Privacy Policy
Effective: 7 September 2026. How we handle personal data across the Utably platform.
Data Controller
The data controller for the personal data described in this Privacy Policy is Utably UG (haftungsbeschränkt), Wuhlestraße 7a, 12683 Berlin, Germany, represented by its managing director Joshua Sievert. You can contact us at support@utably.com or via the details on our Imprint page.
Scope
This Privacy Policy covers personal data processed when you use Utably, including account creation, product usage, content you store, customer support, billing, and security. Analytics-specific processing is covered separately in our Privacy Notice — Analytics.
Categories of Personal Data
Depending on how you use the product, we may process identifiers (name, email), account credentials, profile data you provide, documents and content you upload or generate, subscription and payment metadata, customer support communications, and security or fraud-prevention signals (including bot-protection signals collected via Cloudflare Turnstile when you submit public forms).
SOCIAL LOGIN DATA: If you choose to sign in or register using a social login provider (currently Google, Microsoft, Facebook, and LinkedIn), you initiate a data transfer from that provider to us by clicking "Sign in with [Provider]". Only the standard permissions "openid", "profile" or "public_profile", and "email" are requested; we do not access any other content of your provider account. We receive and process the following data from the social provider:
• Email address — used to identify your account, match existing accounts, or create a new account • Name (given name and family name) — used to populate your profile • Profile picture — downloaded from the social provider and stored on our infrastructure (AWS S3) to ensure reliable availability within the Service. No profile picture is retrieved when you sign in with Microsoft. • Social provider identifier — a unique ID from the provider used to link your social identity to your Utably account
You can change or delete your profile picture at any time in your account settings. If you sign in with multiple social providers using the same email address, those identities are linked to a single Utably account.
SIGNING IN WITH MICROSOFT: Signing in with Microsoft is possible only with personal Microsoft accounts. Work or school accounts (Microsoft Entra ID) cannot be used to sign in.
SIGNING IN DOES NOT GRANT CALENDAR ACCESS: Signing in with Google or Microsoft gives Utably no access whatsoever to your calendar, your email, or your files. The OAuth applications used for sign-in are entirely separate from those used for the calendar connection; connecting a calendar requires separate, explicit consent (see "Calendar Connection (Google Calendar and Microsoft Outlook)").
SPECIAL CATEGORY DATA: The Service does not ask you for special categories of personal data (for example health data, a disability, ethnic origin, religious beliefs, sexual orientation or trade union membership) and has no fields intended for them. CVs, profile information and documents you write, upload or transfer using our features (including the browser extension) may nevertheless contain such data if you decide to include it. If you do, we process that information solely to provide the features you have requested for your own documents and applications, never for any other purpose, and only on the basis of your explicit consent (Art. 9(2)(a) GDPR). You give this consent through a separate control of its own: the switch "Sensitive data in your documents" under Settings → User Data & Exports, or the "I consent" button of the notice that appears when the browser-side check described below flags such a phrase in text an AI feature is about to process. That notice asks you to decide: "I consent" or "I will remove it". Consent is never inferred from accepting the Terms, from any other setting, or from using the editors. If you choose "I will remove it", we record that declaration with its date; it is not a consent, it does not restrict the app, and while it applies the editors remind you not to include such information. To help you keep that declaration, the profile and document editors also check what you type against a list of typical phrases for the categories above (for example a degree of disability, a religious denomination or a union membership) — this check runs entirely in your browser, nothing about your text is sent to us for it, and it is a hint you can dismiss, not a decision. While consent is not given, AI features do not process text the check has flagged until you remove the phrase or give your consent; Document Check lists such phrases as a finding so you can decide. If you choose "I will remove it", you must not submit special-category personal data while that choice applies. If we become aware that such data has been submitted without the required consent, we may remove it or restrict its processing and ask you either to remove it yourself or to give the required explicit consent. We store the consent status, the version of the consent text you agreed to, the date and time of your decision and of any later change, and a short history of these changes on your account record; this record is included in your data export and deleted with your account. You can withdraw the consent at any time with effect for the future using the same switch; withdrawal is recorded with its time, does not affect the lawfulness of processing carried out before it (Art. 7(3) GDPR), and does not delete information you have already entered, which you can remove from your profile and documents yourself. We recommend that you include such information only where it is relevant to an application.
Purposes of Processing
We process personal data to provide and improve the service, generate and store your documents, deliver support, manage subscriptions, prevent abuse, and comply with legal obligations.
AI-Powered Features
Utably uses artificial intelligence (AI) for the following features: cover letters and document drafts with Uta, CV suggestions and rewrites, parsing of uploaded CVs (CV import), design import (evaluation of a page image of your document), Document Check, FitCheck and job-match analysis, career insights and Career Compass, interview preparation, hints, and debrief, journal reflections and weekly/monthly/yearly reviews, evaluation of forwarded emails, Uta's chat and voice mode, and Uta's memory. Depending on the feature, the profile, application, document, journal, and chat data required for it are transmitted to AI services.
AI TRANSPARENCY (ART. 50 AI ACT): When you use the assistant "Uta", you are interacting with an AI system (Regulation (EU) 2024/1689, Art. 50). We expressly inform you that your conversation is with an artificial intelligence and not with a human.
POSITIONING OF THE ANALYSIS FEATURES: The job-match analysis, Document Check, and FitCheck are self-assessment tools that you, the candidate, use on your own materials. They are not employer-side recruitment, selection, screening, or candidate-ranking systems within the meaning of Annex III No. 4 of the EU AI Act (Regulation (EU) 2024/1689). Utably makes no decisions about you; the results are provided solely for your own orientation. Where available, the working style determined in your personality test is one factor among several in FitCheck, job-match analysis, and career insights.
IMPORTANT: AI-generated content is provided "as is" and may contain errors or inaccuracies. You should review, customize, and verify all AI-generated content before use. We do not guarantee that AI outputs will be accurate, suitable, or free from bias.
AI PROVIDERS: We use AWS Bedrock (Amazon Web Services EMEA SARL, Luxembourg) as a processor. Through Bedrock we run models from Anthropic (Claude), Amazon (Nova, including Nova Sonic for voice mode), and Mistral AI; the model providers have no access to your data, and your data is not used to train models. Processing takes place exclusively in AWS regions within the European Union; model invocations run through EU inference profiles which, depending on load, may route a request to a data centre in another EU region, but never outside the EU.
LEGAL BASIS: performance of the contract (Art. 6(1)(b) GDPR) for AI features you invoke yourself. Features that additionally process third-party data or transmit data to third parties (calendar, Interview Live Mode, connected AI assistants, de-identified career data) rely on your consent as described in the respective sections.
RETENTION: Chat histories with Uta are not stored on our servers; your browser keeps the last 50 messages locally until you start a new conversation or sign out. Generated AI content (e.g. cover letters, debriefs, summaries) is stored in your account until you delete it or your account is deleted. Amazon Bedrock processes our requests under a zero-data-retention model: for the models we use, AWS does not store the content of requests or responses and does not share it with the model providers. We do not enable Bedrock model invocation logging, and we do not use models for which AWS retains inputs and outputs for abuse review. Per invocation we log only time, feature, model and token volume to account for your allowance, without the content of the request.
DESIGN IMPORT: If you want to adopt the design of an existing CV, the file is converted in your browser into an image of the first one or two pages; the original file does not leave your device. The page image — which shows the readable content of your document — is transmitted to a vision model (AWS Bedrock, EU) that describes only design characteristics (layout, colours, fonts). The model is instructed not to extract content; the image is not stored after evaluation.
UTA ASSISTANT AND MEMORY: The assistant "Uta" processes your chat messages and relevant profile, application, and journal data via AI services (AWS Bedrock) to help you within the product. So that Uta can support you personally, it keeps a memory with the following categories: preferred form of address, goals (week/month/year), skills and traits noticed in conversation, topics you do not want raised, style preferences, important events, and other durable facts. Entries arise (a) when Uta expressly notes something in conversation, (b) through an automatic evaluation of your own statements after each chat message, and (c) from an interview debrief or journal reflection you request. The memory is capped at about 6,000 characters; goals expire automatically (week 14 days, month 90 days, year 400 days). Legal basis: performance of the contract (Art. 6(1)(b) GDPR). You can view, edit, or delete any entry under Settings → Uta memory, delete the entire memory, and object to automatic memory-building at any time (Art. 21 GDPR) by switching off "Let Uta remember automatically" there; existing entries stay until you delete them. The memory is stored in our EU infrastructure, is included in your data export (Art. 15 and 20 GDPR), is not shared with third parties, and is fully deleted when you delete your account.
VOICE MODE: When you activate Uta's voice mode, your microphone is used only for the duration of the voice session. Audio is transmitted in real time to a speech AI model (AWS Bedrock, Amazon Nova Sonic) in our EU infrastructure and processed there; we do not store audio recordings. Transcripts of the conversation are treated like regular chat messages. Uta's voice is synthetically generated; you are talking to an AI, not to a human.
VOICE INPUT (DICTATION): In addition to voice mode, some text fields — such as the chat with Uta — offer a dictation function. Speech is converted into text not by Utably but by your browser's speech recognition (Web Speech API). Depending on the browser, your audio signal is transmitted to the browser vendor's speech service (in Google Chrome: Google LLC, USA; in Safari: Apple), which is an independent controller in this respect. Utably receives only the recognised text and stores no audio. If you wish to avoid this transmission, type your input instead. The notes on speech recognition in the "Interview Live Mode" section apply accordingly.
Personality Test
The personality test is based on the Big Five model (IPIP-NEO-120). Before you start we ask for your date of birth and country of residence; we use these solely to score your answers against age- and country-specific reference values (norms) and store them in your profile. The results (factors, facets, and the working style derived from them) are stored in your profile and — where you use the respective feature — are used as input to AI features such as FitCheck, job-match analysis, and career insights to indicate fit with a role. They enter the de-identified career dataset only with your separate consent (see "De-identified Career Data").
The test is not a clinical instrument and not an aptitude assessment; we make no decisions about you on its basis. Legal basis: performance of the contract (Art. 6(1)(b) GDPR). You can reset and retake the test at any time in the Personality Hub; the results are then replaced, and they are fully deleted when you delete your account. On request we delete them earlier (support@utably.com).
Automated Decision-Making
We do not make decisions based solely on automated processing — including profiling — that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). AI-powered outputs are suggestions for your own orientation and do not replace a human decision.
Contact Form
When you use our contact form, we process the name, email address, subject, and message you enter, solely to receive and respond to your inquiry. Legal basis: performance of a contract or of pre-contractual measures (Art. 6(1)(b) GDPR) where your inquiry concerns your account, a subscription or a purchase, and otherwise our legitimate interest in answering inquiries addressed to us (Art. 6(1)(f) GDPR); the checkbox on the form confirms that you have taken note of this Privacy Policy. For the spam protection on the form (Cloudflare Turnstile) our legal basis is our legitimate interest in preventing abuse (GDPR Art. 6(1)(f)). Your message is transmitted to our backend hosted on AWS in the EU; Cloudflare Turnstile performs a bot check. We delete contact-form data once your inquiry has been dealt with, unless statutory retention periods require otherwise.
Browser Extension ("Utably Job Importer")
Utably offers an optional browser extension ("Utably Job Importer") for Chrome, Edge, Firefox, and Safari that lets you import job postings from third-party websites into your Utably account, fill application forms with your Utably profile data, and manage your saved applications directly from the extension. This section describes how the extension processes personal data. It supplements, and does not replace, the rest of this Privacy Policy.
DATA WE PROCESS VIA THE EXTENSION: • Job posting content you choose to import (job title, company, location, recruiter name, job description, source URL) — extracted from the page you are actively viewing only when you click "Auto-fill" or paste content yourself, and stored locally in your browser as an import draft until you save it to your account or discard it • Your Utably profile data (name, contact details, employment and education history) — loaded from your Utably account when you use the profile autofill feature and written into the fields of an application form (e.g. Greenhouse, Lever, Ashby) inside your browser, only after you have seen a preview of exactly which fields will be filled on which website and have released that website for filling. This confirmation dialog is shown before every fill — including on websites you have released before. Releases are stored per website locally in your browser, expire automatically after 30 days, are removed when you log out, and can be cleared in the extension at any time. Writing the data into the form does not by itself send it to the website operator — that happens only when you submit the form yourself. • Your application documents stored in your Utably account (CVs, cover letters, certificates, and other attachments you have chosen to make available to the extension in the web app) — retrieved via short-lived protected links only when you click to upload one into a file field on an application page or to download it to your device; the extension does not keep copies of document contents • Text you select on a page and explicitly capture via the text capture feature — assigned to a field of your import draft that you choose and stored locally in your browser as part of that draft (together with the page address) until you save or discard the import; never captured automatically • Your saved Utably applications and their status — loaded from your Utably account so you can view and update them in the extension • Authentication tokens (a short-lived access token and a refresh token) — stored locally in the browser's extension storage and used only to authenticate requests to api.utably.com. Requests from the extension to our API are subject to the same technical server logging as other use of the Service. • FitCheck — when you click "FitCheck", the job details shown in the preview form (job title, company, location, description, source URL) are sent to api.utably.com/extension/llm. Your profile is not sent from your browser; our backend combines the job details with the profile already stored in your account to generate the job-fit analysis using AI services (AWS Bedrock, EU region eu-north-1). Recent FitCheck results (up to 20, for up to 24 hours) are cached locally in your browser so repeating a check does not use up your quota; you can remove this cache at any time by clearing the extension's storage in your browser or uninstalling the extension. • Tab addresses while the extension is open — to prefill the "source URL" field of your import draft, the extension reads the web address (URL) of the tab you are viewing while its panel or popup is open. It does not read page content this way; the addresses are processed locally and are transmitted to us only as part of an import or FitCheck you actively start.
WHAT WE DO NOT DO: • No background browsing or crawling. The extension contains no scripts that run automatically when web pages load. Page content is accessed only after you click "Auto-fill", start a form fill, or explicitly capture selected text in a specific tab. • No password or credential capture. The extension does not collect or transmit passwords, cookies, or browsing history. During form filling it reads field labels and types in order to match fields, and checks locally whether a field already contains a value so that it never overwrites anything you have typed; the contents of form fields are never transmitted anywhere. • No analytics, tracking pixels, or third-party advertising SDKs are bundled in the extension. The extension contains no third-party code at all. • The extension never submits an application form for you. It only writes values into fields and attaches files you have selected; reviewing and sending the application is always your own action. • No data is sold or shared with third parties beyond the processors listed in "Recipients and Processors". The one exception is data you yourself place into an application form using the autofill, document-upload, or text-capture features: that data reaches the operator of the website concerned when you submit the form. See "Third-party application websites" under "Recipients and Processors".
BROWSER PERMISSIONS: • activeTab / scripting — used only at the moment you click "Auto-fill" (to read the job posting on the active tab), start a form fill, or capture selected text • tabs — used to read tab addresses as described above and to focus an already open Utably web app tab instead of opening a duplicate • storage — used to store authentication tokens, your settings, your per-website fill releases, unsent import drafts, and the temporary FitCheck result cache locally in the browser; your profile cache is kept only in session storage (cleared when the browser closes) • sidePanel — renders the extension's side panel in Chrome and Edge; Firefox and Safari use a regular extension popup instead • downloads — used only when you click to download one of your own stored application documents to your device • Host access — the only websites the extension may always contact are our own API endpoints (api.utably.com). To read a job posting or fill a form on other websites, it needs the browser's optional "access to websites" permission (:///*), which your browser asks you to grant the first time you use such a feature. Note that this browser-level grant is general — it is not limited to the website you are on at that moment — and it remains in place until you revoke it, which you can do at any time in your browser's extension settings. Independently of this permission, the extension only ever accesses a page when you actively trigger an action on it (see above).
LEGAL BASIS: Performance of a contract (GDPR Art. 6(1)(b)) — processing the data you choose to import, fill, upload, or analyze is necessary to provide the import, autofill, document, and FitCheck features you have requested. The per-website release described above is an additional safeguard we apply on top of this legal basis, not a separate consent under Art. 6(1)(a); clearing a release stops any further filling on that website. Insofar as the profile data, documents, or text you choose to transfer contain special categories of personal data (Art. 9(1) GDPR — e.g. health data, disability or severe-disability status, religious affiliation, trade union membership), we process these solely on the basis of the explicit consent described under "Special category data" above (Art. 9(2)(a) GDPR), which you give through the dedicated control in Settings or the one-time notice in the editors; the per-website release is an additional safeguard, not the consent itself. You can withdraw that consent at any time with effect for the future; the lawfulness of processing carried out before the withdrawal is unaffected (Art. 7(3) GDPR).
DATA RETENTION: Imported job postings are stored in your Utably account and follow the same retention rules as the rest of your account data (see "Retention" and "Data Retention and Automatic Account Deletion"). Authentication tokens stored in the browser are short-lived and can be revoked at any time by clicking "Logout" in the extension or by clearing extension storage. Per-website releases expire after 30 days and are removed when you log out. Unsent import drafts and the FitCheck result cache remain in your browser until you save or discard the draft, clear extension storage, or uninstall the extension; the FitCheck cache also expires automatically after 24 hours. Your profile cache is held in session storage only and is discarded when the browser closes. Documents you download to your device are outside our control from that point; deleting them is up to you.
UNINSTALLING: Removing the extension from your browser deletes all locally stored extension data (tokens, settings, releases, drafts, caches). It does not delete data already imported into your Utably account; to delete that, use account deletion in the web app.
Connected AI Assistants (MCP)
At your instruction you may connect external AI assistants (e.g. applications supporting the Model Context Protocol) to your Utably account via OAuth 2.0. A connected assistant can then read profile and application data and create or change entries on your behalf. The connection covers all offered tools (reading and editing profile and application data, triggering AI features); the assistant confirms every write action with you before executing it, and you can disconnect at any time.
LEGAL BASIS: performance of the contract (Art. 6(1)(b) GDPR) for the connection you request; your consent (Art. 6(1)(a) GDPR) for the transmission to the assistant's provider, which you give in the OAuth dialog and can withdraw at any time by disconnecting in Settings.
RECIPIENTS AND THIRD-COUNTRY TRANSFERS: The provider of the connected assistant is an independent controller for the data it receives through the connection and may process it outside the EU/EEA. Its terms and privacy notices apply; we have no influence over that processing.
WHAT WE STORE: the name of the connected client, first and last use, and the number and type of tools called. Tools that trigger Utably AI features (e.g. CV import, job-match analysis) consume your AI allowance as if used in the app.
Calendar Connection (Google Calendar and Microsoft Outlook)
You may voluntarily connect your Google or Microsoft calendar to Utably. The connection serves to detect interview appointments in your calendar and suggest importing them into your applications and — if you permit it — to add the interview rounds you plan in Utably to your calendar as events and keep them up to date. Unless you establish a connection, we process no calendar data whatsoever.
LEGAL BASIS: your consent (Art. 6(1)(a) GDPR). You give it by starting the connection flow and confirming access on the relevant provider's own consent screen. You may withdraw your consent at any time with effect for the future by disconnecting the connection in Settings; the lawfulness of processing carried out before withdrawal is unaffected (Art. 7(3) GDPR).
PERMISSIONS: When connecting, you decide yourself whether Utably may only read your calendar or additionally write events. Only calendar-related permissions and your email address (to identify the connection) are requested:
• Google: "openid" and "email" plus "calendar.events" (read and write) or "calendar.events.readonly" (read only) • Microsoft: "openid", "email", and "offline_access" plus "Calendars.ReadWrite" (read and write) or "Calendars.Read" (read only)
The calendar connection uses its own OAuth applications, separate from those used for sign-in. Unlike signing in with Microsoft, work and school accounts may also be used for the calendar connection.
CALENDAR DATA WE PROCESS: Your events are retrieved live from the provider when needed and are not stored permanently; the only exception is the appointment suggestions described below, which are stored temporarily. Technically, the provider transmits the complete event record to our server function; only the following are evaluated: title or subject, start and end, whether the event is all-day, location, online meeting link, cancellation status, and the number of people invited. The description text of an event is scanned automatically for a dial-in link only. We do not store the names or email addresses of other attendees; they are evaluated briefly in memory only, in order to determine whether you are the organizer of an event and whether you are permitted to move it. Interview appointments are detected by rules based on keywords in the title and location — your calendar data is not processed by AI services.
READ WINDOW: When you open the calendar view, Utably reads a rolling window from one day in the past up to 30 days into the future (maximum 60 days, no more than 100 events per provider). For automatic detection, the provider notifies us of changes in your calendar; in that case a window from one day in the past up to 14 days into the future is evaluated.
WHAT IS STORED:
• Access and refresh tokens — encrypted with AWS KMS in our EU infrastructure; they are decrypted server-side only, in order to authorize requests to your calendar • The email address of the connected calendar account, the scope of permissions granted, and your settings for the connection • Appointment suggestions: if Utably detects a possible interview appointment or the rescheduling of an already linked event, we store the title, start and end, location, and dial-in link of the event concerned for a maximum of 21 days in order to display that suggestion. These suggestions are then deleted automatically. If you do not confirm a suggestion, nothing is transferred into your application data. • Links between your Utably entries and the identifiers of the corresponding calendar events • Events you explicitly import become part of your application data and are subject to the general retention rules of this policy
WRITING TO YOUR CALENDAR: Only if you have granted write permission does Utably create events for your interview rounds and planned steps and keep them current. What is transmitted: the title (type of round and company), a description containing the job title, the topic, and a link to the corresponding application in Utably, the location, and the start and end. Utably does not add any other attendees, does not send invitations, and does not set reminders. If a round is deleted or cancelled, or its date is removed, Utably also deletes the corresponding Utably-created event in your calendar. Events you created yourself and merely linked to Utably are neither overwritten nor deleted; only a rescheduling you explicitly confirm will change their time.
RECIPIENTS: Google Ireland Limited or Google LLC and Microsoft Ireland Operations Limited or Microsoft Corporation are independent controllers with regard to processing within your own provider account. Utably retrieves this data solely on your instruction. Processing within your calendar account is governed by the terms and privacy notices of the relevant provider; this may also involve a transfer to third countries under that provider's own safeguards.
WITHDRAWAL AND DISCONNECTION: You can disconnect the connection at any time in Settings. Doing so deletes the stored tokens and terminates the notification subscriptions with the provider. For Google, we additionally revoke the token directly with Google. Microsoft does not offer such a revocation interface; you can withdraw the permission granted there yourself at any time at account.live.com/consent/Manage. Independently of this, you can review and withdraw your Google permissions at any time at myaccount.google.com/permissions. Events already created by Utably in your calendar remain after disconnection; deleting them is up to you.
GOOGLE API SERVICES USER DATA POLICY: Utably's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google Calendar data solely to provide the features you have requested, do not transfer it to third parties, do not use it for advertising, and do not use it to train generalized AI models. No human reads this data except with your explicit consent, for security purposes (such as investigating abuse), to comply with applicable law, or in aggregated or anonymized form.
Forwarding Job Emails (Mail Intake)
You may forward job alerts, invitations, or rejections to a Utably address (jobs@in.utably.com or your private intake address). We process only mail sent from one of your confirmed sender addresses; everything else is discarded.
WHAT WE PROCESS: subject, sender, body text, links, and up to three PDF attachments of a forwarded mail. The content is evaluated by AI services (AWS Bedrock, EU) to detect the company, role, status (e.g. invitation, rejection), and dates. This also involves third-party data contained in the mail (e.g. a recruiter's name and email address). You are responsible for forwarding only mail you are permitted to use for this purpose.
LEGAL BASIS: performance of the contract (Art. 6(1)(b) GDPR) — processing takes place solely at your instruction, by forwarding. For third-party data we rely on our and your legitimate interest in managing your applications (Art. 6(1)(f) GDPR).
RETENTION: The raw email is deleted automatically within 7 days of processing at the latest. Open suggestions you do not confirm are deleted after 45 days. Confirmed entries (status, date, short excerpt, sender) are stored with the relevant application and follow the general retention rules; you can delete them at any time.
An unambiguous invitation or rejection updates the status of the linked application automatically; you are notified and can change the status at any time. No decision with legal effect is involved.
Interview Live Mode
Interview Live Mode is an optional feature that lets you produce notes in text form during a real job interview, so you can receive an AI-assisted debrief afterwards. The feature starts only after you have actively started it within the relevant interview round and confirmed the notice shown beforehand.
LEGAL BASIS: your consent (Art. 6(1)(a) GDPR), which you give by starting Live Mode and which you can withdraw at any time with effect for the future by ending the session (Art. 7(3) GDPR).
YOUR OWN MICROPHONE ONLY: Only the signal from your own microphone is captured. Utably records neither the audio of the video conference nor your screen, and does not access system or conference audio. Please note that a microphone can technically also pick up sounds in your surroundings — for example if you conduct the conversation over a loudspeaker. We therefore recommend using the feature with headphones.
SPEECH RECOGNITION BY YOUR BROWSER — IMPORTANT NOTICE: The conversion of your speech into text is not performed by Utably but by your browser's speech recognition (Web Speech API). Depending on the browser, your audio signal is transmitted for processing to the speech service of the browser vendor — in Google Chrome to the speech service of Google LLC, which acts as an independent controller in this respect and may also process the data outside the EU. Utably has no influence over this processing; the privacy notices of the relevant browser vendor apply. No audio recording is ever transmitted to Utably itself — our servers receive only the finished text. We do not store any audio data.
TRANSCRIPT AND RETENTION: The recognized text is saved periodically to your Utably account during the conversation so that nothing is lost if the session is interrupted, and is additionally stored locally in your browser. What is stored: the text segments with their time offset from the start, the status, and the start, language, and duration of the session. The server-side transcript is deleted automatically after 30 days at the latest. If you apply the debrief, the transcript is deleted immediately by default — unless you explicitly choose "Keep the transcript", in which case it remains stored with the interview round until you delete it. The local copy in your browser is removed when you complete or discard the session.
AI PROCESSING: At your request, the transcript is transmitted together with the company, job title, type of round, topic, the outcome recorded for the round, your prepared questions and the answers you have stored for them, and your notes to AI services (AWS Bedrock) in the EU, in order to generate a debrief (summary, strengths, areas for improvement, observations, and next steps, each with verbatim supporting quotes from the transcript). Optionally, you can additionally request phrasing help or suggested questions during the conversation; in that case only the most recent portion of the transcript is transmitted. If you apply the debrief, its results are stored in the interview round and as a journal entry.
YOUR RESPONSIBILITY TOWARDS OTHERS: Please note that statutory requirements may apply to taking notes on, or recording, conversations with other people. See the "Interview Live Mode" section of our Terms of Service for details.
De-identified Career Data (Optional)
With your separate consent, we use a de-identified extract of your career data to improve Utably — for example to calibrate benchmarks, cohort insights, and recommendations. Without this consent this processing does not take place; it is switched off by default.
WHAT IS INCLUDED: structured information on education, career steps (title, industry, duration), skills, languages, values and preferences, your personality test results (Big Five factors and facets), and the status and history of your applications. Not included: name, contact details, documents, cover letters, and chat histories.
HOW WE DE-IDENTIFY: direct identifiers (name, contact details, account ID) are removed; your record carries only a random identifier that reveals nothing about you; free-text fields are automatically checked for personal data (AWS Comprehend, EU) and cleaned; company names are reduced to public attributes (industry, size) retrieved from the public Wikidata database (Wikimedia Foundation, USA) — only the company name is transmitted, no data about you. Rare combinations of attributes are coarsened or omitted to reduce the risk that a record can be linked to a person. A separate, access-restricted link between your account and that identifier is kept for one purpose only: to remove your record when you withdraw consent or delete your account. Because that link exists, we treat this dataset as pseudonymised personal data under the GDPR, not as anonymous data, and protect it accordingly (access restricted, stored in our EU infrastructure, never combined with your account data). Only aggregated results derived from it (for example benchmarks) are used in the product.
LEGAL BASIS AND WITHDRAWAL: your consent (Art. 6(1)(a) GDPR), given in Settings → User Data & Exports and revocable at any time. After withdrawal, your record is removed from the de-identified dataset at the next daily run. The dataset is not sold or disclosed to third parties.
Referral Programme and Friends
REFERRAL PROGRAMME: Every account can generate a personal referral code and link. You pass the link on yourself — by copying it, through your device's share sheet, or with the "Invite by email" button, which opens your own mail app with a prefilled message; Utably never sends emails to the people you invite and does not receive or store their addresses for this. If someone creates an account through your link, we record the link between the two accounts, show you the part of their email address before the "@" in your referral history, and apply the discounts described in our Terms of Service through our payment provider. The invited person's account stores the referral code it arrived with. To prevent abuse, we keep the IP address from which referred sign-ups and referral checkouts were made, together with the account addresses used, for 30 days, and limit the number of discounts per referral link and day. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); our legitimate interest in running the programme and preventing abuse (Art. 6(1)(f) GDPR) for the abuse records.
FRIENDS: You can connect with other Utably users through friend codes (opaque codes you hand out yourself and can regenerate at any time) or by entering an email address. For an email invitation we store only a one-way hash and a masked form of the address for 60 days, so that a plain address of a person who is not a user is never retained; the person is notified inside Utably only if they already have an account and can accept or ignore the request — whether an address belongs to an account is never revealed. Once connected, friends see what you deliberately share: your progress signals as far as you have switched them on in Settings → Friends, job postings you send them as tips (employer-published data only: title, company, location, link and text; never your status, notes, salary or contacts), employer help notes you have volunteered, documents or templates you explicitly share (available to the friend for 30 days), practice challenges you join, and milestones you unlock. Every signal has its own on/off setting, and the whole feature can be switched off, which hides you from your friends without deleting the connections. Declining a request is not disclosed to the sender. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for the hashed invitation address, our legitimate interest in enabling invitations without retaining third-party data (Art. 6(1)(f) GDPR). When you delete your account, your connections and the copies of your shares held by your friends are deleted as well.
Legal Bases
For GDPR users, our legal bases include performance of a contract (providing the service), consent (where required, such as certain communications), compliance with legal obligations, and legitimate interests (security, fraud prevention, and service improvement where balanced against your rights).
SOCIAL LOGIN: When you sign in via a social provider, you actively initiate the data transfer by clicking "Sign in with [Provider]". Our legal basis for processing the data received from social providers is performance of a contract (GDPR Article 6(1)(b)) — the data is necessary to create and maintain your account as you have requested. For storing your profile picture on our infrastructure, our legal basis is our legitimate interest in ensuring reliable service delivery (GDPR Article 6(1)(f)), balanced against your right to delete or change the picture at any time via your account settings.
Retention
We retain personal data only as long as necessary for the purposes above. Retention periods vary by system and data type. Where possible, we apply minimization, deletion, or aggregation. You can request deletion via Settings or by contacting support.
BACKUPS: To protect against data loss we take encrypted backups of our databases, of the user directory (account data such as e-mail address and name, never passwords or passkeys), and of the files you upload every day. Backups are stored exclusively in AWS data centres in the EU (region eu-north-1, Stockholm); one copy is kept in a separate, specially hardened AWS account that only we can access, using two-factor authentication. Backups are technically protected against modification and early deletion and expire automatically after 35 days. They serve solely to recover from an outage or security incident; we do not restore individual deleted accounts or content from them. If you delete your account or data in it, residual copies may therefore remain in backups for at most 35 days before they are permanently removed there as well.
Data Retention and Automatic Account Deletion
In accordance with the GDPR storage limitation principle (Article 5(1)(e)), we do not retain personal data longer than necessary. Accounts that have been inactive for 360 consecutive days (approximately twelve months) are automatically and permanently deleted, along with all associated data.
DEFINITION OF INACTIVITY: An account is considered "inactive" when the account holder has not logged in to the Service AND does not have an active paid subscription. Cancelled subscriptions that remain inactive follow the same twelve-month rule.
EXCEPTION FOR PAID SUBSCRIBERS: Accounts with an active paid subscription are never subject to automatic deletion, regardless of login activity. As long as your subscription remains active, your account and data are retained.
RESETTING THE INACTIVITY TIMER: Logging in to your account at any point resets the twelve-month inactivity timer. You do not need to take any other action beyond signing in to prevent automatic deletion.
NOTIFICATION SCHEDULE: Before any automatic deletion occurs, we notify you at the following intervals:
• Month 10 of inactivity: First warning email informing you that your account will be deleted in approximately two months if you do not log in • Month 11 of inactivity: Second reminder email informing you that your account will be deleted in approximately one month • One week before deletion (approximately Month 11.75): Final notice email informing you that your account will be deleted in seven days
All notification emails are sent to the email address associated with your account.
WHAT GETS DELETED: Upon automatic deletion, the following data is permanently removed:
• Your Cognito user account (authentication credentials) • All DynamoDB records associated with your account (user data, profile, settings, preferences, and all stored content) • All S3 files associated with your account (profile pictures, uploaded documents, and generated files) • Stripe customer data (deleted or anonymized in accordance with Stripe's data retention requirements) • Any other data associated with your unique user identifier
This deletion is permanent and irreversible. We cannot recover your data after automatic deletion has been carried out. Residual copies in backups expire automatically after 35 days at the latest (see "Retention").
REQUESTING AN EXTENSION: If you are unable to log in but wish to retain your account, you may contact us at support@utably.com to request an extension of the inactivity period.
Recipients and Processors
We do not sell your personal data, and we will not do so.
We use cloud and infrastructure providers as processors under data processing agreements, including AWS services (Cognito, Lambda, DynamoDB, S3, CloudFront, Bedrock). We use Cloudflare (Turnstile) as a data processor for bot-protection signals collected when you submit public forms such as the contact form and email preference management. We use MediaStack (mediastack.com) as a data processor to provide company news and research features; company names associated with your job applications may be sent to MediaStack to retrieve relevant news articles.
PAYMENT PROCESSING: We use Stripe to sell and process paid plans and one-time purchases. The seller for purchases "Sold through Link" is the Stripe company named at checkout and on your receipt (currently Sold through Link, LLC); payments are processed by Stripe Payments Europe, Ltd., Stripe Technology Europe, Limited and Stripe Payments Company. When you buy a paid plan, Stripe acts as merchant of record and seller and processes your payment details, billing address and contact details as an independent controller for payment, tax calculation and remittance, invoicing, fraud prevention, dispute handling and transaction support under Stripe's own privacy policy (link.com/privacy-center). You can manage your orders, subscriptions and payment details, and request refunds, directly in your Link account (app.link.com) and via Link support. Utably receives confirmation of the purchase, your billing country and the subscription status; Utably does not store full card data. Before you are taken to payment we suggest a billing country: from your profile address or, if none is stored there, from the country our content-delivery network (AWS CloudFront, a processor) derives from your IP address; failing that, from your browser language setting. The suggestion is only a preselection that you change in the order dialog. Your IP address is neither stored for this nor sent to Stripe; your browser receives only the two-letter country code. The legal basis is our legitimate interest in a correct tax and country check before the purchase (Art. 6(1)(f) GDPR).
TRANSACTIONAL EMAIL: We use Amazon Web Services Simple Email Service (AWS SES) as a processor to send system and transactional emails (e.g., system notifications, account-deletion reminders, and replies to contact inquiries). This involves processing your email address and the content of the relevant message.
PRODUCT ANALYTICS (POSTHOG): If you consent via our analytics banner, we use PostHog (PostHog EU) as a processor for product analytics and sampled session replay. PostHog is activated only after you opt in via the cookie banner. Hosting is in PostHog's EU cloud (eu.i.posthog.com); there is no transfer to the United States.
GOOGLE MAPS (OPT-IN EMBEDS): If you opt in to "Embedded maps & content" in our cookie preferences, we embed Google Maps (provided by Google LLC, USA) in the application detail and interview calendar pages so you can see locations of offices and interview venues. When you open such a page after opting in, your browser sends your IP address, request data, and basic device signals to Google in the United States. Google may set its own cookies via the embed. Google acts as an independent controller for the data it receives via the Maps embed; data flows are governed by the Google Maps Service Specific Terms and Google's privacy policy (policies.google.com/privacy). Until you opt in, Utably renders a click-to-load placeholder and no map data is sent to Google.
CALENDAR PROVIDERS: If you connect your calendar, we retrieve event data from Google or Microsoft and — where you have permitted it — write events into your account there. These providers are independent controllers for the processing within your own calendar account. For details, see the section "Calendar Connection (Google Calendar and Microsoft Outlook)".
SPEECH RECOGNITION (INTERVIEW LIVE MODE AND DICTATION): In Interview Live Mode and when using the dictation function, the conversion of your speech into text is performed by your browser's speech recognition and therefore, where applicable, by the browser vendor's speech service (in Google Chrome: Google LLC; in Safari: Apple) as an independent controller. We have no data processing agreement with that provider and no influence over this processing; no audio material is transmitted to Utably. See the section "Interview Live Mode".
SOCIAL LOGIN PROVIDERS: If you choose to sign in via Google, Microsoft, Facebook, or LinkedIn, those providers act as independent data controllers for the authentication process on their platforms. We receive data from these providers only when you initiate a sign-in. Profile pictures received from social providers are stored in AWS S3. We do not share your Utably data back with social providers. For details on how these providers handle your data, refer to their respective privacy policies.
THIRD-PARTY APPLICATION WEBSITES: If you use the browser extension to fill an application form, upload a document, or insert captured text, the data concerned reaches the operator of that website — typically an applicant tracking system provider (e.g. Greenhouse, Lever, Ashby) and the employer using it — at the moment you submit the form. Those operators and employers are independent controllers for that data. We have no data processing agreement with them, no control over how they use the data, and no access to what you submit; their own privacy notices apply. Depending on the provider, this can also involve a transfer of your data outside the EU/EEA under that provider's own safeguards. Utably does not select these websites for you and never submits a form on your behalf.
A list of subprocessors may be made available on request.
International Transfers
If we transfer personal data outside the EU/EEA, we apply appropriate safeguards such as Standard Contractual Clauses and technical and organizational measures.
US TRANSFERS VIA GOOGLE MAPS: When you opt in to embedded maps, your IP and request data are transferred to Google LLC in the United States. Google LLC is certified under the EU-US Data Privacy Framework, recognised by the European Commission as providing an adequate level of protection (Adequacy Decision of 10 July 2023). You can withdraw this consent at any time by re-opening the cookie preferences from the footer or your account settings.
CLOUDFLARE (TURNSTILE): Cloudflare, Inc. is a US provider. When you submit public forms, data may be transferred to Cloudflare in the United States. These transfers are safeguarded by Cloudflare's certification under the EU-US Data Privacy Framework and by standard contractual clauses.
POSTHOG: PostHog product analytics are hosted in PostHog's EU cloud (eu.i.posthog.com). There is no transfer to a third country.
AWS: Processing in our core infrastructure takes place in the AWS eu-north-1 (Stockholm) region, as stated elsewhere in this policy. AI model invocations run through EU inference profiles within the European Union.
CALENDAR CONNECTION: If you connect your calendar, we access the account you hold with Google or Microsoft. Processing within that account is carried out by the relevant provider as an independent controller and may, under that provider's own safeguards, also take place outside the EU/EEA. Google LLC and Microsoft Corporation are certified under the EU-US Data Privacy Framework. You are free not to establish the connection, or to disconnect it at any time.
SPEECH RECOGNITION (INTERVIEW LIVE MODE AND DICTATION): If you use Interview Live Mode or the dictation function, your browser transmits your audio signal to its vendor's speech service; in Google Chrome this is Google LLC in the United States, in Safari it is Apple. This transmission is carried out by your browser and not by Utably; we have no influence over it. If you wish to avoid this transmission, do not use Interview Live Mode and type your input instead of dictating it.
Your Rights
You may have rights to access, correct, delete, restrict, or export your personal data. You can also withdraw consent at any time where applicable. To exercise rights, use in-app controls or contact support.
Right to Object (Art. 21 GDPR)
You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data that is based on our legitimate interests (Art. 6(1)(f) GDPR). If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing serves the establishment, exercise, or defence of legal claims. To exercise your right to object, an informal message to support@utably.com is sufficient.
CONNECTED SERVICES AND LIVE MODE: You can withdraw your consent to the calendar connection at any time by disconnecting it in Settings; the stored tokens are deleted in the process. You can delete a transcript created in Interview Live Mode at any time from the interview round concerned.
SOCIAL LOGIN DATA: You can manage data received from social providers in your account settings. You can change or delete your profile picture, update your name, and manage linked social identities at any time. Deleting your Utably account will delete all associated data, including any profile pictures downloaded from social providers.
SUPERVISORY AUTHORITIES: You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority competent for us is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte, datenschutz.sachsen.de), as our registered office is in Leipzig. You may alternatively contact the supervisory authority in your EU/EEA country of residence; a list is available at edpb.europa.eu.
Security
We implement technical and organizational measures to protect personal data, including access controls, encryption in transit and at rest, least-privilege policies, and encrypted, tamper-protected backups held in the EU. No method of transmission or storage is perfectly secure, but we strive to protect your data appropriately.
PASSKEYS (PASSWORDLESS SIGN-IN): You may optionally switch your account to signing in with a passkey (WebAuthn). Your device generates a key pair; our authentication service (AWS Cognito) stores only the public key, the credential identifier, the domain the passkey is bound to, a name you choose, and the creation date. Your private key never leaves your device. Biometric data (fingerprint, face recognition) is verified locally by your device only, is never transmitted to Utably, and is not made accessible to us — we merely receive confirmation that verification on your device succeeded. If you enable passkey-only sign-in, the password held for your account is rendered unusable. As a recovery path, we send a one-time sign-in code by email (AWS SES) to the address associated with your account. You can add or remove passkeys at any time in your security settings.
Children's Data
Utably is not directed to children under 16. You must be at least 16 to create an account; users aged 16 or 17 need the consent of a parent or guardian and may use only the free features. You must be at least 18 to buy a paid plan or a top-up.
We have designed the Service with privacy-protective defaults following the principle of data protection by design and by default (GDPR Article 25), taking into account the special protection of minors. We minimize data collection, use high privacy settings by default, and do not use techniques that encourage users to provide more personal data than necessary.
If you believe a child under 16 has provided personal data without appropriate consent, please contact us so we can take appropriate action.
Changes to this Policy
We may update this policy to reflect product or regulatory changes. We will update the effective date and, when required, provide additional notice.
Contact
Questions about this policy? Contact us at support@utably.com or via the Contact page.