TryCareerMatch

Privacy Policy

Last updated: August 23, 2026

1. Who we are

TryCareerMatch (trycareermatch.com) is operated by Diogo Serino, an individual based in Braga, Portugal. For data protection purposes, Diogo Serino is the data controller responsible for your personal data.

Contact: [email protected]

2. What data we collect

  • Career profile data — your name if you give one, education level, years of experience, skills, work preferences and sector interests. Entered by you during onboarding. Your name is optional and never affects your results: we use it to greet you as you fill the form and to address your own report back to you.
  • Session identifier — a random UUID stored in your browser's session storage to link your profile and results without requiring an account.
  • Visitor identifier — a random, long-lived identifier stored in your browser's local storage and sent with requests as an X-Visitor-ID header. We never store the identifier itself, only a SHA-256 hash of it, so we can tell first-time visitors from returning ones. The hash appears in our aggregate match and product statistics and, if you send us a role suggestion, on that suggestion — there only so we can tell three different browsers asking for the same thing from one browser asking three times. That last hash is computed differently from the others on purpose, so the two cannot be matched up. None of them is linked to a profile, and none is used to track you across other websites.
  • Email address — only if you choose to save your report. We use it to save your report, to email you a link back to it, and — if you later ask us for a paid Deep Report — to find the saved report that one is built from. Nothing else, unless you tick the marketing box described below. It is never required to use the service. Saving your report needs no password and creates no account, and we do not verify the address.
  • Account (optional for everything free) — the site has an email-and-password sign-in, reachable from “Sign in” in the menu. Nothing in the free service requires it: the assessment, your report, and the way back to a saved report all work without an account. The one thing that does need one is asking for a paid Deep Report. If you create one we store your email address, a hash of your password (never the password itself), and the dates you registered and last signed in. When you register — and any time you ask us to resend it — we email you a link to confirm you can read that address, and store a single-use hash of it for 24 hours; confirming records the date, and is what connects a report you saved under the same address to your account (never the other way — signing in alone never opens someone else’s report). If you ask to reset a forgotten password we store a single-use hash of that emailed link for one hour. You can delete the account at any time — section 5 says what that removes and what it leaves.
  • Continue with Google (optional) — instead of a password, you can create or open the account above by signing in with Google. We ask Google for only your email address and the permanent identifier Google uses for your account — never your name, your photo, your contacts, your files or anything else — and those two things are what we store. An account made this way has no password at all, so we store no password hash for it; because Google has already confirmed the address, we treat it as confirmed and send you no confirmation email. That is also what connects a report you saved under the same address to the account. If you would rather have a password later, use the “forgot password” link and the one you set becomes the account’s first. Signing in this way tells Google that you use TryCareerMatch — see section 6.
  • Continue with LinkedIn (optional) — the same as “Continue with Google” above, with LinkedIn in Google’s place. We ask LinkedIn for only your email address and the permanent identifier LinkedIn uses for your account — never your name, your photo, your connections, your posts or anything else. One difference worth stating: LinkedIn does not always tell us an address is confirmed, and when it does not, we cannot treat the account as one either — you would need to confirm it yourself, or sign in with a password instead.
  • Marketing emails — only if you tick the optional box when you save your report. It is unticked by default, it is never a condition of getting your report, and it is the only thing that adds you to our email list. Legal basis: your consent, which you can withdraw at any time using the unsubscribe link in every email.
  • Saved profile — created when you save your report. We keep a durable copy of your career profile linked to your email so you can come back to it through the emailed link. It is kept until you delete it — the save email includes a delete link — or ask us to remove it, or until 12 months pass without a visit, whichever comes first (a report you bought is kept while its access link is still valid).
  • Onboarding research notes — if you type into the optional "Other" boxes during onboarding (a field of study, an industry, a missing skill), or into the optional "What's your current or most recent role?" box, we keep that short text as product research to decide which roles and skills to add next. We store that research copy with your session identifier and nothing else. While that session is still alive (up to 7 days) the identifier links the note to the session it came from; once the session is deleted, nothing connects that research copy back to you, which also means we can no longer look up or delete an individual's research notes. The text you typed also stays in your career profile, alongside everything else you entered — that second copy is not anonymous, and if you save your profile it is linked to your email until you delete it, which you can do at any time with the link in the save email. All of these boxes are optional and none of them affects your results.
  • Role suggestions — only if you suggest a role we should add. The suggestion text is stored as product research, alongside the hashed visitor identifier described above; an email, if you leave one, is optional, used only to follow up, and stored with your consent.
  • Service requests — only if you ask about a paid service. For a coaching call or the career program, no account is needed: we collect the name, email, optional LinkedIn link and free-text description you choose to submit. We do not ask for a CV, phone number, age or nationality. We read that description so we can reply to you; it is not used for matching and does not affect your results.
  • Our own notes on a request — when you ask about a paid service, we may write a short internal note on your request: what you asked, what we replied, what to follow up. It is a note about the conversation, not an assessment of you, and nothing reads it except us — it never touches your results, your ranking or your report. You can ask to see it or to have it deleted, like anything else here.
  • Deep Report requests — only if you ask for one, which is done from your account. We take your email address from the account rather than from a box, so the request is filed under an address you have confirmed. We ask which country you work in, because the report’s salary bands are US-national and it needs to tell you when they are not yours; the country only, never a city or an address. And we ask you to write three things: your recent roles, what you are trying to decide, and anything we should work around, plus an optional link to your LinkedIn profile. We read all three before we write your report. None of them is used for matching or affects your ranking — the report itself is built from the profile you saved. One of them goes further, and this is the only part of what you write that leaves our systems: a shortened version of what you are trying to decide is included when we generate the written parts of your report, which is done by Anthropic’s Claude on our behalf. Before it is sent we automatically strip email addresses, links, social handles and long numbers, and cut it to about three sentences. We cannot automatically remove a person’s or a company’s name, so the form asks you not to put those there. The other two boxes are never sent anywhere. We delete all three twelve months after you write them.
  • Testimonials — only if you choose to submit one. Your name, shown publicly as first name plus last initial (e.g. “Jordan L.”), and your comment are shown on the site with your consent — the full name you type is never stored or shown. An email, if you leave one, is optional, never shown publicly, and used only to reach you. Every testimonial is reviewed before it appears, and you can ask us to remove yours at any time by emailing [email protected].
  • Coach applications — only if you apply to coach with us. We store the professional details you submit (name, email, optional LinkedIn/portfolio, experience and a short pitch) to review the partnership, on the basis of your consent. Nobody outside TryCareerMatch reads them, though the alert that tells us one has arrived carries what you wrote and reaches us through Resend (section 6). You can ask us to delete them at any time.
  • Contact messages — only if you write to us through the contact form. We store your name, email and message to reply to you, on the basis of your consent. Nobody outside TryCareerMatch reads them, though the alert that tells us one has arrived carries your message and reaches us through Resend (section 6). You can ask us to delete them at any time.
  • Hiring requests — only if you ask us to help you hire someone through the /hire form. We store the company, contact name, email, the role and what you tell us you’re looking for, to work on your request, on the basis of your consent. Nobody outside TryCareerMatch reads them, though the alert that tells us one has arrived carries what you wrote and reaches us through Resend (section 6). You can ask us to delete them at any time.

3. How we use your data

  • To run the career matching analysis and display your results.
  • To save your report under the email you give us and to send you a link back to it, which is the service you asked for when you saved it. If you later ask us for a paid Deep Report, we use that same address to find the saved report it is built from.
  • If you tick the marketing box, to send you your archetype and occasional updates about new roles. You can unsubscribe at any time.
  • If you submit a service request, to contact you about it — and, for a coaching call or the career program only and with your consent, to share the details you provided with a vetted career coach so they can deliver the service you asked for. A Deep Report is written by us; no coach ever sees it or what you wrote for it.

We do not use your data for advertising, we do not sell it to third parties, and we do not use it for any purpose beyond providing the service.

4. Legal basis (GDPR)

  • Contract performance — processing your profile to deliver the matching service you requested, saving your report under the email you give us so we can send you a link back to it, and running your account if you choose to create one.
  • Legitimate interest — storing anonymous session data temporarily to provide a seamless experience without requiring an account.
  • Consent — everything you actively choose to leave with us: ticking the marketing box, submitting a service request (including, for the coaching services only, sharing those details with a vetted coach), a testimonial, a coach application, a contact message, or an email with a role suggestion. Each is processed solely for the purpose you asked for, and you can withdraw consent at any time. None of them is a condition of getting your report.

5. Data retention

  • Anonymous sessions — stored for up to 7 days, then removed. The optional research notes described above (the "Other" boxes and the role box) are kept separately, without your identity.
  • Saved profiles — kept until you delete your profile via the link in the save email, or ask us to remove it, or until 12 months after your last visit, whichever comes first. A report you bought is kept while its access link is still valid. Using that delete link erases the saved profile; your email is then kept only as an "unsubscribed" marker so we never email you again. The 12-month deletion is automatic and does not unsubscribe you — that is a separate choice you made, and it ends when you unsubscribe.
  • Email sign-ups — kept until you unsubscribe or ask us to delete them.
  • Onboarding research notes — kept while we use them to decide which roles and skills to add. They carry your session identifier, so for as long as that session lives (up to 7 days) they can still be traced to it; after it is deleted they carry nothing that links them to you.
  • Role suggestions — kept while we use them to decide which roles to add. If you left an email, you can ask us to delete the suggestion at any time; an anonymous one carries no identifier we could look it up by.
  • Service requests — kept while we handle your request and for our records of services provided; you can ask us to delete them at any time.
  • Accounts — kept until you delete the account; there is no automatic expiry. Deleting it removes your profile — including your name and any free-text answers you gave in the assessment — along with your saved skills, experience areas, interests, work preferences, match history, and any password-reset or email-confirmation links. It also erases your email address from the account, replaces the stored password hash with an unusable value and permanently disables sign-in. What remains is a row holding an internal identifier, the dates, and — if you had ever signed in with Google or LinkedIn — the account identifier that provider gave us. We keep those so that a deleted account is recognisably deleted rather than simply unknown: without them, signing in again with the same Google or LinkedIn account would silently create a fresh account instead of being refused. Password-reset links expire after an hour, can be used once, and are deleted on use or when the next one is issued; email-confirmation links expire after 24 hours and work the same way.
  • Deep Report briefs — the three things you write when you ask for a Deep Report are deleted twelve months after you write them, automatically. Deleting your account removes them straight away. The request itself — that you asked, when, and for what — is kept as a record of a service we provided.
  • What deleting your account does not remove — a report you saved by email is a separate thing under a separate permission, and someone can have one without ever creating an account. Deleting your account leaves it in place. To remove that too, use the delete link in the save email, or ask us and we will do it.

6. Third-party processors

We share data with the following processors only to the extent necessary to provide the service:

  • Neon (neon.tech) — database hosting in Europe. Your data is stored on servers located within the European Economic Area.
  • Vercel (vercel.com) — frontend hosting and privacy-friendly, cookieless web analytics (aggregate traffic only, no personal profiles).
  • Railway (railway.app) — hosting for the server that runs the service. Everything you send us passes through it, because it is the machine that receives it, and its application log holds the technical record of those requests. It is not used for analytics and nothing there is shared onward.
  • Sentry (sentry.io) — error reporting, so we find out when something breaks. When a request fails we send a technical report: what went wrong, where in the code, and the address and method of the request. We deliberately turn off the two things it would otherwise include — the values of variables at the point of failure and the body of the request — and we blank our own request headers before sending, so passwords, tokens and session identifiers do not travel with it.
  • Resend (resend.com) — transactional email delivery, in two directions. Emails to you: your address is shared so we can send the link back to your saved report, a password-reset link if you ask for one, an email-confirmation link if you create an account, your Deep Report when it is ready, a confirmation when you make a request, and anything you opted into. Emails to us, about you: when you send a contact message, apply to be a coach, leave a testimonial, suggest a role or request a paid service, we email ourselves an alert that contains what you wrote, in full, along with the name, address and any links you gave — so that message passes through Resend too. We do not use Resend for marketing to anyone who has not ticked the box.
  • Google (google.com) — only if you choose “Continue with Google”. We send Google nothing about you: no profile, no results, and none of your free text. What happens is that Google tells us your email address and a permanent identifier for your Google account, and in doing so Google learns that you signed in to TryCareerMatch. If you never use that button, Google receives nothing at all. What Google does with that fact is governed by Google’s own privacy policy.
  • LinkedIn (linkedin.com) — only if you choose “Continue with LinkedIn”. We send LinkedIn nothing about you: no profile, no results, and none of your free text. What happens is that LinkedIn tells us your email address and a permanent identifier for your LinkedIn account, and in doing so LinkedIn learns that you signed in to TryCareerMatch. If you never use that button, LinkedIn receives nothing at all. What LinkedIn does with that fact is governed by LinkedIn’s own privacy policy.
  • Anthropic (anthropic.com) — AI text generation. If you buy the Deep Report, we send Anthropic a short, fixed set of facts about your results — your archetype, your strongest matches, the skills that move your ranking — with no name, no email and no figures, once, to write the two written paragraphs of your report. Since 17 August 2026 that set also includes a shortened version of what you wrote in what are you trying to decide, with email addresses, links, handles and long numbers automatically removed; the other two things you write are never sent. This applies only to the paid report; the free report never uses it.

7. Your rights

Under the GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Portuguese data protection authority: CNPD (Comissão Nacional de Proteção de Dados) at cnpd.pt.

8. Cookies and local storage

We do not use tracking cookies or advertising cookies. We use your browser's session storage to store a session identifier that links your profile to your results (it is cleared when your browser session ends), and your browser's local storage to store a random visitor identifier that persists between visits, your unfinished onboarding answers, any roles you mark as “aiming for” on your report, and — only if you sign in to an optional account — the tokens that keep you signed in until you sign out. Those last two stay in your browser — the marked roles are never sent to us as a list, and they are not part of your profile or your score. The visitor identifier is sent to our servers with each request and hashed there; we never store it, only the SHA-256 hash (see section 2) — it lets us count unique versus returning visitors, is not linked to your profile, and is not used to track you across other websites. We use Vercel Web Analytics, which measures aggregate traffic without cookies and without tracking you across other sites.

9. Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the most recent update. Continued use of the service after changes constitutes acceptance of the updated policy.