Third-Party Data Sharing

A technical summary of which external services CareerStudioMax's code sends data to, and why.

What this page is: a factual, code-level account of data flows, generated by reviewing the actual integration code — not a legal document. It does not represent a compliance certification, and it does not confirm the status of data processing agreements with any listed provider.

What this page isn't: a substitute for a lawyer's review. If you need this for GDPR Art. 13/14, CCPA, or another compliance framework, have it reviewed and adapted by counsel before relying on it — in particular, confirm and document the actual DPA status with each processor below.

Which of these are actually active depends on which API keys are configured in the live deployment — a service listed here is one the code is capable of using, not a guarantee every one is switched on in every environment.

AI Inference

Powers resume analysis, interview coaching, career advice, and every AI chat feature. Your questions, resume/CV text, and career details are sent to whichever provider is handling that request.

ServiceData sentPurpose
GroqChat messages, resume text, career context you providePrimary fast-inference AI engine
Anthropic (Claude)Chat messages, resume text, career context you provideFallback AI engine when the primary is unavailable
OpenRouterChat messages, resume text, career context you provideSecondary fallback AI engine

Payments

Card and payment details are never stored on CareerStudioMax's own servers — they go directly to the payment processor.

ServiceData sentPurpose
StripeName, email, payment method details (handled directly by Stripe, not our servers)Subscription billing
Paystack / Flutterwave / PayPalName, email, payment method detailsRegional payment processing, where enabled

Communication

ServiceData sentPurpose
SMTP providerYour email address, email content (notifications, verification codes, digests)Transactional email delivery
TwilioYour phone number, message contentSMS and WhatsApp notifications, where enabled
Telegram Bot APIYour Telegram chat ID, message contentBot-based notifications and support, where enabled

Voice

ServiceData sentPurpose
ElevenLabsText to be spoken (AI responses, interview feedback)Text-to-speech voice synthesis

Search & Data Enrichment

ServiceData sentPurpose
Tavily / Brave SearchSearch queries derived from your questions (e.g. role, country, company names)Live web grounding for career/market answers
ApifyPublic profile URLs or search terms you provideLinkedIn profile analysis and lead enrichment, where used
Google Cloud TranslatePage text and your questions, when a non-English language is selectedUI and content translation

Sign-in

ServiceData sentPurpose
Google OAuthBasic profile info you consent to share (name, email, avatar) per Google's consent screen"Sign in with Google"
LinkedIn OAuthBasic profile info you consent to share, per LinkedIn's consent screen"Sign in with LinkedIn"

Infrastructure

ServiceData sentPurpose
MongoDB AtlasAll account and application dataPrimary database hosting
AWS S3Uploaded files (resumes, avatars), where configuredFile storage
← Back to Privacy Policy