Data Retention for AI Interview Coach

Effective Date: August 8, 2026  
Last Updated: September 3, 2026
**Related documents:**  
[Privacy Policy](./PRIVACY_POLICY.md) · [Data Processing Notice](./DATA_PROCESSING_NOTICE.md) · [User Consent Notice](./USER_CONSENT_NOTICE.md) · [Terms of Service](./TERMS_OF_SERVICE.md)

This Data Retention Policy explains how long **AI Interview Coach** (“we,” “us,” or “our”) retains resumes, job descriptions, and related derived data, and when that data is deleted.


---

## 1. Purpose

We retain resume and job-description data only as long as needed to:

1. Provide the interview coaching and document-analysis features you request  
2. Maintain on-device session history you choose to keep  
3. Secure the App and investigate abuse or security incidents  
4. Meet legal, accounting, or regulatory obligations when applicable  

We do **not** retain resume or job-description files longer than necessary for these purposes, and we do **not** sell this content.

---

## 2. Scope

This Policy covers:

| Data category | Examples |
| --- | --- |
| **Resume content** | Uploaded PDF/DOCX/TXT files, pasted resume text, extracted plain text |
| **Job description content** | Uploaded or pasted job postings used for tailored questions or ATS scoring |
| **Derived analysis** | Scores, strengths/weaknesses, rewrite suggestions, keyword-match results, session summaries tied to document analysis |
| **Temporary server uploads** | Files stored briefly on the API server during upload/analyze flows |
| **Technical metadata** | Upload IDs, checksums, timestamps, file size/type (not the full document, once deleted) |

It does not change ownership of your documents. You retain ownership of User Content as described in the Terms of Service.

---

## 3. Retention Schedule

### 3.1 On-device (mobile / web client)

| Data | Retention period | Deletion trigger |
| --- | --- | --- |
| Pasted/uploaded resume or job-description text in active screens | Until you clear the field, leave/reset the flow, clear App data, or uninstall | User action or uninstall |
| Session history entries that reference resume/ATS/mock results | Until you clear session history (App stores a limited recent history, typically up to 50 sessions) or uninstall | “Clear history,” App data reset, or uninstall |
| Language / role preferences | Until changed, cleared, or uninstall | User change or uninstall |

**Default principle:** Resume and job-description content used in the client is stored **locally on your device** unless you use a server AI/upload feature.

### 3.2 Temporary server file storage (secure upload handler)

When you upload a resume file to the API:

| Stage | Retention | Deletion |
| --- | --- | --- |
| **During processing** (`POST /api/analyze/upload`) | File is stored only for the duration of extract → analyze | Deleted in a `finally` block immediately after processing (success or failure) |
| **Staged upload** (`POST /api/upload` then later `/api/analyze` with `uploadId`) | Held temporarily pending analysis | Deleted immediately after analysis using that `uploadId` |
| **Maximum TTL if never analyzed** | **15 minutes** from upload | Automatic expiry + periodic cleanup (about every 5 minutes) removes orphaned files |
| **Storage controls** | Random UUID filenames, restricted directory, file mode `0600`, type/size limits | Files are never exposed as public downloads |

**Server retention target for uploaded resume files: minutes, not days.**  
We aim for **zero residual resume files** on the server after successful or failed analysis, subject only to brief OS/filesystem timing and crash-recovery cleanup.

### 3.3 AI provider processing

When AI analysis is enabled, resume/job-description text may be transmitted to the configured AI provider (e.g., OpenAI) to generate Outputs.

| Item | Retention |
| --- | --- |
| API request payload (document text in the prompt) | Processed to fulfill the request; further retention/logging follows the provider’s then-current API and privacy terms |
| Provider model Outputs returned to the App | May be saved **on your device** as session history until you clear them |
| Provider-side copies | Governed by provider policy / account configuration (including any no-training / zero-retention options you enable on the provider account) |

We do not independently archive full resume or job-description text on our servers for long-term analytics.

### 3.4 Derived results and logs

| Data | Retention |
| --- | --- |
| Analysis results shown in the App | On-device until cleared/uninstalled |
| Operational logs (errors, request timing, non-content diagnostics) | Typically **up to 90 days**, unless needed longer for security investigations |
| Security / abuse investigation records | **Up to 12 months**, or longer if required for an active investigation or legal hold |
| Consent/version acknowledgements (if logged) | **Up to 24 months**, or as required to demonstrate compliance |

Operational logs should avoid storing full resume or job-description bodies. If a log incidentally captures content due to an error dump, it is subject to the same deletion goals and access controls.

---

## 4. Deletion Methods

### 4.1 User-initiated deletion

You can delete or stop retention by:

1. Clearing pasted resume/job-description fields in the App  
2. Clearing session history in the App  
3. Revoking file/microphone permissions in device settings  
4. Uninstalling the App (removes local App storage in typical OS behavior)  
5. Contacting `privacy@madisoninteractive.ca` for assistance with applicable privacy rights  

### 4.2 Automated deletion

- Temp uploads deleted after processing  
- Temp uploads expired after **15 minutes** if unused  
- Scheduled cleanup removes orphaned temp files  
- Client history is capped and user-clearable  

### 4.3 Backup and residual copies

Where backups of server infrastructure exist, deleted temp files are not intentionally restored into active use. Residual encrypted backup media, if any, are overwritten on the backup rotation cycle (**typically ≤ 30 days**). Until rotation completes, access remains restricted.

---

## 5. Legal Holds and Exceptions

We may retain specific data longer than the schedule above when:

- Required by law, regulation, or valid legal process  
- Needed to establish, exercise, or defend legal claims  
- Necessary to investigate security incidents, fraud, or Terms violations  
- You and we agree in writing to a different retention period (e.g., enterprise deployment)

When a legal hold applies, deletion timelines pause for the affected records until the hold is released.

---

## 6. Minimization Rules for Resumes and Job Descriptions

To keep retention short and data use limited, we apply these rules:

1. **Collect only what you submit** for the feature you use  
2. **Prefer on-device storage** for history and drafts  
3. **Prefer delete-after-processing** for server-side file uploads  
4. **Truncate oversized text** in AI prompts where practical  
5. **Discourage** unnecessary sensitive identifiers in uploads (see Consent / Privacy notices)  
6. **Do not** use resume/job-description content for third-party advertising  

---

## 7. Roles and Responsibilities

| Role | Responsibility |
| --- | --- |
| **Madison Interactive** | Defines retention periods; configures server temp storage and deletion; responds to user deletion requests |
| **App user** | Controls what is uploaded/pasted; can clear local history; should avoid uploading unauthorized or overly sensitive content |
| **AI provider** | Processes request payloads under its terms; retains or deletes according to its API configuration and policies |

---

## 8. International Considerations

If document text is processed by a provider in another country, retention on that provider’s systems follows its policies and any contractual data-processing terms. Where GDPR/UK GDPR or similar laws apply, retention is limited to what is necessary for the stated purposes, and you may exercise deletion/access rights as described in the Privacy Policy.

---

## 9. Review of This Policy

We review this Data Retention Policy at least **annually**, and sooner if we:

- Change upload/AI architecture  
- Add cloud accounts or long-term document storage  
- Receive material legal or regulatory requirements  

Material changes will be reflected in the “Last Updated” date and, where appropriate, communicated in-app or via the Privacy Policy.

---

## 10. Contact

Questions about retention or deletion of resumes and job descriptions:

**Email:** `madison.aistudios@gmail.com`  
**Subject line:** AI Interview Coach Data Retention  

---

## 11. Summary Table (Quick Reference)

| Location | Resume / JD files or text | Typical max retention |
| --- | --- | --- |
| Your device | Drafts + history you keep | Until you clear or uninstall |
| API temp disk | Uploaded files | Until analysis completes, or **15 minutes** max |
| AI provider | Prompt text for analysis | Per provider API terms / configuration |
| Our app servers (beyond temp upload) | Not used for long-term resume archives in the current design | N/A (no long-term file archive) |
| Security / legal records | Limited metadata or held content if required | Up to 12 months (or legal hold) |

**Bottom line:** Resumes and job descriptions are processed to provide coaching features, kept briefly (or on your device under your control), and temporary server uploads are deleted after processing.