Privacy Policy
Last updated: May 2026
1. Introduction
Welcome to Debri ("we", "us", or "our"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform at debri.app (the "Service").
By using Debri, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our Service.
2. Data We Collect
We collect the following types of data:
- Account information: Email address and password (stored securely via Supabase Auth).
- Profile information: Your name and professional background, which you provide voluntarily to personalize AI features.
- Interview recordings: Video and audio recordings you upload or record through the platform.
- Interview data: AI-generated analysis, scores, and feedback based on your recordings.
- Pipeline data: Job application details, company names, roles, and notes you enter.
- Research sessions: Chat conversations with our AI research assistant.
- Simulation sessions: Voice transcripts, AI responses, and feedback from interview simulations.
- Usage data: Basic technical data such as browser type and pages visited, for improving the Service.
3. How We Use Your Data
We use your data solely to provide and improve the Service:
- To authenticate your account and keep it secure.
- To power AI features — analysis, research, and simulation — using your input as context.
- To display your history, scores, and progress within the platform.
- To respond to your messages and support requests.
- To improve our product based on aggregate, anonymized usage patterns.
We do not sell your data. We do not use your data for advertising purposes.
4. Third-Party Services
To provide the Service, we share certain data with trusted third-party providers:
- Supabase — Database and authentication infrastructure. Your account data, interview data, pipeline, and research sessions are stored on Supabase servers. See Supabase Privacy Policy.
- Anthropic (Claude) — AI analysis and simulation responses are powered by Anthropic's Claude API. Text you enter or that is transcribed from your sessions may be sent to Anthropic for processing. See Anthropic Privacy Policy.
- OpenAI (Whisper & TTS) — Audio from interview simulations is transcribed using OpenAI's Whisper API. Text-to-speech is powered by OpenAI's TTS API. See OpenAI Privacy Policy.
- Resend — Used to send transactional emails (e.g., contact form confirmations). See Resend Privacy Policy.
5. Data Retention
We retain your data for as long as your account is active. If you delete your account, all your personal data — including recordings, pipeline entries, research sessions, and simulation history — is permanently deleted from our systems within 30 days.
6. Your Rights (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access: Request a copy of the data we hold about you.
- Right to rectification: Request correction of inaccurate data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data.
- Right to restriction: Request that we limit how we process your data.
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to object: Object to processing of your data in certain circumstances.
To exercise any of these rights, please contact us via our contact form. We will respond within 30 days.
7. Cookies
We use essential cookies solely for authentication purposes (to keep you logged in). We do not use tracking, advertising, or analytics cookies. You can disable cookies in your browser settings, but this will prevent you from logging in to the Service.
8. Data Security
We take reasonable technical and organizational measures to protect your data against unauthorized access, loss, or misuse. All data is transmitted over HTTPS. Access to your data is restricted by row-level security policies — only you can access your own data. However, no method of transmission over the internet is 100% secure.
9. Children's Privacy
Debri is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the platform or by email. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please reach out via our contact form.