Privacy
Last updated: July 19, 2026
Private by default
Pipeline stores the identity information needed for your account and the preparation evidence you ask it to remember: plans, tasks, role context, questions, practice attempts, readiness signals, and debriefs. Interview questions and debriefs remain private unless you take an explicit sharing action.
Shared question intelligence
A question enters the shared corpus only after explicit contribution. Shared records are designed to carry useful provenance and role context without publishing the contributor's private notes, answer drafts, practice history, or debrief.
Agent access
Claude or Codex can access your preparation workspace only with a scoped token you approve while signed in. Pairing codes expire quickly. Tokens are stored as one-way hashes on the server, can be replaced or revoked, and are never placed in a public skill package.
Storage and transport
Account and preparation records are stored in PostgreSQL. Passwords are hashed with bcrypt, authenticated API responses are non-cacheable, and production traffic uses HTTPS. The public role-intelligence gateway exposes a fixed read-only projection; it does not expose database credentials.
Service providers
Pipeline uses infrastructure providers to run the site, database, authentication, and operational monitoring. Those providers process only the information required to deliver their service. Pipeline does not sell personal data or use advertising trackers.
Your choices
You can keep every question private, decline or deny an agent pairing, replace an active token, and ask for your account data to be corrected or deleted. Removing a private source record does not necessarily remove a separately contributed, anonymized corpus record where retention is legally permitted.