What we hold, what we send, and what we never keep.
Effective August 2, 2026
Climbora works by holding a careful record of your career and using it to ground what the AI says. That only works if you know exactly what is stored and where it goes. This notice describes what the product actually does today.
Your account
You sign in through ChatGPT. We receive your verified email address and, when available, your display name. We never receive or store your password. We also keep your subscription state and the dates your plan renews or ends.
If you joined the early-access list, we hold the email address, optional target role, consent choice, and signup time you gave us then.
Your career profile and documents
We store what you record: your target role, summary, skills, résumé text, and any notes. We also store documents you import, including the text extracted from them, so they can be used as evidence.
This is the verified record Climbora speaks from. It stays until you delete it.
Connected accounts
Connecting a provider is optional, each connection is separate, and you can disconnect any of them at any time from Integrations. Access tokens are encrypted before they are stored.
- Google Calendar and Outlook Calendar — read to find interview events, so meetings can be linked to the applications they belong to.
- Gmail and Outlook Mail — read only for threads you explicitly select, so recruiter conversations can be tracked and replies drafted. We do not scan your mailbox.
- Google Drive and OneDrive — read only for files you explicitly pick, so a résumé or document can be imported.
Content from a connected account is stored only where it belongs to something you are tracking — the recruiter messages in a conversation, the calendar event attached to an application, the document you imported.
AI processing
Climbora sends content to OpenAI to do its work: your profile and a job description for a fit analysis, selected email text to draft a reply, your background to ground an interview answer.
We send a hashed identifier, not your identity. OpenAI requires a stable per-account identifier so that misuse can be traced to a single account rather than to the platform as a whole. Ours is a one-way hash of your internal account number. Your email address, name, and account number are never sent as the identifier.
Your content is not used to train AI models.
Interview Copilot: what is never stored
During a live session, audio is captured and sent for transcription, and the transcript is used to produce an answer.
Neither the audio nor the live transcript is stored by Climbora. They exist only for the moments needed to produce your answer. What we keep for a Copilot session is timing and billing only: when it started, when it ended, and how many seconds counted toward your allowance. There is no recording for us to retrieve, or for anyone to ask us for.
Mock interviews: what is stored
Mock interviews are different, and we would rather say so than let the section above imply otherwise. Because the point of practice is reviewing it afterwards, mock-interview sessions and their turns — the questions, your answers, and the feedback — are stored against your account until you delete them.
Payments
Payments are processed by Stripe. Climbora never receives or stores your card number. We keep the Stripe customer and subscription identifiers, your plan, its status, and its renewal or end date.
What we do not do
We do not sell your information. We do not use your content to train AI models. We do not read your mailbox or your drive beyond the specific threads and files you choose. We do not store interview audio.
Retention and deletion
Your records stay while your account exists, so your history remains useful to you. You can delete individual items — documents, applications, conversations, mock interviews — from your workspace at any time.
To delete your account and everything associated with it, email privacy@climbora.ai from your account address. Records we must keep for tax or accounting reasons, such as payment history, are retained where the law requires.
Service providers
Climbora runs on Cloudflare infrastructure, uses OpenAI for AI processing, Stripe for payments, and the provider you sign in through for authentication. Connected-account data comes from Google or Microsoft at your instruction.
We apply reasonable safeguards, including encryption of stored access tokens, but no online system can promise absolute security.
Your rights
You can ask what we hold about you, ask for a copy, ask for a correction, or ask for deletion, at privacy@climbora.ai. Depending on where you live you may have further statutory rights; where you do, they apply in addition to anything written here.
Updates
This notice will change as Climbora develops. Material changes will be posted here with a new effective date.
See also our Terms of Service and Trust center.
← Return to Climbora