Privacy
Last updated 29 July 2026
Callback is a one-off tool: you paste a profile, we rewrite it, you download the result. This page describes exactly what we store while that happens.
What we store
- Your email address and a password hash. The email comes from your Stripe payment. Passwords are hashed with bcrypt and are never stored or recoverable in plain text.
- Your purchase record. Amount, currency, Stripe identifiers, and how many rewrites remain.
- The profile text you paste and the rewrite we produce, so you can reopen a result you already paid for.
- Usage records. Which actions ran, when, and roughly how much processing they used.
What we never store
We never see or store your card details — those go directly to Stripe. We do not store your LinkedIn password, and we never sign in to LinkedIn on your behalf; you paste text yourself.
Who else processes your data
- Stripe — payment processing. They receive your email and payment details.
- Anthropic— we call Anthropic's commercial API to generate your rewrite. It receives the profile text you provide and the target role or job description you enter. Under Anthropic's commercial terms, API inputs and outputs are not used to train their models. Anthropic may retain API data for a limited period for safety and abuse-prevention purposes under their own policy; we do not have a zero-retention agreement with them, and we do not claim one.
- Our database and hosting providers — they store the data described above.
We do not sell your data, and we do not use it for advertising.
Your data in your own words
The text you paste is your professional history. We use it for one purpose: producing the rewrite you asked for. We do not publish it, share it, or use it to train models.
We do not store your profile text or your results
This is worth stating plainly, because it is unusual. The free diagnostic runs entirely in your browser — the text never reaches our servers at all. When you run a paid rewrite, your profile text is sent to our server and on to our AI provider to generate the output, held in memory for the length of that request, and returned to you. It is not written to our database, and neither are the results.
A consequence worth knowing: if you close the tab, your rewrite is gone and you will need to run it again. We think that is the right trade for not holding your career history on a server indefinitely.
What we do keep
Your account (email address and a hashed password), your purchase record, and usage totals for each run — the model used, token counts and cost. Usage records contain no profile text. Sign-in sessions expire after 30 days. Purchase records are retained for the tax period required by law even after an account is deleted.
Deleting your data
Email support@getcallback.net and we will delete your account and its usage records. We aim to action deletion requests within 30 days. There is no stored profile text or results to delete, because we never kept them. Purchase records are kept where tax and accounting rules require it, typically seven years.
If you are in the UK or EU
You have the right to access, correct, export, or delete your personal data, and to object to processing. We process your data to perform the contract you entered into when you bought a rewrite. To exercise any of these rights, email support@getcallback.net.
Age
Callback sells to adults. Our terms require purchasers to be at least 18, or old enough to enter a contract where they live. The service is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, email us and we will remove it.
Product analytics
We record anonymous, first-party events so we can see where the product is confusing and fix it — for example, that a diagnostic was run, a checkout was started, or a rewrite finished. These events contain no profile text and no personal data: they are event names plus small non-sensitive context like which example was used or which export format was chosen.
There is no cross-visit identifier and no advertising. To connect a “started” event to its “finished” within a single visit, we use a random id that lives in your browser tab and is discarded when you close it — it is not tied to you and does not persist. We use no third-party analytics, no advertising trackers, and no tracking cookies, and we never share these events with anyone.
Cookies
One cookie, used to keep you signed in. It is httpOnly and expires after 30 days. We set no cookies for analytics or advertising.
Questions? support@getcallback.net