1. What information this service handles
- The content you enter: resume text, story-bank entries, opportunity and interview records, job descriptions you paste in, and the notes and scripts you write.
- Account information: the email address you sign in with. Passwords are not stored in plain text; sign-in is handled by Supabase.
- Local preferences: interface language, theme, and layout settings.
- Student-eligibility information: the account email, institution, country or region, current-student or recent-graduate category, enrollment month, expected or actual graduation month, review status and notes, and eligibility expiry date. Applicants in mainland China may submit the 16-character online verification code for a CHSI Online Verification Report or submit enrollment evidence. For an institution outside mainland China whose authoritative record contains a verifiable domain, you may verify an institutional email matching that institution. The system activates student pricing automatically after the code is verified and the study dates satisfy the eligibility rules. If institutional-email verification is unavailable, you may upload an enrollment letter, valid student card, recent transcript, graduation record, or similar evidence. Email codes are not stored in plain text. Once verified, only a hash, domain, and masked address are retained. CHSI codes are encrypted, and evidence files are held separately in private object storage accessible only to authorised administrators.
- Referral and reward records: referral codes, the internal account identifiers of inviter and invitee, link time, first-real-task status, eligible purchase family, reward amount, and settlement status.
- Payment and entitlement records: SKU, amount, currency, order status, and the order, customer, subscription, and transaction identifiers returned by the payment provider, as well as tax, provider fee, refund, chargeback, entitlement, and credit-lot records. A provider may also return the buyer email and country or region. Greenroom does not store payment credentials.
- Usage and billing records: for metering and billing, the server records the number of calls and the volume of use per feature, per day. Each time credits are charged it also writes one ledger entry: the name of the action, the time, the amount charged, the balance remaining, and an identifier for the feature the charge relates to.
- Cost-attribution records: to calculate service cost and contribution margin, the server records an internal account identifier, provider, model, feature, call time, credits, and actual or estimated cost. These records contain no resume, job description, conversation, audio, or model-output text.
- Operational records: to diagnose faults and improve this service, the server records each run of the service's own features: which feature it was, whether it succeeded or failed, how long it took, and which category the failure falls into (for example timeout, rate limit, incomplete arguments). These records contain none of the content you enter or receive — no resume text, no conversation text, no job descriptions, no file names; every field reported takes one of a fixed set of values, and none is free text. These records are kept for 90 days and then deleted automatically.
- Feedback you choose to send: when you submit feedback in the app, the text you write is stored along with the time you sent it, so that we can read it one entry at a time. It is not aggregated. What you write is up to you — please do not include anything you would not want read.
- This service does not use advertising trackers, does not integrate third-party analytics services, and does not track you across sites. The records above are used only for metering, billing, diagnosing faults, and improving this service.
2. Where that information is stored
- Your workspace belongs to your account. You must sign in before entering the product. Resume, opportunity, story, and interview data is stored in a cloud database provided by Supabase for use across devices. No other user can read your data; the operator and hosting provider can still technically access the database contents.
- Browser working cache. While you are signed in, the browser caches a working copy for responsive editing and recovery from network interruption. This is not an anonymous-use mode and is not the workspace's sole durable store. Account data cached in the browser is cleared when you log out.
- Your credit balance and charge records, payment and entitlement records, student status and review records, referral and reward records, cost attribution, operational records, feedback, and the page snapshot behind a resume share link are stored in a cloud database provided by Cloudflare, held separately from the workspace data above.
- Student eligibility evidence files are held in Cloudflare private object storage. They have no public link and can be read only by an authorised administrator using the authenticated review page.
- Resume exports (PDF, text, JSON) are generated on your own device and do not pass through this service's servers.
- The cloud data above is stored in the United States. Section 3 sets out what is transmitted when you use an AI feature.
3. When content leaves this device
The following send content beyond this device. Each is initiated by you, and only the content required to complete the operation is sent.
- Model provider: models are supplied by third-party providers selected by this service. When you use an AI feature, this service's server sends the provider the content required to complete the operation, and does not store the contents of the request. A provider may be located inside or outside mainland China; the providers currently in use, and the regions they are in, are listed in section 8.
- Images you paste into a conversation: forwarded by this service's servers to a model provider capable of reading images, in order to obtain the text they contain; that text is then handled as above. The request contains only the image and your question — no resume text and no conversation history. The image itself is not stored by this service and is not written into the conversation record; it is gone once you close the page. Note that images may contain other people's information (a name and email address in a screenshot of a message, for example) — please check before sending.
- How the live assistant picks up audio: there are three ways. With your computer's speakers, or with an audio-routing tool such as a virtual audio device, the audio comes from the input device you choose. If you pick the browser tab the call is in, or share your entire screen in order to capture system audio, the browser first asks you to authorise screen sharing, and that authorisation technically covers the picture as well as the sound. This service uses only the audio track: the video track is stopped the moment it is handed over, is never processed, is never recorded, never leaves this device, and is never sent to any third party. If you would rather not grant that permission, use your speakers or a virtual audio device. What then happens to the audio is set out in the speech-transcription item below.
- Speech transcription: the live assistant can transcribe in three ways. With hosted transcription (signed in), audio is relayed over an encrypted connection through this service's server to a speech-recognition provider, processed in real time, and returned as text; this service stores neither the audio nor the transcript. To improve recognition of company, product, and technical names, the browser extracts a limited set of short terms and brief context from the current opportunity materials and sends them temporarily with the hosted-transcription connection. It does not send the complete resume, job description, or story bank to the speech-recognition provider for this purpose. When a transcript is used to generate a prompt, the model-provider item above applies. With the browser's built-in speech recognition, audio is processed by the browser vendor's cloud.
- Resume sharing: when you generate a share link, the browser renders the resume as currently laid out into a read-only page and uploads it to this service's server, which returns a public short link. Anyone holding the link can open it without signing in, so send it only to people you are willing to show the resume to. A link expires after seven days by default, and you may revoke it manually at any time.
- The browser extension (optional): once installed it can do two things, both started by you from within this service. First, updating your application progress: it reads mailbox pages you already have open and signed in to, or opens an opportunity's status page in the background and reads the text on it; that text is sent with the request to the model provider, which determines the stage reached. Second, filling in application forms: it reads the field labels and options on the job site's form and sends them, together with the name, contact details and resume content held in this service, to the model provider, which proposes what to enter in each field; the extension then enters those values into the site's form and uploads the resume file this service generates for that opportunity. Fields covering gender, ethnicity, political affiliation, marital or family status, health, and identity-document numbers are always left blank, as are consent checkboxes and verification codes. The extension never submits for you — you submit on the site yourself. What you enter and submit is then handled by that job site under its own privacy policy. To do either of these, the extension also reads the URLs and titles of the tabs you currently have open, in order to find the mailbox and recruiting-system pages among them. That list passes only between your browser and this service's page; it is not uploaded to any server and is not used for anything else.
- Mailbox connection (optional): with your authorisation, this service reads only the message metadata and body excerpts needed to identify interview progress and passes them to the model to interpret. Attachments are not downloaded, and no mail is sent. You may withdraw the authorisation at any time in your Google account settings.
- Payment providers (only when you pay): depending on region, currency, payment method, and availability, Greenroom may present Paddle, Creem, Afdian, or another provider. Your card number, payment password, and WeChat Pay or Alipay credentials are submitted only to the provider that handles checkout and do not pass through or rest with Greenroom. The provider returns order or transaction identifiers, SKU, amount, currency, tax and refund status, and its customer, subscription, buyer-email, and country or region data. Greenroom uses this information to activate access, manage subscriptions, process refunds, and reconcile payments. Section 5 of the Terms of Service contains the corresponding rules.
- Student eligibility verification (only when you apply for student pricing): institution search may send the institution name you enter to ROR to return or enrich an authoritative organisation record. No account identifier, email address, or evidence is included in that query. If you choose to verify a school email, Resend is used only to send a one-time code to that address. Eligible applications outside mainland China are approved automatically after successful code verification. If you submit a CHSI code, Greenroom first checks the report's validity, institution, study dates, and enrollment or qualification status on the official CHSI page. Approval is automatic only when those details match completely. A page that requires an additional challenge, is incomplete, or differs from the application is referred to an authorised administrator and is never automatically rejected. The report page is processed only during verification, its contents are not stored, and no AI model is used to make this decision. Evidence files are read only within Greenroom's authenticated administrator review page and are not sent to ROR, model providers, or payment providers.
How these providers handle data is governed by their own terms, which this service cannot undertake on their behalf.
4. What you can do
- Export: in Settings, "Export my data" exports everything as a JSON file.
- Delete: in Settings, "Delete cloud data" deletes the cloud workspace and other content available for self-service deletion, clears this device, and signs you out. Sign-in, payment, refund, credit-settlement, security-audit, or abuse-prevention records may remain for as long as needed to perform the transaction, resolve a dispute, or meet a legal or accounting obligation. You may email us to request further deletion; where a record cannot lawfully be deleted immediately, we will explain why.
5. How long it is kept
- Browser working cache: kept until you log out, delete cloud data, or clear browser data.
- Cloud workspace data: kept until you delete it yourself; it will not be deleted because you have not signed in for an extended period.
- Payment, refund, entitlement, and credit-settlement records: kept for as long as needed to complete settlement, refunds, and disputes and to meet applicable legal, tax, accounting, security, and fraud-prevention obligations.
- Student-status, institution, month, evidence-hash, and review records: kept while eligibility is active and, after it ends, for as long as needed to resolve disputes and prevent discount abuse. CHSI codes and evidence files are deleted seven days after review; evidence for an unfinished review is deleted no later than 30 days after upload. One-time school email codes are removed after expiry and are never stored in plain text. Referral and reward records are kept for reward settlement, the refund observation period, and abuse prevention.
- Cost-attribution records: kept for operational accounting, anomaly investigation, and reconciliation; they are deleted or de-identified when account-level attribution is no longer needed.
- Resume share links: they expire after seven days by default. Once expired, the page snapshot is cleared and only a record remains, so that anyone opening the link is told it has expired; that record is deleted after thirty days. Revoking a link manually clears the snapshot immediately.
- Operational records: deleted automatically after 90 days.
- Feedback you send: kept until we have dealt with it, and at most one year.
6. Children
This service is intended for adults who are looking for work. It is not intended for children under 14.
7. Changes
When this policy changes, the effective date on this page is updated at the same time. Any substantive change to how data is used is also announced inside the app.
8. Third-party processors
This service provides the following third parties with the information required to deliver the corresponding features. When this list changes, the effective date on this page is updated at the same time.
- Supabase (United States): sign-in, and storage of cloud workspace data.
- Cloudflare (United States): processing and storage of credit, payment, entitlement, student-status, student evidence and verification email, referral-reward, cost-attribution, operational, feedback, and resume-share records.
- Resend (outside mainland China): delivery of institutional-email codes, manual-review alerts, and student-subscription eligibility reminders.
- ROR (outside mainland China): institution-name search and authoritative organisation matching. Queries contain no account identifier, email address, or eligibility evidence.
- CHSI (mainland China): verification of a mainland Chinese higher-education enrollment or qualification report by Greenroom's system or an authorised administrator using the submitted online code on the official CHSI site.
- OpenRouter (outside mainland China): routing and relay for some AI requests.
- DeepSeek (mainland China or the region stated in its terms): model inference for AI features.
- Alibaba Cloud (mainland China): image reading for users inside mainland China.
- Google (outside mainland China): image reading for users outside mainland China.
- Alibaba Cloud (mainland China): real-time speech transcription. (Image reading: see above.)
- Paddle (outside mainland China): payment, subscription, tax, receipt, and refund processing where available.
- Creem (outside mainland China): payment, subscription, tax, receipt, and refund processing where available.
- Afdian (mainland China): CNY payment collection and order verification where available.