EngBolt

Legal

Privacy Policy

Last updated 23 August 2026

1. Who this policy covers

EngBolt is operated by Sahariar Tanaf Chowdhury as an individual sole trader trading as EngBolt. This policy explains how EngBolt, the service available at engbolt.com, handles personal data when you use the website, create an account, track applications, practise assessments, submit CV content, use interview feedback, or make a payment.

2. Data we collect

  • Account data, including your email address, account identifier and authentication information handled by Supabase Auth.
  • Profile data you provide, such as your name, username, university, degree, graduation year and engineering discipline.
  • Job preferences, including sectors, locations, opportunity types, salary preferences and sponsorship preferences.
  • Application-tracker data, saved jobs, stages, dates and other information you choose to record.
  • CV text and CV-review results. EngBolt currently extracts supported CV files in your browser and stores the extracted text needed for your CV history rather than the original file.
  • Assessment attempts, answers, scores, timings and interview answers or transcripts you submit for practice and feedback.
  • Payment and subscription references, such as Stripe customer, checkout and subscription identifiers. EngBolt does not receive your full card details.
  • Security and anti-abuse data, including a functional device identifier and pseudonymised hashes derived from device and network information.
  • Technical information generated when you use the service, such as request, error and security logs produced by hosting and infrastructure providers.

3. Why we use your data

  • To provide your account, job tracker, practice tools, saved history and paid features.
  • To personalise role matching and career-preparation features from the preferences you provide.
  • To process and verify payments and subscriptions.
  • To generate AI-assisted CV and interview feedback when you request it.
  • To prevent abuse, enforce fair-use limits, investigate faults and protect the service.
  • To display leaderboard information only where your profile is opted in to public rankings.

EngBolt generally relies on performance of the service contract for account and requested features, and legitimate interests for proportionate service security, fraud prevention and reliability. Where consent is used for an optional feature, you can withdraw that choice through the relevant account control.

4. AI processing

EngBolt uses OpenAI APIs for AI-assisted CV review, interview feedback and speech transcription. When you request one of these features, the content required for that request can be sent to OpenAI. This can include CV text, interview answers, an engineering sketch you attach, or interview audio submitted for transcription. Do not include personal information that is not needed for the feedback you want.

AI output is generated automatically and can be incorrect. EngBolt does not use AI output to make employment, admissions, credit or other legally significant decisions about you.

5. Service providers

EngBolt uses the following providers for the stated purposes:

  • Supabase for authentication and the application database.
  • Vercel for website hosting, server execution and associated technical logs.
  • Stripe for checkout, subscriptions, billing management and payment records.
  • OpenAI for the AI and transcription features described above.
  • GitHub hosts EngBolt source code and deployment workflows. Normal production user-submitted content is not intentionally sent to GitHub.

These providers may process information in countries outside the UK. Where UK data-protection law requires safeguards for an international transfer, EngBolt relies on the safeguards made available under the relevant provider contract and applicable law.

6. Public rankings

Public ranking participation is optional for new accounts. If you opt in, your username, optional university and eligible scores can be displayed publicly. You can turn rankings off in Profile. Turning them off removes your eligible data from EngBolt public leaderboard views.

7. Cookies and local device data

EngBolt uses functional authentication storage and a first-party et_device identifier for anti-abuse controls. The device value is pseudonymised before related abuse signals are stored. EngBolt does not currently use this identifier for advertising.

8. Retention and deletion

Account-linked profile, tracker, CV, assessment and interview records are retained while needed to provide your account and saved history. You can permanently delete your EngBolt account and account-linked application data from Profile. EngBolt also limits security and anti-abuse data to what is reasonably needed to protect the service and investigate misuse.

Deleting your EngBolt account does not require independent providers such as Stripe to erase records they must keep for their own legal, accounting, fraud-prevention or regulatory obligations. Backups and provider logs may also expire on their normal protected backup or log-retention cycles rather than instantly.

9. Your rights

Depending on the circumstances, UK data-protection law can give you rights to access, correct, erase, restrict or receive your personal data, and to object to certain processing. Where processing is based on consent, you can withdraw consent without affecting earlier lawful processing. You can delete your account in Profile and change public-ranking visibility there at any time.

You can also complain to the UK Information Commissioner's Office if you believe your personal data has been handled unlawfully.

10. Security

EngBolt uses access controls, row-level database security, server-side authorisation, HTTPS, security headers, restricted server secrets and payment verification controls. No internet service can guarantee absolute security, so please use a strong password and protect access to your account.

11. Contact and policy changes

EngBolt is operated by Sahariar Tanaf Chowdhury, trading as EngBolt. For privacy, data-protection or general legal enquiries, contact tanaf.chowdhury20@gmail.com. Signed-in users can use Profile for correction, ranking visibility and account deletion. EngBolt will update this policy when the service or its data uses materially change and will update the date shown above.

A business contact address will be added once established.

See also the Terms of Service.