Purpose-limited collection
We collect account, profile and tool information only to operate, personalize and protect the GuideCAN features you choose to use.
This policy explains what personal information GuideCAN collects, why it is needed, where it may be processed, how long it is kept, and how you can access, correct or request deletion of it. It also explains exactly what happens when you submit a document, résumé or other text to an AI-powered feature.
Effective date: August 13, 2026
We collect account, profile and tool information only to operate, personalize and protect the GuideCAN features you choose to use.
PDF and text files are read temporarily to extract text. GuideCAN does not save the original uploaded file.
Document and résumé text submitted to an AI feature is sent to Groq to generate the requested result.
You can delete individual saved items in supported tools or contact us to request account and personal-data deletion.
Section 1
This policy applies to the GuideCAN website, accounts, tools, AI features, subscriptions and support channels. GuideCAN is responsible for deciding why and how personal information is handled through these services, including when a service provider processes information on GuideCAN's behalf.
Questions, access requests, complaints and deletion requests can be sent to support@guidecan.ca or submitted through the Contact Us page. Use the subject Privacy or data request so the request can be routed correctly.
Section 2
When you create an account, GuideCAN collects your name, email address and authentication information. The signup experience also asks for information used to personalize the service, such as country of origin, province or territory, immigration stage or status, profession or field and household size.
This includes preferences, plans, checklists, reminders, saved jobs, generated results, saved document explanations, saved résumé versions, messages and other content you choose to enter into a GuideCAN feature.
When you use an AI feature, GuideCAN receives the prompt, form fields or text you submit. If you upload a supported document or résumé, GuideCAN temporarily receives that file in order to extract readable text. Section 4 explains this process in detail.
Stripe processes payment details for subscriptions. GuideCAN receives billing and subscription identifiers, status and related transaction information, but does not receive your full card number. If you contact us, we receive the name, email address, subject and message you provide.
GuideCAN and its hosting or security providers necessarily receive limited technical information such as IP address, browser or device information, request time, requested page, session or authentication identifiers and error information. This information is used to deliver and protect the service, apply rate limits and diagnose failures.
Remove Social Insurance Numbers, passport or permit numbers, health-card numbers, banking credentials, full account or card numbers, passwords and other identifiers that are not necessary for the feature. Only submit information about another person when you have authority to do so.
Section 3
GuideCAN uses personal information only for identified purposes, including to:
GuideCAN does not sell personal information and does not use uploaded documents, résumé text or private workspace content for targeted advertising.
Section 4
GuideCAN uses Groq's API to produce many AI responses. This means Groq receives the submitted prompt and the information needed to generate the result. For the Document Explainer and Résumé Canadianizer, this includes the extracted or pasted document text. Groq states that inference inputs and outputs are not used to train models without permission. Depending on Groq account data controls, inputs and outputs may be retained temporarily for service reliability or abuse monitoring for up to 30 days. Groq states that retained customer data is stored in the United States.
Some GuideCAN tools use OpenAI to search for current public information before generating an answer. GuideCAN limits that research request to selected context such as topic, category, profession, city or province, removes common contact details where detected, and sends the request with response storage disabled. GuideCAN does not send uploaded document text or résumé text through this OpenAI research workflow.
AI features are optional. Submitting information to an AI action directs GuideCAN to send the disclosed input to the identified AI provider for that request. If you do not want the text processed by an AI provider, do not submit it to an AI action. Remove unnecessary personal information first. AI output can be incomplete or incorrect and must not replace an official or qualified professional for legal, immigration, health, tax, financial or other high-impact decisions.
Section 6
GuideCAN asks for consent in context: account creation identifies the account and profile information required to provide the service; contact forms explain how the message will be used; and AI submission controls identify that information will be processed to generate the requested response. Collection or disclosure that is not necessary for a requested service should be offered as a separate choice.
Withdrawing consent does not reverse processing that was already lawfully completed and may prevent GuideCAN from providing a feature that requires the information.
Section 7
GuideCAN keeps personal information only for the period connected to its purpose, subject to legal, billing, security and dispute-resolution requirements. The current retention approach is:
Processed temporarily in server memory for the request and not saved by GuideCAN as an uploaded file.
Not deliberately stored by GuideCAN after the request unless you choose to save the generated result. Groq may temporarily retain inputs and outputs for service reliability or abuse monitoring for up to 30 days, depending on the account data-control settings and legal requirements.
Kept while your account remains active or until you delete the saved item where that control is available, or request account deletion.
Kept while your account is active. Necessary billing, fraud-prevention or legal records may be retained longer when required by law or to resolve a dispute.
Kept to administer monthly limits, prevent misuse and investigate service problems. They are linked to your account and are included in the account-deletion process, subject to legal or security exceptions.
Kept only as long as reasonably needed to answer the request, maintain an appropriate support record, prevent abuse or meet legal obligations.
Remains on that browser or device until GuideCAN removes it through a feature control, you clear site data, or the browser removes it.
When information reaches the end of its retention period, it should be deleted or de-identified. Residual copies may remain temporarily in encrypted backups until the applicable backup cycle replaces them.
Section 8
You may ask GuideCAN what personal information it holds about you, request access to it, correct inaccurate information, ask for a portable copy where reasonably available, or request deletion of your account and personal information.
An approved account-deletion request covers the GuideCAN authentication account, profile and linked GuideCAN database records, including saved workspaces and AI-usage records, unless a record must be retained for legal, billing, fraud-prevention or dispute-resolution reasons. Information already sent to a provider remains subject to that provider's documented retention cycle and applicable law.
Account deletion cannot automatically erase GuideCAN browser storage on a device that GuideCAN can no longer access. To remove those copies, clear site data for guidecan.ca in each browser or device you used. GuideCAN may refuse or limit a request only where permitted or required by law and will explain the reason where allowed.
Section 9
GuideCAN uses administrative, technical and organizational safeguards appropriate to the information handled. These include HTTPS for web traffic, access controls, server-side protection of secret API keys, input and file-size limits, rate limits, and user-specific database access rules.
Supabase states that hosted project data is encrypted at rest and its HTTP APIs enforce encrypted connections. GuideCAN applies Row Level Security policies to supported user workspace tables so authenticated users can access only their own rows.
No internet transmission or storage system is completely secure. Users should use a unique password, protect their device and avoid submitting information that a feature does not require.
If GuideCAN determines that a breach of safeguards creates a real risk of significant harm, it will provide notifications and reports required by applicable law.
Section 10
GuideCAN is not designed to collect personal information directly from children under 13. A child under 13 should not create an account or submit personal information without a parent or guardian. Parents, guardians and young users should not enter a child's sensitive identifiers, school records, health information or confidential family information into general planning or AI tools unless the feature clearly requires it and appropriate consent and safeguards are in place.
A parent or guardian who believes a child's information was submitted improperly should contact GuideCAN so it can be reviewed and deleted where appropriate.
Section 11
GuideCAN may update this policy when its services, providers or legal obligations change. The effective date will be updated. If a change materially affects how personal information is collected, used or shared, GuideCAN will provide a prominent notice and request new consent where required before the new practice takes effect.
Section 12
For privacy questions, complaints, access, correction, export or deletion requests, contact support@guidecan.ca or use the Contact Us form. Do not send identity documents, passwords, banking credentials or other sensitive proof unless GuideCAN specifically requests a secure verification method.