Pending final legal review. This page reflects our current practices and applies to your use of the service. We are completing a final attorney review and may refine the wording before public launch.

Privacy Policy

Last updated: August 12, 2026

This Privacy Policy explains how Nuvortex LLC, doing business as InterviewSurge (“InterviewSurge,” “we,” “us,” or “our”) collects, uses, stores, and shares your personal data when you use our website and services. By creating an account or using the service, you acknowledge the practices described here.

Who we are

InterviewSurge operates a job-search service that finds relevant roles, tailors your CV to each one, finds recruiter contacts, drafts your outreach, and — where you have given us consent and the employer’s application route allows it — submits applications on your behalf. We fulfill applications using a combination of automated tools and trained human specialists; the mix varies by platform. The contracting entity is Nuvortex LLC d/b/a InterviewSurge. For any privacy question, contact us at support@interviewsurge.com.

Data we collect

We collect the following categories of data:

  • Account data — your name, email address, and authentication identifiers (including any data provided by Google when you sign in with Google).
  • CV content and the personal data within it — the CV file you upload and the information it contains, such as work history, education, skills, and contact details.
  • Job preferences — target roles, locations, salary expectations, and other search criteria you configure.
  • Application profile data — details required to submit applications on your behalf, which may include legal name, address, work-history answers, screening responses, and the credentials we hold for applicant tracking systems on your behalf.
  • Job-search mailbox data — where you use a job-search mailbox with the service, we read message content and metadata in order to label messages and surface what needs your attention, to retrieve the one-time codes application platforms send while an application is being completed, and to record confirmation that an application was submitted. We also place outreach drafts in that mailbox for you to send. We store the access credentials that authorize this. See Job-search mailbox access below.
  • Purchase and usage data — which package you bought, when, how much of its allowance you have used, and a record of each application counted against it. Card details are collected and processed directly by Stripe; we do not store your card number.
  • Usage and device data — analytics events, pages viewed, approximate location derived from your IP address, and cookie identifiers (see Cookies).

Data about recruiters and hiring contacts

To surface a hiring contact for each job, we hold professional contact data about recruiters and hiring staff who are not our customers and have not signed up for our service. If you are such a person, this section is about you.

  • What we hold: name, job title, employer, LinkedIn profile URL, and a business email address, together with when we first and last saw the record.
  • Where it comes from: public professional sources — principally public job postings and public LinkedIn profile pages — and a third-party lookup service that returns a business email address for a given public profile.
  • What we use it for: showing our client the right person to contact about a specific job, and drafting an outreach message our client then sends. It concerns you in your professional capacity, not your private life.
  • How long and how widely: a contact record is kept in a shared store and may be surfaced to more than one of our clients if it is the right contact for more than one job. We do not sell it, and we do not use it for advertising.
  • How to see it, correct it, or have it deleted: email us at support@interviewsurge.com and we will action it. You do not need an account with us to make that request.

How we use your data

We use your data to:

  • Deliver the service — match you to roles, tailor your CV to each one, find recruiter contacts, draft your outreach, submit applications where you have consented and the platform allows it, and label your job-search mailbox so the things needing your attention surface.
  • Provide support and maintain oversight — authorized members of our team access your account to prepare and submit your applications, to provide support, to maintain quality, to investigate abuse, and to meet legal obligations.
  • Process your purchase and track how much of your package allowance remains.
  • Communicate with you — transactional email such as account confirmation, password resets, and your daily summary.
  • Measure usage and improve the product through aggregate analytics.
  • Comply with legal obligations and protect against fraud and abuse.

Voluntary self-identification questions

Some applications ask voluntary questions about who you are — for example gender, race or ethnicity, veteran status, or pronouns. Answering them is always optional. You decide, question by question.

We only ever send an answer you gave us yourself. If you provide one in your dashboard, we enter exactly that answer, word for word. We never guess, and we never work an answer out from your name, your photo, your CV, your school, your address, or anything a computer produced. Anything you leave at “prefer not to say” we answer that way, or leave blank.

Keeping your answers and sending them to employers are two separate permissions, and both start switched off. We store what you give us for one purpose only — filling the matching voluntary question on an application you asked us to send — and we do not use these categories for profiling, matching, ranking, analytics, advertising, or model training. We never sell them. We share them only with the employer whose form you asked us to complete.

You may edit or withdraw any answer at any time in your dashboard, as easily as you gave it. Withdrawal applies to applications we send afterwards; it cannot recall one already sent. Declining is not a condition of the service, and we make no claim that answering helps or hurts your chances.

Two questions we always decline, and we are telling you so. We do not collect disability status, and we do not collect community or affinity group membership — that list includes disability and neurodiversity options, so it carries the same information. On every application we select “I do not wish to answer” for both. If we ever change that, we will update this policy first and — for any disability-related information covered by Washington’s My Health My Data Act or similar laws — publish a separate Consumer Health Data Privacy Policy before any collection begins.

Job-search mailbox access — Google API Services User Data Policy

The service uses a dedicated job-search mailbox. We may provision that mailbox for you on our Google Workspace domain, or you may grant us access to one you already own. Either way, this is what our access does and does not permit:

  • We read your mail. Our access includes reading message contents. We use it to classify and label messages so your dashboard can show what needs you, to retrieve the one-time verification codes application platforms send while an application is being completed, and to capture confirmation that an application was submitted.
  • We create drafts, and you send them. Outreach we prepare is placed in your mailbox as a draft for you to review, edit, and send. We do not send email from your mailbox on your behalf.
  • InterviewSurge’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • We do not sell or transfer your mailbox data, use it for advertising, or use it to develop, improve, or train generalized AI/ML models.
  • Classification is performed by automated systems. Human access to your mailbox is limited to the specialist assigned to your account completing an application for you, and to security, abuse investigation, legal compliance, or support you have asked for.
  • You can revoke our access at any time through your Google Account security settings or by contacting us at support@interviewsurge.com.

How we store and protect your data

Your data is stored in our managed PostgreSQL database hosted by Supabase. Sensitive fields — such as the credentials you provide for applicant tracking systems — are encrypted at rest in our database provider’s vault using libsodium authenticated encryption, and are accessed only through audited database functions that record each use. All data is encrypted in transit and at rest. Access to production data is restricted to the systems and personnel that require it to operate the service.

Third parties we share data with

We share the minimum data necessary with the following sub-processors, each of which acts under its own privacy and security commitments:

  • Supabase — database, authentication, and file storage. Your CV files, generated CVs, and application evidence are stored here.
  • Hostinger — virtual-server infrastructure on which our application services and queues run, and the mail server that sends our own transactional and daily-summary email to you.
  • Stripe — payment processing.
  • OpenRouter — the gateway through which every one of our AI model calls is made. Depending on the task this carries your CV content, the job description, and the outreach we draft for you. On every call we require that the provider does not retain the data and does not collect it for its own purposes.
  • Google — the Gemini models we use for most tasks, including tailoring your CV, run on Google infrastructure and are reached through OpenRouter. We do not authorize the use of your data to train models.
  • Together AI, Fireworks AI, DeepInfra, and Lambda — United States hosts for the open-weight models we fall back to if the primary model is unavailable. We deliberately pin this fallback to these four so that the list of companies able to see your data stays short and knowable.
  • Google Workspace and the Gmail API — used to provision and operate your job-search mailbox, as described above.
  • Bright Data — the data source we use to discover public job listings. It receives your search criteria, such as job titles and locations. It does not receive your identity or your CV.
  • Apify — used to look up a business email address for a recruiter’s public profile, and, for some accounts, as a second source of public job listings. It does not receive your CV.
  • Sentry — error monitoring, so we find failures before you do. It is configured not to attach personal data, and email addresses and phone numbers are stripped from reports before they are sent.
  • Telegram — operational alerts to our own staff when part of the pipeline fails. These can identify the affected account.
  • Google Analytics 4 — website and product analytics. Analytics run only after you grant consent.

We do not sell your personal data. We may disclose data when required by law or to protect our rights and the safety of our users. We will update this list when it changes.

Cookies

We use a small number of cookies. Strictly necessary cookies keep you signed in and remember your cookie choice; these are always active. Analytics cookies set by Google Analytics 4 are off by default and load only after you select “Accept” in our cookie banner. The GA4 cookies are:

  • _ga — distinguishes visitors; expires after about two years.
  • _ga_<container-id> — persists session state for the GA4 property; expires after about two years.
  • _gid — distinguishes visitors; expires after about 24 hours.

You can change your choice at any time using the “Cookie preferences” link in the site footer. Rejecting analytics cookies keeps Google Analytics fully disabled.

How long we keep your data

We retain account and profile data for as long as your account is active, and for a limited period afterward to meet legal and operational requirements. Job listings discovered by our scraper are retained for approximately 15 days. On account deletion or offboarding, we delete or de-identify your personal data — including application profile data and any mailbox content we have stored — and revoke or destroy stored credentials and mailbox access within 30 days, except where we are required to retain data by law.

Your rights

Subject to applicable law, you have the right to access, correct, export, and delete your personal data, to withdraw consent (including for analytics) at any time, and — where your state law provides — to limit the use of sensitive personal information and to opt out of any sale or sharing (we do not sell or share personal data for cross-context behavioral advertising). To exercise any of these rights, email us at support@interviewsurge.com. We will respond within the timeframe required by applicable law.

International users

We operate online and process your data in the United States, where our infrastructure and all of the sub-processors listed above are located. If you use the service from outside the United States, your personal data is transferred there. Where we transfer data across borders, we take steps to ensure it remains protected in line with this policy.

Children

The service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. Continued use of the service after an update constitutes acknowledgment of the revised policy.

Contact

For any question about this policy or your personal data, contact us at support@interviewsurge.com.

Privacy Policy | InterviewSurge