Skip to content
Gig History
Menu

Privacy

Gig History holds two kinds of writing: the record you keep private and the record you publish. This page explains how each is treated, and what else we collect to run the product.

Updated September 9, 2026

Who this covers

This policy applies to people who create a Gig History account and to visitors who open a published record. Gig History is operated from Durham, North Carolina.

What stays private

Drafts, notes, set-aside topics, uploaded documents, coaching output, and anything you have not approved are visible only to you. An unpublished record has no public address, so there is nothing for anyone else to open.

What becomes public

Publishing makes your name, headline, location, availability, approved topics, and the contact methods you enabled readable by anyone with the link. Public answers are built only from that approved material. If you attach a custom domain, that hostname becomes another door to the same public page.

What hiring teams leave behind

Questions asked on a published page are recorded so you can see what hiring teams wanted to know. Visitors do not create accounts and are not asked to identify themselves. We may still receive a technical address, user agent, and time with the request, the way any web server does.

Account and billing data

When you create a profile we store your name, email, password hash or Google account identifier, and the time you agreed to the Terms of Use. If you subscribe, Stripe processes the card. We store the customer and subscription identifiers we need to keep the plan in sync. We do not store a full card number.

Connected Google accounts

Sign-in with Google receives your name, email address, and Google account identifier to create or sign in to your account. These account identity fields are separate from the public display name you enter in About Me; we do not automatically copy or fall back to a Google name for public profiles or AI context. Connecting Google Calendar is optional. We store the connected email address, connection time, and encrypted access and refresh tokens. We use the calendar.events.owned permission to create a meeting invitation and Google Meet link in your primary calendar when someone books with you.

For each booking, we send Google the organizer and visitor names and email addresses, meeting time, and a short booking description. Google sends the invitation to the attendees. We store the booking time, status, Google event identifier, and Meet link. We do not fetch your existing events, event contents, or free/busy data. Available times come from the schedule you save in Gig History and bookings made through Gig History.

Disconnecting Google Calendar from the desk removes the stored calendar email, tokens, and connection time and disables new bookings. You can also revoke access in your Google account. Disconnecting does not delete invitations already created in Google Calendar; you can manage those in Google Calendar. Stored booking records remain subject to the retention and deletion provisions below.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect sensitive data

Gig History uses HTTPS/TLS to protect information sent between your browser and the service and between the service and Google or our AI providers. Google Calendar access and refresh tokens are encrypted at rest using AES-256-CBC with the application encryption key. The key is kept in server configuration and is not sent to your browser or AI providers. Passwords are stored as one-way hashes, not readable passwords.

Access to private records and calendar connection settings requires authentication and account ownership checks. Production session cookies are Secure and HttpOnly. Our production database runs on an internal container network without a public database port, and detailed application debug output is disabled.

AI processing

We use DeepInfra to run language models for intake, uploaded document text, coaching, rehearsal, and answers to public questions. Depending on the feature, we send the record material, conversation, or question needed for that request. Public answers use approved, published material; private intake and coaching can use the private material you provide for those features.

If you choose voice input, we send your recording to the xAI speech-to-text API. The transcription is returned for you to review and edit before sending it as a message. Gig History does not retain the audio or save the transcription through the transcription endpoint; a transcript you send is saved as a normal conversation message.

DeepInfra and xAI are used through their commercial APIs. DeepInfra states that it does not train on inputs or outputs for our configured text-model API or forward those requests to the model author. xAI states that API inputs and outputs are not used for training without explicit permission. Provider retention and security processing are governed by their API policies.

Google data and AI model training

We do not use, transfer, or sell Google user data, including raw, aggregated, anonymized, or derived data, to create, train, or improve foundational or generalized AI or machine-learning models. We do not authorize our AI providers to use Google user data for that purpose.

Google account identity and the Google Calendar integration are separate from AI processing. Google-provided sign-in names, account emails, and identifiers are not selected as AI context. Calendar authorization tokens, the connected calendar email, event identifiers, Meet links, and Calendar API responses are not included in AI requests. The calendar integration does not import events into your record, conversations, documents, or voice input. The availability text in a record is information you write, not availability read from Google Calendar.

For accounts linked to Google before this separation was introduced, the public display name is cleared for you to enter yourself. Earlier coaching conversations may contain Google-derived names in messages or generated replies. They remain available to read but cannot be continued or reused as AI context; start a new conversation instead. Experience and company interviews, uploaded documents, and voice input use content you supply, not Google API imports. This separation does not undo requests processed before the change.

We do not operate self-hosted or offline AI models. DeepInfra hosts the language model, and xAI processes optional voice recordings through its API.

Product analytics

The marketing site and the signed-in desk load PostHog so we can see which pages people open, which buttons they use, and where they drop off. On the desk we identify you by your account. We do not record sessions. A published record does not load PostHog.

How we use information

We use the information above to operate your desk and public page, to create bookings, to understand how booking and other features are used, to generate answers and drafts, to bill paid plans, to prevent abuse, to fix the product, to see how the marketing site and desk are used, and to comply with law. We do not sell personal information.

Retention

We keep account and record data until you delete it or we close the account. Billing records, security logs, and copies we must keep for law or dispute handling may last longer. Unpublished drafts remain until you delete them or the account.

Deleting things

You can unpublish a record at any time, which removes its public address. You can also delete the record and the account outright from the desk. Deletion does not erase a copy a visitor already made, a payment record Stripe keeps, or a backup that has not yet rotated out.

Processors

We use vendors to host the application, send mail, process payment (Stripe), authenticate and book through Google, run language-model features, and measure how the marketing site and desk are used (PostHog). Those vendors see only what they need to perform that work. Published records do not load PostHog.

Your choices

You can access and edit the record from the desk, unpublish it, disconnect Google Calendar, cancel a paid plan, and delete the account. You can also stop using a public page. If you are in a place that grants additional privacy rights, contact us and we will handle the request as the law requires.

Contact us

Children

Gig History is not directed at children under 18. We do not knowingly collect personal information from them. If we learn we have, we will delete it.

Changes

We may update this policy. The date at the top of the page is the current version. Material changes will be posted here.