Privacy Policy
Last updated June 25, 2026
InterviewOS is built local-first and privacy-first. This policy explains what we collect, what stays on your device, and exactly what leaves it when you use the managed live copilot.
1. Our local-first principle
The desktop application stores your interview materials — your CV, extracted evidence, STAR stories, job descriptions, flashcards, transcripts, and reports — in a local database on your own machine. Any API keys you provide are encrypted at rest. By default, this content does not leave your device.
The desktop windows are also excluded from screen capture and kept off the taskbar and Alt-Tab, so your information is not exposed when you share your screen.
2. Data we process in the cloud (managed tier)
To deliver the real-time copilot without requiring your own AI key, we operate a managed proxy. When you use a cloud-backed feature, the following data flow applies:
- What is sent. Only the minimum needed to answer a request — for example, the transcribed question and the specific snippets of your materials retrieved to ground the answer. We do not upload your entire local database.
- Where it goes. Our proxy calls third-party AI providers (such as OpenAI) under our organization key to perform transcription and answer generation. Their processing is governed by their terms and privacy policies.
- What we keep. We record usage metadata needed to operate the credit system (for example, which feature was used, token or minute counts, and timestamps) in an audit-grade ledger. We aim to minimize retention of request/response content and do not use your content to train third-party models where avoidable.
3. Account & billing data
For the web app we process your account information (such as email and authentication identifiers) via our authentication provider (Supabase), and your subscription and payment information via our payment processor (Stripe). We do not store full card numbers; Stripe handles payment details. We retain billing records as required for accounting and legal compliance.
4. How we use data
- To provide, secure, and improve the Service for you.
- To operate subscriptions, enforce plan limits, and meter credits.
- To communicate about your account, billing, and support.
- To comply with legal obligations and prevent abuse.
We do not sell your personal information.
5. Sharing
We share data only with service providers that help us run the Service (such as hosting, authentication, payments, and AI providers), under appropriate contractual safeguards, and where required by law. A list of subprocessors is available on request.
6. Security
We use industry-standard measures including encryption in transit, server-side enforcement of access (row-level security on our database), and least-privilege access to keys. Server secrets such as AI provider keys are never exposed to the browser or the desktop client. No system is perfectly secure, and you are responsible for safeguarding your own device and credentials.
7. Your choices & rights
- Local data. You can delete your local materials at any time from the desktop app.
- Account data. You may access, correct, or delete your account information, subject to records we must retain by law.
- Depending on your location, you may have additional rights under laws such as the GDPR or CCPA. Contact us to exercise them.
8. Data retention
Local content persists on your device until you remove it. Cloud-side usage and billing records are retained for as long as your account is active and thereafter as needed for legal, accounting, and audit purposes.
9. Children
The Service is not directed to children under 18, and we do not knowingly collect their personal information.
10. Changes & contact
We may update this policy; material changes will be communicated through the Service or by email. For privacy questions or requests, contact [email protected]. See also our Terms of Service and Acceptable Use Policy.