Privacy Policy
Effective 14 September 2026
Calibrd is an interview preparation tool, available as a web app at calibrd.com and as a Chrome extension. This policy covers both, and explains what data we collect, why, and how it is protected. We have written it to be short and plain — not to bury anything.
What we collect
Account. When you sign in we collect your email address via Clerk (our authentication provider). We do not store passwords.
CV text. When you are signed in, the CV you paste or upload stays in your account, encrypted at rest, only to personalize your reports: every scan reads it without asking you to upload again, and the same CV is there on any browser you sign in to. It is visible as “CV on file” wherever the workspace uses it, and Remove purges it from your account and your devices at once, along with the CV score and the tailored versions built from it; your reports stay. Without an account (a guest report, the Chrome extension without sign-in), the CV is transmitted to our API over HTTPS for that one report and is not stored server-side beyond the duration of the request.
Your workspace. When you are signed in, your reports live in your account: the report itself, the jobs you track and their stages, your interview dates, your practice answers and their grades, your mock-interview transcripts and debriefs, and the notes you paste from recruiters. Each is encrypted at rest with a key held by Calibrd before it is written to the database, so the database never holds it in the clear. That is what lets the same workspace open on any browser you sign in to. It is not end-to-end encrypted: our servers read your reports to build your coaching from them. Nothing in your workspace is sold, shared with advertisers, or used to train AI models, and you can delete all of it at any time (see Data retention). Without an account, nothing is kept: a guest report stays in that browser only.
Job postings. The job description text from the page you are viewing is sent to our API to generate your report. It is not kept afterwards. What we keep from it are counts with nothing about you attached: which roles and employers get scanned, the pay range a posting states, and the skills it asks for, recorded by week and never joined to an account, an IP address or a CV.
Voice recordings. If you record a spoken answer — in the free practice tool on our interview-prep guides, in the optional Speak input mode, or while running a voice mock interview — your audio is transmitted to OpenAI's Whisper API for transcription. A practice take is capped at 90 seconds; a Speak or mock take can run to roughly three minutes. The audio is not stored after the transcript is returned, and OpenAI does not train on API traffic by default. The transcript is then sent to Anthropic's Claude API to be scored, and we do not store that either. Voice recording is opt-in: nothing is captured unless you start a recording.
Mock interviews. During a voice mock interview your transcribed answers are sent to our API for AI grading, and the interviewer's spoken questions are generated from text via OpenAI's text-to-speech. Your mock transcripts and debriefs are part of your workspace: encrypted at rest in your account when you are signed in, and on your device only when you are not.
Interview reminders. If you set an interview date for a job in your workspace while signed in, we store that date, your timezone, and the number of gaps your report flagged (a number, nothing else from the report) so we can send you one reminder email two days before. The job itself is stored as a one-way fingerprint, not its title or employer. Clearing the date deletes the record; the reminder's own link turns it off for that interview; unsubscribing turns all of them off.
Free scan & free resume review. These two work differently from the rest, so here is exactly what happens. You give us an email address, we write the report, and we send it to you as a PDF. To reach you, that report passes through our email provider, Resend. We keep your address so that each address gets one free scan and one free review.
There is a tick box on the form. Tick it and we also add you to our email list and send you occasional interview-prep guides, each with an unsubscribe link. Leave it alone and the report is the only thing you ever get from us. The box starts unticked.
Your CV, the job description and the report are all discarded once the email is sent.
Practice answers and feedback. Spoken practice on our interview-prep guides is anonymous: we do not attach a name or an account to it. We keep a count per IP address for one day, to stop one person exhausting a free service for everyone else. Feedback you leave through the thumbs or the feedback button carries no user ID at all.
Usage & billing. We record report generation events and credit usage tied to your account in order to enforce plan limits. Payments are handled by Stripe — we do not see or store your card details.
How we use it
We use your data solely to:
- Authenticate you and manage your account
- Generate your interview report and AI coaching responses
- Transcribe spoken answers, and voice the interviewer's questions, when you use Speak mode or a mock interview
- Enforce credit and plan limits
- Send transactional emails (sign-in codes, receipts, and the PDF report from a free scan or free resume review)
- Send you interview-prep guides, but only if you ticked the box asking for them
We do not sell your data, share it with advertisers, or use it to train AI models. Your reports, practice answers, scores and your CV are stored only to give them back to you and to build your reports from them, encrypted at rest and deletable at any time.
Third-party services
These are every company that touches your data on our behalf, and what each one is for:
- Clerk — authentication and session management
- Stripe — payment processing
- Vercel — hosting for the website and our API, and the page-view analytics described below
- Neon — the database holding account records, access state, anonymous usage counts, and your workspace (reports, practice, interview dates, and the CV on file), which is encrypted before it is written there.
- Resend — email delivery: sign-in notices, receipts, the PDF report from a free scan or free resume review, and the interview-prep guides if you opted in
- Upstash — rate limiting, so one person cannot exhaust a shared service
- Cloudflare — the bot check (Turnstile) on forms that anyone can submit without an account
- Sentry — error monitoring, so we find out when something breaks. Reports include your account ID when you are signed in, so we can tell whether a fault hit one person or everyone. They do not include your CV, job descriptions or report content.
- Anthropic — AI inference for report generation and interview coaching, including mock-interview grading and debriefs (Claude API). Prompts are not used to train models. Anthropic may retain API data for up to 30 days for safety purposes per their usage policy.
- OpenAI — voice-to-text transcription (Whisper API) for spoken answers, and text-to-speech for the interviewer's voice in a mock interview, only when you use those voice features. Audio is sent for transcription and not stored after the transcript is returned; OpenAI's published data-retention table lists the transcription endpoint with no abuse-monitoring retention and no application-state retention. OpenAI does not train on API traffic by default; see their enterprise privacy commitments.
Calibrd Agent (Claude, ChatGPT and Grok)
Calibrd Agent runs inside your assistant. Your CV, the job description and the report pass through your assistant's provider (Anthropic, OpenAI or xAI) under their terms. Calibrd itself keeps none of it: reports and CVs are generated and returned, not stored.
When you connect it, you sign in once and your assistant receives a token for your Calibrd account. The token lets it run the same tools you could run on the web, under the same limits and access. Disconnect the connector in your assistant's settings to stop it. We record the same usage counters as the web (reports today, access) and nothing about the conversation.
Data retention
Your workspace and account records are kept for as long as your account is active. Deleting a job in the workspace deletes its report and everything attached to it from your account at once. To delete everything, open your profile in the workspace and choose Delete my account: your reports, practice history, interview dates, the CV on file, usage records and the account itself are removed immediately, and a deletion made through our authentication provider does the same. You can also email privacy@calibrd.com and we will do it for you within 30 days.
Three things outlive a single request. The email address you gave for a free scan or free resume review, which we keep so the offer stays one per address, and to send you guides if you ticked the box. A count of anonymous voice practice per IP address, which resets after a day. And anonymous usage counts that show us which parts of the product to improve. Those counts hold no name, no account and no employer, and nothing in them can be traced back to you. You can leave the email list from any email we send, and the address above removes you entirely.
Cookies & tracking
We do not use advertising cookies or cross-site tracking, and there are no advertising or social pixels anywhere on the site. Clerk sets a session cookie required for authentication.
We do run one analytics script: Vercel Web Analytics, which counts page views so we can see which pages are worth keeping. It is served from our own domain, sets no cookie, does not build a profile of you, and cannot follow you to other sites.
Security
All data in transit is encrypted with TLS. Your workspace is encrypted at rest with a key held by Calibrd, separate from the database, before anything is written; the database and its backups hold ciphertext. The CV on file is part of that encrypted workspace; job descriptions are not written to persistent storage on our servers. We apply the principle of least privilege to all internal data access.
Your rights
Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights email privacy@calibrd.com.
Changes to this policy
If we make material changes we will update the effective date above and, where appropriate, notify you by email. Continued use of Calibrd after the update constitutes acceptance.
Contact
Questions about this policy? privacy@calibrd.com