What happens to your data while you job-hunt
The copilot hears the interview, your resume sits in the account, and applications go out in your name — «is this even safe» is a fair question. Here it is point by point: what we store, what we delete immediately, who we share with.
The provider's company details are published on the terms page — not everyone in this niche does that.
What people worry about
Three questions that come up before signing up. Answered directly, without hedging.
«They'll know it isn't me»
The copilot window never enters screen sharing, nothing appears in the participant list, and we don't connect to the meeting service at all.
«The interview recording will leak»
There is no recording: audio is processed on the fly and dropped. The only stored audio is your own mock-interview practice, deleted with the session.
«What happens with account access»
The connection runs through OAuth on your command only, the token is stored encrypted, and applications go out under your name and stay visible in your own profile.
The audio path: mic to hint
The most common question about the desktop copilot is «do you record my interviews?». We don't; here's what actually happens.
Captured on your machine
The app hears the call's audio on your device. It keeps no separate recording for us.
Encrypted transfer
The stream goes to our servers over TLS 1.3 with HSTS on. LLM traffic is isolated and request contents aren't logged.
Recognition and answer
Speech becomes text and the hint is built from it. At that moment the fragment passes through LLM providers (OpenAI, Anthropic, xAI) over a secured API.
Deleted after processing
The audio is discarded; no archive of conversations remains. The exception is mock interviews, where the recording is stored in your account so you can replay it — and removed with the account.
What we do and don't do
Short answers to what usually hides in the middle of a privacy policy.
Data isn't sold
We don't sell or rent personal data. It's shared only with cloud providers, LLM providers, and on a lawful request.
Job board access is yours to start
The connection runs through OAuth and only when you initiate it. Tokens are stored encrypted at the application level.
Invisible on the call
The copilot window is excluded from the screen-share stream: what you see, the other side doesn't.
Export and deletion
Export a copy of your data from settings, or delete the account: related data is erased within 90 days, except what the law requires us to keep.
Staff access on a need-to-know basis
Must-know only, recorded in an audit log — plus regular security reviews and dependency updates.
GDPR and Russian data law
Access, correction, deletion and withdrawal of consent are described in the policy — and available from settings, not via a support thread.
What is stored, where and for how long
The short version of the privacy policy: per data type, where it lives and when it disappears.
| — | Where it lives | When it goes |
|---|---|---|
| Interview audio | Nowhere: processed as a stream, no archive of conversations. | As soon as the hint has been produced. |
| Mock interview audio | In your account, so the session can be replayed. | When the session or the account is deleted. |
| Resumes and letters | In your account, available to the tools you run. | Within 90 days of account deletion. |
| Integration access tokens | In the database, encrypted at the application level. | When the integration is disconnected or the account deleted. |
| Visit analytics | Our own analytics and Yandex.Metrica, de-identified. | Switched off via the consent banner; retention is in the policy. |
Interview audio
Where it lives:Nowhere: processed as a stream, no archive of conversations.
When it goes:As soon as the hint has been produced.
Mock interview audio
Where it lives:In your account, so the session can be replayed.
When it goes:When the session or the account is deleted.
Resumes and letters
Where it lives:In your account, available to the tools you run.
When it goes:Within 90 days of account deletion.
Integration access tokens
Where it lives:In the database, encrypted at the application level.
When it goes:When the integration is disconnected or the account deleted.
Visit analytics
Where it lives:Our own analytics and Yandex.Metrica, de-identified.
When it goes:Switched off via the consent banner; retention is in the policy.
Security FAQ
Nothing here? Ping @Jobpath_help.
