Your information
Privacy Policy
Clear feedback should come with clear information about your privacy. Here is what ProfileLab processes, what we keep, and how to contact us about your data.
Last updated: September 22, 2026
1. Who we are
This policy describes how ProfileLab (also referred to as The Profile Lab, “we,” “us,” or “our”) handles personal information when you visit this website, request a profile critique, or use its administration tools.
It covers our service. LinkedIn and the other services linked from this website have their own privacy practices.
2. Information we collect
Information you provide
When you request a critique, we receive the LinkedIn profile URL, access code, and roast level you submit, plus a target role or profile goal if you choose to provide one. We also receive information you send when contacting us.
The critique form does not ask for an email address or phone number. Contact details may still appear in public profile content we retrieve or in messages you send us.
Public profile information
Our profile-data provider retrieves publicly available information associated with the submitted URL. This may include a name, headline, location, profile photo and banner, About section, experience, education, skills, featured work, certifications, recommendations, and other available profile sections. We also process up to five recent posts and available engagement counts.
We do not ask for your LinkedIn password or access private messages. Please submit your own profile or a profile you are authorized to have reviewed, and avoid entering confidential or sensitive information in optional fields.
Technical and security information
We collect the submission time and your IP address when available. We record access-code usage and failed-code attempts to manage access and prevent abuse. Failed-attempt records use a protected identifier derived from the IP address. Hosting and infrastructure providers may also process connection details, request metadata, and diagnostic logs needed to operate and secure the service.
3. What we save
Our submission database stores:
- The submitted profile URL, submission time, and IP address when available.
- The access code associated with the submission and its usage record.
- The roast level and any target role or profile goal supplied.
- For a completed review, the public profile name, overall numeric score and letter grade, available scores for the ten review sections, and quick-roast quote and description.
We also keep encrypted access codes, their batch labels, usage limits and counts, and creation, last-use, and revocation information. A submission is recorded when a valid code is accepted, so its submission details and code usage can remain even if the critique later fails.
We process the fetched profile and full critique to deliver your results, but do not save the full profile, complete critique, or detailed rewrites in our submission database. A PDF you download is created in your browser and saved to your device. Our service providers may separately retain information as described below.
4. How we use information
We use information to retrieve the public profile, generate and display an automated critique, apply your chosen roast level, and lightly tailor suggestions to any optional career context you provide.
We also use stored records to administer access codes, review usage and results, create administrator reports, investigate errors or misuse, respond to requests, and meet applicable legal obligations. The critique is guidance for improving a profile; ProfileLab does not make hiring or eligibility decisions.
5. Who can access it
Service providers
We use service providers to retrieve public profile information, perform automated review, store submission records, and host the website. They process the information needed to provide those services.
Providers may retain information for service operations, security, or legal requirements under their applicable terms. Information may be processed in countries other than where you live.
Other disclosures
We may disclose information when required by law or when necessary to respond to lawful requests, protect the service, or address fraud, abuse, or threats to someone’s safety. If you download or share a review, the recipients’ handling of that copy is outside our control.
6. Retention and deletion
Submission and access-code records currently have no automatic expiration period. They remain in our database until an administrator deletes them. We use these records for the administration, reporting, and security purposes described above; you can request deletion using the contact details below.
Failed-code attempt records older than 24 hours are removed when the access-code system next performs its cleanup during a code attempt. They may therefore remain longer than 24 hours when the service is inactive.
Deleting a submission removes its saved profile and review fields from the active submission database. It does not reset an access code’s usage totals or automatically erase provider logs, backups, or previously downloaded reports. Those copies may have separate retention periods; legal obligations may also require some information to be retained.
7. Cookies and external content
The public critique form does not require a user account. We do not add advertising cookies or third-party analytics trackers to it. The administrator area uses an essential sign-in cookie that expires after eight hours. Browser settings let you manage cookies; blocking that cookie prevents normal administrator sign-in.
Profile photos and other external images may load directly from their source. Those image hosts receive ordinary connection information, such as your IP address and browser details, when your browser requests an image. Following an external link takes you to a service governed by its own privacy policy.
8. Protecting information
We use access controls for administrator tools, keep service credentials on the server, and encrypt stored access codes. Our submission database is not directly accessible to public website visitors. No online service or method of storage can guarantee absolute security.
9. Your choices and rights
You can leave the target role and profile goal blank. To ask about your information or request access, correction, or deletion, email privacy@theprofilelab.app. Include the relevant profile URL and, if known, the approximate submission date so we can locate the record. Do not send passwords or other sensitive documents in your initial message.
We may need to verify that you are the person concerned or an authorized representative before fulfilling a request. Depending on your location and applicable law, you may also have rights to a copy of your data, to object to or restrict certain processing, or to complain to a privacy regulator. We will handle requests in accordance with applicable law.
Deleting a ProfileLab record does not remove the original information from LinkedIn or other public sources. To change the source information, use the controls provided by those services.
10. Children and policy updates
ProfileLab is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child’s information has been submitted, contact us so we can investigate and remove it as appropriate.
We may update this policy as the service changes. We will post the revised policy here, update the date above, and provide any additional notice required by applicable law.
For questions about this policy, contact privacy@theprofilelab.app.