Privacy Policy

Your information, explained plainly

How StrongHire Labs collects, uses, stores, and shares personal information across its career preparation services.

Effective and last updated: 25 August 2026

On this page

Who we are and what this policy covers

StrongHire Labs is the name used for this online project. The service is currently operated by an individual in Victoria, Australia, and is not an incorporated company or a registered business name. In this policy, “StrongHire Labs”, “we”, “us”, and “our” refer to that operator.

This policy explains how personal information is handled through our public website, accounts, resume and cover-letter tools, job and application tools, Hiro career assistant, AI interview practice, browser extension, social features, support, security, and credit usage.

The Health Records Act 2001 (Vic) and its Health Privacy Principles can apply to health information handled by a private-sector operator in Victoria regardless of annual turnover. Whether the Privacy Act 1988 (Cth) and Australian Privacy Principles apply depends on the operator's activities and the statutory exceptions. We use the Australian Privacy Principles as a baseline where practicable, but do not claim that a small-business exemption applies to every activity or that the operator has formally opted into that Act.

The project has not completed its controls for unsolicited health information or every interstate and overseas health-information transfer. Do not submit health or disability information or medical details. Nothing in this policy limits duties imposed by applicable privacy or health-records law.

Privacy contact: [email protected]. The operator and service are based in Victoria, Australia. A legal name, telephone number, and postal contact have not yet been published.

Personal information we collect and create

  • Account and profile information: username, email address, password hash and authentication records, role, account settings, legal-document versions and acceptance time, profile bio, location, and other profile details you add.
  • Career and application information: uploaded resume files, extracted resume text, employment and education history, skills, career goals, job descriptions and links, applications, stages, notes, hiring-manager details, and generated resumes, cover letters, answers, evaluations, and suggestions.
  • Interview information: interview settings, resume and role context, microphone audio while it is processed live, messages and transcript, session metadata, and AI-generated scores, summaries, strengths, and suggested improvements.
  • Hiro assistant information: your prompts, AI replies, thread titles and message metadata. We also create and store account-specific profile, experience, tone, and memory notes, limited excerpts from past turns, and locally generated numerical lexical vectors used to retrieve relevant past context.
  • Social information: exact username or email search input, search results, connection requests and connections, relationship and mutual-connection information, profile details visible to connected users, connection dates, and your social discoverability choice.
  • Browser-extension information: the URL and host of the current tab, job title, company, job description, extraction method, your signed-in email or username, resume filenames, the resume and preferences you select from your account, draft applications, generated cover letters and answers, and a limited event recording the job board and extraction method.
  • Credit usage: daily and monthly allocations, remaining balances, reset dates, feature uses, restoration of credits for failed operations, and technical records used to prevent duplicate deductions. The current validation launch does not request payment or card details and does not offer a paid subscription.
  • Communications: support requests, product feedback, privacy or deletion requests, and emails sent to or from you, including verification and password-reset messages.
  • Technical and security information: IP address, browser and device details, identifiers, requested paths, request and response times, account and session IDs, bot-challenge results, service events, errors, diagnostics, and security events. Error logs can exceptionally include a short fragment of content involved in a failed AI response.

AI outputs, scores, summaries, inferred profile details, memories, and retrieval vectors can themselves be personal information because they relate to your account or career history.

How we collect and hold information

We collect information directly when you register, complete forms, upload files, speak during an interview, use Hiro or other tools, connect with another user, or contact us. We collect some information automatically through browser storage, essential cookies, service requests, security checks, and operational logs. We also derive information through AI analysis and collect job-page content from a link when you ask the service to process that page. While its side panel is open, the browser extension locally reads the active tab URL and host when the panel opens or the active tab changes so it can identify a supported site and update its badge. It does not transmit that URL at this stage. It captures page content, including the job title, company and description, only after you select “Read this page” and grant any permission requested by Chrome.

Our primary application databases, uploaded files, and operational monitoring systems are hosted on privately operated infrastructure in Australia. Some information is also stored in your browser and is processed or held by the external providers described below. We do not publish the physical server location or network topology.

At the effective date of this policy, the project does not maintain a separate backup system for application databases or uploaded files. This creates a risk that information cannot be restored after hardware failure, corruption, deletion, or another incident. Keep your own copy of important resumes, applications, transcripts, and generated documents.

Chrome browser extension

The extension lets you capture a job advertisement visible in your current tab and create a draft application. While the side panel is open, it locally checks the active tab URL and host when the panel opens or the active tab changes to identify supported job sites and update its badge. It does not transmit that URL merely because of this check. When you select “Read this page”, it uses Chrome's active-tab and scripting capabilities to capture the job title, company, description, page URL, and extraction method. It does not continuously monitor browsing history or capture page content before that action. For a site outside the listed job boards, Chrome asks you to grant access first.

The extension sends the captured job fields to StrongHire Labs when you save the draft and sends the job board and extraction method as an operational metric. If you request a cover letter or screening answer, it retrieves the resume and preferences you selected from your account and sends the relevant job, resume, question, and saved tone information to our service and DeepSeek to generate the result. It does not submit a job application to an employer.

The extension does not receive your password. It uses the existing StrongHire Labs sign-in cookie to request a short-lived access token, which is stored in Chrome session storage and cleared when the browser session ends. Theme and environment preferences are stored in local extension storage. The downloads permission is used only when you ask to save a generated cover-letter PDF.

When a signed-in user opens the panel, before selecting “Read this page”, the extension exchanges the existing sign-in cookie for an access token, displays the account email or username, and retrieves resume filenames to populate the resume selector. It does not retrieve the selected resume's content until a feature needs that content.

We collect and disclose information obtained through extension permissions for the user-requested job-capture, application, document and answer features, related security and support, or legal compliance. We do not sell it or use it for personalised advertising. External AI provider retention and model-improvement handling remains subject to the qualifications in the AI section. The same access, correction, retention, deletion, provider, and overseas-processing provisions in this policy apply to information saved through the extension.

Sensitive, health, and third-party information

These career tools are not intended to collect health information, disability details, identity documents, financial account details, biometric templates, criminal records, union membership, political or religious beliefs, sexual-orientation information, or other sensitive information. Do not include that information in a resume, job record, Hiro message, interview answer, or support request.

A privacy-policy acknowledgement is not consent to collect sensitive information. If a future feature genuinely needs sensitive or health information, we will provide a specific notice and seek express, informed consent where required before collection. The current service does not automatically identify, quarantine, or delete unsolicited sensitive or health information. If the operator becomes aware of such information, the operator will assess it and take the steps required by applicable law, which may include restricting further processing, deletion, or de-identification. Email the privacy contact promptly if you submitted it by mistake.

Do not provide another person’s resume, contact details, referee or hiring-manager information, messages, or other personal information unless you have authority and a legitimate reason to do so. We may use that information only for the feature you requested and related security, support, and legal purposes.

Why we use personal information

  • create, verify, secure, and administer accounts;
  • store and process resumes, job applications, career records, and documents you ask us to generate or review;
  • run voice interviews, create transcripts, and generate practice questions, feedback, summaries, and scores;
  • provide Hiro conversations, relevant past context, and account-specific memory and personalisation;
  • provide search, connection, and limited social features;
  • allocate, display, consume, and restore free usage credits;
  • send service, verification, security, and support communications;
  • diagnose faults, monitor reliability, prevent misuse, and protect users and systems; and
  • investigate complaints, enforce applicable terms, resolve disputes, and meet legal obligations.

AI, speech, and voice providers

The current service uses the following providers:

  • DeepSeek processes resume, cover-letter, job, application, Hiro, memory, and interview context to generate, structure, summarise, or analyse text.
  • Google Gemini converts short excerpts of your Hiro chat exchanges into numerical vectors so that Hiro can find relevant earlier conversations. Each excerpt holds up to roughly 600 characters of your message and 600 characters of Hiro's reply. Gemini is used for this retrieval step only and does not generate text for you.
  • Deepgram processes microphone audio into text and, for all current interviewer voices, text into speech. Current requests opt out of Deepgram’s Model Improvement Program, but an Australian processing endpoint is not currently configured.
  • LiveKit Cloud operates the real-time voice room and media transport. Agent-observability upload of session audio, transcripts, traces, and logs is disabled, but LiveKit still processes live media and operational information needed to provide the room. Participant tokens do not include raw job, resume, interview, or focused-notice context. The voice agent retrieves authorised session context separately from our orchestration service.

Provider retention and model-improvement practices depend on our provider agreements, account tiers, and settings. The current DeepSeek configuration does not establish a verified contractual zero-retention or no-training commitment, and its public terms do not establish an API-specific promise for downstream end-user content. Provider handling may therefore include retention or model improvement under the applicable provider terms. Do not submit sensitive or confidential information to an AI feature.

We do not use AI feedback to make an employment decision. Generated content, scores, and suggestions may be inaccurate, incomplete, or biased. Review them before use and do not treat them as professional advice or a guarantee of a career outcome.

What happens during an AI interview

Your microphone audio is transmitted through LiveKit and processed by Deepgram in real time so speech can be converted to text and the voice interviewer can respond. We do not store raw microphone audio in StrongHire Labs application storage, and LiveKit agent-observability upload is disabled. This does not mean providers process no transient media or operational data.

The current camera preview remains local to your browser. It is not published to the LiveKit room, received by the interview agent, or stored by StrongHire Labs. If video handling changes, we will update this policy and the interview notice before enabling it.

The transcript, interview settings, role and resume context, and AI feedback are saved to your account. When a session ends, the transcript and context are sent to DeepSeek for evaluation. Before a session begins, the interview screen asks you to confirm the focused voice and AI-processing notice. You can choose not to start, or stop the session to end further microphone collection.

Social search and profile visibility

Accounts are hidden from user search by default. You can enable social discoverability in Account Settings. While enabled, a signed-in user who already knows your exact username or email address can find your account and send a connection request. The search uses an email only to locate the account and returns the account ID and username, never the account email.

Connected users can see limited profile information, including username, bio, location, account age, and connection date. Connection requests, relationship status, and mutual-connection counts are also shared where needed to operate the feature. Do not put information in your profile that you do not want connections to see. You can remove a connection using the available controls. Turning discoverability off hides the account from new searches but does not remove existing connections.

When we disclose information

We disclose only the information reasonably needed to operate a feature, secure the service, process a request, or meet a legal obligation. Recipients include:

  • the AI, voice, speech, and real-time providers listed above;
  • Cloudflare, which provides DNS, TLS termination, reverse-proxy and content-delivery services, network and security reporting, abuse protection, and Turnstile. Depending on the request, Cloudflare can process IP address, URL, host and path, request headers, user agent, browser, device and network signals, timing and security telemetry, challenge tokens, and content carried through its proxy;
  • Google and Gmail, which process recipient email addresses and email content used for verification, password reset, support, and other service messages, and serve website fonts;
  • other users as described in the social-features section;
  • professional advisers, regulators, courts, law-enforcement bodies, or other recipients where required or authorised by law or reasonably necessary to establish, exercise, or defend legal claims; and
  • a genuine buyer, investor, or successor if the service or business is reorganised, financed, or transferred, subject to appropriate confidentiality and legal safeguards.

Overseas processing and disclosure

Primary StrongHire Labs application storage is in Australia, but use of the service can send personal information overseas. Likely locations include:

  • the People’s Republic of China for DeepSeek processing;
  • the United States for some LiveKit, Deepgram, Google (including Gemini AI processing), Gmail, and Cloudflare operations; and
  • other countries used by the global subprocessor networks of LiveKit, Google, Gmail, and Cloudflare.

Exact locations can depend on provider account settings, routing, and subprocessors. No Australian region pinning has been verified for the current LiveKit or Deepgram configuration. Where Australian privacy law applies to an overseas or interstate transfer, we must have an applicable legal basis and take the steps required by that law. A general acknowledgement of this policy does not itself provide consent for every transfer of sensitive or health information.

Cookies and browser storage

We use an essential HttpOnly refresh-token cookie with a lifespan of up to seven days to maintain your sign-in session. A short-lived access token is stored in session storage. Basic cached account details and interface preferences, such as theme, navigation, panel, and filter settings, are stored in local storage.

These are functional storage technologies, not advertising cookies. Cloudflare's edge, security, network-reporting, and Turnstile services may use HTTP headers, challenge tokens, cookies, and browser, device, or network signals as applicable. Google Fonts also receives ordinary web-request information when a font is loaded. You can clear browser storage through your browser, but doing so may sign you out or reset preferences.

We do not currently run Microsoft Clarity or another session-replay analytics tool. If analytics or advertising tracking is introduced, we will update this policy and provide any notice or choice required before enabling it.

How long information is kept

Account, career, application, interview, and Hiro content is generally kept while your account is active and the information is needed to provide the requested features. Archiving a Hiro conversation hides it from the active list but does not delete it. We do not store raw microphone audio or camera video in StrongHire Labs application storage.

Operational metrics are configured for about 30 days and distributed traces for about seven days. Application logs do not yet have an automatic deletion schedule and remain until manually deleted. Logs may be retained longer where reasonably needed to investigate an incident, prevent fraud, resolve a dispute, or meet a legal obligation.

Gmail retains sent service emails until they are deleted from the account. Other providers keep information under their own retention requirements, including records needed for security, fraud prevention, disputes, and legal compliance. AI provider retention and model-improvement handling is described in the AI section and must not be assumed to end when local account content is deleted.

Where applicable law requires it, we will take reasonable steps to destroy or de-identify personal information that is no longer needed, unless it must or may lawfully be retained. The current deletion process is manual and does not support a promise of immediate or complete erasure from every log, provider, or legally retained record.

How we protect information

We use password hashing, access controls, authenticated service requests, encrypted web transport, bot and abuse protection, and separation between public and protected application features. We also minimise interview media by keeping the camera preview local and disabling LiveKit agent-observability recording.

No online service can guarantee absolute security or availability. Do not upload sensitive, confidential, or irreplaceable material. If you believe your account or information has been compromised, contact us promptly at [email protected].

Access, correction, account closure, and deletion

You can update available profile information through your account. You may ask for access to or correction of personal or health information we hold by emailing [email protected]. We may need to verify your identity, and a lawful exception may apply to part of a request. If we refuse a request, we will explain why where required.

Account closure and deletion are currently handled manually by verified request to [email protected]. The current workflow is best-effort and may require separate follow-up across services and providers. Removing the main account record may not immediately remove every underlying uploaded file, separate service record, provider copy, or log. We will assess a verified request and take the steps required by applicable law, subject to information that must or may lawfully be retained. We do not promise immediate or complete erasure from every location.

The current free-validation launch does not create a subscription. Account closure does not itself cancel any legacy Stripe subscription. If you used earlier paid functionality, ask us to confirm its status before closing the account.

Service and marketing communications

We send verification codes, password resets, security messages, service notices, and replies that are necessary to operate your account or answer your request.

We will not treat account creation as agreement to unrelated marketing email. If optional marketing is introduced, it will use a separate choice and include a way to unsubscribe, subject to messages that are still necessary for your account.

People under 18

The service is intended only for people aged 18 or older, and we do not knowingly invite people under 18 to create an account. We do not use age-verification documents in the current registration process.

If you believe a person under 18 has provided personal information, contact us so we can investigate and take appropriate steps, including restricting the account or deleting information where required.

How to raise a privacy concern

Email [email protected] with the subject “Privacy complaint”. Describe what happened, the information involved, and the outcome you seek. We will acknowledge the complaint and aim to provide a substantive response within 30 days, or tell you if more time is reasonably needed.

If you are not satisfied after raising the matter with us, and the relevant law is within its jurisdiction, you may contact the Office of the Australian Information Commissioner. For a complaint about health information handled in Victoria, you may also contact the Victorian Health Complaints Commissioner.

Changes to this policy

We may update this policy when our information handling, providers, or legal obligations change. We will update the effective date and provide a prominent notice where a change materially affects how career, interview, social, or other personal information is handled. Where consent is legally required for a new use, an updated policy alone will not replace that consent.

Privacy contact: [email protected]

Back to top