Privacy Policy
Last updated: February 2026
1. Introduction
ReadyCue (“we”, “us”) operates readycue.ai. This policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
- Account data: email address, display name.
- Career data: work experiences (role, company, timeframe, STAR stories), skills, interview themes.
- Session data: practice session responses and scores, live interview transcripts, AI-generated coaching feedback.
- Interview prep data: role titles, company names, job descriptions, predicted questions.
- Uploaded files: CVs, resumes, performance reviews — stored securely, never shared.
- Usage data: page views, feature usage (via PostHog, if consented).
- Error data: crash reports, session replays on errors (via Sentry, if consented).
3. How We Use Your Data
- AI processing: sent to OpenAI and Anthropic for STAR extraction, scoring, and coaching. Data is processed but not retained by providers for training per their enterprise terms.
- Real-time transcription: audio sent to Deepgram for speech-to-text during live sessions.
- Email: via Resend for waitlist confirmation and support communications.
- Analytics: PostHog for product improvement (only with consent).
- Error monitoring: Sentry for bug detection (only with consent).
4. Sub-Processors and Data Transfers
| Provider | Location | Purpose |
|---|---|---|
| Supabase | US | Database, auth, file storage |
| OpenAI | US | AI processing (extraction, scoring, matching) |
| Anthropic | US | AI processing (refinement, answer generation) |
| Deepgram | US | Real-time speech-to-text |
| Resend | US | Transactional email |
| Sentry | US | Error monitoring |
| PostHog | EU | Product analytics |
| Railway | US | Application hosting |
5. Data Retention
- Active accounts: data retained while your account is active.
- Deleted accounts: all data permanently deleted within 30 days of account deletion.
- Waitlist: email retained until signup or manual removal request.
6. Your Rights (GDPR)
- Right of access: download all your data from Account settings.
- Right to erasure: delete your account and all data from Account settings.
- Right to rectification: edit your data directly in the app.
- Right to data portability: export your data as JSON.
- Right to withdraw consent: manage cookie preferences at any time.
- Right to object: contact us to object to processing.
To exercise any of these rights, contact [email protected].
7. Cookies and Local Storage
- Essential: Supabase auth session cookie.
- Preferences: theme (light/dark), audio device selection.
- Analytics: PostHog (with consent).
- Error monitoring: Sentry session replay (with consent).
- Consent: your cookie preference choices.
8. Security
We protect your data with encryption in transit (HTTPS), encryption at rest (Supabase), rate limiting on API endpoints, row-level security policies on all database tables, and server-side file validation for uploads.
9. Children
ReadyCue is not intended for users under the age of 16. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via email to all registered users.
11. Contact
If you have any questions about this Privacy Policy, contact us at [email protected].