Labruest

Privacy

Privacy Policy.

Last updated 11 September 2026

You are about to hand us your CV, which is one of the more personal documents you own. So this page is written to be read rather than to cover us: what we collect, why, who else sees it, how long it stays, and what you can do about any of it.

The short version. Your CV, the job descriptions you paste and your answers are used to produce your own results and nothing else. They are never used to train an AI model, and we do not sell or share your data for advertising. You can see what we hold and delete it yourself at any time. Analytics does not run unless you accept it.

1Who this is and how to reach us

Labor.quest is an interview preparation service at labor.quest. This policy covers that site and the signed-in app behind it, and it explains what we hold about you, why, who else sees it, how long it stays, and what you can do about any of it.

Everything here is written to the standard the GDPR sets, and we apply it to every user wherever you live, rather than only to visitors from Europe. That is a choice about how we want to run, not a statement about where we are based.

For anything to do with your data, including any of the requests in section 8, write to hello@labor.quest. That address reaches a person, not a queue.

2What we collect

Two systems hold your data. Sign-in and identity are handled by our authentication service; everything you make with the tools is held by the app. Both run in the same infrastructure and this policy covers both.

Your account

  • Your email address, typed at signup or taken from the Google account you signed in with. It is how your account is identified.
  • Your display name, typed at signup or taken from your Google profile.
  • Your password, if you signed up with one. It is held only by the authentication service, never by the app, and never in a readable form.
  • Which sign-in method you use, and if you signed in with Google, the profile picture and name Google gives us.
  • Whether your email is verified, and when. Signing in is blocked entirely until it is.
  • Verification and password reset tokens, generated and emailed to you. Reset tokens stop working one hour after they are sent.
  • Sign-in records, so a session can be issued and ended.

What you give the tools

This is the part that matters most, because it is the part you author. The same list appears in the app under Settings, Privacy, and it is not shorter there than it is here.

  • Your CV or resume, exactly as you uploaded it.
  • Job descriptions you paste or save.
  • The results the tools produce: CV analyses, fit matches and their scores, tailored CVs and their change logs, preparation plans, and question banks.
  • Applications you track: the role, the stage, your own notes, the interview date, and the interviewer's name if you enter one.
  • Practice rounds: the questions you were asked and a transcript of your answers as text.
  • Your avatar image, if you set one.

A CV is a dense document, and we take it as given

A CV can carry your address, your nationality, dates that imply your age, and sometimes health, religion or trade union membership. We do not ask for any of that and we do not look for it, but we store the file as you uploaded it and we send its text to an AI model to analyse, so we do process whatever is in it. If there is something in your CV you would rather we never held, take it out before you upload. Please also only upload a CV that is your own.

The interviewer name field holds someone else's data

It is the one field where you can enter personal data about a person who is not you. We keep it because knowing who you are meeting is genuinely useful for preparing, but please put in no more than you need, a first name is usually plenty, and nothing you would not be comfortable having stored. You can clear it at any time by editing or deleting the application.

What the app works out about you

  • A career profile: your location, recent roles and employers, seniority and work preferences, extracted from your CV by an AI model so job search can be pre-filled. Every field of it is visible and editable on Your profile, and correcting it there is the fastest way to exercise the right in section 8.
  • A running summary of you, written by an AI model and used to make later output fit you better rather than starting from nothing each time. This is profiling in the sense the GDPR uses the word. It makes no automated decision about you, it produces no score that anyone but you sees, and you can object to it under section 8.
  • Skill demand figures, calculated when you look at them from the job descriptions you have already saved. Nothing extra is stored.

Payments

No card number ever reaches us

Card details, expiry dates and security codes are typed on Stripe's own hosted checkout page and go straight to Stripe. They do not pass through our servers and we could not show them to you if you asked.

What we do keep is the result of a payment:

  • Your credit balance, and lifetime totals of credits granted and spent.
  • A ledger with one line per change to that balance, including what the credits were spent on.
  • For each payment: the amount, the currency, whether it succeeded, Stripe's reference for it, and when it happened.
  • For a subscription: its status, when the current period ends, whether it is set to cancel, and how many cycles have been billed.

Technical data

  • A session cookie while you are signed in. It is what keeps you signed in and the app cannot work without it.
  • Your light or dark preference, and your answer to the analytics question in section 4, both stored in your browser rather than sent to us.
  • Server and security logs. Our servers and the network in front of them record IP addresses, page paths, user agents and timestamps. Separately, the app records an event including your user id whenever you save something, which is what lets us investigate a problem or an abuse report.
  • Google Analytics, but only if you accepted it. Section 4 is entirely about this.

3Why we use it, and on what basis

Under the GDPR every use of your data needs a named basis. Ours are these, and there are only four of them:

  • To give you what you signed up for: reading your CV and the job descriptions you paste, producing analyses, plans, question banks and practice rounds, keeping them for you, and running your account and its email. Basis: performing our contract with you.
  • To take payment and grant credits, and to keep an accurate, auditable record of both. Basis: performing our contract, and for the payment records themselves, our legal obligations around accounting.
  • To keep the service secure and working: logs, abuse prevention, and debugging when something breaks. Basis: our legitimate interests, which we have weighed against the fact that these logs are not read routinely and are not used to build any picture of you.
  • To improve what the tools produce for you across sessions, using the running summary described in section 2. Basis: performing our contract, since it is part of what the product is. You can still object to it.
  • To understand which pages people read, using Google Analytics. Basis: your consent, and nothing loads until you give it.

Three things we never do

We do not sell your data, we do not share it with data brokers, and we do not use it for advertising. Your CV, your job descriptions and your answers are used to produce your own results. They are not used to train any AI model. Section 6 has the detail behind that last one, because it is the question a CV upload most deserves an answer to.

4Cookies, browser storage and analytics

This section is our cookie policy. There are four things stored in your browser and they fall into two groups.

Strictly necessary, always present

  • The session cookie. Set when you sign in, holds your access token, and is what stops you having to sign in again on every page. It expires when your session does. Without it there is no signed-in app, so there is nothing to consent to.
  • Your theme preference, stored in your browser's local storage, so the app can be dark before it paints instead of flashing white first. It never leaves your browser.
  • Your answer to the question below, also in local storage, so we do not ask again. Storing a refusal is how a refusal is kept.

Analytics, only with your consent

We use Google Analytics 4 to see which pages people read and which they leave. It sets its own cookies, and Google receives your IP address, the page you are on, where you came from, your device type and an approximate location worked out from your IP.

None of that happens unless you accept. The Google tag is not in the page. It is loaded by us, after you say yes, and if you say no or have not answered then nothing is requested from Google and no analytics cookie is set. Declining costs you nothing: every page behaves identically either way.

We never send your user id, your email address or anything you typed to Google. On the sign-in pages the address we report to Analytics has its query string removed on purpose, so that the tokens in a password reset or verification link cannot reach Google in a page address.

You can change your mind here, at any time, in either direction:

Your current choice

You have not been asked yet, so nothing is being sent to Google. Accepting takes effect straight away.

You can also clear or block these cookies in your browser's own settings, and Google publishes a browser add-on that opts you out of Analytics on every site at once.

One thing loads from Google either way

Our fonts are served by Google Fonts, which means Google receives your IP address and browser when a page loads, whatever you choose above. That is not analytics and it does not identify you to us, but it is a request to Google, so it belongs in this section rather than being left out of it.

5Who else sees your data

We use other companies to run the service. None of them is allowed to use your data for their own purposes, and this is the complete list rather than a sample of it.

Running the product

  • Amazon Web Services hosts everything: the servers, the databases, the file storage holding your CVs, the email that reaches you, and the network in front of it all. All of it is in AWS's Northern Virginia region in the United States.
  • Anthropic's Claude, running inside AWS, is the AI model behind every tool. Your CV text, the job descriptions you paste, your career profile and your practice answers are sent to it to produce your results. It runs in the same AWS region and your content is not used to train it. Section 6 is about this in more detail.
  • Amazon Polly, also inside AWS, turns the interviewer's questions into the voice you hear in a practice round. It receives the question script, which we wrote, not your answers.

Payments and sign-in

  • Stripe takes payments. It receives the name and email you enter on its checkout page, your card details directly from you, and a reference identifying your account so we know which balance to credit. Stripe operates in the United States and Ireland.
  • Google, if you choose to sign in with a Google account. Google learns that you signed in here, and gives us your email address, name and profile picture.

Job search

  • Adzuna and JSearch supply the job postings you search. They receive the keywords, location and country you searched for. Both are called by our servers rather than by your browser, so neither of them sees your IP address.

Analytics and fonts

  • Google Analytics, only if you accepted it, and only what section 4 describes.
  • Google Fonts, which receives your IP address and browser on every page load.

Your own browser, in practice rounds

Read this one if you use practice rounds

Speaking your answers uses the speech recognition built into your browser, not anything of ours. We never receive, store or upload audio or video. What reaches us is the text your browser transcribed. But the transcribing itself is your browser's job, and some browsers do it in the cloud rather than on your device: notably Google Chrome sends the captured audio to Google's speech service to turn it into text. That happens inside Chrome, outside our code and outside any contract we have. If that matters to you, a browser that transcribes locally, or typing your answers instead, avoids it entirely.

6AI models and your content

Every tool here works by sending what you gave us to an AI model and showing you what comes back. That is worth being plain about, because it is the whole product and it is also the thing people most want a straight answer on.

  • Your content is not used to train any model. Not ours, not Anthropic's, not anyone's. It is sent to produce your result and that is the end of it.
  • The model runs inside our own AWS account, in the same region as the rest of the service, rather than being called as a public consumer product.
  • The output is generated text and it can be wrong. Scores, gaps, plans and feedback are suggestions, not measurements of you. The Terms of Service says more about what output is and is not.
  • We count how much you use it, in order to charge credits. That count is per account, and the ledger entry records which tool spent them.

7How long we keep things

  • Practice round transcripts: your choice. In Settings you can have them kept forever, or deleted automatically after 30, 90 or 365 days. If you pick a window, the database itself deletes them when it expires. It is not a promise we have to remember to keep.
  • Everything else you made: until you delete it. Your CVs, job descriptions, analyses, plans, question banks and tracked applications stay for as long as your account does. There is no automatic expiry, and running out of credits never deletes anything.
  • Payment and credit records: kept. They survive clearing your data, deliberately. Accounting rules require us to keep records of money received, and the credit ledger is append only so that a balance can always be explained.
  • Your account itself: until you ask us to remove it. See section 8, which is honest about the fact that this one is not a button.
  • Server and security logs: as short as is useful. They are kept only as long as they are needed to investigate a security or reliability problem, and they are not used for anything else.

8Your rights, and where each one lives

Most of these you can exercise yourself, right now, without asking us. Where a screen already does the job we have named it, because a right you have to write a letter for is a worse right than a button.

  • To know what we hold. Settings, Privacy lists it in plain language. This document is the longer version.
  • To correct it. Your profile makes every field the app worked out about you editable, and your notes and applications are yours to edit. For anything else, write to us.
  • To delete it. Settings, Privacy, Deleting your data. It happens immediately, tells you what it removed, is safe to run twice, and neither costs nor grants a credit. Section 9 covers what it cannot reach.
  • To get a copy to take elsewhere. You can re-download any CV you uploaded and export a tailored one at any time. There is no single download everything button yet, so ask us at hello@labor.quest and we will put your data together and send it to you.
  • To object to the profiling described in section 2, meaning the running summary the app keeps of you. Write to us and we will stop maintaining it and delete it.
  • To restrict what we do with your data while a complaint or a correction is being sorted out. Write to us.
  • To withdraw analytics consent. The control is in section 4 of this page.
  • To stop practice transcripts being kept at all, or to have them expire. Settings, retention window.
  • To cancel a subscription. The Credits page. It runs to the end of the period you paid for and takes no further payment.
  • To have your account removed entirely. Email hello@labor.quest and ask. There is deliberately no self-service button for this: your sign-in record lives in the authentication service, which has no delete route, so a person has to do it. Clearing all of your content, by contrast, is immediate and yours to do.
  • To complain to a regulator. If you think we have handled your data badly, tell us first if you are willing, but you can go straight to the data protection authority where you live. Doing so costs you nothing here.

We answer requests within one month. If one is genuinely complicated we will tell you so inside that month rather than after it.

9What deleting your data does not reach

Deleting your data removes everything you made. It does not erase every trace of you, and we would rather say why than let you find out later.

  • Your payment and credit records stay. The ledger only ever has lines added to it, never removed, because that is what makes a balance explainable and a dispute answerable. Accounting rules require the payment records separately. This is the one place a legal obligation outranks a deletion request.
  • The security log keeps a record that an action happened, including your user id and the deletion itself with a count of what it removed. It holds no content, and it is the only trace left afterwards.
  • Company research is shared and stays. Research about an employer is gathered once and shown to everyone tracking that company. It is public information about a business, it is not linked to you or to anything you did with it, and it cannot be removed while another user is relying on it.
  • Your avatar and the fact that you finished setup stay, on purpose. An avatar is part of your identity rather than content you made, and removing the setup marker would send you back through the onboarding wizard and spend your credits doing it.
  • A deletion can partly fail. Your content sits across a number of separate stores, and they are not one transaction. If part of it fails, the app tells you which part, and running it again is safe.

If any of that is not acceptable for your situation, write to hello@labor.quest and say so. Removing your account entirely is a separate and more complete step, described in section 8.

10Where your data is processed

Everything we run is in the United States, in AWS's Northern Virginia region. Stripe processes payments in the United States and Ireland, and Google's services run on Google's own global infrastructure.

If you are in Europe or the United Kingdom, that means your data leaves your country. AWS, Stripe and Google all publish the Standard Contractual Clauses that the GDPR requires for this, and those are the terms we are on with each of them. If you would like to know more about the arrangement covering a particular one, ask us.

11How your data is protected

Rather than claim industry standard security, here is specifically what is true:

  • Everything is served over HTTPS, so nothing travels in the clear.
  • The bucket holding uploaded CVs is private. Each account has its own area of it, and uploads go through links that are valid for fifteen minutes and then stop working.
  • The server can reach exactly the storage area, AI model and functions it needs and nothing else, enforced by its own permissions rather than by convention.
  • Access tokens last fifteen minutes and are not renewed in the background, so a session left open ends rather than lingering.
  • Your session cookie is signed, so it cannot be altered or forged.
  • Passwords are handled only by the authentication service, and never by the app.
  • Files and databases are encrypted at rest using AWS's own default encryption. We are naming that specifically rather than claiming anything stronger.

If something does go wrong and your data is affected, we will tell you and the relevant authority. If you think you have found a security problem, please write to hello@labor.quest before telling anyone else, and we will treat it seriously.

12Changes to this policy

When we add a tool or a supplier, this page changes. The date at the top of it is the date of the version you are reading, and the current version always lives at labor.quest/privacy.

If a change is significant, meaning it alters what we collect, why, or who else sees it, we will tell you in the app rather than only editing this page and hoping you look. A change never applies retroactively to data we have already collected under an earlier version.

Questions about this document, or a request you want to make? Write to hello@labor.quest and a person will read it.