Overview
PrepCard ("we", "our", or "the app") is an AI-powered interview preparation tool. This policy describes what data we collect, why we collect it, and how we protect it. We take your privacy seriously and will never sell your personal data.
Data We Collect
- Account information — email address and display name, collected at sign-up.
- Calendar data — when you connect a calendar, we read upcoming events to detect interviews. We do not store your full calendar; only detected interview events are saved.
- Resume content — files you upload are stored securely and used only to personalize your prep briefs and generate cover letters.
- Interview notes — notes you take during calls are stored in your account and never shared.
- Usage data — basic analytics to understand how the product is used (page views, feature usage). No behavioral profiling.
How We Use Your Data
- To generate AI prep briefs, cover letters, and follow-up emails on your behalf.
- To send you notifications about upcoming interviews (push or email, per your settings).
- To sync your calendar and detect scheduled interviews automatically.
- To improve the product based on aggregate usage patterns.
We do not use your data to train AI models, sell to third parties, or serve advertising.
Third-Party Services
- Supabase — database and authentication (EU/US data centers).
- Anthropic— AI model provider. Your interview context is sent to Anthropic APIs to generate briefs. Anthropic's privacy policy applies.
- Nango — OAuth connection management for Google Calendar and Microsoft Outlook. OAuth tokens are stored securely by Nango.
- Resend — transactional email delivery.
- Vercel — hosting and edge functions.
Data Retention
Your data is retained as long as your account is active. You can delete your account and all associated data at any time from Settings. Upon deletion, your data is permanently removed within 30 days.
Your Rights
You have the right to access, export, correct, or delete your data at any time. To exercise these rights, email us at hi@prepcard.app.
Security
All data is encrypted in transit (TLS) and at rest. Authentication is handled by Supabase Auth with row-level security enforced on all database tables. We do not store plain-text passwords.