Privacy Policy
How Fennec collects, uses, stores, exports, and deletes account and career data.
What Fennec collects
Fennec stores account identity data from the login provider, such as user ID, name, and email address.
Fennec also stores career profile data you enter: job title, role, career track, SFIA or framework assessment, target level, summary, contact details, education, work experience, skills, goals, certifications, evidence, progress history, and report/CV fields.
If you connect GitHub, Fennec stores the connected account identifier, authorised scopes, sync timestamp, and encrypted access token. Suggested evidence may include pull request titles, links, repositories, merge dates, and pull request descriptions.
How Fennec uses data
Fennec uses your data to provide the product: skill tracking, evidence management, promotion coverage, GitHub suggestions, learning and certification views, generated career reviews, CV exports, notifications, import/export, and account support.
Fennec does not run advertising or sell personal data. Fennec uses Cloudflare Web Analytics to measure aggregate site traffic, such as page views and referrers. It is a cookieless service: it does not set cookies, does not use browser storage or fingerprinting, and does not track you individually across other sites.
Where data is stored
The hosted Fennec service runs on AWS. Account data is stored in the Fennec API database, and authentication is handled by Cognito.
If you run Fennec yourself for development or self-hosting, data lives wherever that environment is configured to store it.
The app also uses browser storage for preferences such as theme, sidebar state, notification dismissal, migration prompts, authentication session state, and cookie/storage preferences.
Legal bases and purposes
Core account and product data is processed to provide the service you request. Optional connected-service processing, such as GitHub evidence suggestions, happens when you choose to connect that provider.
Operational processing may be used for security, service reliability, abuse prevention, legal compliance, and support.
Sharing and processors
Fennec may use service providers for hosting, authentication, email delivery, connected-account integrations, and privacy-focused traffic analytics (Cloudflare Web Analytics). Those providers process data only as needed to provide the service.
When you export or share CVs, reports, or links outside Fennec, you are choosing to disclose that content to the recipients.
Your controls
You can export your data from Settings. You can disconnect GitHub in Settings. You can delete your account from Settings, which removes your active account data from Fennec.
You can also contact support@getfennec.co.uk for access, correction, deletion, or privacy questions.
Retention
Account data is kept while your account exists. If you delete your account, Fennec removes the user profile and associated career records from the account database.
Backups, security logs, and operational records may persist for a limited period where required for continuity, security, or legal reasons.
Security
Production access is authenticated through Cognito. API requests require an access token. GitHub access tokens are encrypted at rest before storage.
No service can be guaranteed perfectly secure, so avoid storing information in Fennec that you are not comfortable using for career-document generation or evidence tracking.