Draft for review — this policy has not yet been reviewed by an attorney and may change before launch.
Privacy Policy
Draft — last updated July 7, 2026
1. What we collect
- Account: email address and password (password handled by our auth provider; we never see it in plain text).
- Profile & documents: the profile details, résumés, and job postings you add so interviews and analyses have context.
- Interview responses: your written answers, and — only with your separate written consent — voice recordings and their transcripts.
- Consent records: an append-only ledger of when you granted or withdrew recording consent, including the policy version you saw and the name you typed.
2. How we use it
To run the product: transcribing and scoring your answers against interview rubrics, generating feedback and tailored documents you request, tracking your practice progress, and sending you decision emails about your own sessions. We do not sell your personal data or use it for third-party advertising.
3. AI processing
Your answers, résumé text, and imported postings are processed by Anthropic's Claude API to produce scores, feedback, analyses, and documents. Content sent to the API is used to provide the service, not to train models on your data per Anthropic's commercial API terms.
4. Voice recordings (biometric information)
Voice answers are off by default. Before the microphone is ever requested, we ask for a written release naming the purpose and retention term, as required by biometric privacy laws such as Illinois BIPA. Recordings are private to your account, are retained for at most 12 months after the session, and are permanently destroyed earlier if you withdraw consent (profile → "Withdraw consent") or delete your account. A daily automated job enforces this schedule. Transcripts and scores are not biometric data and remain as your interview record.
5. Where your data lives
Data is stored with Supabase (Postgres + storage, AWS us-east-1) with row-level security so each account can only read its own rows. The app is hosted on Vercel. Transactional email is sent via Resend. These processors handle data on our instructions.
6. Your rights
You can access and edit your profile data in the app, withdraw recording consent at any time, and request export or deletion of your data by emailing johnbucmoore@gmail.com (account deletion removes profile data, documents, responses, and recordings; the consent ledger is retained as a legal record). Depending on where you live (GDPR, CCPA), you may have additional statutory rights — we honor requests regardless of region.
7. Cookies & analytics
We always use the session cookies required to keep you signed in. Beyond that, we use two analytics services — Google Analytics (site usage) and PostHog (product analytics, with autocapture and session recording disabled) — and neither loads unless you accept analytics cookies on the consent banner. Your choice is stored for one year in a first-party cookie (si_consent) and in your browser's local storage, and you can change it at any time via "Cookie preferences" in the page footer. Declining does not limit the product in any way. We do not use advertising trackers.
8. Changes and contact
Material changes will be announced by email or in-product notice before they take effect. Questions or requests: johnbucmoore@gmail.com. See also the Terms of Service.