Privacy

Privacy Policy

How we handle your data, AI inputs and your rights.

Version 2.0 · Last updated 2026-07-0113 min read

Privacy Policy

This Privacy Policy explains how Kelroda ("Kelroda", "we", "us", "our") collects, uses, shares and protects your personal data when you use the Kelroda website and application (the "Service"), an AI career‑mentor that provides guided career discovery, a personalized roadmap, an ATS‑aware CV/resume builder, a LinkedIn analyzer and weekly task planning.

We process personal data in accordance with Regulation (EU) 2016/679 (the GDPR) and the Lithuanian Law on Legal Protection of Personal Data. Please read it together with our Terms of Service.

Who we are (data controller)

The controller responsible for your personal data is:

  • Trading name: Kelroda
  • Legal entity: Marius Sereika
  • Legal form & business-activity code: Natural person carrying out individual activity (individuali veikla) · certificate No. 940137
  • VAT code (if registered): Not VAT-registered
  • Registered address: Polocko St. 26, 10205 Vilnius, Lithuania
  • Email: admin@kelroda.com
<!-- If you appoint a Data Protection Officer, add their contact here. A DPO is not strictly mandatory for an operation of this size, but profiling of users may make one advisable — confirm with counsel. -->

We have not appointed a Data Protection Officer. For any privacy question, or to exercise your rights, contact us at admin@kelroda.com.

What data we collect

We collect only what we need to run the Service. The categories are:

CategoryExamplesSource
Account dataEmail address, hashed password, authentication method (password / magic link), email‑verification status, account ID, language setting, terms‑acceptance and consent timestampsYou, at sign‑up
Profile dataName, avatar/profile image, headline, career goals and preferencesYou
CV / resume contentCVs you upload or build, work history, education, skills, generated documents and export filesYou
Discovery & assessment answersYour responses, ratings and rankings in the guided career‑discovery interviewYou
Chat transcriptsMessages exchanged with the AI coach and related threadsYou
AI‑derived memory & insightsLong‑term "memory" the AI builds about your background, strengths, working style, goals and other psychological/career insights inferred from your activity, used to personalize guidanceGenerated by us from your inputs
Career & task dataRoadmap, tasks, attachments, job applications, LinkedIn import/analysis content, weekly reviews, XP/progress eventsYou and the Service
Subscription & payment metadataPlan, subscription status, billing period, cancellation state, Stripe customer/subscription identifiers, refund requests. We do not receive or store full card numbers — these are handled by Stripe.Stripe + you
Usage & technical dataProduct‑event logs, AI usage logs (model, token counts, latency, feature label, success/error — not the content of your prompts), rate‑limit counters, AI feedback (👍/👎), device/browser info, IP address, approximate location, error logsAutomatically
Communications dataNotifications, notification preferences, email send/suppression logs, push subscriptions, support tickets and messages, NPS responses and testimonial consent, referral dataYou and the Service
Phone numberMobile phone number collected at sign‑up, used for account security and — with your consent — marketing SMS or callsYou

Please do not enter special‑category data (e.g. health, religion, political views, ethnicity) into free‑text fields, your CV or chat unless necessary. If you choose to, you consent to our processing it to provide the Service.

We rely on the following legal bases under Article 6 GDPR (and Article 9 where you voluntarily provide special‑category data — Art. 9(2)(a), explicit consent):

PurposeLegal basis
Create and manage your account; provide the core Service (coach, CV builder, roadmap, tasks, LinkedIn analyzer); process payments and subscriptions; deliver transactional emails and notificationsContract — Art. 6(1)(b)
Build AI‑derived memory and psychological/career profiling from your discovery interview and activity to personalize guidanceConsent — Art. 6(1)(a) (recorded in‑app; you can withdraw it)
Send marketing emails and product updates; load non‑essential analytics and marketing cookies/trackersConsent — Art. 6(1)(a)
Keep the Service secure: fraud and bot prevention (CAPTCHA), abuse rate‑limiting, security and error logging, first‑party product analytics, and product improvementLegitimate interests — Art. 6(1)(f)
Retain billing, invoicing and tax recordsLegal obligation — Art. 6(1)(c)
Establish, exercise or defend legal claimsLegitimate interests — Art. 6(1)(f)

Where we rely on legitimate interests, we have weighed those interests against your rights and you may object at any time (see Your rights). Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

Automated processing and profiling

The Service is built around AI. We use automated processing and profiling to tailor your coaching, roadmap, CV suggestions and task plans, including the AI‑derived memory and psychological/career insights described above. This profiling does not produce legal effects or similarly significant effects on you within the meaning of Article 22 GDPR — it generates guidance and suggestions, not binding decisions. You can review and delete memory entries in your profile, object to the profiling, and ask for human review of any output by contacting us.

How AI processing works

To generate coaching responses, CV improvements, roadmaps and similar output, relevant content (e.g. your CV, chat messages, memory, discovery answers, job descriptions, LinkedIn content) is sent to AI models operated by Google (Gemini), accessed only through the Lovable AI Gateway. Your free‑text content is isolated from system instructions and wrapped with an injection guard. We do not use your content to train third‑party foundation models, and we do not give AI providers the right to train on it for their own purposes.

Who we share data with (processors / sub‑processors)

We do not sell your personal data. We share it only with service providers ("processors") who process it on our behalf under a GDPR Article 28 data‑processing agreement, and only as needed to run the Service.

<!-- VERIFY each entity name, role, region and transfer mechanism before launch. -->
ProcessorRoleLocation / hostingTransfer safeguard
SupabaseDatabase, authentication, file storage (avatars, uploads, generated assets)Hosted on AWS, region eu-central-1 (Frankfurt)Data stored in the EU (EEA) — no transfer outside the EEA
Cloudflare, Inc.Edge hosting/CDN, web application firewall, Turnstile bot/CAPTCHA defenseGlobal edge; US companyEU SCCs + EU-US DPF
Lovable (Lovable Labs Incorporated)Application build & hosting (Lovable Cloud) and AI gateway routingUS company (Delaware); operations in Stockholm, SwedenEU SCCs (+ EU-US DPF where certified)
Google (via Lovable AI Gateway)AI model inference (Gemini) for coaching, CV and roadmap generationEU/USEU SCCs + EU-US DPF
StripePayment processing, subscriptions, billingStripe Payments Europe (Ireland) / Stripe, Inc. (US)EU SCCs + EU‑US DPF
Omnisend (UAB Omnisend)Email service provider — transactional and (with consent) marketing emailLithuania (EU); some storage via affiliates on US serversEU SCCs + EU-US DPF (per Omnisend DPA)

Optional analytics & marketing providers load only if you consent to the matching cookie category and the relevant tag is enabled: Google Analytics 4 and Microsoft Clarity (analytics); Meta Pixel (marketing). See the cookies table. If these tags are not configured, no data is sent to them.

We may also disclose data where required by law, to enforce our Terms, or in connection with a merger, acquisition or sale of assets (you will be notified of any such change of controller).

International data transfers

Some processors are located outside the European Economic Area (EEA), primarily in the United States. Where data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR — the European Commission's Standard Contractual Clauses and, where the importer is certified, the EU‑US Data Privacy Framework — together with supplementary measures as needed. You can request a copy of the relevant safeguards by emailing admin@kelroda.com.

How long we keep your data

We keep personal data only as long as necessary for the purposes above. Indicative retention periods (to be confirmed by the operator):

  • Account, profile, CV, chat, AI memory, discovery and task data — for the life of your account. When you delete your account, this data is deleted, with any residual copies in encrypted backups purged within 30 days.
  • Billing, invoicing and tax records — retained as required by Lithuanian accounting and tax law (generally up to 10 years).
  • Security and error logs — up to 12 months.
  • AI usage logs (metadata only) — up to 18 months.
  • Support communications — up to 24 months.
  • Marketing-consent records — for the duration of consent plus 3 years as proof of consent/withdrawal.
  • Cookies and similar storage — per the durations in the cookies table.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict or object to processing, including profiling and direct marketing;
  • Data portability — receive your data in a structured, machine‑readable format;
  • Withdraw consent at any time, where processing is based on consent;
  • Not be subject to a decision based solely on automated processing producing legal or similarly significant effects (see Automated processing).

How to exercise them. Most rights are self‑service in Profile → settings: use Export my data to download a machine‑readable copy, and Delete my account to erase your data. You can manage AI memory in the Memory section, marketing in notification settings, and cookies via Cookie settings in the footer. You can also email admin@kelroda.com. We respond within one month (extendable by two further months for complex requests, with notice). We will not discriminate against you for exercising your rights.

Complaints to the supervisory authority

If you believe we have mishandled your data, please contact us first so we can help. You also have the right to lodge a complaint with the Lithuanian supervisory authority, VDAI:

  • Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate)
  • L. Sapiegos g. 17, 10312 Vilnius, Lithuania
  • Email: ada@ada.lt · Tel.: +370 5 271 2804 / +370 5 279 1445
  • Web: https://vdai.lrv.lt

If you are in another EU/EEA country, you may also complain to your local data protection authority.

How we protect your data

We use access controls and database Row‑Level Security so users can only reach their own data, encryption in transit (HTTPS), encryption at rest at our hosting providers, signed payment webhooks, bot/CAPTCHA defenses, rate‑limiting and abuse controls, and error monitoring. No system is perfectly secure, but we work to protect your data and will notify you and the supervisory authority of a personal data breach where required by law.

Children

The Service is not directed at children. Under Lithuanian law, the minimum age to consent to information‑society services is 14; users under that age may not use the Service. Users under 18 should use the Service only with the involvement of a parent or guardian. If you believe a child has provided us data without proper authorization, contact admin@kelroda.com and we will delete it.

Cookies & similar technologies

We use a small set of cookies and similar browser storage (such as localStorage) to run Kelroda, keep you signed in and — only with your permission — to measure usage and show relevant content. You can change your choices at any time via the Cookie settings link in the footer. We use Consent Mode v2: non‑essential categories are denied by default until you accept them. Rejecting non‑essential cookies will not reduce any feature you paid for.

Categories

  • Strictly necessary — required for login, security, fraud prevention and core features. Always on; the Service cannot function without them.
  • Analytics — helps us understand which pages and flows work so we can improve the product. Off by default; only with your consent.
  • Marketing — measures the performance of ads and shows you more relevant content on other sites. Off by default; only with your consent.

The specific cookies/storage we may use (vendors marked optional load only if consented and configured):

Name / patternProviderCategoryPurposeTypical duration
sb-*-auth-tokenSupabaseNecessaryKeeps you signed in (session)Session / up to 1 year
kelroda_consent (localStorage)KelrodaNecessaryStores your cookie choices~12 months
__cf_bm, cf_clearanceCloudflareNecessaryBot management & security30 min – 1 year
Turnstile tokenCloudflareNecessaryCAPTCHA on the login formSession
__stripe_mid, __stripe_sidStripeNecessaryFraud prevention in checkoutSession – 1 year
_ga, _ga_*Google Analytics 4 (optional)AnalyticsUsage measurement (IP anonymized)Up to 2 years
_clck, _clskMicrosoft Clarity (optional)AnalyticsSession/behavior analyticsUp to 1 year
_fbpMeta Pixel (optional)MarketingAd measurementUp to 3 months

Exact cookie names and lifetimes can vary as providers update their products; the Cookie settings panel always reflects the live state.

Your privacy choices — US residents (CCPA/CPRA)

If you are a resident of California or another US state with comparable privacy laws (CPRA, VCDPA, CPA, CTDPA, UCPA, OCPA), this section describes how those laws apply to your use of Kelroda.

Categories of personal information we collect. Identifiers (email, account ID), professional information (CV content, work history, career goals), commercial information (subscription status), and internet activity (session logs, error reports). We collect this directly from you and from cookies you have consented to.

No sale or sharing. We do not sell your personal information and do not share it for cross‑context behavioral advertising as those terms are defined under the CCPA/CPRA, and have not in the preceding 12 months.

Your rights. You have the right to know, delete, and correct your personal information; to opt out of any sale or sharing; to limit the use of sensitive personal information; and to non‑discrimination for exercising these rights.

How to exercise them. Use Export my data and Delete my account in your profile settings, or email admin@kelroda.com (we respond within 45 days). To set a global opt‑out, use Your Privacy Choices in the footer; we also honor the Global Privacy Control browser signal.

Changes to this policy

We may update this policy from time to time. We will post the new version here with an updated "last updated" date and, for material changes, notify you in‑app or by email. Continued use of the Service after the effective date means you accept the updated policy.

Contact us

Questions about this policy or your data? Email admin@kelroda.com.


Questions? Email us at admin@kelroda.com