Skip to main content
Your Data, Your Control

Privacy Policy

Version 2.0 · Effective May 21, 2026

1. Who We Are & What This Covers

This Privacy Policy explains how HAMRA (a service operated by Ehtisham Rasool) (“HAMRA”, “we”, “us”) collects, uses, shares, and protects your personal data, and the rights you have over it.

It applies to hamraofficial.com, the HAMRA web application, and the HAMRA Companion browser extension (together, the “Service”).

This is a single, global policy. The core sections apply to everyone. Additional, legally-mandated rights for residents of the European Economic Area and United Kingdom, the State of California, and India are set out in the Regional Addenda in Section 14. Where an addendum grants you more, the addendum prevails for you.

For most processing described here, HAMRA is the data controller (GDPR) and Data Fiduciary (India's DPDP Act, 2023) — meaning we decide why and how your personal data is processed. When you direct the HAMRA Companion to enter your data into a third-party job site, you do so on your own behalf.

2. Information We Collect

We collect only what the Service genuinely needs:

  • Account & identity. Your name, email address, a securely hashed password, and — if you sign in with Google — your Google account identifier.
  • Career & resume data. Resumes you upload or create, work history, education, skills, career goals, and target roles.
  • Profile photo (optional). If you upload a headshot, we score it only on observable image-quality signals — composition, lighting, background, attire, posture, eye contact, and expression. We do not infer personality, character, attractiveness, perceived age, race, ethnicity, gender, religion, or disability from your photo. Your photo is not stored — it is deleted immediately after analysis and only the resulting quality score is retained.
  • Conversation transcripts. Transcripts of profiling sessions and AI mock interviews, used to give feedback and track your progress.
  • Generated insights. Your Career Readiness Score, DISC personality profile (computed from your written questionnaire, never from a photo), skill-gap analysis, and job matches.
  • Payment data. We do not receive or store your full card number or CVV — those go directly to our payment processors. We retain your plan, subscription status, billing region, payment/refund identifiers, and invoices.
  • Usage & device data. Pages and features you use, actions you take, device and browser type, and an approximate region derived from your IP address. Behavioural analytics are collected only if you opt in to analytics cookies.
  • Communications. Emails and support messages you send us.

We do not knowingly collect special-category data (e.g. health, religion). Please do not include such information in your resume or messages.

3. How & Why We Use Your Data

We use your data for the purposes below. For each, we identify the legal basis we rely on under the GDPR and the corresponding ground under India's DPDP Act, 2023.

PurposeLegal basis
Provide the Service — scoring, matching, AI features, your dashboardPerformance of our contract with you
Account security, fraud and abuse preventionLegitimate interests; compliance with legal obligations
Service and transactional emails (receipts, security, subscription state)Performance of our contract with you
Product analytics and improvementYour consent (analytics cookies) — withdrawable any time
Marketing, lifecycle, and digest emailsYour consent — withdrawable any time
Tax records, accounting, and responding to lawful requestsCompliance with legal obligations

Where we rely on consent, you may withdraw it at any time without affecting processing done before withdrawal. Where we rely on legitimate interests, you may object — see Section 13.

4. How AI Processes Your Data

HAMRA uses Google Vertex AI (Gemini) as a processor to analyse resumes, evaluate interview answers, generate career guidance, and critique photo image-quality.

  • We do not train models on your data. We do not use your personal data to train any HAMRA model, and Google does not use Vertex AI customer data to train its foundation models.
  • AI transparency. Features such as the AI mock interview involve an automated AI system. Outputs are AI-generated, probabilistic, and may be inaccurate.
  • No binding automated decisions. Your Career Readiness Score, DISC profile, and job matches are decision-support. They do not produce a legal or similarly significant effect on you — every career decision is made by you, a human. We do not engage in solely-automated decision-making within the meaning of GDPR Article 22.
  • Human review. You may request a human review of, or an explanation for, any insight by emailing privacy@hamraofficial.com.

5. The HAMRA Companion Extension

The HAMRA Companion is an optional browser extension that runs in your own browser when you choose to install it. It acts as your personal agent during sessions you initiate on supported job sites, and it is click-initiated — it never runs on its own.

The Companion has its own, more detailed privacy notice covering exactly what it reads, stores, and never does: hamraofficial.com/extension/privacy.

6. How We Share Your Data — Sub-processors

We never sell your personal data, and we never share it for cross-context behavioural advertising. We share it only with the service providers (“sub-processors”) below, each engaged under a data-processing agreement that limits them to acting on our instructions:

ProviderPurposeRegion
SupabaseDatabase, authentication, and encrypted file storageUnited States / EU
Google Cloud (Vertex AI / Gemini)AI processing — resume analysis, interview feedback, career guidanceGlobal
VercelApplication hosting, edge network, and CDNGlobal (US-headquartered)
CloudflareDNS, network security, and email routingGlobal
ResendTransactional and lifecycle email deliveryUnited States
PostHogProduct analytics — only when you opt in to analytics cookiesUnited States / EU
SentryError monitoring and application diagnosticsUnited States
RazorpayPayment processing for payments made in Indian Rupees (INR)India
Dodo PaymentsPayment processing and merchant of record for international paymentsGlobal

We may also disclose personal data:

  • to comply with a law, regulation, or valid legal request;
  • to protect the rights, safety, and security of HAMRA, our users, or the public;
  • in connection with a merger, acquisition, or sale of assets — in which case we will notify you and any new owner will remain bound by this policy;
  • with your direction or consent.

7. International Data Transfers

HAMRA operates from India, and the sub-processors above operate globally. Your data may therefore be processed in countries other than your own.

  • For transfers of personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), or on an adequacy decision where one applies.
  • For personal data governed by India's DPDP Act, 2023, transfers are permitted except to any country restricted by notification of the Central Government.

You may request a copy of the relevant transfer safeguards by emailing privacy@hamraofficial.com.

8. How Long We Keep Your Data

DataRetention
Uploaded photosDeleted immediately after analysis (0 days)
Account, profile, and career dataKept while your account is active
Generated insights and transcriptsKept while your account is active
Payment and tax recordsRetained as required by applicable tax law (up to 8 years)
Data of deleted accountsPermanently purged within 30 days
Encrypted backupsOn a rolling cycle, purged within 90 days
Support communicationsUp to 24 months

When you delete your account, your career scores, personality profiles, resume analyses, transcripts, and queue are permanently removed within 30 days. We retain only what the law requires us to keep, such as tax records.

9. How We Protect Your Data

  • Encryption in transit (TLS) and at rest.
  • Database-level row security so each account's data is isolated from every other account.
  • Passwords stored only as salted, hashed values — never in plain text.
  • Strict, least-privilege access controls for the small team that operates HAMRA.

No method of transmission or storage is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security — see also our breach commitment below.

10. Data Breach Notification

If a personal-data breach occurs that is likely to affect you, we will act promptly:

  • we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (GDPR Articles 33–34);
  • we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act, 2023;
  • we will tell affected users what happened, what data was involved, and what steps to take, where the breach is likely to result in a high risk to them.

11. Cookies & Tracking

We use a minimal set of cookies and similar technologies:

  • Necessary — authentication and session. Always on; the Service cannot function without them.
  • Analytics — anonymised product usage via PostHog. Off by default; set only if you opt in.
  • Marketing — campaign measurement. Off by default; set only if you opt in.

We do not use third-party advertising cookies, and we honour browser Do Not Track and Global Privacy Control signals for analytics. You can review or change your choices at any time through the cookie banner or your browser settings.

12. Children

HAMRA is not directed to children. You must be at least 18 years old to use the Service on your own. Users aged 1617 may use it only with the verifiable consent of a parent or legal guardian.

We do not knowingly collect data from anyone under 16. Consistent with the DPDP Act, 2023, we do not carry out behavioural monitoring of, or direct targeted advertising at, anyone we know to be a child. If you believe a minor has created an account, contact grievance@hamraofficial.com and we will delete it.

13. Your Rights

Wherever you live, you can ask us to:

Access

Get a copy of the personal data we hold about you.

Correct

Fix data that is inaccurate or incomplete.

Delete

Erase your personal data and close your account.

Port

Receive your data in a portable, machine-readable format.

Withdraw consent

Turn off any processing based on your consent.

Object / restrict

Object to, or restrict, certain processing.

The fastest way to export or delete your data is in-app at Settings → Account. You can also email privacy@hamraofficial.com. We respond within 30 days, free of charge, and we will never penalise you for exercising a right.

14. Regional Addenda

The following rights apply in addition to everything above, based on where you live.

European Economic Area & United Kingdom (GDPR / UK GDPR)

The data controller is HAMRA (a service operated by Ehtisham Rasool). Our legal bases are set out in Section 3. Beyond the rights in Section 13, you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). We do not carry out solely-automated decision-making with legal or similarly significant effects (Article 22). International transfers rely on Standard Contractual Clauses or the UK IDTA (Section 7).

EU/UK representative: until a representative under Article 27 is formally appointed, EEA and UK residents may contact us directly and exclusively at privacy@hamraofficial.com for any GDPR matter.

California (CCPA / CPRA)

In the past 12 months we have collected the categories of personal information described in Section 2 (identifiers, professional information, internet activity, and inferences). We do not sell your personal information and do not share it for cross-context behavioural advertising. You have the right to know, delete, and correct your information, to opt out of sale/sharing (not applicable, as we do neither), and to limit use of sensitive information. We will not discriminate against you for exercising these rights. You may use an authorised agent to make a request. Submit requests at privacy@hamraofficial.com.

India (Digital Personal Data Protection Act, 2023)

HAMRA is the Data Fiduciary and you are the Data Principal. We process your data on the basis of your consent or for legitimate uses permitted by the Act. You have the right to access, correction, and erasure, the right to grievance redressal, and the right to nominate another individual to exercise your rights in the event of death or incapacity.

Grievance Officer & Privacy Contact: Ehtisham Rasool grievance@hamraofficial.com. We respond to grievances within 30 days. If you are not satisfied with our resolution, you may escalate to the Data Protection Board of India under the Act.

15. Changes to This Policy

We may update this Privacy Policy as the Service and the law evolve. When we do, we will revise the version number and effective date at the top of this page. For material changes, we will give you advance notice by email or an in-app notice before the change takes effect.

16. Contact Us

Privacy & data requests: privacy@hamraofficial.com

Grievance Officer & Privacy Contact (DPDP Act, 2023): Ehtisham Rasool grievance@hamraofficial.com

Security reports: security@hamraofficial.com