanding and improving the private beta, balanced against the limited data and user controls. |
| Privacy rights and data-protection complaints | Legal obligation and legitimate interests in demonstrating compliance and handling legal claims. |
| GradPlan Briefing and its preference/deliverability records | Consent. You can withdraw it using an email preference link without affecting beta access. |
5. Special-category and criminal-offence data
GradPlan is not designed to collect health, ethnicity, religion, sexual-orientation, trade-union, biometric-identification, political-opinion, genetic, or criminal-offence information and does not intentionally infer those matters. Do not put that information in a CV, email, chat, forum post, recording, or other field unless GradPlan has first provided a specific lawful route.
AI processing remains disabled until the controller has approved a policy that blocks unapproved Article 9 and Article 10 processing. If such data is received incidentally, GradPlan will restrict or delete it unless a documented legal condition and necessity assessment permits the processing.
6. AI processing and profiling
During the paid beta, enabled AI features use Google Gemini only for requested Tracker Smart Imports, Application Studio CV or cover-letter generation and its included review, and optional Offline Audio Interview feedback. Relevant extracted text and the minimum useful context may be sent to Google. For interview feedback, accepted microphone audio is sent to Google Cloud Speech-to-Text in the configured EU location; the resulting transcripts and frozen rubrics are then assessed together by Gemini. Audio is not sent to Gemini and is not retained after successful transcription. Question Cards, Psychometric Practice, Improve and Insights are deterministic and do not send their work to Gemini. GradPlan's production build must refuse AI requests unless the 18+ declaration, paid-provider tier, DPIA, lawful-basis and Article 9/10 approval gates all pass.
A recognised LinkedIn-generated profile PDF is parsed locally using its standard sections and is not sent to Gemini. The paid beta does not use Gemini as a fallback for career-profile import.
AI outputs and practice scores are guidance for you. They do not decide whether you receive GradPlan access, employment, education, credit, or another legal or similarly significant outcome. Review and edit every output; you can correct source data, reject a suggestion, export data, or delete the account.
7. Recipients and providers
Depending on the enabled feature, GradPlan uses:
- Google Firebase and Google Cloud: for authentication, database management, file storage, hosting, server functions, security checks, and operational logging.
- Google reCAPTCHA Enterprise and Firebase App Check: for bot, fraud and application-integrity checks.
- Google Cloud Speech-to-Text and Google Gemini: only when the approval gates pass, respectively for temporary offline-interview audio transcription and consolidated transcript feedback, plus requested Tracker Smart Imports and Application Studio generation or review.
- Stripe: to handle secure one-time beta-pass payments, receipts, refunds, and disputes.
- Resend: to send newsletter confirmation messages and GradPlan Briefing emails, maintain the confirmed audience, and handle delivery, bounces, complaints, preferences, and unsubscribes.
- Google Calendar: only if that integration passes its separate contract/transfer gate and you choose to connect it, to read busy-time events and create or update GradPlan interview events.
Public portfolio and Community content is also disclosed to the audience you choose or, for Community, other active beta members. Do not publish private third-party information.
8. Cookies, device storage and PECR
GradPlan uses local/session storage and browser caches for authentication continuity, preferences, application state and offline/service-worker operation. These are used only where needed to provide or secure the service. GradPlan does not currently use advertising or general audience-analytics cookies.
Invisible reCAPTCHA is loaded only when you submit a protected signup or newsletter action. The visible sign-in security check loads on the sign-in page and Google may set the _GRECAPTCHA cookie. GradPlan treats this access as strictly necessary for security. If non-essential analytics or advertising storage is introduced, it must remain off until you have made a valid choice.
9. Payments
Payment card details are handled directly by our secure third-party payment processor. GradPlan does not store your full card number. We only store limited transaction records, such as secure payment identifiers, payment status, amount paid, and beta access expiry, so that the app can confirm whether you should have access.
10. How long we keep data
GradPlan keeps identifiable data only for the relevant purpose and applies these rules:
- Account, application, CV, and preparation data: until you delete it, request deletion, or the beta account is closed.
- Published portfolio snapshots: until you unpublish the portfolio, request deletion, or the account is closed. A copied or cached version outside GradPlan may remain outside our control.
- Beta access requests: up to 18 months after the request or last interaction.
- Payment, tax/accounting, legal-acceptance, complaint and essential audit records: only the fields needed for the approved legal/claims period. Account deletion pseudonymises the subject reference and removes ordinary account data. The deletion service remains disabled until that period is approved.
- GradPlan's default Google Cloud Logging bucket currently retains logs for 30 days, unless an incident or legal hold requires a documented exception.
- Beta feedback and support correspondence: normally up to 18 months after resolution, subject to an active complaint or legal claim.
- Pending newsletter confirmations: the confirmation link expires after 24 hours and the short-lived confirmation record is scheduled for deletion.
- Confirmed newsletter consent evidence: while you remain subscribed and normally up to 24 months after you unsubscribe, so GradPlan can respect and demonstrate your choice. Provider-event deduplication records expire after 30 days.
- Access, administrative audit, and AI-usage records: normally up to 24 months, except for a documented security, dispute, legal, or accounting hold.
Firestore point-in-time recovery and Storage soft deletion currently provide recovery for up to seven days. An erased item may remain in that protected recovery layer until expiry; restore procedures must not reintroduce an erased account into the live service.
11. Security
GradPlan uses industry-standard authentication protocols, strict database security rules, restricted file storage access, and secure server routes to limit access to user data. No online service is completely risk-free, so you should avoid uploading unnecessary sensitive information.
12. Your rights
Under UK data protection law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. Signed-in users can download a JSON account export and delete their account from Settings without needing active paid access. You can also contact aranda.tuduwage2003@gmail.com. Legal exemptions may apply; GradPlan will explain any restriction.
Every GradPlan Briefing includes a link to unsubscribe or change the available email preference. Using that link withdraws newsletter consent without affecting a beta request, account, purchase, or service message.
Newsletter consent is separate from requesting or purchasing beta access.
13. Data-protection complaints
Email the privacy contact or choose “Data-protection complaint” on the signed-in support form. GradPlan will acknowledge the complaint, make appropriate enquiries, provide progress information where appropriate and communicate an outcome without undue delay. You may complain at any time to the Information Commissioner's Office.
14. International transfers
GradPlan's Firestore database is in Google's European multi-region, while Functions and the active file-storage bucket run in London. Some Google services, Stripe and Resend may still provide processing, support or subprocess from other countries. Affected optional providers and AI features remain launch-blocked until the controller records the applicable UK adequacy regulation, UK-US data bridge eligibility, IDTA or UK Addendum and completes the required transfer risk/data-protection assessment. You can ask the privacy contact for information about the safeguard that applies to your data.
15. Is the information required?
Email, authentication and the 18+ declaration are required to request and operate an account. Workspace content is optional, but a requested feature cannot work without the fields or document it needs. Payment information is required only if you choose a paid pass; newsletter information is entirely optional.
16. Changes to this notice
This notice may be updated as the beta changes. If a change materially affects how personal data is used, GradPlan will take reasonable steps to make the update clear.