Interview Recipes

Interview Recipes

Privacy Policy

How Interview Recipes collects, uses, and protects your personal data — the providers involved, the legal basis for each use, and how to exercise your rights.

Effective 23 July 2026

This Privacy Policy explains how personal data is collected, used, and protected when you use Interview Recipes (the "Service"). We are committed to handling your data responsibly and in line with the EU General Data Protection Regulation (GDPR) and applicable Finnish data protection law.

Please read this alongside our Terms of Service.

1. Who we are (data controller)

Interview Recipes is operated by Max Korpinen, an individual sole trader based in Finland ("we", "us", "our"). For the purposes of the GDPR, we are the data controller responsible for your personal data.

You can reach us for any privacy question, or to exercise your rights, at maxkorpinen@gmail.com.

We have not appointed a Data Protection Officer, as we are not required to do so. Privacy enquiries are handled directly by us at the address above.

2. Scope of this policy

This policy applies to personal data we process about:

It does not cover third-party websites we link to, which have their own privacy policies.

3. What personal data we collect

We collect only what we need to run the Service. Depending on how you use it, this includes:

Account and profile data. When you create an account, we collect your email address and the authentication method you choose. You can sign in with an email magic link, or via Google or LinkedIn (see "Sign-in providers" below). We store your subscription plan (free or premium) and your newsletter preference.

Content you create. The interview templates ("recipes"), the sections within them, and any custom interview questions you write, save, or favourite. This content is private to your account unless you deliberately create a public share link for a recipe.

Newsletter and waitlist data. If you opt in to our newsletter, we store your email address, where you signed up from, and your opt-in status. If you join a waitlist for an upcoming feature, we store your email, the feature you were interested in, and — only where you choose to provide it — your company name, team size, and role.

Payment data (premium). When paid subscriptions are available and you purchase one, payment is handled by our payment processor, Stripe. We do not receive or store your card number. We store a Stripe customer and subscription identifier, your subscription status, and the current billing-period end date so we can manage your access.

AI feature usage. If you use our AI generation feature to draft questions or recipes, we keep a record of each generation: the time, the model used, whether it succeeded, the number of tokens it consumed and what it cost us, and a short label describing what was generated. We use this to enforce usage limits, to control costs, and to understand how the feature is used. We do not store the prompts you write, and we do not store the generated output beyond what you choose to save into your own recipes — the prompt is sent to our AI provider, used to produce your draft, and not retained by us afterwards.

Technical and security data. Like most websites, we automatically process limited technical data needed to operate and protect the Service. When you use a feature that costs us money to run, we store a hashed version of your IP address — a one-way fingerprint, never the address itself — as a counter for rate-limiting and abuse prevention. Our hosting provider also generates standard server logs, which include IP addresses, as a normal part of delivering and securing the site.

Analytics data. We use privacy-conscious, EU-hosted product analytics (PostHog) to understand how the Service is used. We run it without cookies and without collecting your IP address. See "Cookies and analytics" below.

We do not intentionally collect any special categories of data (such as health, ethnicity, or political opinions). Please do not enter such data into interview templates or AI prompts.

Under the GDPR we must have a lawful basis for each use of your personal data. The table below sets these out.

What we doWhyLegal basis (GDPR Art. 6)
Create and manage your account; authenticate sign-inTo provide the Service you asked forPerformance of a contract (Art. 6(1)(b))
Store the templates, questions, and favourites you createCore functionality of the ServicePerformance of a contract (Art. 6(1)(b))
Generate AI drafts you request and enforce fair-use limitsTo provide the premium feature and prevent abuse of costsPerformance of a contract (Art. 6(1)(b)); our legitimate interest in cost control (Art. 6(1)(f))
Process payments and manage your subscriptionTo sell and provide premium accessPerformance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting records (Art. 6(1)(c))
Send you our newsletterBecause you asked to receive itConsent (Art. 6(1)(a)) — you can withdraw at any time
Record waitlist interest for upcoming featuresTo gauge demand and notify youConsent (Art. 6(1)(a))
Rate-limit requests, prevent abuse, and keep the Service secureTo protect the Service and control costsLegitimate interests (Art. 6(1)(f))
Measure and improve how the Service is used (cookieless analytics)To understand and improve the productLegitimate interests (Art. 6(1)(f)) — we store nothing on your device for this, so no consent is required
Respond to your enquiries and support requestsTo help you and keep records of our communicationsLegitimate interests (Art. 6(1)(f))
Comply with legal obligations (e.g. tax, responding to lawful requests)Because the law requires itLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced our interests against your rights, and you can object at any time (see "Your rights"). Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.

5. Cookies and analytics

Strictly necessary cookies. When you sign in, our authentication provider (Supabase) sets cookies that keep you securely signed in and rotate your session. The Service cannot work without these, so they do not require consent. They are set only once you sign in — browsing the public library sets no cookies at all.

Analytics, without cookies. We use PostHog (hosted in the EU) to understand how the Service is used — which pages are visited, which features are used, where people get stuck. We run it in a cookieless configuration: it stores nothing on your device, and IP address collection is turned off. Because we neither store nor access information on your device for analytics, no cookie consent banner is required, and we rely on our legitimate interest in understanding and improving the Service.

If you do not have an account, analytics events carry no identifier that survives after you close the tab. If you do have an account, events are linked to your account identifier so we can understand how the product is genuinely used over time — for example, whether people come back and build more than one recipe. That linkage is what tells us whether the product is working; it is not used to build a profile of you for any other purpose.

We do not sell analytics data, we do not use it for advertising, and we use no third-party advertising or cross-site tracking technologies. We honour the Do Not Track and Global Privacy Control signals — if your browser sends either, analytics do not load at all. You can also object to analytics at any time by contacting us (see "Your rights").

6. Who we share your data with

We do not sell your personal data. We share it only with service providers ("processors") who help us run the Service, and only as needed. Each is bound by a data processing agreement. Our key providers are:

ProviderPurposeLocation / safeguard
VercelWebsite hosting and content deliveryUS company; EU Standard Contractual Clauses (SCCs) for any transfer
SupabaseDatabase and authenticationEU region (eu-north-1)
PostHogProduct analyticsEU-hosted
AnthropicAI generation (Claude) for the "write it for me" featureUS-based provider; SCCs / EU–US Data Privacy Framework as applicable. Under Anthropic's commercial API terms, your prompts are not used to train its models
StripePayment processing for premium subscriptionsUS/EU; SCCs and PCI-DSS compliant; processes card data directly
ResendOperational email — currently a daily internal cost report, which includes the email addresses of the accounts using the AI feature most heavilyUS-based provider; SCCs as applicable
Google / LinkedInOptional sign-in (only if you choose that method)You authenticate with them; they act as independent controllers of your login with them
ButtondownNewsletter delivery, where configuredUS-based provider; SCCs as applicable

A note on the newsletter list. Our newsletter subscribers are held in a shared list operated by us across the Kops Works experiments, with your subscription tagged to this project. If you subscribe here, you are subscribing to that list under the tag for Interview Recipes; we do not use it to email you about anything you did not sign up for.

We may also disclose personal data if required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or ourselves.

7. International data transfers

Our database, authentication, and analytics are hosted in the European Union. Some providers listed above (for example, Anthropic, Stripe, Vercel, Resend, and Buttondown) are based in the United States or may process data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under the GDPR — typically the European Commission's Standard Contractual Clauses, an adequacy decision, or the provider's certification under the EU–US Data Privacy Framework. You can ask us for more detail using the contact details above.

8. How long we keep your data

We keep personal data only as long as we need it:

9. Your rights

Under the GDPR you have the right to:

To exercise any of these rights, email us at maxkorpinen@gmail.com. We will respond within one month, though we may extend this by up to two further months for complex requests, in which case we will let you know. We will not charge a fee unless your request is clearly unfounded or excessive.

Some things you can do without asking us: every newsletter we send has a one-click unsubscribe link, any recipe you have shared can be unshared from the recipe itself, your own questions and recipes can be deleted from within the app, and premium subscriptions can be cancelled from the billing portal in your account. For anything else — a copy of your data, a correction, or deleting your account entirely — email us and we will take care of it.

You have the right to complain to the Finnish supervisory authority:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) · tietosuoja.fi · tietosuoja@om.fi

If you are in another EU/EEA country, you may also contact your local data protection authority.

10. Automated decision-making and AI

Our AI feature produces draft interview questions and templates at your request. These are suggestions for you to review and edit — they are generated content, not decisions about you, and we do not use them to make any decision that produces legal or similarly significant effects about you. We do not carry out solely automated decision-making within the meaning of Article 22 GDPR.

AI-generated content can be inaccurate or incomplete. You are responsible for reviewing it before use, and for ensuring that how you interview and assess candidates complies with applicable employment and anti-discrimination law. See our Terms of Service for more.

11. Security

We take reasonable technical and organisational measures to protect your data, including database-level access controls (row-level security, so users can only reach their own private data), encryption in transit, server-side handling of secrets and payment data, and rate-limiting to prevent abuse. No online service can be completely secure, but we work to protect your information and will notify you and the relevant authority of a personal data breach where the law requires.

12. Children

The Service is intended for professional use by adults and is not directed to children. You must be at least 18 years old to create an account or purchase a subscription. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

The Service may link to third-party websites and uses third-party sign-in providers (Google, LinkedIn). We are not responsible for the privacy practices of those third parties. When you sign in with a provider, that provider processes your login according to its own privacy policy, and shares a limited set of profile information (such as your email address) with us so we can create your account.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after an update means you accept the revised policy.

15. Contact us

For any question about this policy or your personal data, contact us at maxkorpinen@gmail.com.