Privacy statement
This statement explains how InterviewFit handles information in the current public CV-analysis service.
Last updated: 26 July 2026
At a glance
- InterviewFit processes your CV and job description to create one report.
- For an ordinary analysis, InterviewFit does not retain your uploaded file, extracted CV text, job description or generated report after the request finishes.
- InterviewFit saves a CV only when a signed-in user explicitly chooses to save it.
- InterviewFit sends extracted or pasted text—not the original uploaded file—to the OpenAI API.
- The report remains in your browser session unless you copy or download it.
Information InterviewFit processes
The analysis uses the CV file or text you provide, the job description and any optional role context you select. These documents may contain personal or commercially sensitive information.
InterviewFit also processes limited operational metadata such as a request ID, duration, status, file type, file-size band, model name, token-usage band and safe error code. Operational logs must not contain CV text, job-description text, prompts or reports.
Why InterviewFit processes it
InterviewFit uses the supplied documents to produce the requested interview preparation report. It uses short-lived technical identifiers and counters to limit abuse, control free capacity and keep the service reliable.
Retention
InterviewFit processes uploaded documents and extracted text in memory during the request. It does not create a CV archive, report history or application database for the public workflow.
When a signed-in user chooses Save this CV to my account, InterviewFit stores the extracted or pasted text and CV metadata in Supabase Postgres. It also stores the original PDF or DOCX in private Supabase Storage. Pasted CVs have no original file.
InterviewFit keeps a saved CV until the user deletes it or deletes their account. Each account can hold no more than 10 saved CVs. InterviewFit never saves the job description, prompt, generated report or analysis with the CV.
A signed anonymous allowance cookie and associated hashed counters expire after the applicable 24-hour window. Global capacity entries also expire after 24 hours.
Service providers
OpenAI processes extracted CV text, pasted CV text and the job description to create the report. OpenAI does not train its models on API data by default unless the API customer opts in. Its default abuse-monitoring controls may retain API content for up to 30 days.
Vercel hosts InterviewFit and provides anonymous aggregate page-view analytics. InterviewFit does not send CV, job-description or report content to Vercel Analytics. Upstash stores privacy-reduced rate-limit and capacity counters; it does not receive document or report content.
Clerk processes account and session information when you choose to sign in. InterviewFit uses a keyed hash of your Clerk user ID for a 24-hour analysis allowance counter. Signing in alone does not save your CV, job description or report.
Supabase stores explicitly saved CV records and original files. Clerk session tokens and Supabase row-level security restrict normal access to the account owner.
Your choices
- Remove information you do not want analysed before submitting it.
- Paste CV text instead of uploading the original document.
- Stop an analysis while it is running; your inputs remain in the browser.
- Close or refresh the page to clear the in-browser report.
- Rename, download or delete a saved CV from My CVs, or delete every saved CV.
- Do not upload a document unless you have permission to use it.
Changes to this statement
InterviewFit will update this page when its data handling changes, including before it adds saved reports, billing or other persistent features.