The short version: your live interview audio goes from your browser straight to the model — it never passes through this server. Answers you don’t share are never uploaded anywhere. Your résumé is never published. Your email address never appears on a page a recruiter can see. You can export everything or delete all of it yourself, free, at any time.
1Who this is about
Firsthand is an independent service run by one person, who is the data controller for everything below and is reachable at support@hearfirsthand.com. That reaches the operator directly; ask there for the legal name and service address behind it, including for a data request that needs one. This page describes what happens to information belonging to two different kinds of people, because the answers are very different:
- Candidates — people who sign in, record a session, and publish a link. Nearly everything below is about you.
- Recruiters and anyone else opening a published link — you are not asked to sign in, not asked for anything, and not identified. Section 7 is the whole of what happens on your side.
2What we hold about a candidate
Your account
There are two ways to have an account, and we hold slightly different things depending on which you used.
With Google. Signing in with Google gives us your name, email address, profile picture URL, and a stable identifier from Google for your account. We ask Google for nothing else. Firsthand cannot read your mail, cannot post anywhere as you, and never sees your Google password.
With an email address and a password. We hold the address, the name you gave us if you gave one, and a hash of your password — the output of a one-way function (scrypt), salted, from which the password itself cannot be recovered. We never store what you typed, and nobody here can read it or tell you what it is. If you forget it, it is replaced rather than recovered. Your password is never sent anywhere outside this service, and it is never written to a log.
While you are creating an account with an address and a password, and before that account exists, we hold the address, the name you gave, the hashed password and something that can recognise the emailed code — for fifteen minutes. If you never type the code, that row is all there ever was, and it goes away on its own.
Asking for a reset link puts one more short-lived row in our store: a hash of the emailed token, the account it belongs to, and when it stops working. We do not keep the link we sent you — only something that can recognise it — and the row is deleted the moment the link is used. Unused ones stop working an hour after they are sent.
The two are separate accounts unless you join them yourself. We never merge them on a matching email address: nothing about typing an address into a sign-up form proves the mailbox is yours, so treating a match as proof would let a stranger take an account over. If you want both ways into one account, sign in the way that already works and add a password from your account page.
Your résumé
When you upload or paste a résumé, its text is sent to OpenAI so the roles on it can be pulled out and offered to you as things to be interviewed about, and so the interviewer knows enough to ask a sharp question rather than a generic one. If you are signed in, one copy is kept on your account — the text, the roles found in it, and the file name — so your next session doesn’t begin by uploading the same document again. Uploading a new one replaces it entirely; there is no history. You can remove it from your account page in one click, and it is included in full in your export.
No part of a résumé ever reaches a published page.
The session itself
This is the part worth reading carefully, because it does not work the way most recording products do. When a session starts, this server mints a short-lived key and hands it to your browser. Your browser then connects directly to OpenAI and streams your microphone there. The audio does not travel through Firsthand’s servers, and we do not have a copy of the live stream.
Your browser records the conversation locally as you talk — your microphone and the interviewer’s voice, combined into one file so that an answer plays back as the exchange it actually was. The combining happens in your browser. The interviewer’s half is taken from the connection itself rather than from your speakers, and echo cancellation stays on so your microphone does not add a second copy of it. While that happens, this server keeps its own written record of the sitting: the questions as they were asked, when each one started and ended, your name, and the project you chose. No audio.
What you publish
Nothing is uploaded until you press publish, and then only the answers you marked as shared. Answers you left unshared never leave your browser — not to us, not to anyone. What we store for a published link is: the shared recordings, their transcripts, the question wording, the date and duration of the sitting, the project name and any context you typed, and the name you gave.
Recordings live in private storage. They are served only through this site, and the archived and taken-down states are enforced on the way out, so a link you kill stops serving audio.
Payment
Payments are handled by Creem, and Creem is the merchant of record — meaning it is the seller for the transaction itself, not merely a processor we hired. Practically, that is why Creem and not Firsthand is the name on your card statement, and why the tax on your purchase is calculated, collected and filed by them.
We never see or store your card number. It goes from you to Creem and never touches this service. What we keep is an identifier for your Creem customer record, the credits you have bought and spent, your plan’s status and dates, and a record of which Creem events we have already processed.
Creem holds what a seller has to hold to sell you something: your email address, your card details, and the country and any tax identifiers needed to work out what tax is owed. They are the controller of that information rather than our processor, which is the practical difference a merchant of record makes — so a request about the payment record itself goes to them, and their privacy policy governs it. Write to us anyway if that is the wrong door; we will say who to ask.
The private beta
If you joined the waitlist, we hold the email address you gave and the note you wrote about what you would use Firsthand for. If you came in on an invite code, we record which code it was.
Feedback and bug reports
Every page carries a feedback tab. If you send something through it we keep what you wrote, the address you gave us to reply to, and four details that make a bug reproducible: the path of the page you were on, your browser’s user-agent string, the size of your window, and — if you were signed in — your account. The panel lists all four before you send, with the actual values filled in, so nothing about it is a surprise.
What it deliberately does not take: the query string of the page you were on. That matters because a link’s manage address carries its takedown key there, and a bug report is not a place to keep one. It also takes no screenshot, reads nothing else on the page, and is not on the pages recruiters see.
3Who else touches it
Firsthand is small, so it runs on other people’s infrastructure. Each of these receives only what it needs to do its job, and none of them are given data to use for their own purposes:
- OpenAI — conducts the interview and transcribes it, and reads your résumé to find the roles in it. Your live audio goes to them directly from your browser. One more thing, and only if you ask for it: when you open the panel to attach a link to a job, the transcript of the answers on that page is sent to them once, to produce the notes about what a listener does not learn from it. Nothing is sent unless you open that panel, and those notes never decide whether you may attach the link.
- Google — sign-in only, and only if you choose to sign in that way. An account made with an email address and a password involves Google not at all.
- Creem — payments, subscriptions and card handling, as merchant of record. See the payment paragraph in section 2: on the payment itself Creem is the seller rather than a supplier acting on our instructions.
- Resend — sends the handful of transactional emails described in section 4.
- Fly.io, Cloudflare and Neon — hosting for the application, storage for published recordings, and the database holding billing records.
We do not sell personal information, we do not share it for advertising, and we do not use it to train any model of our own —Firsthand has no model of its own.
4Email we send
Account email is only ever about something happening to your account: a warning before a plan you have cancelled actually ends, a notice when your links have been archived, a notice when a bank payment fails, and a confirmation with the link when you publish for the first time. Creem sends your receipts and the link to its customer portal. None of that is a mailing list and none of it can be unsubscribed from, because we do not send anything you did not cause.
There is one list, and it is entirely separate: the Firsthand Market updates — new openings in the lanes you pick, and job-market briefings. It is opt-in and it is confirmed: asking for it stores your address, the topics you chose, and which page you asked from, and we send nothing at all to that address except one confirmation link until you open it. If you never open it, you never hear from us again. You do not need an account, and having an account does not put you on it.
Every message on that list carries a one-click unsubscribe that needs no sign-in and asks you nothing. We keep the row after you leave, so that it stays left — not so that we can write to you. The list is never sold, never rented, and never shared; the only third party that sees an address on it is the mail provider in §3, which sees it in order to deliver the message.
5Putting your answers in front of an employer
On the openings we match for you you can attach one of your published links to a specific job. That is an instruction to us: it means we may show that link, with the name that appears on the page, to people hiring for that role. Nothing else about your account travels with it — not your email address, not your résumé, not your other links, not any answer you chose to keep private.
We ask for that permission explicitly, with a tick box, and record when you gave it. Your link was already public, but sending it to a named employer is a different act from leaving it at an address, and it is not something we would infer from a button press.
You can take it back at any time, from the same place you gave it or from your account page, without signing anything or asking us. Withdrawing stops us showing that link for that role from then on; it cannot recall a message already sent, and we will not pretend otherwise. We keep the record that you attached and then withdrew, so that both facts stay on the record.
Two things we do not do here. We do not rank, score or grade the candidates who attach links, to employers or to anyone else — what an employer receives is your recording and the plain facts about it. And we do not harvest anyone’s email address to do this: employers are contacted at addresses a person found on a public careers page, by a person, one at a time.
Saving a position is not this, and it is worth being clear about the difference. On the same rows you can save an opening to come back to, and the saved ones are listed for you at your positions. That tells nobody anything. The employer is not informed, the public list the row came from is not informed, and it has no effect on anything we do. We keep the job it was, the date you saved it and the fact that it was your account — nothing else, and no reason for it beyond showing you the list back. Removing a save deletes the row outright; unlike a withdrawn attachment there is nothing to keep on the record, because nothing was ever done with it.
6A published link is genuinely public
This is the point of the product, but it deserves saying plainly: anyone holding the URL can open the page, play the audio and read the transcripts. No sign-in, no gate. If you post the link somewhere public, the page is as public as the place you posted it.
We do ask search engines not to index published pages, so that your voice does not become a search result for your own name long after the job search ended. That is a request, and honest search engines honour it — but it is not a lock, and it cannot stop someone who already has your link from sharing it onward. Treat a published page as something you have handed out, not something you can call back.
You decide what goes on it, one question at a time, before publishing. Afterwards you can take the page down from its manage link or from your account, and you can delete it and its recordings outright.
The contact line is yours and it is optional. On the review screen you may add an email address or an https link for recruiters to reach you; if you do, it is printed on the public page and is as visible as everything else there. It is blank unless you fill it in. We do not put your sign-in address there for you, we never sell or share it, and we send nothing to it ourselves beyond the account email described in §4. Taking it off is republishing without it, or taking the page down.
7Cookies, and what little we count
Firsthand sets one cookie, for keeping you signed in. It is strictly necessary for the site to work and it is not used to track you anywhere. There is no advertising cookie, no third-party analytics, no tag manager, no pixel, and no consent banner to click through because there is nothing to consent to.
A published page counts two things and nothing else: that someone opened it, and that someone listened past thirty seconds. So that a refresh isn’t counted as a second person, the page stores a random identifier in the viewer’s browser. That identifier is generated by the browser itself, says nothing about who anyone is, and is never stored by us in the form it was created — the server keeps only a one-way hash of it. Nothing about location, device, referrer or identity is recorded. A candidate looking at their own stats learns how many people opened the page and how many listened. That is the whole of it.
IP addresses arrive with every web request, as they must. We use them in memory to rate-limit abuse and then discard them; they are not written to the record of any link, session or account.
8If you are here to listen to someone
You are not asked to sign in and you are not identified. You are counted, once, as described above. Nothing you do on the page is reported to the candidate beyond the two numbers — not which answers you played, not how long you stayed, not who you are.
9How long any of this lasts
- Published links and their recordings — until you take them down or delete your account. A link whose plan has lapsed is archived rather than deleted, and comes back when the plan does.
- Your account and the résumé on it — until you delete them. The résumé can be removed on its own, at any time, without touching anything else.
- Unshared answers — never held at all. They stay in your browser and are gone when you close the tab.
- Billing records — kept after account deletion, because tax and accounting law requires a seller to keep records of what was sold. These are amounts, dates and identifiers, not recordings.
- A link you attached to a job — until you take it back, or until you delete your account, whichever comes first. Deleting the account removes these outright rather than anonymising them: an attachment is a standing permission to show a recording that is itself being deleted, so there is nothing left to keep it for.
- A position you saved — until you remove it, or until you delete your account. Removing one leaves nothing behind: it was never shown to anybody, so there is no record worth keeping of the fact that it existed.
- A Firsthand Market subscription — until you unsubscribe, which you can do from any message we send you without signing in. The row is kept afterwards, marked as unsubscribed, precisely so that it stays unsubscribed. An address that never confirms is simply an address we never write to.
- Feedback and bug reports — kept, but cut loose from you when you delete your account: your email address and the link to your account are removed, and the note itself stays. A bug report is a record of something wrong with the product rather than a record of the person who noticed, and deleting an account should not quietly un-report the bug. Your reports are included in your export while the account exists.
One honest gap: recording is anonymous until you publish, so the server’s written record of a sitting you never published is not attached to your account — which means deleting your account does not reach it. It holds the questions asked, their timings, and the project name, and never any audio. Ask us and we will delete it.
10What you can do about all of it
These are self-serve, free, on any plan, and available after you stop paying — none of them are behind a support queue:
- Take a copy — your account page exports everything we hold as one file, including your résumé text in full and a direct link to every recording.
- Delete everything — your account page deletes the account, every link it owns and every recording behind them. Published pages stop existing. It cannot be undone.
- Remove just the résumé — one button on the same page.
- Take one link down — from the link’s manage page or your account.
- Stop us showing a link to an employer — one click, from the job row itself or from your account page. Withdrawing takes effect immediately; it cannot recall a message already sent, and we say so rather than implying otherwise.
- Cancel — in the Creem customer portal, reachable from your billing page, without asking anyone.
If you are in the UK, the EU, or somewhere else with similar law, you also have the right to ask for access, correction, deletion, restriction, portability, and to object to processing we do on the basis of legitimate interests. Most of that is the self-serve list above; for anything it doesn’t cover, write to us and a person will do it. You can complain to your local data protection authority, though we would rather you told us first and gave us the chance to fix it.
The legal bases we rely on, in the same order they come up: performing our contract with you (running sessions, publishing links, taking payment); our legitimate interests (keeping the service up, preventing abuse, counting opens so a candidate knows whether their link was read); and legal obligation (keeping financial records).
11Where it is, and who it is not for
Firsthand is operated from the United States and its providers are largely United States companies, so if you are elsewhere your information is transferred there. Where that transfer needs a legal mechanism, our providers offer the European Commission’s standard contractual clauses, and we rely on them.
Firsthand is not intended for anyone under 16, and is not directed at children. If you believe a child has recorded a session, tell us and we will delete it.
12When this page changes
If we change something that matters — a new provider receiving your data, a new category of information, a real change in what is published — we will say so on this page and update the date at the top, and email you if the change is significant enough to deserve it. Continuing to use Firsthand after that means the new version applies.
Questions, corrections, or a request that isn’t on the self-serve list: support@hearfirsthand.com. Also see the Terms of Service.