Privacy Policy

How CareerStudioMax collects, uses, and protects your data.

Status of this document: this is a starter policy written directly from CareerStudioMax's actual code and data handling — not a template filled in blind, but also not something a lawyer has reviewed. Fields like [LEGAL ENTITY NAME], [REGISTERED ADDRESS], and [GOVERNING LAW / JURISDICTION] are placeholders — have counsel fill those in and review the whole thing (especially GDPR/CCPA applicability) before treating this as your operative policy.

1. Who we are

[LEGAL ENTITY NAME] ("CareerStudioMax", "we", "us") operates careerstudiomax.com, an AI-powered career development platform. Registered address: [REGISTERED ADDRESS]. Contact for privacy questions: support@careerstudiomax.com.

2. What we collect

Account information

Career data you provide

Usage data

Payment information

Cookies

3. How we use it

We do not sell your personal data.

4. Who we share it with

Certain features send data to external providers to work — AI inference engines, the payment processor, email/SMS providers, and similar. A full technical breakdown of exactly which service receives what, and why, is maintained at /data-sharing — treat that page as the authoritative, code-level source of truth for third-party data flows, and this policy as the plain-language summary.

5. AI processing

Career Studio uses third-party AI providers to generate advice, feedback, and content. Your resume text, career details, and questions are sent to whichever provider is handling that specific request. AI outputs can be inaccurate — review anything AI-generated before relying on it, especially before submitting a job application or making a career decision based on it.

6. Data retention & deletion

7. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these yourself from Account Settings; for anything else, contact support@careerstudiomax.com. [If you operate in the EU/UK/California, add the specific GDPR/CCPA rights language and any required regulator contact here.]

8. Security

Data is encrypted in transit and at rest. Passwords are hashed with bcrypt and never stored in plaintext. Sessions expire after 7 days. No system is perfectly secure, and we can't guarantee absolute security of information transmitted over the internet.

9. International data transfers

[Describe where data is hosted/processed and, if you have users outside that region, what transfer safeguards apply — e.g. Standard Contractual Clauses.]

10. Children

CareerStudioMax is not directed at children under [MINIMUM AGE — confirm your intended age floor], and we don't knowingly collect data from them.

11. Changes to this policy

We'll post updates here and, for material changes, notify you by email or an in-app notice.

12. Governing law

This policy is governed by the laws of [JURISDICTION], without regard to conflict-of-law principles.

See the technical Third-Party Data Sharing breakdown →

CareerStudioMax · Last updated 2026 · This is a starter document — see the notice above before relying on it.