Privacy policy
Privacy Policy
This policy explains how Scrubmyo handles personal data for the waitlist, account workspace, document upload, AI-assisted extraction, and NHS supporting statement generation.
Last updated: 30 September 2026
1. Who we are
Scrubmyo is the service available at scrubmyo.io. In this policy, "Scrubmyo", "we", "us" and "our" mean the operator of scrubmyo.io.
For privacy questions, data requests, or account deletion requests, contact hello@scrubmyo.com.
2. What Scrubmyo does
Scrubmyo helps people applying for NHS roles structure a supporting statement around their own experience, job description, person specification and career evidence. Scrubmyo is not part of the NHS and does not ask for, store, or need your NHS login details.
3. Personal data we collect
- Waitlist and marketing data: email address, subscription status, signup source, consent records, and email engagement information handled through Kit.
- Account data: email address, authentication identifiers, password hash handled by our authentication provider, login/session information, and security logs.
- Profile and career data: full name, summary, work experience, education, training, courses, skills, ATS keywords, employment gap history, role pattern, and the stories and job notes that you choose to enter.
- Uploaded documents: CVs, NHS job descriptions, person specifications, supporting documents, extracted text and file metadata.
- Story data: your answers to the Profile Intelligence questions and your progress through them, the stories you save, and the checks we run on them: scores, check results, whether a story seemed to contain identifiable information, and which of your stories match each job criterion.
- Generated content: supporting statement drafts, word counts, character counts, match scores, profile scores and edits.
- Technical data: IP address, browser and device information, error logs, cookies, local storage, and similar information needed for security and operation.
- Support and billing data: messages you send us, support history, and payment or invoice records if paid plans are introduced.
4. Sensitive information and NHS confidentiality
Scrubmyo is designed for career and application evidence. Do not upload patient identifiable information, confidential NHS records, or information you do not have permission to use.
Some career examples may reveal sensitive information about you, such as health, ethnicity, religion, trade union membership or other special category data. If you choose to provide that information, we process it only to provide the service you requested and not for advertising, resale, or model training. You can edit, remove, or ask us to delete this information.
Our automatic checks look for information that could identify a person, such as a patient or a colleague, in the stories you save to your Library. A story that seems to contain it is held back: it is not used in your job analysis or statements until you edit it or, for a lower-confidence flag, confirm it is fine. The checks can miss things, and they do not apply to job notes or to the rest of your profile text, so keep patient and colleague details out of everything you write.
5. How we use your information and our lawful basis
- To provide your account and workspace: contract, because we need this to provide the service you request.
- To parse documents, check and match your stories, and generate drafts: contract. If you voluntarily provide special category data, we rely on your explicit consent for that sensitive element and you may withdraw it by deleting the content or contacting us.
- To operate the waitlist and send product updates: consent, or the limited soft opt-in rules where UK law allows them. Every marketing email should include an unsubscribe option.
- To keep the service secure, debug errors and prevent misuse: legitimate interests in running a secure and reliable service.
- To answer support requests: contract or legitimate interests, depending on the request.
- To keep tax, accounting and legal records: legal obligation, if those records are created.
6. AI processing
Scrubmyo uses AI-assisted processing to extract structure from CVs, job descriptions and supporting documents, to structure, check and match your stories, and to help create supporting statement drafts. The output is a draft for you to review, edit and decide whether to use.
- Structuring: when you write a story in your own words, an AI model arranges it into Situation, Action, Result and what you learned without adding facts. You review the arranged version before it is saved and checked. If you add details to make a story stronger, the model fits them into the story the same way and you review the result before it is checked again. If a check thinks something was added that you did not say, it is shown beside your own words.
- Scoring: a specialist evaluation model (Jev, from TypeSafe) checks whether your story answers the question, whether it seems to contain identifiable information, and whether the arranged or updated version added anything you did not say. Another model may write a short explanation for marks it is unsure of. Scores are guidance for you; they never decide an outcome about you.
- Matching: when you analyse a job, the same evaluation model compares your checked stories with the job's criteria and suggests which story covers which criterion ("Covered by your story" or "Suggested"). If matching is unavailable, your analysis is still saved and your statement draws on all your checked stories.
Masking. Before the text of a story or a job note is sent to an AI provider, and before it is used in a job analysis or statement, we replace obvious identifiers with placeholders: NHS numbers, UK phone numbers, email addresses, dates of birth written after a cue such as "born" or "DOB", and UK postcodes (for example [NHS number], [phone], [email], [date of birth] and [postcode]). Masking works on patterns. It cannot catch names, places or details written in free text, so do not enter patient information. Job notes that you type against a job requirement are not scored or checked for identifiable information; they are only pattern-masked before use. Other profile text used for analysis and statements, such as your summary and work history, is not masked. The CV and job description files you upload are not masked either: the AI provider reads them as you upload them.
We do not use your career information to train public AI models. We do not make solely automated decisions that decide whether you get a job, interview, visa, NHS role or any similar outcome. Our own logs are designed to record only technical details of AI requests, such as the time, task, model and size, and we take steps to keep your documents, stories and generated text out of them. If a request fails, the logs record technical details of the failure only (the kind of error, a status code and a short provider error code) and never the content of your documents, stories or the AI's output.
7. Who we share data with
We do not sell your personal data. We share it only where needed to run Scrubmyo.
- Hosting, database, authentication and private document storage providers.
- Email and waitlist providers, including Kit, for signup and product emails.
- AI processing providers, where needed to process your documents and stories:
- Anthropic (Claude models): Analyse your profile against a job description, write supporting statement drafts, and help draft evidence, summaries and assistant replies.
- Google (Gemini models): Read your CV and job descriptions, arrange your written stories into Situation, Action, Result and what you learned, add the details you write to a story when you choose to make it stronger, and explain story marks the evaluation model is unsure of.
- TypeSafe (Jev evaluation model): Scores your stories (whether a story answers the question, whether it seems to contain identifiable information, and whether the arranged or updated version added anything you did not say) and matches your checked stories to a job's criteria. According to the AI Gateway's model listing, requests to this model are not used for training, but this route is not covered by a zero-data-retention agreement, so a request may be kept for a time by TypeSafe or the hosting providers below.
- Vercel AI Gateway (Request routing): Carries every request above to its provider. The gateway may pass requests to hosting providers, including DigitalOcean, to run these models.
- Cloud and security providers used to deliver and protect the website.
- Payment processors, accountants, legal advisers or regulators if paid services are used.
- Law enforcement or public authorities if we are legally required to disclose data.
Some providers may process data outside the UK. Where that happens, we use appropriate transfer safeguards such as UK-approved contractual terms, international data transfer agreements, or other lawful mechanisms.
8. Cookies and local storage
We use essential cookies, local storage and similar technologies for sign-in, session security, preferences and core app functions. These are needed to provide the service.
With your consent, we use Google Analytics cookies to understand how people use Scrubmyo. They are off until you choose Accept, and you can change your choice at any time: .
The same choice covers the Google Analytics events that record how you move through the Profile Intelligence questions, for example that a question was answered or skipped. These events never contain the text of your stories or answers. Separately, we keep a record of your progress in the questions in our own database as part of your account data.
9. How long we keep data
- Waitlist and marketing data: until you unsubscribe or ask us to delete it.
- Account, profile, document and generated statement data: while your account is active.
- Stories, their scores and check results, your answers to the Profile Intelligence questions, and the story matches saved with each job analysis: while your account is active, and deleted with it.
- Deleted account data: removed from live systems where practical, with backup copies expiring in ordinary backup cycles.
- Support messages: normally up to 24 months after the last contact.
- Security logs: normally up to 12 months unless needed to investigate misuse.
- Payment, tax and accounting records: normally up to 6 years where legally required.
10. Your rights
Under UK data protection law, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, and complain to the Information Commissioner's Office.
Contact us at hello@scrubmyo.com to exercise these rights. You can also visit ico.org.uk if you are unhappy with how your personal data is handled.
11. Security
We use access controls, private document storage, row-level security, encrypted connections, authentication controls and limited administrative access. No online service can promise perfect security, so please use a strong password and do not upload information that is unnecessary for your application.
12. Children
Scrubmyo is intended for people aged 18 or over who are preparing job applications. It is not intended for children.
13. Changes to this policy
We may update this policy as the service develops or legal requirements change. The latest version will be posted on this page with the updated date. This version was last updated on 30 September 2026.