Switch Sprint
/ Privacy Policy

Privacy Policy

Last updated: 18 July 2026

Switch Sprint ("we", "us", "our") operates switch-sprint.com (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, and your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act) (India) and other applicable law.

By creating an account you agree to this policy. If you disagree, do not use the Service.

1. Data We Collect

Category / RecipientWhat / WhySafeguard
Account dataEmail address, hashed password (if email/password sign-up), Google profile (if Google OAuth)Account creation & authentication
Job application dataCompany, role, status, notes, CTC, location, dates you enter into the ServiceProviding the job-tracking feature
Resume filesPDF/DOCX files you upload, extracted text, AI analysis resultsResume parsing & JD-fit analysis
AI provider settingsProvider name, model name, API key (AES-256-GCM encrypted at rest), optional base URLRouting your AI requests to your chosen provider
Usage & gamificationXP events, badge state, study log, STAR bank, activity log, roadmap tasksDelivering gamification & progress tracking
Technical logsServer-side request logs (IP address, timestamp, HTTP method/path, response code) — retained ≤ 30 daysSecurity, debugging, uptime

We do not sell your data. We do not run advertising. We do not share your personal data with third parties except as described in Section 4.

2. How We Use Your Data

  • Authenticate you and maintain your session.
  • Store and display your job applications, resumes, and prep materials.
  • Route AI requests to the provider you configured (using your own API key).
  • Calculate XP, streaks, badges, and mission progress.
  • Send transactional emails (email confirmation, password reset) via Resend from noreply@switch-sprint.com.
  • Detect and prevent abuse or security incidents.

3. AI Processing & Your API Key

Switch Sprint uses a Bring Your Own Key (BYOK) model. You paste an API key from your chosen AI provider (Anthropic, OpenAI, Groq, Gemini, etc.).

  • Your API key is encrypted (AES-256-GCM) before storage. The encryption key never leaves our server environment.
  • Your API key is never sent to your browser and never logged.
  • When you trigger an AI feature, your job/resume data is sent to your chosen AI provider under your API key. That provider's own privacy policy governs how they process that data.
  • We do not store raw AI responses beyond what is displayed in the UI and saved to your account (e.g. analysis results).

4. Data Sharing

Category / RecipientWhat / WhySafeguard
Supabase (Supabase Inc., USA)Database, authentication, file storageData Processing Agreement in place
Vercel (Vercel Inc., USA)Application hosting, CDN, serverless computeDPA in place; SOC 2 Type II certified
Resend (Resend Inc., USA)Transactional email (confirmation, password reset)Only your email address is passed
Your AI providerAI inference — your job/resume data sent under your API keyGoverned by their privacy policy

We do not share data with any other third party without your explicit consent.

5. Data Retention

  • Active accounts — data retained until you delete your account.
  • Soft-deleted accounts — data is flagged for deletion immediately on request. A background job permanently deletes all rows and storage files within 30 days. You can cancel within this window by logging in again.
  • Server logs — retained for 30 days then purged automatically.

6. Your Rights (DPDP Act 2023)

As a data principal under India's DPDP Act you have the right to:

  • Access — know what personal data we hold about you.
  • Correction — request correction of inaccurate data.
  • Erasure — delete your account and all associated data (Settings → Danger Zone, or email us).
  • Grievance redressal — raise a complaint with our Grievance Officer (see Section 9).
  • Nominate — nominate a person to exercise rights on your behalf in the event of your death or incapacity.

To exercise any right, email support@switch-sprint.com with subject line "DPDP Request". We will respond within 30 days.

7. Cookies & Sessions

We use a single first-party HTTP-only session cookie (sb-*) set by Supabase Auth to maintain your login session. No advertising or tracking cookies are used.

8. Security

  • All data in transit encrypted via TLS 1.2+.
  • Database access controlled via Row-Level Security — each user can only query their own rows.
  • API keys encrypted at rest (AES-256-GCM); decrypted only inside server-side request handlers.
  • Production secrets managed via Vercel environment variables, never committed to version control.

No system is 100% secure. In the event of a data breach we will notify affected users within 72 hours of discovery.

9. Grievance Officer

For privacy complaints under the DPDP Act, contact our Grievance Officer:
Email: support@switch-sprint.com
Subject line: "Privacy Grievance – Switch Sprint"
We will acknowledge within 48 hours and resolve within 30 days.

10. Children

The Service is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the account.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email or an in-app notice at least 7 days before taking effect. The "Last updated" date at the top always reflects the current version.

Terms of Service →Back to app