Privacy
Last updated 11 September 2026
You are about to hand us your CV, which is one of the more personal documents you own. So this page is written to be read rather than to cover us: what we collect, why, who else sees it, how long it stays, and what you can do about any of it.
The short version. Your CV, the job descriptions you paste and your answers are used to produce your own results and nothing else. They are never used to train an AI model, and we do not sell or share your data for advertising. You can see what we hold and delete it yourself at any time. Analytics does not run unless you accept it.
Labor.quest is an interview preparation service at labor.quest. This policy covers that site and the signed-in app behind it, and it explains what we hold about you, why, who else sees it, how long it stays, and what you can do about any of it.
Everything here is written to the standard the GDPR sets, and we apply it to every user wherever you live, rather than only to visitors from Europe. That is a choice about how we want to run, not a statement about where we are based.
For anything to do with your data, including any of the requests in section 8, write to hello@labor.quest. That address reaches a person, not a queue.
Two systems hold your data. Sign-in and identity are handled by our authentication service; everything you make with the tools is held by the app. Both run in the same infrastructure and this policy covers both.
This is the part that matters most, because it is the part you author. The same list appears in the app under Settings, Privacy, and it is not shorter there than it is here.
A CV is a dense document, and we take it as given
A CV can carry your address, your nationality, dates that imply your age, and sometimes health, religion or trade union membership. We do not ask for any of that and we do not look for it, but we store the file as you uploaded it and we send its text to an AI model to analyse, so we do process whatever is in it. If there is something in your CV you would rather we never held, take it out before you upload. Please also only upload a CV that is your own.
The interviewer name field holds someone else's data
It is the one field where you can enter personal data about a person who is not you. We keep it because knowing who you are meeting is genuinely useful for preparing, but please put in no more than you need, a first name is usually plenty, and nothing you would not be comfortable having stored. You can clear it at any time by editing or deleting the application.
No card number ever reaches us
Card details, expiry dates and security codes are typed on Stripe's own hosted checkout page and go straight to Stripe. They do not pass through our servers and we could not show them to you if you asked.
What we do keep is the result of a payment:
Under the GDPR every use of your data needs a named basis. Ours are these, and there are only four of them:
Three things we never do
We do not sell your data, we do not share it with data brokers, and we do not use it for advertising. Your CV, your job descriptions and your answers are used to produce your own results. They are not used to train any AI model. Section 6 has the detail behind that last one, because it is the question a CV upload most deserves an answer to.
We use other companies to run the service. None of them is allowed to use your data for their own purposes, and this is the complete list rather than a sample of it.
Read this one if you use practice rounds
Speaking your answers uses the speech recognition built into your browser, not anything of ours. We never receive, store or upload audio or video. What reaches us is the text your browser transcribed. But the transcribing itself is your browser's job, and some browsers do it in the cloud rather than on your device: notably Google Chrome sends the captured audio to Google's speech service to turn it into text. That happens inside Chrome, outside our code and outside any contract we have. If that matters to you, a browser that transcribes locally, or typing your answers instead, avoids it entirely.
Every tool here works by sending what you gave us to an AI model and showing you what comes back. That is worth being plain about, because it is the whole product and it is also the thing people most want a straight answer on.
Most of these you can exercise yourself, right now, without asking us. Where a screen already does the job we have named it, because a right you have to write a letter for is a worse right than a button.
We answer requests within one month. If one is genuinely complicated we will tell you so inside that month rather than after it.
Deleting your data removes everything you made. It does not erase every trace of you, and we would rather say why than let you find out later.
If any of that is not acceptable for your situation, write to hello@labor.quest and say so. Removing your account entirely is a separate and more complete step, described in section 8.
Everything we run is in the United States, in AWS's Northern Virginia region. Stripe processes payments in the United States and Ireland, and Google's services run on Google's own global infrastructure.
If you are in Europe or the United Kingdom, that means your data leaves your country. AWS, Stripe and Google all publish the Standard Contractual Clauses that the GDPR requires for this, and those are the terms we are on with each of them. If you would like to know more about the arrangement covering a particular one, ask us.
Rather than claim industry standard security, here is specifically what is true:
If something does go wrong and your data is affected, we will tell you and the relevant authority. If you think you have found a security problem, please write to hello@labor.quest before telling anyone else, and we will treat it seriously.
When we add a tool or a supplier, this page changes. The date at the top of it is the date of the version you are reading, and the current version always lives at labor.quest/privacy.
If a change is significant, meaning it alters what we collect, why, or who else sees it, we will tell you in the app rather than only editing this page and hoping you look. A change never applies retroactively to data we have already collected under an earlier version.
Questions about this document, or a request you want to make? Write to hello@labor.quest and a person will read it.