Matchscope policies

Privacy Policy

A plain-language account of the information Matchscope processes and the choices available to you.

Last updated: 8 August 2026

1. Scope and who we are

This Privacy Policy explains how Matchscope, operated as an unregistered individual business in India, handles personal data when you use matchscope.pro and its resume analysis services. By using Matchscope, you acknowledge the practices described here.

2. Data we collect

Depending on how you use the service, we collect:

  • Account data: your name, email address, profile image, account identifier, and authentication information supplied through Google and our authentication provider.
  • Resume, job, and interview data: resume text, contact details included in your resume, employment and education history, skills, job descriptions, job URLs, edits, saved resumes, generated analysis, practice-interview settings, answer transcripts, progress, scores, and coaching reports.
  • Usage data: feature activity, AI request type, model/provider, token, voice-character, or transcription-session counts, estimated processing cost, quota usage, timestamps, and basic security or diagnostic records.
  • Transaction data: selected pack, credits, amount, currency, payment status, and payment/order identifiers. We do not directly receive or store complete card, bank, or UPI credentials.
  • Messages: information you include when contacting support or making a privacy, delivery, or refund request.
  • Device storage: theme preference and, in local development or fallback modes, saved workspace information stored in your browser.

3. How we use data

We use personal data to provide authentication, extract resume text, generate analysis and rewrites, create and evaluate practice interviews, save requested workspace data, manage quotas and purchases, provide exports, prevent abuse, troubleshoot the service, respond to support requests, and meet legal obligations.

We do not sell personal data or use resume content for behavioral advertising. Where consent is the applicable basis for processing, you may withdraw it by contacting us, although this does not affect processing already completed.

4. AI processing

Resume text, job descriptions, interview transcripts, and relevant instructions are sent to our configured paid AI processors—OpenAI, Google Gemini, or Anthropic—to produce structured resume data, analysis, rewrites, interview questions, live interview reactions, and coaching reports. Our production API use is governed by paid or commercial terms under which submitted content is not used to train or improve generalized AI models. Do not submit sensitive personal data that is unnecessary for this purpose.

We extract text from uploaded PDF and DOCX files and do not intentionally retain the original uploaded file after the request finishes. Structured resume content and analysis may be stored when required for your saved resumes and analysis history.

Practice-interview voice.Practice interviews are voice-based. After the interviewer finishes a question, your browser streams microphone audio directly to OpenAI’s Realtime service for real-time speech-to-text processing under its privacy policy and our configured account controls. Matchscope receives the resulting live text and stores only the submitted answer transcript and answer duration; Matchscope does not record or retain raw microphone audio. OpenAI may process and retain provider-side request data according to its terms, privacy policy, and the controls available on our plan. Camera video remains in your browser and is not sent to Matchscope or either AI provider.

To speak the interviewer’s lines, Matchscope also sends only the generated introduction or current interview question to ElevenLabs for text-to-speech processing. That text-to-speech request does not include your answer transcript, resume, camera video, or candidate microphone audio. The returned interviewer audio is played in your browser and cached only in the current tab; browser or operating-system speech synthesis is used if interviewer voice generation is unavailable.

5. Gmail sync and Google user data

Connecting a mailbox is optional and off by default. If you choose to connect a Google account, Matchscope requests a single read-only permission, gmail.readonly. We cannot send, reply to, modify, label, or delete anything in your mailbox, and we never act as you.

Raw Google user data we access. Within the lookback window you choose in Settings (90 days by default), Matchscope searches for likely job-application messages. For messages that pass that search and our initial filtering, we may read the sender, recipients, subject, date, message identifiers, headers, snippet, links, and the portion of message text needed to determine whether the message is a confirmation, assessment, interview, offer, rejection, or another recruitment update. Messages outside the selected search window are not processed, and attachments are not downloaded or read.

How we use the data. We use the accessed message data only to provide the application-tracking features visible to you: identifying recruitment events, matching them to applications you track, suggesting or applying status updates, creating a review queue and timeline, and showing reminders and per-account application insights. We do not use Google user data to build advertising profiles, make lending or credit decisions, or provide unrelated services.

What we store and derive. For each message concluded to be job-related, we store the subject, sender name, address and domain, received date, a short snippet, message and thread identifiers, and derived results such as event type, suggested status, confidence, one-line summary, company, role, deadlines, matching outcome, and user corrections. We may aggregate these derived results within your account to show funnel counts, upcoming actions, and application insights. We do not store full message bodies or attachments. We do not create a cross-user email-content dataset or use raw, derived, aggregated, or anonymized Google user data to train generalized AI or machine-learning models.

Service providers and transfers. To classify a likely job-related message, limited message text—including a truncated portion of the body—is sent to our configured paid AI processor, Google Gemini or Anthropic, solely for that request and user-facing feature. Our database and hosting providers process the stored records as necessary to operate Matchscope. We require processing terms under which submitted content is not used to train or improve generalized models. We do not sell Google user data or transfer it to advertisers, data brokers, information resellers, or other third parties except as necessary to provide the feature you requested, address security and fraud, comply with law, or complete a business transfer with any consent required by law and Google policy.

Human access. Matchscope personnel do not read Gmail message data except when you give explicit consent for support involving specific data, when access is necessary to investigate abuse or a security incident, or when required by law. Any permitted access is limited to what is necessary for that purpose.

How the data is protected. Data is transmitted over HTTPS and stored with provider encryption, access controls, and row-level database policies. Google access and refresh tokens receive additional application-level AES-256-GCM encryption and are held in a separate table that browser sessions cannot read; only restricted server-side credentials can decrypt them.

Retention, disconnection, and deletion. Imported Gmail records are retained while your account and the application-tracking feature remain active so that your review queue, application timeline, and insights continue to work. They remain until you permanently delete them or close your account; there is currently no automatic expiry. In Settings, you can disconnect Gmail while keeping previously imported activity, or choose Disconnect and delete datato revoke Matchscope’s Google access and permanently delete the connection, imported email records, sync jobs, and Gmail-derived timeline events. You can also revoke access directly at myaccount.google.com/permissions or request account deletion using the contact details below.

Matchscope’s use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Service providers and sharing

We disclose data only as needed to operate Matchscope, including to:

  • Supabase for authentication, account records, database storage, and security controls.
  • OpenAI, Anthropic, and Google for AI processing as described above. OpenAI also provides live interview transcription and response intelligence.
  • ElevenLabsonly for generating the practice interviewer’s spoken audio as described above.
  • Razorpay for checkout, payment confirmation, fraud prevention, and refunds when payments are enabled.
  • Hosting and infrastructure providers that deliver and secure the website.
  • Authorities or advisers when reasonably necessary to comply with law, protect users, enforce our terms, or address fraud and security incidents.

Some providers may process data outside India under their own security and data-protection obligations.

7. Retention and deletion

We retain account data while your account remains active. Saved resumes, analysis history, and practice-interview transcripts and reports remain until you delete individual items or request account deletion, subject to backups and legal retention needs. Raw practice-interview audio is not retained by Matchscope. Usage, transaction, fraud-prevention, tax, and support records may be retained for the period reasonably required by law and legitimate business needs.

When data is no longer required, we delete or de-identify it where reasonably practicable. Browser-stored data can be cleared through your browser settings.

8. Security

We use access controls, encrypted network connections, row-level database policies, restricted server credentials, and authentication safeguards designed to protect your information. No internet service is completely secure, so we cannot guarantee absolute security.

9. Your choices and rights

Subject to applicable law, you may ask us to provide information about your personal data, correct inaccurate data, delete data, withdraw consent, or address a grievance. We may need to verify that the request belongs to you before acting.

Email vijaysaiwal223@gmail.com from your account email with the subject “Privacy request.” You may also nominate another person to exercise applicable rights on your behalf where the law permits.

10. Children

Matchscope is intended for people aged 18 or older. We do not knowingly offer the service to children or knowingly collect their personal data. Contact us if you believe a child has provided data.

11. Changes and contact

We may revise this policy as our services or legal obligations change. We will update the date above and provide additional notice when a change materially affects your rights.

For privacy questions or grievances, email vijaysaiwal223@gmail.com or visit our Contact page.