Security & Privacy

Your interview audio
never lives on our servers.

SubcueAI is built native, encrypted in transit and at rest, and deliberately stateless when it comes to your interview audio. Here's exactly how.

Last updated: October 10, 2026

Audio handling

Interview audio is transcribed in the cloud — and never stored.

Encryption

Transit + at-rest

In transit

TLS 1.3

Forced HTTPS via Cloudflare. HSTS preloaded with max-age=63072000 (2 years).

At rest

AES-256

Cloudflare R2 (resumes / job descriptions / release binaries) uses SSE-256 server-side encryption by default.

Authentication

PBKDF2 + JWT

Password hashing: PBKDF2 100,000 iterations. Session tokens: JWT signed with HMAC-SHA256.

Sub-processors

Who touches your data

Subcue AI LLC is the data controller. The following sub-processors handle specific slices of customer data under contract. Each entry lists what they see and where their infrastructure is located.

ProviderPurposeRegion
CloudflareHosting, CDN, D1 (database), KV, R2 (object storage), Vectorize (embeddings), Workers AI (transcript search index, resume-image text recognition), AI Gateway (relays AI requests), Turnstile (bot protection)Global edge / US-EU
OpenAIAI answer suggestions, mock-interview questions, interview analysis, resume parsing and optimization, support-chat repliesUnited States
xAIMock-interview voice (text-to-speech); alternative AI model for the features above (Grok)United States
AnthropicResume parsing for scanned or image-only PDFs (Claude)United States
GoogleSign in with Google, Google Play billing, alternative AI model for resume parsing (Gemini)United States
Alibaba Cloud (Qwen)AI features and mock-interview voice for users in countries where our default providers are unavailableChina
DeepSeekAlternative AI model for users in countries where our default providers are unavailableChina
ElevenLabsSpeech-to-text (real-time)United States
DeepgramSpeech-to-text in countries where ElevenLabs is unavailableUnited States
StripePayment processing, billing, and sales-tax calculation (Stripe Tax)United States
AppleApp Store In-App Purchases (iOS/macOS users), Sign in with AppleUnited States
PaddlePayment processing for purchases made before July 2026United Kingdom
ResendTransactional email (verification codes, account and billing notices, support replies)United States
Google AnalyticsWeb analytics — anonymized usage metrics (IP-masked)United States
Microsoft ClarityWebsite usage analytics (page views, clicks, scrolling; input fields masked)United States

Updates to this list are announced in Terms of Service revisions.

Access & authentication

Tokens, sessions, revocation

HTTP security headers

What every response carries

Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()
Content-Security-Policy-Report-Only: ...

Compliance

Regional regulations

GDPR (EU / EEA / UK)

We process EU personal data under lawful bases including consent, contract performance, and legitimate interests. Data subject rights (access, correction, erasure, portability) are honored — email contact@subcueai.com with your request.

CCPA (California)

California residents have the right to know, delete, and opt out of data sale. We do not sell personal data. Submit CCPA requests to the same address as GDPR.

Data retention

What we keep, for how long

Responsible disclosure

Found a vulnerability?

Email contact@subcueai.com with subject line [SECURITY]. We commit to:

Out of scope: social engineering, physical attacks, attacks on third-party sub-processors.

Questions about this page? Email contact@subcueai.com.

See also: Privacy Policy · Terms of Service