1. Who We Are
gotfaangd.ai is operated by Karma Labs LLC, a software company. When this policy refers to "we", "us", or "our", it means Karma Labs LLC. When it refers to "you" or "your", it means the individual using our Service.
For privacy inquiries or to exercise your rights, contact us at: privacy@gotfaangd.ai
2. What Data We Collect and Why
We collect only the data necessary to deliver the Service.
2a. Account & Identity Data
- Email address — provided by Google or Microsoft OAuth at sign-in.
- OAuth profile metadata — name and profile picture from your identity provider.
2b. Career Profile Data
- Current role, target role, experience level, key skills — entered during onboarding.
- Resume text — extracted from a PDF you upload. Used to generate interview strategies, tailored resumes, and STAR stories. We do not share your resume with third parties for any purpose other than AI processing on your behalf.
2c. Interview Preparation Data
- Target companies, prep plans, STAR story bank, practice session transcripts and AI feedback — stored to power your prep workspace and progress history.
2d. Usage & Analytics Data
- AI feature usage logs — action type and timestamp, used solely to enforce your plan's usage quota.
- Login timestamps and login count — used for security monitoring.
2e. Billing Data
- Billing plan and status — stored to gate premium features.
- Stripe Payment Intent ID — stored to support refund requests. We never store card numbers, CVV, or bank account details.
2f. Consent Records
- Terms and cookie consent records — retained as a legal audit trail.
2g. Feedback
- Bug reports and feature requests — used only to improve the product.
3. How We Use AI
Our Service uses Google Gemini to generate interview prep plans, tailor resumes, extract STAR stories, and provide coaching feedback. When you trigger an AI feature, relevant portions of your data are transmitted to Google's API servers for processing. We do not use your data to train any AI model.
4. Legal Basis for Processing (GDPR)
- Contract performance — processing necessary to deliver the Service.
- Legitimate interests — usage logging for quota enforcement and security monitoring.
- Consent — for non-essential cookies and any processing you explicitly opt in to.
- Legal obligation — retention of billing and consent records as required by applicable law.
5. How We Share Your Data
We do not sell, rent, or trade your personal data. We share data only with: Supabase (database/auth), Google Gemini API (AI processing), and Stripe (payments). No other third parties receive your personal data.
6. Data Retention
- Account data: deleted within 30 days of account deletion.
- Billing records: retained for 7 years as required by financial regulations.
- Consent records: retained for 3 years as a legal audit trail.
- AI usage logs: retained for 13 months for quota tracking, then purged.
7. Your Rights
To exercise any right, email privacy@gotfaangd.ai. We will respond within 30 days.
Rights include: Access, Rectification, Erasure, Data Portability, Restrict Processing, Object, Withdraw Consent, Lodge a Complaint.
California Residents (CCPA): We do not sell personal information.
8. Cookies
- Strictly necessary cookies — authentication session tokens. Cannot be disabled.
- Preference cookies — UI preferences in localStorage.
- Analytics cookies — only set if you accept optional cookies in the consent banner.
9. Data Security
All data transmitted over HTTPS (TLS 1.2+). Row-Level Security ensures users access only their own data. Authentication via OAuth — we never store your password. Payment processing via Stripe — we never handle card numbers.
10. Contact Us
- Email: privacy@gotfaangd.ai
- Company: Karma Labs LLC