Who we are and who this covers
Lemonable is an early-stage product operated from British Columbia, Canada. It is currently available only to people who have been invited to a small private test. This policy describes what the application actually collects and does today, not what it may do in future.
What we collect
- Account email address and authentication information (password hash, email verification state, and optional two-factor settings) held by our authentication provider.
- Profile information you enter: preferred or display name, country, province or region, city, industry, job function, seniority, years of experience, education level, degree and school, and optional salary information.
- Employment and work history you add: roles, organisations, dates, descriptions and reasons for leaving.
- Career experiences and stories: turning points, transitions, goals, moments, experiments, accomplishments, reflections and the narrative answers you write.
- Skills you list and capability evidence you record.
- Career goals, direction notes and learning topics.
- Work-style answers you choose to complete, and any AI summary generated from them.
- Security and access information: IP address, browser user-agent, sign-in attempts, and an audit log of account and administrative actions.
- Support conversations you start, and product usage events such as which surface a search was run from and whether it returned results.
You are not required to complete any career section. Anything you leave blank is simply not collected.
Why we hold it
To run your account, to show you your own career record and insights, to operate the invitation-only test, to keep the service secure, and — only in aggregated, privacy-protected form — to show community patterns. Aggregate figures derived from member data are only published when at least five qualifying members sit behind them.
Cookies and browser storage
We use only what the application needs to work: sign-in and session storage, session timing values used for automatic sign-out, a short-lived Cloudflare security check when a challenge is shown, and small preference values such as a dismissed interface message. We do not use cookies or browser storage for advertising, cross-site tracking or advertising profiles, and we do not use third-party analytics scripts. Full detail is in the Cookie & Browser Storage Notice.
Product analytics
Lemonable measures product usage with its own first-party events, stored in Lemonable's database — there is no third-party analytics service, advertising pixel or tracking script. An event records the account it came from, a fixed event name (such as a search or a saved profile), which screen it came from, how many results a search returned, and whether the action succeeded. For occupation searches it also records the official occupation code your search matched, or simply “unmatched” when nothing matched. Text you type into a search box is never stored. Events never contain your career record, insight text, salary, email or name. Events are deleted with your account and in any case after 180 days; the daily aggregate totals derived from them are not tied to you and remain.
AI processing
AI features are optional and controlled by you. When AI analysis is on, career information you have permitted — About, Experience, Skills, Goals, Work Style, each with its own switch — is sent to a large language model to produce a summary or suggestion for you. A category that is switched off is not read from the database and is never included in an AI request. When the master AI switch is off, no personal career data is sent to any model. Your name, email address, contact details, employer name and exact city are never sent.
Service providers we use
We share information with a small number of providers only as needed to run and secure Lemonable. We do not share it for advertising or cross-site profiling, and we do not sell it.
- Supabase — database, authentication and file storage (hosted in Canada or the United States).
- Lovable — hosting and delivery of the application, including its Cloudflare-based edge network, which processes technical request data such as your IP address.
- Google Gemini, accessed through the Lovable AI Gateway — processes AI requests described above.
- Cloudflare Turnstile — a bot check on sign-in and related authentication screens.
- Google — optional sign-in with a Google account, if you choose that option.
- Google Forms — used for the optional feedback form; anything you type there goes to Google, not into your Lemonable profile.
Your privacy, your choice
You control your privacy settings. If you choose to keep your profile private, it won't be visible to other members.
Discover and community patterns
Discover has two separate parts. Career stories can show a member's profile details, and your record is included only when your visibility is Public or Custom with sharing switched on — your name is shown only if you have chosen to share your identity. Aggregated community patterns are separate again: your record counts towards them only if you switch on “Contribute to career intelligence”, which is off until you turn it on, and a figure is shown only when at least five qualifying members sit behind it.
A Private profile is excluded from both. Career Story narratives, work-style answers, turning points, goals, experiments and AI insights are never published in Discover.
Administrator access
Administrators can see account metadata — email, sign-up date, access level, account status — for running the test. They cannot browse your private career content. Corrections are limited to name fields, require a super administrator with two-factor authentication, and are written to an audit log.
Your controls
- Choose Public, Custom or Private visibility at any time. Private removes your profile from discovery.
- In Custom, choose section by section what can appear, and show or hide employer, education and salary independently.
- Switch contribution to community career intelligence on or off.
- Turn AI analysis off entirely, or per category (About, Experience, Skills, Goals, Work Style).
- Download a full copy of your data, or delete your account permanently.
All of these live under Me → Privacy.
Security
Data is stored with row-level access rules so an account can only read its own records. Access requires a verified email and an active invitation, with strong password rules, optional two-factor authentication, session timeouts and audit logging of administrative actions. Sign-in attempt logs are kept for a limited period and then purged.
Deletion, retention and contact
Deleting your account permanently removes your login, profile, work and education history, career stories, turning points, goals, experiments, accomplishments, work-style answers, AI insights, support conversations, points and product events. They cannot be recovered, and re-registering with the same email creates a completely new, empty account.
A small set of security and administration records is kept afterwards so we can account for what happened: an administrative audit log (which can include the email address involved and the action taken), sign-in attempt logs, aggregate daily usage totals, and your invitation record, which is returned to an unused state. Audit log entries older than 12 months are automatically de-identified: the email address, name, IP address and browser details are erased and only the action, category and time remain. Sign-in attempt logs are deleted after 90 days. These records contain no career content and cannot be used to rebuild your profile.
For any privacy question or request, email hello@lemonable.ca.

