Privacy Policy
Last updated June 29, 2026
Maybole (“WSMM”, the “service”) is operated by Maybole Limited, a company incorporated in Hong Kong (“Maybole”, “we”, “us”). This policy explains what we collect, how we use it, and the choices you have. It covers two groups: (A) registered users (students who create an account) and (B) professionals in our contact directory whose business contact information we hold. Section 4 is for group B.
In plain English (the full policy controls)
- You (students): we store your account, your résumé, and your profile, and use them to build your profile and draft your outreach. We do not sell your data and do not advertise to you.
- AI: we send your résumé text and the single contact you’re emailing to Anthropic’s Claude to parse and draft. It is not used to train AI, and every draft is reviewed and sent by you.
- The directory: business-only contact information on finance professionals, gathered through professional networking and from publicly available professional sources. It is shown redacted and revealed only when a subscriber unlocks a contact.
- Your rights: access, correct, delete, and export. You can delete your account and all your data yourself from the Account page, or email us.
1. Who we are; our relationship to your school
Maybole helps university students reach finance professionals for career networking. Maybole is an independent product. We are not affiliated with, endorsed by, or acting on behalf of any university, college, or career center. If you sign up with a .edu email, we use it only to contact you and to optionally confirm you are a student — it creates no relationship between us and your school.
2. Information we collect from registered users
| What | Examples | How we get it |
|---|---|---|
| Account | Name, email, password (stored only as a bcrypt hash — we never see your password) | You, at registration |
| Résumé | The file’s full text plus parsed fields (school, major, graduation year, clubs, internships) | You, by uploading a résumé |
| Profile / onboarding | Hometown, high school, interests, hobbies, email templates | You, during onboarding |
| Contacts you add | People you upload by CSV, and contacts you unlock from the directory | You |
| Drafts & feedback | AI-generated email drafts, your edits, and feedback you leave | Generated for you / by you |
| Billing | Stripe customer and subscription identifiers, plan, email quota used | Created when you subscribe (§7) |
| Referral | Your referral code, who referred you, and bonus-email credits earned | Created when you join or refer via a referral link |
| Draft-feed token | A personal token that lets the self-run mail tools fetch your unsent drafts (§6) | Generated for your account |
| Technical | A session cookie to keep you logged in | Automatically (§9) |
Sensitive content in résumés. A résumé may contain more than the fields we parse. The full text is sent to our AI provider to parse and draft (see §5) — please remove anything you do not want processed. We do not ask for or intentionally use special-category/sensitive data.
We do not sell or rent the résumés, profiles, drafts, or contacts you provide, and we do not use your student data for third-party advertising.
3. How your identity is shared (you control it)
Your profile is not public. Your name and contact details are shared with a professional only when you choose to email them. Our administrators can view account and directory data to operate the service.
4. Professionals in our contact directory
If you are a professional and want to know what we hold or to be removed, see §4.3.
4.1 What we hold. Business-context information only: name, employer, job title and group, work history, education, professional interests, location, a professional email address, and a link to a public professional profile. We do not seek special-category data.
4.2 Where it comes from. This information is gathered through professional networking and from publicly available professional sources. We hold it in a business/professional capacity for the purpose of helping students make individual career-networking introductions — not for advertising, profiling, or resale to data brokers.
4.3 Your choices. You can ask us what we hold, correct it, ask to be removed, or report unwanted outreach. Email tech@maybole.ai (subject “Directory request”). We verify the request and action it. Note that once a subscriber has unlocked a record, our removal cannot retract the copy they already hold.
5. How we use AI
We use AI to read your résumé and write first-draft outreach emails. You stay in control — nothing is emailed automatically.
- Provider/model. Our provider is Anthropic; the model is Claude, called over Anthropic’s API. We do not run our own model or use your data to build one.
- What we send. When you upload a résumé, its full text (to extract profile fields). When you generate a draft, your profile and the single contact you’re emailing. We never send your password, billing details, or other contacts.
- Server-side only. All AI calls are made by our servers over an encrypted connection with our own API key. Your browser never talks to Anthropic directly.
- No training on your data. Anthropic does not use data submitted through its API to train its models.
- Human in the loop. AI output can be inaccurate. Every draft is reviewed, edited, and sent by you. We make no solely automated decisions about you.
- How to avoid AI. Don’t upload a résumé (fill your profile manually) and write your own emails. Account creation, browsing, unlocking, and exporting do not call the AI.
6. Email “on your behalf” — the self-run model
Maybole does not send mail from our servers and does not hold your mailbox password. We generate drafts; you run a small tool on your own Google or Microsoft account that creates those drafts there. The tool uses a personal access token tied to your account. Treat it like a password: it authenticates by itself, does not expire automatically (valid until you regenerate it), and anyone who obtains it can read your unsent drafts and their recipient addresses. Regenerate it any time.
7. Payments
We use Stripe. We store only your Stripe customer/subscription identifiers and plan info. We never store your card number. See the Terms for billing details.
8. Your rights
We will not discriminate against you for exercising a privacy right. Depending on where you live, you may have rights to access, correct, delete, and export your personal information, and to opt out of any “sale” or “sharing” of it. To exercise a right, email tech@maybole.ai (subject “Privacy request”); we verify your identity and respond within the time your law allows.
Self-serve deletion. Registered users can permanently delete their account and all associated data at any time from the Account page (“Danger zone”). This removes your profile, résumé, contacts, drafts, and history.
9. Cookies & tracking
We use a deliberately minimal set of cookies — only to keep you logged in and to protect a security-sensitive flow — not to track, profile, or advertise. We use no advertising trackers, no analytics trackers, and no marketing pixels. Blocking the essential session cookie signs you out.
10. Data retention
We keep account data while your account is active and as needed for the service and for legal, tax, and fraud-prevention obligations. When you delete your account, we remove your account data; some records may be retained briefly in backups before they age out, and where retention is required by law.
11. Security
See our Security page: encrypted transport, hashed passwords, encrypted token storage, and access controls. No system is perfectly secure.
12. International & children
Maybole is operated by a Hong Kong company; our infrastructure providers are located primarily in the United States, and the service is intended for users in the United States. Maybole is for university students and professionals and is not directed to anyone under 16; we do not knowingly collect data from children.
13. Changes & contact
We may update this policy; we will change the “Last updated” date and, for material changes, notify registered users. Questions or requests: Maybole Limited (Hong Kong), tech@maybole.ai.