Privacy Policy
This policy explains what personal data Cannen collects, why, where it is stored, and what you can do about it. It is written to be read, not to be skimmed past.
Last updated: 18 August 2026
1. Who we are
Cannen is a subscription career platform operated by Cannen Ltd, a company registered in England and Wales under company number 17381013, whose registered office is at 29 Cambridge Road West, Farnborough, GU14 6QA. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller for the personal data described below.
Data protection enquiries: [email protected]
ICO registration number: ZC213553
2. What we collect, and why
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Email address and display name | To create and secure your account, and to send you service messages about it: a welcome, payment receipts, and changes to your plan or to Cannen | Contract |
| Your career track, UK region, and the blocker you describe | To place you on the Career Map and choose your weekly sprints | Contract |
| Career Map and sprint progress | To show your progress and pick the next stage | Contract |
| Community posts, comments and reactions | To run the community features you chose to use | Contract |
| Markers you set on The Climb, and what you write on them: the headline, the story, the employer if you name one, and the Career Map stage you were on | To show them on your own route, and, unless you say otherwise, on our public page (see section 4) | Contract |
| AI tool usage counts (number of uses, token totals) | To enforce the fair-use limits on your plan | Contract |
| Subscription tier, status and Stripe reference IDs | To give you the access you have paid for | Contract |
| Server and security logs | To keep the service running and detect abuse | Legitimate interests |
| When you were last active, shown to your accountability pod | Pro members are placed in a small group whose stated purpose is to notice when somebody stops. If you go a week without ticking a sprint task, posting a marker or writing in the pod, the other members are told. This is explained on the pod page before you post anything, and you can leave the pod at any time. | Contract |
| Whether you want the weekly emails | To send members the Monday sprint email and the weekly Climb digest, and to stop them the moment you ask us to | Contract |
| Marketing emails | To send you the newsletter, if you ask for it | Consent |
3. Your CV is not stored
This is worth stating plainly, because it is unusual. When you use the CV Rewriter, the text you paste is sent to our AI provider to generate your result and is then discarded. We do not write it to our database, and we cannot retrieve it later. All we keep is a count of how many times you used the tool and how many tokens it consumed, so we can apply your plan's limits.
The CV Scorecard goes further: it runs entirely on our own servers using rules, not AI. Your CV is never sent anywhere at all.
The Decoder works the same way, and it matters more there because you are pasting something an employer sent you. Email addresses, phone numbers, links and the name in the greeting are stripped before the message is read, the reading happens in memory on our own servers, and the text is then discarded. It is never written to our database and never sent to an AI provider. What we keep is that a pattern matched and which round you had reached, with no link to your account, so we can see which stage members are losing at without holding anything anybody pasted.
4. What you choose to publish
Most of what we hold is private to your account. The exception is The Climb, and it is worth being exact about it.
When you set a marker, unless you choose otherwise, it appears at cannen.app/climb. That page is readable by anyone, with no account, and search engines can index it. Anything you write on a marker is published: the headline, the story, the employer if you name one, the Career Map stage you were on, and your display name. A salary figure you put in the text is published too.
You have two ways to change that, and both are offered every time you post:
- Post anonymously. The marker is signed by your track and UK region instead of your name, for the public and for other members. We still hold it against your account so it counts on your own route.
- Keep it to yourself. The marker appears only on your own route. It is never published and never shown to other members.
You can delete any marker you have set, at any time, from your own climb. Deleting removes it from the public page. Because that page is cached for up to a minute, and because search engines keep their own copies on their own schedules, we cannot promise it disappears from the internet the instant you press delete. That is worth knowing before you publish something, rather than after.
5. Where your data is stored
- Database (your account and everything in it): United Kingdom (London).
- Application servers: Netherlands (EU). The UK Government recognises the EEA as providing an adequate level of protection, so no additional safeguards are required for this.
6. Who else processes your data
We use a small number of specialist providers. They act on our instructions and are bound by contract.
| Provider | What they do | What they receive |
|---|---|---|
| Clerk | Authentication and login | Email, name, login credentials |
| Stripe | Payments and subscriptions | Email, payment details, billing history |
| Anthropic | Powers the AI CV Rewriter | The CV text you submit, transiently |
| Resend | Delivers our emails | Your email address, your name, and the contents of the email |
| Supabase | Database hosting (UK) | Everything in section 2 |
| Railway | Application hosting (EU) | Data in transit and server logs |
| Cloudflare | DNS and network protection | IP address, request metadata |
We never store your card details. Payments are handled entirely by Stripe; we hold only the reference IDs Stripe gives us.
Some of these providers are based in, or transfer data to, countries outside the United Kingdom - principally the United States. We only use providers that offer a recognised safeguard for that transfer, and we rely on whichever applies to the provider in question: the UK's adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where a provider is certified under it, or the ICO's International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum. These are the standard mechanisms the providers named above operate under worldwide.
If you want to know which safeguard applies to a particular provider, or would like a copy of it, email [email protected] and we will tell you.
7. How long we keep it
- Your account data: for as long as your account exists. Delete your account and it is erased immediately - see section 8.
- Markers on The Climb: until you delete them, or until you delete your account, which removes them too.
- Financial records: Stripe retains transaction records to meet its own legal obligations, and we may need to keep basic records for up to six years to satisfy HMRC requirements.
- Server logs: a short rolling window, then discarded.
8. Your rights
Under UK GDPR you have the right to:
- Access your data. Go to your account page and click Download my data. You get everything we hold, as a JSON file, immediately - you do not have to ask us.
- Erase your data. Your account page has a Delete account option. This is a genuine deletion, not a hidden flag: your account, progress, posts and comments are permanently removed from our database, and your login is deleted too. It cannot be undone.
- Correct inaccurate data, via your profile or by contacting us.
- Port your data - the export is machine-readable JSON for exactly this purpose.
- Restrict or object to processing, and to withdraw consent for marketing at any time.
If you have an active subscription, cancel it before deleting your account - otherwise you would lose access while continuing to be billed.
If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office. We would rather you told us first so we can put it right.
9. Cookies
We use no analytics, advertising or tracking cookies, so there is nothing here to opt into. Browsing Cannen while signed out sets no cookies at all.
| Purpose | Set by | When |
|---|---|---|
| Keeping you signed in as you move between pages | Clerk | Only once you sign in |
| Telling real visitors from automated traffic, and protecting the site from abuse | Cloudflare | While you are browsing |
Both are strictly necessary to deliver a service you have asked us for, so under the Privacy and Electronic Communications Regulations they do not require your consent. You can block or delete them in your browser settings, but you will not be able to stay signed in if you do.
Payments are taken on Stripe's own checkout pages rather than on Cannen. Any cookies set there are Stripe's, and are covered by Stripe's notice rather than this one.
If we ever add analytics or marketing cookies, we will ask for your consent before they are set, and you will be able to decline without losing access to anything.
10. Children
Cannen is not intended for anyone under 18, and we do not knowingly collect data from children.
11. Changes
If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect. The date at the top always reflects the current version.
Questions about any of this? Email [email protected]. See also our Terms and Conditions.