The Privacy Risk of AI Interview Tools Most People Don't Consider
After Cluely exposed 83,000 users' interview transcripts in a 2025 breach, what your AI meeting assistant stores — and who controls it — matters.

The Privacy Risk of AI Interview Tools Most People Don't Consider
In mid-2025, a hacker group called Ivy Dark Agent announced they had breached Cluely — at the time one of the most widely used AI interview assistance tools on the market. The vulnerability they exploited required no sophisticated attack: Cluely's developers had left an admin password file in a public GitHub repository. That single oversight, combined with weak API protections, handed attackers unrestricted access to the company's database.
What they found there: the personal data, full interview transcripts, and screenshots of more than 83,000 users.
Every interview those users had run through Cluely — the questions they struggled with, the answers the AI generated for them, the names of companies they'd been interviewing at — was now in someone else's hands.
Most people using AI meeting tools don't think about what's being collected until something like this happens. It's worth thinking about before the breach, not after.
What AI Meeting Tools Actually Collect
The category of AI tools that assist in real-time meetings works by processing live audio. That's the core function: listen to what's being said, understand the context, and surface something useful.
But processing audio in real time requires infrastructure that extends well beyond your laptop. The audio gets sent somewhere for transcription. The transcript gets sent somewhere for analysis. The analysis generates a suggestion that returns to your screen. At each step in that chain, data is being transmitted, processed, and in most cases retained.
Cluely's privacy policy specified that it collected audio, transcripts, screenshots, usage data, and device information. According to a privacy analysis published following the breach, sixteen third-party subprocessors — including OpenAI, Grok, and Anthropic — could potentially access user conversations and data. If you used Cluely during a job interview at a company with an NDA, the conversation traveled through all of those systems.
None of this was unusual for the category. It's how real-time AI assistance works. The breach just made visible what had always been true: a tool that records and transcribes your sensitive conversations is a centralized vault of sensitive information. Vaults get robbed.
The Specific Vulnerabilities the Breach Revealed
Beyond the database breach, security researcher Jack Cable discovered a separate critical vulnerability in Cluely's desktop application.
The app contained a postMessage handler flaw — a web-to-native communication channel that wasn't properly sandboxed — that allowed any website opened through Cluely's built-in browser to continuously capture screenshots of everything on the user's screen, without any notification or consent. The exploit worked silently. A user could have no idea their entire display was being recorded by a site they'd opened in passing.
Cable also found that Cluely's complete system prompts — the instructions defining how the AI behaves — were stored in plaintext in the application's code, distributed to every user who installed the app.
When Cable reported his findings publicly, Cluely's response was a DMCA takedown notice against his tweet, claiming the system prompt constituted proprietary source code. The company's CEO publicly denied having filed the notice. It later emerged a Cluely employee had filed it without checking with leadership, and admitted as much when identified.
Cluely subsequently patched the vulnerabilities. By late 2025, the company had also quietly dropped its "Cheat on Everything" marketing positioning and rebranded as a general AI meeting assistant.
The Questions That Matter Before You Use Any Tool
The Cluely situation raised a set of questions that apply to any AI meeting assistant.
What does the tool collect and how long does it keep it? Most privacy policies answer this, but require reading. Look specifically for retention periods — how long transcripts are stored by default — and whether there's a way to delete them manually. Indefinite retention means a breach years from now could expose conversations you have today.
Who are the subprocessors? An AI meeting tool is almost never processing everything itself. The transcript goes to a transcription service. The analysis goes to an LLM provider. The data flows through intermediaries before anything reaches your screen. Each one is a potential point of failure. A tool with sixteen subprocessors has sixteen potential breach surfaces.
Do you control when it starts and stops? A tool that runs continuously — monitoring audio passively and activating when it detects relevant content — is collecting more than one you manually trigger for specific conversations. The difference matters both for privacy and for what ends up stored. Ambient recording during a layoff conversation or salary negotiation is a different risk profile than a session you deliberately activated.
What happens if the company gets acquired, shut down, or breached? The privacy policy you agreed to today is the policy of the company as it exists today. Acquisitions change data terms. Breaches bypass them entirely. The relevant question isn't just "what does the policy say?" — it's "what happens to this data if the company's situation changes?"
Is the tool operating on your device or in the cloud? Fully local processing has a fundamentally different risk profile than cloud-dependent tools. Local is slower and computationally expensive, which is why most tools don't do it. But knowing where your audio leaves your control is the minimum due diligence.
What "Transparent" Actually Looks Like
Most privacy concerns with AI meeting tools don't involve malicious intent. They involve structural incentives. A company that stores transcripts indefinitely is holding something valuable: training data, usage analytics, product improvement signal. The incentive to keep that data rarely aligns with the user's interest in minimizing retention.
Transparency in practice means: you can see what's collected, you can delete it, and you understand who else has access. A privacy policy that requires you to get consent from everyone on a call before recording is more honest about the legal landscape than one that doesn't mention it — but it still puts the compliance burden on you, in the middle of an interview, which is rarely how it plays out.
The most meaningful form of control is operational: you decide when the tool is on. Not passive, always-on audio monitoring — a manual trigger you engage at the start of a session and disengage at the end. That design decision limits the blast radius of any future breach to the specific sessions you chose to run, rather than a continuous stream of ambient recording.
This is also the design that makes you the decision-maker, not the tool. You know when it's listening. You know what sessions it has data from. You're not discovering that retroactively after a breach announcement.
Choosing With Clear Eyes
The point isn't to avoid AI meeting tools. Real-time assistance during high-stakes conversations — a job interview, a salary negotiation, a competitive sales call — is genuinely useful. The tools that do this well provide a meaningful advantage in moments that matter.
The point is to choose them with the same judgment you'd apply to any service handling sensitive information: understand what you're giving access to, and understand what the downside looks like if something goes wrong.
Meeting Copilot's interview assistant is built around the principle that you control when it runs. You start it, you stop it, and the overlay is visible only to you — not to anyone on the call. For job interviews and sales conversations where the stakes are high and the content is sensitive, that operational control is the baseline worth insisting on.
The Checklist Before Your Next Call
Before using any AI meeting tool for something sensitive:
- Read the retention policy. How long are transcripts stored by default? Is auto-deletion available, or do you have to request it?
- Check the subprocessor list. Who else touches your data, and under what terms?
- Find the delete mechanism. Can you delete your transcripts manually and immediately, or does it require a support ticket?
- Understand the activation model. Does the tool listen continuously, or only when you start it for a specific session?
- Know the consent requirements. Many jurisdictions require all-party consent for recorded conversations. You're the one responsible for compliance, not the tool vendor.
- Look at the security incident history. A company that has been breached and responded with legal threats against the researcher who found the vulnerability is a different risk profile than one that responded by fixing the issue and notifying users.
Eighty-three thousand people found out the hard way that what their AI assistant knew about them was not actually theirs to control. The information to make a better decision is all publicly available now.
Read it before the call, not after.