InterviewBuddy

Privacy Policy

InterviewBuddy listens to interviews, so it is fair to want the details. This page says exactly what the extension can reach, what leaves your machine, who processes it and when it is deleted.

Last updated 10 September 2026

1. Who we are

InterviewBuddy is a Chrome extension and web service built by BuildStory. In this policy “we” and “us” mean the operator of InterviewBuddy, and “you” means the person using it. We are the data controller for the information described below.

Questions about anything here go to admin@buildstory.studio.

2. The short version

  • Audio is never stored. Your microphone and meeting-tab audio are streamed for transcription and discarded. We keep the text, not the sound.
  • We never record video, and we never capture your screen unless you press the screen-answer shortcut yourself.
  • Sessions delete themselves after 90 days. That is enforced by the database, not by a person remembering to do it.
  • We do not sell your data, we do not run advertising, and this website carries no analytics or tracking scripts of any kind.
  • We never see your card. Payments go directly to Stripe.

3. What the extension can access

Chrome makes every extension declare its permissions up front. Here is each one InterviewBuddy requests and the honest reason for it.

PermissionWhy it is needed
tabCaptureCaptures the audio of the meeting tab so the extension can hear the interviewer's questions. Audio only — never video.
activeTabLets the extension act on the tab you are currently in when you trigger it, rather than on everything you have open.
offscreenRuns the audio processing in a hidden document, because Chrome service workers cannot handle audio directly.
sidePanelDraws the InterviewBuddy panel beside your meeting.
scriptingPlaces the floating answer card on the page and moves it where you put it.
storageSaves your preferences — answer length, job role, card colour, size, position — in your browser.
identityPowers Sign in with Google. We request only your name, email address and profile picture.
api.interviewbuddy.expertThe only server the extension is allowed to talk to. It cannot reach any other site.

What the extension cannot do

It has no permission to read the pages you browse, your history, your bookmarks or your saved passwords. It cannot talk to any server other than ours.

4. What we collect and why

Account details. Your name and email address. If you sign up with a password we store only a bcrypt hash of it, never the password itself. If you use Sign in with Google we store your Google account identifier instead, and no password exists.

Audio, while a session is running.When you start listening, audio from the meeting tab and from your microphone is streamed to our server over an encrypted connection and passed straight to OpenAI’s transcription service. The audio is held in memory for the moment it takes to transcribe and is then gone. We do not write it to disk and we cannot play it back.

Transcripts and answers. The text that comes back is what we keep: the question that was detected, the answer that was generated, and the end-of-session recap. This is what makes your history, notes and exports work.

Screenshots, only when you ask. The screen-answer shortcut takes a single still image of your current tab and sends it to be read. Nothing is captured before you press it, and nothing continues after.

Your CV and target role, if you add them. Uploading a CV extracts the text — skills, projects, roles, education — so answers can be grounded in your own experience. The same applies to a job description you paste in. This is optional and you can clear it at any time.

Video captions and page text, only when you ask for notes. When you ask for notes on a YouTube video you are watching, the extension reads that video’s own captions in your browser and sends the text, along with the title, channel and chapters, to our server so the notes can be written. When you ask for notes on a page you are reading, it reads the article on that page — or only the part you selected — and sends that instead, with the title and the site it came from. We do not download videos, we never read a page or a video you have not asked about, and the text is used for that one request and not stored. The notes themselves are kept on your device; you can delete them from the panel.

Reminders, if you set them. The title you give a reminder, the time you set, your time zone and the note you attach, so we can email you before it. Deleted when the reminder is cancelled or when you delete your account.

Practice rounds. Your spoken answers are transcribed and scored, and we keep the transcript, the scores and the feedback so you can compare rounds.

Support tickets. The subject and message you send us, plus our reply.

Billing. Stripe handles the payment and gives us back a customer reference, your plan, and whether the subscription is active. Your card number never touches our servers.

Preferences. Answer style, job role, experience level, language, theme and the appearance of the floating card. Some of this stays in your browser and some is saved to your account so it follows you.

5. How long we keep it

DataKept for
Interview sessions — transcripts, answers, recaps90 days, then deleted automatically by the database
Practice rounds and scores90 days, then deleted automatically
Account, preferences, CV and target roleUntil you delete your account or clear them
Reminders you setUntil the reminder is sent or cancelled, or you delete your account
Captions or page text sent for notesNot kept — used for that one request and discarded
Support ticketsUntil you ask us to remove them
Billing recordsAs long as tax and accounting law requires
AudioNot kept — discarded as soon as it is transcribed

6. Who else processes your data

We use a small number of providers to run the service. They may only act on our instructions.

ProviderWhat it handles
OpenAITranscribes speech, detects questions, generates answers, reads screenshots and scores practice rounds
StripeSubscriptions and payments, including all card details
ResendSends transactional email — password resets, session notes, replies to your support tickets
MongoDB AtlasStores the database
RailwayHosts the application servers

We do not sell personal information, and we do not share it for advertising or cross-context behavioural advertising.

8. Your rights

Depending on where you live you may have the right to access your data, correct it, export it, delete it, restrict or object to how we use it, and to complain to your local data protection authority. Two of these you can exercise yourself without asking us:

  • Export. Any session can be downloaded as a PDF, or emailed to you, from the panel. Video notes can be saved as a PDF too.
  • Delete. Individual sessions can be deleted from your history at any time.
  • Delete everything.Settings → Delete Account closes your account and removes your CV and profile, every session and its answers, practice rounds, reminders and support tickets, along with the conversations and notes held on your device. Any Pro subscription is cancelled at the same time. It happens immediately and cannot be undone.

For anything else — a full copy of your data, for instance — email admin@buildstory.studio from your account address and we will action it within 30 days.

9. How we protect it

  • Everything travels over TLS. Audio streams over an encrypted WebSocket.
  • Passwords are stored as bcrypt hashes and are not recoverable, by us or anyone else.
  • Sessions are authenticated with signed tokens, and the extension may only reach our API.
  • Access to production data is limited to the people who need it to run the service.

No system is perfectly secure. If we ever discover a breach affecting your data we will tell you and the relevant authority as the law requires.

10. Age

InterviewBuddy is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us information, write to us and we will delete it.

11. Where your data goes

Our providers operate internationally, so your information may be processed in countries other than your own, including the United States. Where the law requires a safeguard for that transfer, we rely on the standard contractual clauses offered by those providers.

12. Changes to this policy

If we change what we collect or who processes it, we will update this page and move the date at the top. Material changes will be announced in the extension before they take effect.

13. Contact

Email admin@buildstory.studio for any privacy question, data request or complaint.