Legal
Privacy Policy
Last updated: July 5, 2026
This Privacy Policy explains how Redline HQ, Inc., a Delaware C Corporation(“Redline HQ,” “we,” “us,” or “our”), operator of Playbook at consultingplaybook.io (the “Service”), collects, uses, discloses, and safeguards personal information when you access or use the Service, including our website, web application, communications, and related tools. This Policy applies to visitors, registered users, users who access the Service through an organization license, and users who purchase paid passes. By using the Service, you acknowledge that you have read and understood this Policy.
Introduction and Scope
Redline HQ, Inc. operates Playbook, an educational and organizational platform that helps candidates prepare for consulting recruiting. This Policy covers all personal information we handle in connection with the Service. It does not cover the practices of third-party websites, services, or applications that you may access through links from the Service; those third parties operate under their own privacy policies.
Definitions
- Personal data means any information that identifies, or could reasonably be linked to, an identified or identifiable natural person.
- Processing means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- Data controller means the entity that determines the purposes and means of processing personal data. For the Service, Redline HQ is the data controller.
- Data processor means a party that processes personal data on behalf of the controller under a written contract.
- Service means Playbook, including the website, web application, APIs, and any related features made available by us.
- You means the individual using the Service, whether as a visitor, an individual account holder, or a user provisioned under an organization license.
Information We Collect
Information You Provide Directly
- Account data: your name, email address, and password. If you sign in with Google, we receive an OAuth token and the profile information listed below in place of a password.
- Profile data: school, graduation year, target firms, career stage, recruiting goals, and any optional biographical details you choose to add to your profile.
- Resume content: resume files you upload and the text extracted from them, along with AI-generated analysis of your resume.
- Fit and case content: fit stories, personal narratives, notes, and case practice history you create and store in the Service.
- Application and network tracking data: applications you add, deadlines, statuses, interview reports, contacts, outreach logs, and follow-up notes.
- Payment information: processed directly by Stripe. We do not receive or store your full card number, CVC, or full bank account details. We receive limited transaction metadata (amount, currency, last four digits, billing country, and a Stripe customer identifier).
- Communications: messages you send to support, feedback you submit, survey responses, and referral submissions.
Information Collected Automatically
- Log data: server logs that record requests to the Service, including timestamp, HTTP method, path, response status, and approximate location derived from IP address.
- Device data: browser type and version, operating system, device type, screen size, and language settings.
- Session data: authentication tokens and session identifiers used to keep you signed in and to secure your session.
- IP address: collected for security, abuse prevention, and to protect the integrity of your account.
Information From Third Parties
- Google OAuth: if you sign in with Google, we receive your name, email address, and (if available) profile picture.
- Organization licensing: when your access is provided by an employer, school, or other organization, we receive the organization name, seat allocation status, and the email address the organization administrator uses to invite you.
- Payment provider: Stripe provides us with payment confirmation, refund status, and dispute notices.
How We Use Your Information
We use personal information for the purposes below. Where the GDPR, UK GDPR, or a similar law applies, the lawful basis for each purpose is indicated in parentheses.
- Provide, operate, and maintain the Service (performance of a contract).
- Personalize recommendations, dashboards, readiness scoring, and next-step suggestions (performance of a contract).
- Process payments, manage passes and subscriptions, and issue receipts (performance of a contract).
- Send transactional emails such as receipts, invite links, verification messages, and important account notices (performance of a contract).
- Send product update and non-essential nudges or announcements (consent, with an opt-out available in Settings and in each email).
- Improve the Service by analyzing aggregate, de-identified usage patterns (legitimate interest in improving the product).
- Prevent, detect, and investigate fraud, abuse, unauthorized access, and violations of our Terms of Service (legitimate interest in protecting the Service and its users).
- Comply with legal obligations, respond to lawful requests, and enforce our agreements (legal obligation).
AI Processing Disclosure
Several features of the Service use artificial intelligence to generate responses, feedback, and analysis. This includes the AI Coach for case practice, resume analysis, cover letter drafts, fit story feedback, and firm intelligence briefs.
- AI outputs are generated by machine learning models and may contain errors, omissions, or outdated information.
- AI outputs are not professional advice and are not a substitute for career counseling, legal, financial, or employment guidance.
- Redline HQ, Inc. does not train third-party AI models on your personal content. Prompts and responses may be transmitted to upstream AI providers solely to generate a response, subject to those providers’ contractual obligations to us.
- You are responsible for reviewing and verifying AI outputs before relying on or submitting them to any third party.
Voice Data
When you enable voice input during case practice or coaching, your speech is transcribed in real time by ElevenLabs Scribe. No audio recordings are created or stored by Redline HQ, Inc. or, per ElevenLabs’ documentation for the Scribe streaming transcription flow, by ElevenLabs. Only the resulting text is retained and it is treated as your user content, subject to the same protections and rights described elsewhere in this Policy. You may disable voice input at any time in your session settings.
How We Share Your Information
We disclose personal information only in the circumstances below. We do not sell your personal information. We do not share your personal information with advertisers. We do not use your personal information for cross-context behavioral advertising.
- Supabase — provides authentication and database hosting. Data shared: account credentials, profile data, user content, and any data stored in the Service. See Supabase Privacy Policy.
- Stripe — processes payments and refunds. Data shared: your email, billing address (if provided at checkout), and transaction details. See Stripe Privacy Policy.
- ElevenLabs — provides real-time voice transcription. Data shared: streamed audio during a voice session, which is transcribed and discarded. See ElevenLabs Privacy Policy.
- Google — provides OAuth sign-in. Data shared: OAuth authorization tokens. See Google Privacy Policy.
- Email delivery provider — sends transactional and notification emails on our behalf. Data shared: recipient email address and message content.
- Legal disclosures: when we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process, or is necessary to protect the rights, property, or safety of Redline HQ, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal information may be transferred as part of the transaction. We will notify you of any change in ownership or control of your personal information.
Organization Licensing
Some users access the Service through a license purchased by an employer, school, or similar organization. When this is the case, the following applies to how information flows between you and your organization.
- Visible to the organization administrator: your name, the email address associated with your seat, and seat status (invited, active, or revoked).
- Not visible to the organization administrator: your activity data, cases practiced, scores, applications, contacts, fit stories, resume content, notes, AI conversations, or any other usage information.
- On revocation or license expiration: your access reverts to the free tier. Personal data associated with your account is retained under your own account and remains under your control, subject to this Policy.
Data Retention
- Active accounts: personal information is retained for as long as your account is active or as needed to provide the Service.
- Deleted accounts: personal data is deleted within thirty (30) days after we receive and verify a deletion request or you delete your account.
- Payment and transaction records: retained for approximately seven (7) years to comply with tax, accounting, and financial recordkeeping requirements.
- Server logs: retained for approximately ninety (90) days for security and troubleshooting purposes.
- Backup copies: purged within approximately sixty (60) days of the original deletion.
Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption in transit using industry-standard TLS, encryption at rest for stored databases, row-level security policies that limit access to a user’s own data, principle-of-least-privilege access controls for personnel, secure credential storage, and payment tokenization through Stripe so that card numbers are never stored on our systems.
No security program is perfect and no method of transmission or storage is one hundred percent secure. If we become aware of a personal data breach affecting your information, we will notify you and applicable regulators without undue delay and consistent with applicable law.
Your Rights
You have the following rights with respect to your personal information. To exercise any of them, email hello@consultingplaybook.io. We will verify your identity and respond within thirty (30) days, subject to extensions permitted by applicable law.
- Right to access the personal information we hold about you.
- Right to correction of inaccurate or incomplete personal information.
- Right to deletion of your personal information, subject to legal exceptions.
- Right to data portability — receive an export of your data in a commonly used, machine-readable format.
- Right to restrict processing in specific circumstances.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent at any time where processing is based on consent.
- Right to opt out of marketing communications using the unsubscribe link in any marketing email or the notification controls in Settings.
California Privacy Rights (CCPA/CPRA)
This section applies to California residents. In the preceding twelve months, we have collected the following categories of personal information as defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”).
- Identifiers — name, email address, IP address, account identifiers, and OAuth identifiers.
- Commercial information — records of passes purchased, refunds, and payment history.
- Internet or other electronic network activity — session data, feature usage, and interactions with the Service.
- Professional or employment-related information — school, graduation year, target firms, resume content, and career stage.
- Inferences — readiness scoring and personalized recommendations derived from your activity.
We collect these categories from the sources described in “Information We Collect,” use them for the purposes described in “How We Use Your Information,” and disclose them for a business purpose only to the recipients described in “How We Share Your Information.” We do not use or disclose sensitive personal information for purposes that would trigger the right to limit under the CCPA.
California residents have the following rights: the right to know what personal information we have collected, used, disclosed, and sold or shared; the right to delete personal information we have collected from you; the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information. We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA.
You will not be discriminated against for exercising any of these rights. To submit a verifiable consumer request, email hello@consultingplaybook.io from the address associated with your account. You may designate an authorized agent to submit a request on your behalf by providing the agent with written permission and, upon our request, verifying your identity directly with us.
European Privacy Rights (GDPR/UK GDPR)
This section applies to users located in the European Economic Area (EEA), the United Kingdom, and Switzerland. For personal data covered by the GDPR or UK GDPR, Redline HQ, Inc. acts as the data controller.
Legal bases. We process personal data on one or more of the following bases: (a) performance of a contract with you; (b) your consent, which you may withdraw at any time; (c) our legitimate interests in operating, improving, and securing the Service, which we balance against your rights and freedoms; and (d) compliance with legal obligations to which we are subject.
International transfers. Redline HQ, Inc. is located in the United States, and personal data is processed in the United States. Where required, transfers of personal data from the EEA, UK, or Switzerland to the United States are safeguarded by the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.
Your rights. You have the rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent, in each case subject to the conditions set out in the GDPR or UK GDPR. You also have the right to lodge a complaint with your local supervisory authority if you believe that our processing of your personal data infringes applicable law.
Other US State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other US states with comprehensive consumer privacy laws have rights similar to those described above, including the rights to access, correct, delete, and receive a portable copy of their personal information, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not engage in targeted advertising or the sale of personal data. To exercise your rights, email hello@consultingplaybook.io.
Children's Privacy
The Service is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a person under 18, we will delete it promptly. If you believe a person under 18 has provided us with personal information, please contact us at hello@consultingplaybook.io.
Cookies and Similar Technologies
We use a small number of cookies and similar technologies to keep you signed in and to secure your session. We do not use analytics cookies or advertising cookies. Details are described in our Cookie Policy.
Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. If we make material changes, we will notify you by email or through an in-product notice before the changes take effect.
Contact Us
Redline HQ, Inc.
State of Delaware, United States
Email: hello@consultingplaybook.io