Legal
Privacy Policy
Last updated: June 2026 · Governing jurisdiction: Florida, USA
AiProof CareersHub ("we", "us", or "our") is operated by Kinson Digital Hub LLC, Jacksonville, FL, USA. This policy explains what personal data we collect, why we collect it, how it is stored, and your rights regarding that data. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable US data privacy standards.
1. What Data We Collect
- Email address — collected when you complete the career quiz and enter your email, or subscribe to our newsletter.
- Career quiz answers — your job category, job title or field of study, task descriptions, years of experience, and work-style answers. These are stored only in your browser's
localStorage during the session and are never stored on our servers.
- Payment information — if you purchase a full diagnostic report ($4.99), payment is processed by Stripe. We do not store card numbers or payment credentials. We only receive a confirmation that payment was successful.
- Analytics data — Google Analytics 4 (GA4) collects anonymised usage data including pages visited, time on page, browser type, and approximate geographic location. This is subject to Google's own privacy policy.
- Account data — if you create an account after purchasing a paid report, Clerk stores your email address and payment confirmation status.
2. Why We Collect It (Legal Basis)
- Email address — collected with your consent to deliver your diagnostic report and, if opted in, our career intelligence newsletter. Legal basis: consent (GDPR Art. 6(1)(a)).
- Payment confirmation — processed to fulfil the paid service contract. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- Analytics — used to improve the platform. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) for aggregated analytics; consent for cookies where required.
3. Third-Party Data Processors
We use the following third-party services to operate the platform. Each is a data processor acting under our instructions:
- MailerLite (mailerlite.com) — stores your email address and handles newsletter delivery. Servers in the EU. MailerLite Privacy Policy.
- Stripe (stripe.com) — processes one-time payments. Stripe Privacy Policy.
- Netlify (netlify.com) — hosts the website and serverless functions. No user data is stored in Netlify beyond server logs (IP addresses, request paths), which are retained for 30 days. Netlify Privacy Policy.
- Anthropic (anthropic.com) — powers the AI diagnostic report. Your quiz answers are sent to Anthropic's API to generate a personalised report. Anthropic does not use API inputs for model training by default. Anthropic Privacy Policy.
- Google Analytics (google.com/analytics) — collects anonymised usage analytics. Google Privacy Policy.
- Clerk (clerk.com) — provides user authentication and account management for users who create an account after purchasing a paid diagnostic report. Stores your email address, account details, and payment confirmation status. Clerk Privacy Policy.
4. Cookies
We use the following cookies:
- _ga, _gid, _ga_* — set by Google Analytics 4. Used for anonymised traffic analysis. These are analytics cookies. Duration: up to 2 years.
- apch_state, apch_lite_state, apch_result — set by our own site in browser
localStorage (not cookies). Used to save your quiz progress across the Stripe payment redirect. Cleared immediately after the report is generated. These do not leave your device.
- Cookie consent preference — stored in
localStorage to remember your analytics consent choice.
You can control or delete cookies through your browser settings at any time. Disabling analytics cookies will not affect your ability to use the diagnostic tool or receive your report.
5. Data Retention
- Email address — retained in MailerLite until you unsubscribe or request deletion.
- Quiz answers — not retained server-side. Cleared from your browser's localStorage after your report is generated.
- Payment records — retained by Stripe per their standard retention policy (typically 7 years for financial records).
- Server logs — retained by Netlify for approximately 30 days.
- Account data (Clerk) — retained until you request account deletion. Email aiproofcareershub@gmail.com to delete your Clerk account and all associated authentication data.
6. Your Rights (GDPR — EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights:
- Right to access — request a copy of the data we hold about you.
- Right to erasure — request deletion of your personal data (email address from MailerLite, etc.).
- Right to rectification — request correction of inaccurate data.
- Right to portability — receive your data in a machine-readable format.
- Right to object — object to data processing for legitimate interest or direct marketing.
- Right to withdraw consent — withdraw consent at any time (e.g., unsubscribe from the newsletter).
To exercise any of these rights, email us at aiproofcareershub@gmail.com. We will respond within 30 days.
7. Your Rights (CCPA — California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used.
- Request deletion of your personal information.
- Opt out of the sale of personal information. We do not sell personal information.
- Non-discrimination for exercising these rights.
To submit a CCPA request, email aiproofcareershub@gmail.com with the subject line "CCPA Request".
8. Data Security
We implement industry-standard security measures including HTTPS encryption on all pages, server-side storage of all production secrets (Anthropic API key, Stripe secret key, MailerLite key — stored exclusively in Netlify environment variables), HMAC-signed payment tokens, and CORS restrictions limiting API access to our domain. A non-secret site identifier is embedded in client-side JavaScript by design to authenticate frontend calls to our serverless functions; it is not a credential and does not provide access to any third-party systems. However, no method of electronic transmission or storage is 100% secure. We encourage you to use strong, unique passwords and report any security concerns to us promptly.
9. International Data Transfers
Our service providers (Netlify, MailerLite, Stripe, Anthropic, Google, Clerk) may process your data in the United States and the European Union. We rely on Standard Contractual Clauses and the Data Privacy Framework where applicable to ensure lawful transfer of data from the EU.
10. Children's Privacy
Our platform is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately at aiproofcareershub@gmail.com.
11. Changes to This Policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
12. Contact
For any privacy questions, data requests, or concerns:
📄 Download Privacy Policy (PDF)