Privacy Policy
Last updated: August 21, 2026
Interview Copilot ("we", "us", "our") operates the website interviewcopilot.co and the Interview Copilot platform (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
1. Information We Collect
We collect the following types of information:
- Account information: email address, name, and password hash when you create an account.
- Usage data: interview prep content you create, resumes you upload, job descriptions you provide, interview transcripts, and tracker pipeline data.
- Live interview audio: when you explicitly choose interview-tab audio and confirm you have permission, short audio segments are processed transiently by Google Gemini to produce transcript text. Interview Copilot does not store the audio files; saved transcript text is part of your session data.
- Billing information: payment details are collected and processed directly by Stripe. We store only your Stripe customer ID and subscription status.
- Technical, reliability, and analytics data: infrastructure may process IP address, browser and device information, access timestamps, error stack traces, page route, release, and coarse performance timing for security and reliability. Sentry reliability monitoring runs independently of optional analytics, with replay and default personal-data collection disabled. Request bodies, query strings, cookies, names, email addresses, IP addresses, resumes, prompts, transcripts, and authentication material are removed before events are sent; a pseudonymous account identifier may be retained to correlate affected sessions. Optional Google Analytics and PostHog record page and feature events only after you opt in; event properties are filtered to exclude email addresses, names, account content, resumes, job details, audio, and transcripts.
- First-party aggregate funnel counts: acquisition pages and selected conversion actions, such as arriving from an owned placement, generating a preview, or opening or sharing a practice link, request aggregate counter increments. Visitor and selected conversion counts are limited to once per browser per UTC day when browser storage is available. The database stores only the date, event name, and total count — not an IP address, browser identifier, source, URL, referrer, company, role, email, or other event property.
- Account lifecycle and operational milestones: for signed-in accounts, our backend records a pseudonymous account identifier with selected events such as account creation or verification, onboarding completion, resume readiness, job scans, application-stage changes, practice sessions, checkout, payment, renewal, cancellation, and billing failures. These records contain only allow-listed coarse statuses and counts; they exclude names, email addresses, companies, roles, resumes, job descriptions, URLs, payment details, audio, and transcripts.
2. How We Use Your Information
We use your information to:
- Provide and improve the Service, including AI-powered features such as role-specific question generation, resume tailoring, practice coaching, and compensation analysis.
- Process payments and manage your subscription.
- Send account-related communications (e.g., billing receipts, security alerts).
- Monitor and prevent abuse, fraud, and unauthorized access.
- Measure activation, retention, and conversion, and send privacy-minimal internal operational alerts about important account, product, and billing milestones.
- Comply with legal obligations.
3. Data Storage and Security
Your data is hosted using Amazon Web Services (AWS) and Supabase infrastructure in the United States. We use security measures including:
- Encrypted AWS storage and AES-256-GCM encryption for user-supplied AI provider keys at rest.
- TLS 1.2+ encryption for all data in transit.
- Secure password hashing using bcrypt.
- Rate limiting and brute-force protection on authentication endpoints.
4. Third-Party Services
We share data with the following third parties only as necessary to provide the Service:
- Stripe: payment processing. Stripe receives your payment information directly and is governed by the Stripe Privacy Policy.
- Google Gemini: primary AI processing for prompts and content you submit to AI features, including transient processing of live interview-audio segments when you enable that feature. See the Gemini API Terms and Google Privacy Policy.
- Anthropic and OpenAI: AI processing when the applicable provider is used, including when a Premium user configures a supported personal provider key. See the Anthropic Privacy Policy and OpenAI Privacy Policy.
- Google Analytics: optional website and product usage analytics, loaded only after you opt in. We disable advertising signals and do not send account identifiers, resumes, job details, interview audio, or transcripts. See Google's analytics privacy and data safeguards.
- PostHog: optional product analytics and session replay, loaded only after you opt in. Replay masks all text and form inputs, blocks images, video, audio, canvas, and embedded frames, and does not record interview audio or transcripts. See PostHog's privacy information.
- Sentry: essential application error and low-sample performance monitoring used to detect and diagnose failures. Session replay and default personal-data collection are disabled; request bodies, query strings, cookies, names, email addresses, IP addresses, resumes, prompts, transcripts, and authentication material are removed before events are sent. A pseudonymous account identifier may be retained to correlate affected sessions. Sentry events are retained only for the provider's configured operational retention period. See Sentry's privacy information.
- Slack: internal operational notifications for selected product, billing, deployment, and application-error milestones. Slack receives only a shortened pseudonymous account identifier, event time, deployment release, request correlation identifier, route template, status, duration, and coarse allow-listed status or count fields. It does not receive names, email addresses, raw URLs or query strings, companies, roles, resumes, job descriptions, payment details, audio, prompts, or transcripts. See the Slack Privacy Policy.
- Amazon Web Services: application hosting, storage, content delivery, and email infrastructure. See the AWS Privacy Notice.
- Supabase: managed PostgreSQL database infrastructure. Product tables are accessed only by the backend application role; browser roles are denied access to the private lifecycle-event outbox. See the Supabase Privacy Policy.
We do not sell, rent, or share your personal information with any other third parties for marketing purposes.
5. Cookies and Browser Storage
We and our analytics providers use cookies and browser storage for authentication, preferences, analytics, and abuse prevention. These technologies may include:
- Authentication token: stored in localStorage to keep you logged in.
- Preferences: UI settings such as sidebar state stored in localStorage.
- Aggregate counter deduplication: the UTC date of selected successful acquisition and conversion counts, stored in localStorage so the same browser is counted at most once per day for each deduplicated metric.
- Analytics: Google Analytics and PostHog may use cookies and browser storage only after you choose “Allow analytics.” Your allow/deny choice and coarse campaign parameters (such as UTM source, medium, and campaign) are stored locally; full referring URLs and unapproved query parameters are not retained for analytics.
We do not run third-party advertising on the Service or sell personal information for targeted advertising. You can restrict cookies and browser storage through your browser settings, although doing so may affect authentication and preferences.
6. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Export your data in a portable format.
- Restrict or object to certain processing of your data.
- Request deletion of your data (see below).
7. Data Deletion
You can delete your account and all associated data at any time from your account settings or by contacting us at support@interviewcopilot.co. Upon deletion:
- Your account, resumes, interview data, tracker pipelines, and all AI-generated content will be permanently removed.
- Billing records may be retained as required by law for up to 7 years.
- Deletion is processed within 30 days of your request.
8. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible until you delete your account. Inactive accounts with no login for 24 months may be subject to deletion after prior notification. Processed, privacy-minimal account lifecycle and operational milestone records are retained for up to 400 days for cohort, conversion, delivery, and incident analysis.
9. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service or sending an email to your registered address. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at: