Privacy Policy
Last updated: 2026-04-25
Draft notice: This is a draft for development purposes. Final policy will be reviewed by counsel before launch.
The short version
- We collect what we need to make the product work — your account details, the resume you upload, the jobs you save, your interview transcripts.
- We never sell your data. We share it only with the services that make Cruto run (payments, sign-in, AI, code sandbox).
- Live interview audio streams between your browser and the AI — we never store or even see the audio itself.
- Your transcripts are encrypted and visible only to you, unless you choose to publish a cert.
- You can download everything we have on you, or delete your account in one click, from Profile → Privacy & data.
The full policy below is what governs how we actually handle your data — read it too.
1. Introduction
This Privacy Policy explains what information Cruto.AI (“Cruto”, “we”, “us”) collects, how we use it, and the choices you have. It applies to the Cruto web app, mobile app, and related services.
2. Information we collect
- Account information. Email and username are collected through our authentication provider, Clerk.
- Profile information. Voluntary fields you choose to provide, such as target role, seniority, technology stack, and resume content.
- Usage data. Test attempts, interview sessions, transcripts, and product interactions needed to operate the service.
- Payment information. Card and billing details are handled by Stripe. Cruto does not store your card details on our servers.
- Cookies and analytics. Essential cookies are used for authentication and session management. Product analytics (PostHog) is opt-in via the cookie banner.
3. How we use information
- provide, maintain, and improve the service;
- generate AI-powered tests, debriefs, and interview feedback;
- process payments and manage subscriptions;
- send service-related communications such as billing receipts, security notices, and product updates;
- detect, prevent, and respond to abuse or fraud.
4. Information sharing
We do not sell your personal data. We share data only with vendors that help us run the service and only to the extent needed:
- Stripe — payments and subscription billing.
- Clerk — authentication and session management.
- Google Gemini — AI generation of tests and interview content.
- Judge0 — sandboxed execution of user-submitted code.
- JSearch (RapidAPI) — job-listing aggregation across LinkedIn, Indeed, Glassdoor, and ZipRecruiter. Receives only the search filters you configure (target role, seniority, location); never your account identity.
- PostHog — opt-in product analytics.
We may also disclose information if required by law or to protect the rights, safety, or property of Cruto or its users.
5. Data retention
Test and interview session records are retained for ninety (90) days by default. You may delete your account and associated data at any time from your settings page; deletion is irreversible. Some records may be retained longer where required by law (for example, billing records).
6. Your rights
You have the right to access, correct, export, and delete the personal information we hold about you. These rights are offered to all users regardless of location, in line with GDPR principles, even though our initial launch is US-only. Requests can be sent to privacy@cruto.ai.
7. Security
We use industry-standard safeguards including TLS encryption in transit, encrypted storage with our infrastructure providers, and access controls on internal systems. No system is perfectly secure and we cannot guarantee absolute security.
8. Children’s privacy
Cruto is not directed to children under the age of 16 and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
9. International transfers
Cruto is operated from the United States. If you access the service from outside the US, your information may be transferred to and processed in the US, where data protection laws may differ from those in your jurisdiction.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.
11. Contact
Privacy questions or requests can be sent to privacy@cruto.ai.