Skip to main content

Privacy Policy

What Hey Vitae collects, why, and what you control.

Effective date · May 7, 2026

Hey Vitae is operated by Functioning Labs LLC and handles a lot of personal job-search material. This page explains how that data is collected, used, shared, and protected — and how to change your mind.

TL;DR

The friendly version.

  • We collect the information needed to run your job-search workspace, support the features you choose to use, keep Hey Vitae secure, and improve the product.
  • We don't sell your personal information, and we don't use your private workspace content to train public AI models.
  • When you use AI features, relevant prompts and context may be sent through Vercel AI Gateway to providers such as OpenAI and Anthropic. We may store AI inputs and outputs to power features like saved analyses, drafts, and history — and you can delete them.
  • Spotlight pages and job-specific share URLs are public the moment you publish or share them. Treat those links as public.
  • You can manage analytics and marketing cookies anytime at /privacy-choices and delete your account anytime from Settings.

Section 1

What we collect.

From you, when you use the product:

  • Account info: name, email, profile picture, and authentication identifiers.
  • Job-search content: jobs, applications, statuses, notes, resumes, cover letters, interview prep, and tagged contacts.
  • Spotlight content: anything you publish on a public Spotlight page or job-specific share URL.
  • Email content: messages and attachments delivered to a Hey Vitae mailbox address you've created, plus the metadata needed to thread replies.
  • Browser-extension data: job-posting pages and form fields you choose to capture into Hey Vitae.
  • Billing details: handled by Stripe — we receive subscription status, plan, and the last four digits of your card; we never see full card numbers.
  • Support communications: anything you send us by email or in-app.

Automatically:

  • Usage data: pages viewed, features used, approximate location from IP, device and browser type, and referrer.
  • Diagnostics: error reports and performance traces from Sentry, Vercel, and Supabase.
  • Cookies and similar storage: see the Cookies section below for the full breakdown.

Sensitive content.Hey Vitae is designed for job-search information, not highly sensitive records. Please avoid uploading government ID numbers, financial account numbers, medical records, immigration documents, or other sensitive information unless it's necessary for your job search — and avoid sharing details about other people that you don't have permission to share.

Section 2

How we use it.

  • Operate and improve the product, including syncing your data across the web app, browser extension, and email features.
  • Process payments and manage subscriptions through Stripe.
  • Generate AI analyses, suggestions, and drafts when you invoke an AI feature.
  • Send transactional messages (account, billing, security) and, with your consent, product updates.
  • Detect abuse, prevent fraud, and keep the service secure.
  • Comply with legal obligations.

We don't sell your personal information, and we don't share it for cross-context behavioral advertising unless you opt in to the marketing cookie category at /privacy-choices.

Section 3

AI features.

When you invoke an AI feature (job analysis, document feedback, drafting, interview prep, etc.), Hey Vitae may send the relevant prompt and context through Vercel AI Gateway to a model provider. Current providers include OpenAI and Anthropic.

The provider processes your prompt to generate a response and returns it to us. Under standard OpenAI and Anthropic API terms, commercial inputs and outputs are not used to train their public models by default, and we don't use your private workspace content to train models either.

We may store AI inputs and outputs when needed to power product features — for example, saved analyses, drafts, and history — and you can delete them.

AI features may analyze resumes, job descriptions, emails, notes, and other workspace content you provide or select. AI output may be incomplete, outdated, biased, or incorrect. You are responsible for reviewing AI-generated drafts, recommendations, and analyses before relying on them.

Section 4

Email features.

When you create a Hey Vitae mailbox address (an address on a Hey Vitae domain), messages sent there are delivered to our processing pipeline, parsed into your workspace, and tied to the relevant job, application, or thread. Replies you send from Hey Vitae are routed back through that pipeline.

These messages may contain personal information about you and the people you're corresponding with. We process them only to operate the email features for you, and we apply the same retention and deletion controls as other workspace content.

People who email your Hey Vitae mailbox address may not have a direct relationship with Hey Vitae. You are responsible for using the mailbox feature appropriately and for not forwarding or importing messages you don't have the right to process.

Section 5

Browser extension.

The Hey Vitae browser extension reads page content only when you actively invoke it on a job posting or supported page, and sends the captured fields to your account so they show up alongside your other jobs. It does not run in the background, track your browsing, or read pages you don't explicitly capture.

The extension may require browser permissions to read supported pages, but it only transmits content to Hey Vitae when you choose to capture it.

Section 6

Cookies and similar storage.

We group cookies into three categories:

  • Essential— required to sign you in, keep your session safe, and remember the choices you make on this page. Always on.
  • Analytics— Google Analytics 4 via Google Tag Manager, used to understand which features people actually use. Off by default, on only with your consent.
  • Marketing— ad and attribution storage used to measure campaign performance. Off by default, on only with your consent.

Manage your choices anytime at /privacy-choices. Disabling optional cookies will not break the product. We may store a record of your cookie preferences so we can remember and honor your choices on future visits.

Section 7

Spotlight and public pages.

Spotlight portfolio pages and job-specific share URLs are public by design. Anything you publish on them — bio, photo, links, pitch — is visible to anyone with the URL and may be indexed by search engines. Treat job-specific share URLs as public links, not private secure portals; anyone they're sent to can re-share them.

Unpublishing or deleting a page removes it from Hey Vitae, but copies, screenshots, search-engine caches, or links already shared with others may remain outside our control. Don't put information on a Spotlight page that you don't want to be public.

Section 8

Who we share data with.

We share personal information only with service providers who help us operate Hey Vitae, and only to the extent they need it. Current providers:

  • Functioning Labs LLC / Functioning Human — our related product family, shared identity and billing infrastructure, and optional bundled access for eligible Hey Vitae plans.
  • Supabase — primary database, authentication, and file storage (US region).
  • Vercel — hosting and the AI Gateway that proxies model requests.
  • Stripe — payment processing and subscription billing.
  • OpenAI and Anthropic — AI providers that respond to prompts you submit through AI features.
  • Google (Tag Manager and Analytics) — only if you accept the analytics cookie.
  • Sentry — error and performance monitoring.
  • Postmark — transactional and mailbox email delivery for Hey Vitae mailbox addresses.
  • Brevo — marketing email and broadcast campaigns, only when you opt in.
  • These providers are bound by contract to use your personal information only to deliver their service to us — not for their own marketing.

We may also disclose information if required by law, to enforce our terms, or to protect the rights, property, or safety of users or the public.

Section 9

Where data lives.

Hey Vitae primarily uses US-based infrastructure (Supabase and Vercel). If you access Hey Vitae from outside the United States, your information may be processed in the United States and other countries where our service providers operate. Where required by law, we rely on appropriate safeguards for international transfers.

Section 10

How long we keep it.

Account data is kept as long as your account is active. When you delete your account, we aim to delete or anonymize personal data within roughly 30 days, except where we're required to keep records for legal, billing, security, backup, or fraud-prevention purposes (for example, Stripe transaction records).

Backups are retained on a rolling schedule and overwritten in the normal course of operations.

Section 11

Security.

We use reasonable administrative, technical, and physical safeguards — encryption in transit, scoped credentials, access controls, error monitoring — to protect your information. No system is perfectly secure; if a breach affects you, we'll notify you as required by law.

Section 12

Other sites and Functioning Labs products.

Hey Vitae links to and integrates with other sites and products, including Functioning Human and other Functioning Labs products. When you leave Hey Vitae or sign in to a different Functioning Labs product, the terms and privacy policy of that site or product apply to your activity there. We're not responsible for the privacy practices of external sites linked from Hey Vitae.

Section 13

Your rights and choices.

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct or update inaccurate information from your Settings page or by contacting us.
  • Delete your account and the personal data tied to it.
  • Export your data in a machine-readable format.
  • Withdraw consent for analytics or marketing cookies at any time.
  • Object to or restrict certain processing where applicable law gives you that right.

You can exercise most of these directly in Settings. For anything else, email hello@heyvitae.com and we'll respond within the timeframe required by applicable law.

Section 14

California residents (CCPA/CPRA).

We do not sell personal information for money. If you have analytics or marketing cookies enabled, that may be considered “sharing” for cross-context behavioral advertising under California law. To opt out, set the Marketing toggle off at /privacy-choices. California residents also have rights to know, delete, correct, limit the use of sensitive personal information, and not be discriminated against for exercising those rights — see Section 13.

Categories of personal information we handle:

CategoryExamplesSourcePurpose
IdentifiersName, email, auth IDYou, auth providerAccount access
Job-search contentJobs, applications, notes, resumes, cover letters, interview prepYouWorkspace features
Internet/activity dataPages viewed, feature usage, device and browser typeAutomaticallyAnalytics and security
Commercial informationPlan, subscription status, last four digits of cardStripeBilling
CommunicationsSupport messages, mailbox content and attachmentsYou and people who email your mailboxEmail features and support
InferencesAI-generated suggestions, job-fit analysisProduct use and AI featuresProduct features

Section 15

EEA, UK, and Swiss residents.

Where the GDPR or UK GDPR applies, we process your personal data on the legal bases of contract performance (to provide the service you signed up for), legitimate interests (to keep the service secure and improve it), consent (for optional cookies and marketing email), and legal obligation. You can object, restrict, or withdraw consent at any time using the controls described above.

Section 16

Children.

Hey Vitae is intended for users 13 and older. We don't knowingly collect information from children under 13. If you believe a child has given us information, email hello@heyvitae.com and we'll delete it.

Section 17

Changes to this policy.

When we update this policy, we'll change the effective date at the top. Material changes will be flagged in-product or by email before they take effect.