HV World / Privacy Policy

Privacy Policy

Last updated: 6 October 2026

This policy explains what personal data HV World, HV Test, HV Reset, HV Vault and HV AI collect, why, who it is shared with, how long it is kept, and the rights you have over it.

1. Who we are

HV World, HV Test, HV Reset, HV Vault and HV AI (the "Services") are built and run by Harsh Goyal, an individual based in India ("we", "us", "our"). For personal data handled through the Services, we act as the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023 (DPDP Act), and we follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

This policy explains what we collect, why, where it goes, how long we keep it, and your rights. By using the Services you agree to this policy and our Terms and Conditions.

2. The short version

  • No ads, no third-party trackers. We do not use advertising or third-party tracking tools, and we do not sell or rent your data. We count visits and feature use anonymously with our own simple tool (no cookies, no names, no IDs) to see what helps people. How it works and how to opt out.
  • We don't look at your data. Your account data is private to you. We do not look at what you save in it.
  • HV Test needs no account. Your answers, age and profession stay in your browser. We save data only if you choose to save a scorecard, plus an anonymous count of finished tests.
  • HV Reset works without an account, saving on your device. If you sign in, your plan and history sync to your private account.
  • HV Vault uses Google sign-in and stores your job search in your private account. Only you can read it.
  • HV AI sends what you ask it to Google's Gemini AI to process.
  • Your data is stored with Google Firebase. You can export or delete it.

3. What we collect, app by app

HV World website

  • We do not ask for any personal data on the website, and we do not use cookies there.
  • The site is hosted on GitHub Pages. Like any web host, GitHub automatically receives technical data such as your IP address, browser type and the pages requested, to deliver and secure the site. We cannot see or control GitHub's logs.
  • Your browser may store small preferences locally (for example whether a video has sound).

HV Test

  • Stays on your device only: the name, age, profession and focus you enter, every answer, your response times, your full results and your PDFs. These are never sent to us.
  • Saved only if you choose "Add ID and QR code": a scorecard record containing the name you confirm, the test name and category, the date and time you finished, your overall score and level, how many questions you answered, your score for each skill, your top strengths and areas to work on, and the scorecard ID. Your answers, age and profession are not saved.
  • Anonymous counter: when anyone finishes a test, we add 1 to a daily count for that test. It contains no name, answers, device or location data.
  • On your device: your theme choice and similar settings, in local storage.

HV Reset

  • Without an account: your tasks, plans, timers, habits, goals, dashboard history and settings are saved in your browser's local storage on that device.
  • If you sign in with Google: we receive your Google account ID, name, email address and profile picture from Google, and we sync your plan, history and settings to your private space in our database.
  • Profile details you choose to give, such as your name, role or goals, to personalise the app.
  • Sync code (optional): if you use a sync code instead of sign-in, your data is saved under that long private code.
  • With HV Vault: if you use both apps with the same Google account, HV Reset reads your follow-ups due and weekly numbers from HV Vault to show them next to your day.
  • Beta (optional, off by default): if you turn on Beta while signed in, we keep a tester record: your tester number, name, email, the date and time of each time you join or leave the Beta, when you last opened the app, device and browser type, app version, which Beta features you turned on and how often you used them, and your points. Only the admin can see it. Other testers see only your short name (for example "Riya S.") and points on the leaderboard and in Credits.
  • Beta reports, ideas and answers: a bug report you send includes your text, the screenshot you took and drew on (only if you send one), the screen you were on, and, if you leave it ticked, device and app details (browser, screen size, recent app events). Only the admin sees reports. Ideas you share are visible to other testers with your short name. Survey and poll answers are seen only by the admin. Turning Beta off stops new data; ask us to delete what is stored.
  • Private data link (Beta, optional): if you make one, a copy of your exported task history is stored under a long random key. Anyone who has the link can read that copy, so keep it private. "Turn off" deletes it.

HV Vault

  • Account: your Google account ID, name, email address and profile picture, from Google sign-in.
  • Your job search: jobs, companies, links, salaries, locations, notes, statuses, follow-ups, interviews, calendar items, message templates and analytics.
  • Contacts you add, such as recruiters or referrers (names, roles, emails, phone numbers or links). Please add only what you need and have a lawful reason to keep.
  • Resume and profile: resume files you upload and the details read from them, such as your name, role, skills, experience and education.
  • Items you paste or upload for AI auto-fill, such as job post text, PDFs and screenshots.
  • The Windows desktop app stores data on your computer. If you connect it to your account, it syncs the same way as the web app.

HV AI

  • The messages you type, your voice recordings when you use the mic, and the information needed to act on them (for example your current tasks or jobs) are sent to Google's Gemini models through Google Firebase AI Logic to produce a reply.
  • Your recent HV AI conversation may be saved on your device and, if you are signed in, with your account, so it can continue where you left off.
  • If you add your own AI key under Advanced settings, it is stored on your device and your requests go directly to that provider under their terms.

Security checks

  • To block abuse, some requests include a Google reCAPTCHA Enterprise / Firebase App Check token. Google may collect device and browser signals, and may use cookies, to produce it, under Google's own privacy policy.

4. Sensitive information

We do not ask for passwords, financial information, card or bank details, health or medical records, biometric data, government ID numbers, caste, religion or sexual orientation. Please do not put this kind of information into notes, resumes, AI messages or any other field. HV Test results are a self-assessment about behaviour, not health data, and we do not store your answers.

5. Why we use your data

  • To provide the features you ask for: saving and syncing your plans and job search, showing your dashboard, running tests, issuing and verifying scorecards, and answering HV AI requests.
  • To keep the Services secure, prevent abuse and fake records, and fix problems.
  • To understand usage at a high level through the anonymous count of finished tests and the total number of scorecards issued.
  • To respond to your requests and complaints, and to meet legal obligations.

Our legal basis is your consent, given when you choose to use a feature (for example signing in, saving a scorecard or asking HV AI), and certain legitimate uses allowed by the DPDP Act, such as complying with law. You can withdraw consent at any time by stopping use of the feature and deleting the related data. Withdrawing consent does not affect processing already done.

We do not look at the contents of your account, we do not use your data for advertising, we do not sell or rent it, and we do not use your content to train our own AI models.

6. Who we share data with

We share data only with service providers that run parts of the Services for us, and only as needed:

  • Google (Firebase): authentication, database storage, App Check and AI processing (Gemini through Firebase AI Logic). Google may process data on servers outside India.
  • GitHub: hosts the website and web apps.
  • Google Fonts and Cloudflare (cdnjs): deliver fonts and code libraries to your browser. They receive technical data such as your IP address when your browser loads them.
  • Public scorecards: a saved scorecard summary can be seen by anyone who has its ID or QR code. You decide who to share it with.
  • Legal reasons: we may disclose information if required by law, a court order or a lawful request from a government authority, or to protect the rights, safety or property of users, the public or us.

We do not share your data with employers, recruiters, colleges or any other organisation unless you share it yourself.

7. Where your data is stored

Data is stored in Google Firebase (project "harsh-reset") and processed by the providers above. Their servers may be located outside India. Where we transfer data outside India, we do so as permitted under the DPDP Act and any restrictions notified by the Government of India.

8. How long we keep data

  • Data on your device stays until you delete it or clear your browser data.
  • HV Vault and HV Reset account data is kept while you use your account. When you delete it (for example with "Delete all data" in HV Vault) or ask us to, we delete it from our active database, normally within 30 days. Short-lived copies held by our providers may take a little longer to expire.
  • Scorecards are kept so they can be verified, until you ask us to remove them or we remove them under our Terms.
  • The anonymous count of finished tests contains no personal data and may be kept indefinitely.
  • We may keep limited information for longer where the law requires it or to resolve a dispute.

9. How we protect your data

  • All connections to the Services use HTTPS encryption.
  • Our database rules allow a signed-in user to read and write only their own data. Scorecards can be created once and read by ID, but cannot be listed, edited or deleted by the public.
  • Firebase App Check helps block requests that do not come from our apps.
  • Access to the admin view of scorecards is limited to one owner account.

No system is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the Data Protection Board of India as required by law.

10. Your rights

Under the DPDP Act and other applicable law, you have the right to:

  • access a summary of the personal data we hold about you and how we use it;
  • correct, complete or update it;
  • delete it (erasure), unless we must keep it by law;
  • withdraw consent at any time;
  • nominate another person to exercise your rights if you die or become unable to;
  • raise a grievance with us, and if you are not satisfied, complain to the Data Protection Board of India.

Many of these you can do yourself: edit or delete items in the apps, export or delete everything in HV Vault's Settings, and clear local data in your browser. For anything else, including removing a scorecard, contact us (section 14). We may need to confirm it is you before acting.

11. Children

The Services are meant for people aged 18 and over. People under 18 should use them only with a parent or guardian's consent and supervision, and should not sign in or save a scorecard without it. We do not knowingly process children's personal data without verifiable parental consent, and we do not track or target advertising at children. If you believe a child has given us personal data without consent, contact us and we will delete it.

12. Cookies and local storage

  • We do not use advertising or analytics cookies.
  • The apps use your browser's local storage to save your data and settings on your device, and Firebase uses browser storage to keep you signed in.
  • Google's reCAPTCHA Enterprise may set its own cookies for security checks.
  • You can clear this data from your browser settings at any time. Clearing it removes data that is saved only on that device.

13. Anonymous usage counts

To learn which pages and features help people, the Services count visits and actions with our own simple tool. It does not use cookies or third-party analytics services.

  • What is counted: numbers only, per day, such as visits, page views, how a visit arrived (for example "LinkedIn", "search" or a campaign name in the link), device type, browser, operating system, a broad region guessed from your browser's time zone, and actions such as "test started", "task completed" or "job added".
  • What is never sent: your name, email, account ID, IP-based location, answers, scores, task or job details, notes, files or anything you type. Counts cannot be linked back to you.
  • On your device: to tell new visits from returning ones, your browser keeps a small note in local storage (for example the day of your first visit). It stays on your device.
  • Who can see it: only the HV World admin, as totals.
  • Your choice: browsers that send "Do Not Track" or "Global Privacy Control" are never counted. You can also turn counting off on this device (or turn it back on).

14. Changes to this policy

We may update this policy as the Services change. The "Last updated" date at the top shows the latest version. If we make a significant change to how we use personal data, we will point it out on the website or in the apps, and ask for your consent again where the law requires.

15. Contact and grievance officer

For privacy questions, requests to access, correct or delete your data, to remove a scorecard, or to raise a grievance, contact Harsh Goyal, Grievance Officer and Data Fiduciary for the Services, through LinkedIn (Harsh Goyal) or GitHub (harshvittori).

We will acknowledge your message within 24 hours and aim to resolve it within 15 days, or sooner where the law requires. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

See also: Terms and Conditions