Where your data goes
Last updated: September 30, 2026
Crush Job is an AI product, so some of what you give it has to be sent to an AI provider to be worked on. This page lists each kind of data the desktop app and this website handle, where it goes, how long it is kept, and whether anyone trains an AI model on it.
Every row was checked against our own code and against each provider's published terms, read on September 30, 2026. The Privacy Policy is the full legal version.
| Data | Where it goes | How long it is kept | Trains a model? |
|---|---|---|---|
| Your resume, job postings, LinkedIn profile text and the answers you type | Sent from the app to our server, which forwards it to Anthropic (the company behind Claude) to tailor, score and write. Our server keeps no copy of the text. | Our server: not kept. Anthropic: deleted within 30 days, unless it has to keep it longer to enforce its usage policy or by law (Anthropic). | No. Anthropic does not train its models on API data by default (Anthropic). |
| Interview transcript text — the words transcribed in Interview Copilot (yours and the other participant's) and in Mock It! | Sent the same way, through our server to Anthropic: for Copilot's live suggestions and debrief, and for Mock It!'s follow-up questions and scoring. The full transcript is also saved on your computer. | Same as the row above. | No, as above. |
| Live audio — your microphone in Mock It! and Interview Copilot; in Copilot, also your computer's audio output, which carries the other participant's voice | Streamed from your computer straight to AssemblyAI for transcription. Our server gives the app a pass that expires after 60 seconds; the audio itself does not pass through our server. | Set by AssemblyAI. Its streaming service keeps no audio or transcripts for accounts opted out of model training; otherwise see AssemblyAI's policy. | Depends on an account setting. AssemblyAI's terms allow it to train on some customer audio unless the account has opted out. See AssemblyAI's policy. |
| The interviewer's questions in Mock It! — the text the AI interviewer is about to say | Sent from your computer straight to Deepgram, which turns it into speech with its Aura voice, using the same 60-second pass. Every mock interview uses this voice. | By Deepgram's default, kept to improve its models (Deepgram). | Yes, by Deepgram's default. Its model improvement program applies unless a request opts out, and the app's requests do not opt out. |
| Usage records — token counts, model names, the name of each AI operation, app version, audio minutes and credits charged. Never your prompts, resumes or transcripts | Our database, so we can bill your plan and show you your usage. A copy is also written to the app's folder on your computer. | Until you delete your account. We also keep a one-way fingerprint of some AI replies for 30 minutes, to check retry requests; it cannot be turned back into the text. | No. |
| Crash reports from the desktop app — the error type, where in our code it happened, app version and operating system. Home folder paths, email addresses and long numbers are removed on your computer before sending | Our server, and only from a device linked to an account. When a new kind of crash arrives, its details and the email address of the account that reported it are also emailed to our support inbox (through Zoho ZeptoMail) and filed on the task board we use to track fixes. | No fixed end date. Deleting your account removes the link in our database between a report and you; the scrubbed report is kept, and so are support emails and task-board entries already sent. | No. |
| Cloud Data Sync (off by default) — copies of the profiles, applications, battle cards, mock-interview sessions and Copilot session records you create. Not transcripts, debrief text or recordings | Our database, only while you have it switched on. | Until you delete the cloud copy (from the Hub's Account tab or your account page) or delete your account. | No. |
| Files the app saves — tailored resumes, cover letters, battle cards, transcripts, Copilot session audio (on by default, and you can turn it off), Mock It! recordings (only if you turn them on), settings and usage history | Your computer: documents in the folder you choose, and app data in %LOCALAPPDATA%\CrushJob on Windows, ~/Library/Application Support/CrushJob on macOS and ~/.local/share/CrushJob on Linux. The rows above say which parts are sent anywhere. | Until you delete them. Uninstalling the app does not remove them. | No. |
| Job posting links you paste | The app fetches the page itself, straight from your computer, so the job site sees that request the way it would see your browser. The posting text then goes to Anthropic as in the first row. | Set by the job site. | Ours: no. |
| LinkedIn posts you choose to share | Sign-in to LinkedIn goes through our server; the post itself is sent from your computer straight to LinkedIn. | Set by LinkedIn. | Ours: no. |
| Linked devices — a device name (your computer's name unless you change it), a one-way fingerprint of the machine, app version and when it was last seen | Our database, when you link the app to your account. | Until you delete your account. | No. |
| Your account — your email address, and the name your sign-in provider shares if you use Google, Microsoft, LinkedIn, GitHub or Apple | Our database. | Until you delete your account. After that we keep a note of the deleted account (its email address, name and join date) and our record of the emails we sent to your address. | No. |
| Installer downloads — which installer, your account (downloading needs one), your IP address and browser user-agent | Our database. | No fixed end date. Deleting your account removes the account link; the rest is kept. | No. |
| Contact form — your name, email address, message and IP address | Our database. Cloudflare Turnstile checks the form for bots first, and we email you an acknowledgement through Zoho ZeptoMail. | No fixed end date. | No. |
| Payments — your card details, and what Stripe tells us about each payment | Card details are entered on Stripe's own checkout page and never reach us. We keep a Stripe customer reference, your plan status, each payment's amount, the card brand and last four digits, receipt links, and a card fingerprint (a code, not the card number). | Stripe keeps payment records under its own policy. Our copy is deleted with your account. | Ours: no. Stripe: see Stripe's policy. |
| Website analytics — pages you visit and events such as signing up, only if you accept the cookie banner | PostHog. | See PostHog's policy. | PostHog's policy lets it use customer data to develop its own products and models unless the customer opts out in its settings. See PostHog's policy. |
| Website errors — the error, the page, your browser and operating system, and your account id if you are signed in. Not your name or email address | Sentry. | 30 to 90 days, depending on the Sentry plan (Sentry). | See Sentry's policy. |
| Email — your email address and the messages we send you | Zoho ZeptoMail delivers account email; Amazon SES delivers product updates and marketing (the site can switch that mail to Resend). Opens and clicks are recorded on our own server, without your IP address. | Our send records keep your address and the kind of message, including after you delete your account. The senders: see Zoho, Resend and AWS. | Ours: no. The senders: see their policies. |
A few plain notes
"Our server" means crushjob.ai, which runs on Vercel. "Our database" means its database, which runs on Supabase.
Where a row says "see the policy", we could not confirm the answer from the provider's published terms alone, so we point you to them rather than guess.
If something here stops being true, we change this page. Questions go to the address on the contact page.
Sources
Each provider page below was read on September 30, 2026.
- Anthropic: how long API data is kept — last updated July 1, 2026
- Anthropic: is my data used for model training — last updated August 18, 2026
- AssemblyAI: data retention and model training — no date shown on the page
- Deepgram: your data at Deepgram — no date shown on the page
- Stripe privacy policy — last updated April 28, 2026
- PostHog privacy policy — no date shown on the page
- Sentry data retention periods — no date shown on the page
- Zoho privacy policy (ZeptoMail) — last updated December 22, 2025
- Resend privacy policy — last updated August 27, 2026
- AWS privacy notice (Amazon SES) — last updated May 18, 2026
