Skip to main content

Privacy Policy

What Hey Vitae collects, why, and who controls it.

Effective date · July 31, 2026

Hey Vitae is operated by Functioning Labs LLC. This policy covers the job-seeker product and Hey Vitae for Coaches, including information a practice keeps about its own clients.

TL;DR

The friendly version.

  • You keep ownership of the material you put in your job-search workspace. We use it to provide the product, not to train public AI models.
  • A coaching practice may keep its own client records in Hey Vitae. The practice controls that Practice Data; Hey Vitae is the service provider that stores and processes it for the practice.
  • A practice can see your live Hey Vitae workspace only after you accept its connection, and you can end that access in Settings.
  • Ending a connection stops live workspace access. It does not automatically delete the practice's own notes, files, CRM fields, session records, or other Practice Data.
  • Optional analytics and marketing tools are off unless you choose them. You can change that choice at /privacy-choices.
  • We don't sell personal information.

Section 1

Who this policy covers.

This policy applies when you use Hey Vitae as a job seeker, visit our public pages, join or operate a coaching practice, appear in a practice's client records, or contact us.

Functioning Labs LLC is responsible for information used to run Hey Vitae itself: accounts, direct job-seeker workspaces, billing, product security, support, and optional analytics.

A coaching practice may also use Hey Vitae to keep information that it collected from or about its clients. We call that Practice Data. The practice decides why that data is kept and how it is used. Hey Vitae does not own Practice Data; Functioning Labs processes it for the practice as a service provider or processor, where those terms apply. The practice remains responsible for its relationship with the client and its own privacy obligations.

Section 2

What we collect, and where it comes from.

Information you provide:

  • Account and profile information: name, email, profile picture, authentication identifiers, settings, and support messages.
  • Job-search workspace content: jobs, applications, statuses, notes, resumes, cover letters, interview prep and results, job-search preferences, contacts, and other material you save.
  • Email content: messages and attachments delivered to a Hey Vitae mailbox address you create, plus the metadata needed to organize and send replies.
  • Browser-extension content: job-posting pages and form fields you choose to capture into Hey Vitae.
  • Public content: anything you publish on a Spotlight page or job-specific share URL.
  • Practice information: practice name and settings, team membership, client records, notes, files, custom fields, session records, and other information a practice chooses to store.
  • Billing information: Stripe handles payment-card details. We receive information such as plan, subscription and payment status, invoices, and limited card details such as brand and last four digits.

Information others provide:

  • A coaching practice may give us a client's name, email address, intake details, notes, files, custom fields, session history, and related records. This is information the practice provides and controls; Hey Vitae does not create or supply it.
  • People may send messages and attachments to a Hey Vitae mailbox address you created.
  • Authentication, payment, analytics, and infrastructure providers send us the account, transaction, device, and diagnostic information needed to provide their part of the service.

Information collected automatically:

  • Essential technical data: IP address, request and security logs, device and browser details, and information needed to authenticate you, prevent abuse, and keep the service working.
  • Optional product analytics: pages viewed, features used, referrer, approximate location derived from IP, and session interactions when Analytics is enabled.
  • Diagnostics: error reports, traces, and performance information from infrastructure and error-monitoring services.

Information we read from public job boards:

  • Public job postings: we read openly published listings from employer applicant-tracking systems such as Greenhouse, Lever, Ashby, and Workable, and keep them in a catalog that is shared across Hey Vitae rather than stored in one account.
  • What prompts a read: naming a company as a target in your search profile, or saving a job whose link points at one of those systems, tells us which employer's board to read.
  • What the catalog holds: employer postings only — job title, company, location, description, and the apply link the employer published. It holds nothing about you, and no other user can see who caused a company to be added.

Hey Vitae is built for job-search and coaching records, not medical files, government identifiers, financial-account numbers, or similarly sensitive records. Please do not add that material unless it is genuinely needed and you have the right to process it.

Section 3

How we use information.

  • Provide, secure, support, and maintain Hey Vitae and sync data across the features you choose to use.
  • Process payments, manage subscriptions and practice credits, and keep required transaction records.
  • Generate analyses, briefs, suggestions, and drafts through AI features.
  • Read public employer job boards and maintain a shared catalog of those postings, so we can suggest open roles matching the search profile you set. Your target companies and the links on jobs you save tell us which boards to read.
  • Send account, billing, security, invitation, and other transactional communications.
  • Measure and improve the product when you allow optional Analytics, and measure marketing when you allow optional Marketing.
  • Detect abuse, prevent fraud, troubleshoot problems, enforce our terms, and comply with law.

We do not sell personal information. We do not use private job-seeker workspace content or Practice Data to train public AI models, and we do not use Practice Data for our own advertising.

Section 4

AI features.

Hey Vitae sends the prompt and limited context needed for an AI feature through Vercel AI Gateway or directly to the provider serving that feature. Providers may include OpenAI, Anthropic, and Hume, and may change as the product evolves.

Job-seeker AI features may process the resumes, job descriptions, notes, interview material, preferences, or other workspace content you select or that the feature needs. Coaching AI may automatically prepare a coach-only pre-session brief from limited information already available to the connected practice. It may also draft a recap or next steps when a coach asks, using the practice's own session notes. Those drafts do not automatically change a client's workspace, send a message, or assign a task.

The automatic coach brief does not send resume or cover-letter text, private free-text interview reflections, mailbox content, contacts, or account and billing settings to the model. A client's private practice reflection is not sent for the brief, even if the client chose to share that reflection with the practice.

We may store AI inputs and outputs when needed for saved analyses, history, cached briefs, and drafts. AI output can be incomplete, biased, outdated, or wrong. A person should review it before sending, publishing, or relying on it.

Section 5

When you connect with a coaching practice.

A practice may send an invitation or give you a join code, but it does not receive access to your existing Hey Vitae workspace until you accept. The invitation screen explains the current access before you decide. Declining does not remove your job-seeker account.

While connected, every active coach at the practice can use its shared roster to see the workspace information listed on that consent screen. This currently includes tracked jobs and stages, Apply IQ analysis, resumes and cover letters, interview prep, selected interview results, job-search preferences, and the email address used for the invitation. It does not include your mailbox or message threads, contacts, account and billing settings, practice-interview recordings or transcripts, or anything from your camera.

Coaches can add clearly labeled jobs, tasks, shared notes, document comments, suggested documents, and proposed AI rules. A proposed rule does nothing unless you accept it. Coaches cannot apply, send messages as you, edit or delete material you created, change your settings, or act as you. Practice access is logged for you to review.

Your private practice-session reflection stays private unless you choose to share it in Settings. Practice-session scores and summaries are included in the connection either way.

Section 6

Practice records and offline clients.

A practice can create an offline client record without inviting the person or linking a Hey Vitae account. That record may include a name, email address, notes, files, custom fields, sessions, packages, outcomes, and other CRM information the practice chooses to add. Hey Vitae does not supply that information, and no invitation is sent unless the practice separately chooses to send one.

Practice-private notes, files, custom fields, internal CRM records, and other Practice Data are visible to authorized members of the practice, not to the client through Hey Vitae. A connected client's live workspace is different: it belongs to the client and remains available to the practice only while the connection is active.

If you are listed in a practice's records and want to access, correct, or delete that Practice Data, contact the practice first. It is the data owner or controller for that record. If you contact Hey Vitae, we may direct or forward the request to the practice and will assist it as required by law and our service-provider role.

Section 7

Ending a coaching connection.

A connected client can end a practice's access in Settings. The practice can also close the engagement. In either case, access to the client's live workspace ends immediately for the practice and its connected assistants.

Ending the connection does not automatically delete Practice Data. The practice may keep its private notes, files, CRM fields, session and package records, outcomes, closing summaries, and other records it created or supplied until it deletes them or asks us to do so, subject to legal retention requirements. It can no longer use the ended connection to read the client's live list of jobs, employers, documents, or other workspace content.

If a practice pays for a client's subscription, we tell the practice whether it is providing that coverage and whether the connection is active. We do not give it the client's payment-card details.

Section 8

Connected AI assistants.

A practice may connect a third-party assistant such as ChatGPT or Claude. When it does, the client is told before connecting or in the product. The assistant can read a limited summary of client names, applications, interviews, and practice totals, but not client email addresses or the text of resumes and cover letters. Access is logged.

Information read through a connected assistant is also processed by the company that provides that assistant under its own terms and privacy practices. The practice chooses and controls that connection and is responsible for its use.

Section 9

Email, browser extension, and public pages.

Messages sent to a Hey Vitae mailbox are processed and stored so we can organize them in the workspace and route replies. People who email that address may not have a direct relationship with Hey Vitae, so the account owner is responsible for using the feature lawfully.

The browser extension reads supported page content when you actively use it to capture a job. It sends the selected content to your account; it does not use that permission to track unrelated browsing in the background.

Spotlight pages and job-specific share URLs are public when you publish or share them. Anyone with the URL may view or re-share them, and search engines may index public pages. Unpublishing removes the Hey Vitae page, but not screenshots, caches, or copies outside our control.

Section 10

Cookies and optional analytics.

We group browser storage and related tools into three categories:

  • Essential — authentication, security, preference storage, fraud prevention, and diagnostics needed to operate the service. Always on.
  • Analytics — PostHog, Google Analytics, Vercel Analytics, and Vercel Speed Insights, including optional session recording. Off unless you enable Analytics.
  • Marketing — campaign, advertising, and attribution tools. Off unless you enable Marketing.

You can change your choice at /privacy-choices. Turning off optional categories does not disable the core product. We keep a record of consent choices so we can honor them and demonstrate compliance.

Section 11

Who receives information.

We disclose information to providers that help us deliver Hey Vitae, limited to what they need for their role:

  • Functioning Labs product family — shared account, billing, and optional bundled-access infrastructure.
  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting, performance services, and the AI Gateway that routes model requests.
  • Stripe — payments, invoices, subscriptions, and billing management.
  • OpenAI, Anthropic, and Hume — AI and realtime interview providers used for analysis, drafting, and interview features.
  • PostHog — product analytics and optional session recording, only when Analytics is enabled.
  • Google — Tag Manager, Analytics, and campaign measurement, only when the applicable optional category is enabled.
  • Sentry — security, error, trace, and performance monitoring.
  • Greenhouse, Lever, Ashby, and Workable — public employer job boards we read to build the job catalog. We send them only a company identifier; no information about you is disclosed to them.
  • Postmark — transactional email, invitations, and Hey Vitae mailbox delivery.
  • Brevo — product updates and marketing email when you opt in.

We may also disclose information during a business transaction, when required by law, to enforce our terms, or to protect users, Functioning Labs, or the public. We do not let service providers use personal information for their own marketing.

Section 12

Where information is processed.

Hey Vitae primarily uses US-based infrastructure. Information may be processed in the United States and other countries where our providers operate. When transfer rules apply, we use the safeguards required by applicable law.

Section 13

How long we keep it.

Direct account and workspace information is generally kept while the account is active. When an account is deleted, we aim to delete or anonymize personal data within roughly 30 days, except for billing, security, fraud-prevention, legal, and backup records we need or are required to retain.

Practice Data is kept until the practice deletes it or asks us to delete it, subject to legal holds and records that must be retained. A practice owner can contact hello@heyvitae.com to close a practice and request deletion while in-product practice deletion is not available.

Backups are kept on a rolling schedule and overwritten in the normal course. Consent, access, billing, security, and audit logs may outlive an account or connection where needed to document permissions, prevent abuse, resolve disputes, or comply with law.

Section 14

Security.

We use reasonable administrative, technical, and physical safeguards, including encryption in transit, scoped credentials, access controls, audit records, and error monitoring. No system is perfectly secure. If a breach affects you, we will notify you when the law requires it.

Section 15

Your rights and choices.

Depending on where you live, you may have the right to:

  • Ask for access to personal information we hold about you.
  • Correct inaccurate information.
  • Ask us to delete personal information or your account.
  • Request a portable copy of information, where applicable.
  • Withdraw consent for optional analytics or marketing.
  • Object to or restrict certain processing where applicable law provides that right.
  • Appeal a decision or complain to a data-protection authority where applicable.

For a Hey Vitae account or direct job-seeker workspace, use Settings or email hello@heyvitae.com. For Practice Data, contact the practice that collected it. We may need to verify identity and authority before completing a request.

Section 16

California and other US state privacy rights.

We do not sell personal information for money. Optional advertising or campaign technology may be considered “sharing,” targeted advertising, or a sale under some state laws. Turn off Marketing at /privacy-choices to opt out. We do not discriminate against people for exercising privacy rights.

In the last 12 months, the categories handled may include identifiers, professional and employment information, internet activity, commercial information, communications, user content, approximate location, and inferences. We collect them from users, practices, communications, providers, and product use for the purposes described in Sections 2 and 3, and disclose them to the providers and practices described above.

When Hey Vitae processes Practice Data for a practice, the practice is the business or controller and Functioning Labs acts as its service provider or processor. Requests about that data should go to the practice.

Section 17

EEA, UK, and Swiss residents.

When applicable, we rely on contract performance to provide the service, legitimate interests to secure and improve it, consent for optional analytics and marketing, and legal obligations. Where a practice controls Practice Data, the practice determines its lawful basis and we process the data on its instructions. You may withdraw consent without affecting processing that already occurred lawfully.

Section 18

Children.

The direct job-seeker product is intended for people 13 and older. We do not knowingly collect direct account information from children under 13. Practice owners and team members must be at least 18. If you believe a child's information was added improperly, contact the practice if it is Practice Data or email us at hello@heyvitae.com.

Section 19

Other products and sites.

Hey Vitae may link to Functioning Human, connected AI assistants, and other services. Their own terms and privacy practices apply when you use them. We are not responsible for independent third-party sites merely because Hey Vitae links to them.

Section 20

Changes and contact.

We may update this policy as the product or law changes. We will change the effective date above and provide additional notice of material changes when appropriate.

Privacy questions about Hey Vitae can go to hello@heyvitae.com. Questions about a practice's own records should go to that practice first.