Privacy Policy

Last updated: 2026-05-13

This policy explains what data Phantum collects, why we collect it, who we share it with, and the rights you have over it. If you have questions, email support@phantum.app.

1. The information we collect

  • Account. When you sign in with Google we receive your email address and a stable user identifier. We do not receive your Google password.
  • Documents you upload. Resumes and job descriptions you upload through the app or website are stored in our database, along with the text we extract from them.
  • Session metadata. For each interview session we record the start time, end time, duration in seconds, and a reference to the upstream AI provider session. We do not store the audio captured during a session or the transcripts produced from it.
  • Billing information. If you purchase a paid plan, Stripe processes your payment. We store the resulting Stripe customer identifier and the subscription status — never the card number itself.
  • Technical logs. Our servers log request metadata (timestamp, route, status, latency, anonymous request ID) for up to 30 days for operational debugging.

2. Why we use it

  • To provide the Service. Documents and session metadata are required to mint interview sessions and ground the AI’s answers in your context.
  • To bill you. Stripe customer and subscription data is used to authorise access and process renewals.
  • To debug and improve reliability. Logs are used to investigate errors and abuse. We do not use them for advertising or profile-building.

3. Third parties we share data with

Phantum is operated on a small number of well-known infrastructure providers. Each one only receives the minimum data needed to do its job.

  • Google (Sign in with Google). Receives your sign-in request to authenticate you. We do not send Google any of your interview content.
  • Supabase. Hosts our authentication, database, and document storage. Data is encrypted at rest and in transit and is not used by Supabase for any other purpose.
  • Stripe. Receives the information needed to process payments and manage subscriptions.
  • OpenAI. At the start of each interview session, we send OpenAI the extracted text of your active resume, your active job description, and the company name you entered, so their model can produce relevant answers. During the session, audio streams peer-to-peer from your computer to OpenAI’s realtime endpoint — it does not pass through our servers and we do not store it. OpenAI’s own data-handling terms apply to this traffic.
  • Vercel. Hosts this website and our API. Receives standard request metadata.

We do not sell your data. We do not use it for advertising. We will only disclose information when required by law, when necessary to protect rights and safety, or with your explicit consent.

4. Retention

  • Account and profile data are retained while your account is active. Deleting your account triggers immediate deletion (see section 6).
  • Documents are retained until you delete them or your account.
  • Session metadata is retained for as long as we need it to calculate usage caps, reconcile billing, and meet tax/accounting obligations (typically 7 years).
  • Operational logs are retained for up to 30 days.

5. Security

Session tokens on the desktop are stored in your operating system’s keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service) — never as plain files. All traffic between the app, our servers, and our providers uses TLS. Storage objects are private and gated by per-user policies. Our OpenAI API key never leaves our backend.

6. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access and portability. Export everything we hold about you as JSON from Dashboard → Account (or in the desktop app, Settings → Export my data).
  • Deletion. Permanently delete your account and all associated data from Dashboard → Account (or in the desktop app, Settings → Delete my account).
  • Rectification. Update your documents at any time via Dashboard → Documents.
  • Withdrawal of consent. Stop using the Service and delete your account. Subscriptions will be cancelled.
  • Complaint. Lodge a complaint with the relevant supervisory authority in your country.

7. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

8. International transfers

Our infrastructure providers are based in the United States and European Union. By using the Service you consent to the transfer of your data to and from those jurisdictions, subject to appropriate safeguards required by applicable law.

9. Cookies

On the website, we use a single authentication cookie set by Supabase to keep you signed in. We do not use analytics, advertising, or tracking cookies.

10. Changes to this policy

We will post any changes to this policy here and update the “Last updated” date above. Material changes will be announced in-app at least 14 days before they take effect.

11. Contact

Email support@phantum.app with questions, deletion requests, or privacy-related concerns.

Note: this policy is a starting template intended for review by qualified counsel before public launch. EU/UK/CCPA deployments may require additional disclosures (DPO contact, specific lawful bases, “Do Not Sell” link, etc.).
Privacy Policy — Phantum