Privacy notice

Version 2 · Last updated August 2026 · Strut early access

What Strut is

Strut is a job search tool in early access. You can use two of its tools without an account: a job fit evaluator (paste a job description and your CV to get an AI score across five dimensions) and a STAR story builder (turn rough interview answers into structured stories).

You can also create an account. An account saves your work and adds the rest of the product: a pipeline of the roles you track, a CV profile, AI CV tailoring, cover letters and follow-up tasks.

The two cases are different, and this notice describes both. Without an account, what you enter is not linked to your identity. With an account, the data listed in What data we collect is linked to your name and your email address.

Where Strut is offered

Strut is run from the United Kingdom and is offered to people in the United Kingdom. It is not directed at people in the European Union, and Strut has not appointed an EU representative.

Strut does not block anyone from creating an account, and some people outside the United Kingdom have already done so. If you are one of them, this notice still describes what Strut does with your data, and you still have the rights set out below.

Strut plans to offer the product in the United States when early access ends. That has not happened yet, and this notice describes the position today. Strut updates this notice before the change takes effect, and you will see a new version number.

What data we collect

If you use the tools without an account, we collect only anonymous usage data:

  • An anonymous visitor ID stored in your browser (persists across sessions on the same device)
  • A per-visit session ID reset each time you open the page, used for usage analytics
  • A separate anonymous session identifier stored in a first-party cookie for up to 30 days, used only to enforce free-tier usage limits and to confirm a later "email me my results" request came from the same browser that ran the evaluation — see Cookies and local storage below
  • Usage events: when you run an evaluation or generate a STAR story
  • Aggregate scoring data from the job evaluator (overall score, dimension scores)

This data cannot be linked back to you — it contains no name, email, or other identifying information.

If you create an account, we store the following and link it to your account:

  • Your name and your email address. The email address is how you sign in.
  • Your CV — the file you upload, and the text Strut reads from it. That text includes the name, email address and phone number printed on the CV itself, and often more than that — see Sensitive detail in a CV below.
  • Your work history and skills — the roles, dates, bullet points and skills you keep in your profile.
  • The roles you save — the job description text, the score and the reasons for it, the pipeline stage, and the dates you record against each role.
  • Your notes on each role.
  • Follow-up tasks you create, with their due dates.
  • STAR stories you write, and the skills tagged on them.
  • Tailored CVs and cover letters you generate, and the files Strut builds from them.
  • Your settings — language, start page, target roles and location preferences.
  • A record of the notifications Strut has scheduled or sent to you.

Strut does not store contact records. An earlier version of this notice said it did. That was wrong: the feature has not been built, and Strut holds no names, employers, email addresses or LinkedIn addresses of other people. If Strut adds it, this notice will say so before the feature ships.

Strut applies a row-level access rule to every one of these tables, so one account cannot read another account's rows.

We use your email address to send you the messages the product needs to send — sign-in links, and confirmation of a change you asked for, such as closing your account. We will not send marketing email or share your address with third parties.

Your CV, job description, and interview answers

Content you paste into the tools is processed to generate results. Here is exactly what happens:

  • CV text — before any AI evaluation, your name, email address, and phone number are removed. What remains — your employers, job titles, dates, qualifications and locations — is still sent, and a person could often work out who you are from that combination. So the text the AI receives is not anonymous. It is your CV with the direct identifiers taken out, and data protection law still treats it as your personal data. The removal applies to what Strut sends to the AI, not to what your account holds: if you have an account, your CV stays in it in full.
  • Job description — processed and scored by AI. Job descriptions are usually public documents, but one can name a hiring manager or a recruiter, and Strut sends whatever text you paste. Do not paste a job description if you do not want the names in it sent to the AI.
  • Interview answers (STAR builder) — your answer is sent to the AI to generate a structured story. Answers typically describe work situations rather than identifying information, but if your answer contains personal details (names of colleagues, employers, etc.) those will be included in the AI request. Nothing from the STAR builder is saved unless you create an account.
  • Job evaluator results, without an account — Strut saves the evaluation result: the score, the dimension breakdown, and a parsed summary of your CV and the job description. Your raw CV text and the raw job description text are not saved. The summary is kept so you can return to your result and, if you choose, email it to yourself — see Data retention below for how long.
  • Job evaluator results, with an account — a role you save keeps its job description text, its score and the reasons for it in your account. Strut keeps them until you delete the role or you close your account.

Sensitive detail in a CV

A CV or an interview answer often carries detail that data protection law treats as special category data, and holds to a higher standard than ordinary personal data. Strut does not ask for it, but it arrives inside the text you provide. The usual sources are:

  • Health or disability — a career gap explained by illness, a note about adjustments you need, a role in a condition-specific charity
  • Religion or belief — a faith school, a religious charity, a role at a place of worship
  • Trade union membership — a union role, a workplace representative position
  • Sexual orientation — an LGBTQ+ employee network you led or joined
  • Political opinions — party work, campaign work, an elected position
  • Racial or ethnic origin — a diversity network, a nationality, a language described as a mother tongue

What Strut does with it. Nothing specific. Strut does not look for this detail, does not pull it out into its own field, and does not use it to score you. It is stored as part of your CV text like any other sentence, and it is sent to the AI provider as part of that text. Removing your name, email address and phone number does not remove any of it.

Strut does not yet ask for your explicit consent to this. The law normally requires explicit consent before a service processes special category data. Strut has not built that step. We are telling you this rather than describing a consent process that does not exist. Until it is built:

  • You can leave it out. Edit your CV before you upload it, or edit the text in your profile afterwards. Strut works with whatever you give it.
  • You can object or ask us to stop. Contact support@strutcareer.com and we will act on it.
  • You can remove it at any time. Correct your profile in the product, delete the CV, or close your account and everything goes — see Data retention below.

Why Strut is allowed to use your data

Data protection law requires a legal ground for each purpose. These are the grounds Strut relies on:

What Strut doesLegal groundWhat that means
Runs the evaluator and the STAR builder for a visitor with no accountLegitimate interestsYou asked the tool to do a job. Running it is what you came for, and no account exists to form an agreement with.
Runs your account and everything in itPerformance of a contractYou asked for the service. Holding your roles, stories and CV is how Strut delivers it.
Sends you sign-in links and confirmation messagesPerformance of a contractYour account cannot work without them. Strut sends no marketing email.
Emails an evaluation result to you when you askConsentYou choose this by entering an address. You can decline and still use the tool.
Counts anonymous usage to see whether the tools workLegitimate interestsThe records hold no name, email or other identifier.
Enforces free-tier limits and prevents abuseLegitimate interestsA random identifier in a cookie. Strut cannot run a free tier without it.
Handles special category detail inside your CVNo ground is in place yetSee Sensitive detail in a CV above. Strut is telling you this rather than claiming a consent step it has not built.

Who else handles your data

Strut uses four other companies to run the product. Each one only processes your data to do the job in this table, and none of them may use it for their own purposes.

The companies that process your data on Strut's behalf, and where they do it

CompanyWhat it does for StrutWhereProtection relied on
AnthropicRuns the AI that scores roles, reads CVs and builds STAR storiesUnited StatesStandard contractual clauses with the UK addendum, under Anthropic's terms for API customers
SupabaseHolds the database, your uploaded CV file, and the documents Strut buildsEuropean Union (Frankfurt, Germany)UK adequacy regulations for the European Economic Area
VercelServes the website and runs the code behind every requestUnited StatesStandard contractual clauses with the UK addendum, under Vercel's terms
ResendDelivers the email Strut sends youUnited StatesStandard contractual clauses with the UK addendum, under Resend's terms

Strut uses no third-party analytics or advertising company, and sells your data to nobody.

Sending your data outside the UK

Strut is run from the United Kingdom, but none of the companies above is a UK company. So your data leaves the United Kingdom, and this is where it goes:

  • To the European Union. Your account, your CV file and the documents Strut builds are held in Frankfurt, Germany. The United Kingdom recognises the European Economic Area as giving equivalent protection, so no extra safeguard is needed for this.
  • To the United States. This is the more significant one. The text of your CV, the job descriptions you paste and your interview answers are sent to Anthropic in the United States every time you use an AI feature. The website itself runs on US infrastructure, and the email Strut sends you passes through a US company. US law does not give the same protection as UK law, so these transfers rely on standard contractual clauses — a contract term the UK government publishes that binds the recipient to protect the data.

To ask about the safeguards for any of these transfers, contact support@strutcareer.com.

AI processing and Anthropic

Scoring, parsing, and story generation use the Anthropic Claude API. Your experience data with the direct identifiers removed, job description text, and interview answer text are sent to Anthropic for processing.

Anthropic does not use API inputs to train its models. This policy applies to all API usage and is distinct from Anthropic's consumer product (Claude.ai), which has different terms. You can review Anthropic's API data usage policy at anthropic.com/legal/privacy.

Usage telemetry

Anonymous usage events are stored in Supabase (a hosted Postgres database in the EU). These records contain no personal data — only event types, scores, and the anonymous IDs described above.

Strut uses this telemetry only to evaluate tool quality and to inform product development.

Account records are held in the same database. The CV file you upload and the documents Strut builds for you are held in the file storage of the same Supabase project. Account records are not anonymous — What data we collect above lists what an account holds. Strut uses them to operate the product for you, not as analytics.

Your rights (UK GDPR)

Steve Bailey, a sole trader trading as Strut, is the data controller for personal data processed by Strut.

If you used the tools without an account: usage telemetry is anonymous and cannot be linked back to you — there is no personal data to access or delete. An evaluation result you asked Strut to email to you holds your email address, and Strut deletes it automatically — see Data retention below.

If you have an account: the data listed above is personal data, and you have the right to:

  • Access and portability — open the Account section of your profile and choose Download my data. Strut builds a ZIP file that holds your profile, your saved roles and their scores, your notes, tasks, STAR stories, tailored CVs and cover letters. You do not have to ask us for it.
  • Erasure — open the Account section of your profile and close your account. Strut deletes your account and everything in it 30 days later. See Data retention below.
  • Rectification — correct your profile, roles and stories in the product at any time, or ask us to correct anything you cannot reach.
  • Object — tell us to stop using your data for anything Strut relies on legitimate interests for, listed in Why Strut is allowed to use your data above. This includes the sensitive detail described earlier.
  • Restrict — ask us to hold your data but stop using it, while a complaint or a correction is being sorted out.
  • Withdraw consent — consent is the ground for one thing only: emailing an evaluation result to you when you ask. You withdraw it by not asking again, and the copy is deleted on the schedule below. For everything else, use the objection right above or close your account.

To exercise a right you cannot exercise in the product, contact support@strutcareer.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk), the UK data protection regulator.

Cookies and local storage

We use your browser's localStorage to store your anonymous visitor ID.

If you tick "Remember my email on this device" when signing in, we also store that email address in your browser's localStorage (strut.rememberedEmail), so you do not have to retype it next time. It is stored only if you ask for it, only on that device, and it is never sent to us or to anyone else — the choice itself is not submitted with the sign-in form. Untick the box and sign in once to remove it, or clear your browser's site data at any time.

We set one first-party, httpOnly cookie (strut_sid) to identify your browser for up to 30 days. It holds a random, unguessable identifier — not derived from your IP address, browser fingerprint, or any personal information — and is used only to enforce free-tier usage limits on the job evaluator and CV parser, and to confirm a later "email me my results" request came from the same browser that ran the evaluation. It is not used to track you across other sites and is never shared with any third party.

No third-party analytics or advertising trackers are used.

Data retention

Anonymous usage telemetry is retained for the duration of the early access period and reviewed before any public launch.

Job evaluator results for anonymous (non-account) use — including the email address, if you used "email me my results" — are automatically deleted 30 days after the evaluation was run. If you create an account before then, your most recent result is carried over into your profile and the temporary copy is deleted on the same schedule.

Account data is retained for as long as your account is open. You can delete an individual role, story or task in the product at any time, and Strut removes it.

If you close your account, Strut deletes your account and everything in it — roles, stories, CVs and notes — 30 days after you ask it to. Your account stays fully usable for those 30 days, and you can cancel on any day inside them, from your profile or from the link in the confirmation email. After that date the data cannot be recovered.

Emails Strut sends you. When Strut cannot deliver an email immediately, it holds the message in a queue and tries again. Each entry in that queue holds your email address and the text of the message. Strut deletes an entry 30 days after the message is delivered, or 30 days after Strut stops trying to deliver it. Strut keeps the entry for that period so that a message which never arrived can be traced. If you close your account, Strut deletes every entry addressed to you at the same time as the rest of your data.

Version history

When this notice changes what Strut does with your data, the version number goes up and the change is listed here.

  • Version 2 · 2026-08-27Added the sensitive detail, legal ground, international transfer and recipient sections. Corrected the statement that Strut stores contacts, which it does not. Stated that Strut is offered in the UK.
  • Version 1 · 2026-08-01First published notice: what Strut collects, how long it keeps it, and the rights you have over it.

Contact

Strut is operated by Steve Bailey, a sole trader. For any privacy-related questions or to exercise your rights, contact support@strutcareer.com.