Privacy Policy
Last updated: July 2026
This policy explains what data AI Interview Practice (the "Service") collects, how it is used, and the choices you have. The short version: we collect what is needed to run a practice platform with AI coaching, we do not sell your data, and we do not run advertising trackers.
1. Data We Collect
- Account data. Your email address and authentication credentials, managed by our authentication provider (Supabase). Passwords are stored hashed; we never see them in plain text.
- Practice activity. The code you write in scenarios, including periodic snapshots saved while you work, test results, messages you exchange with the AI coach, session events (such as when you run tests or view an answer key), and the AI-generated scores and feedback for your sessions. Snapshots are sent to our server about every 30 seconds during a session so an unfinished attempt is not lost. This history powers your review and progress screens.
- Survey responses. If you answer one of the short in-app questions (for example, why you signed up, whether you have an interview coming up, or why you left a session), we store your answers alongside your account. Every question is optional and can be dismissed.
- Payment data. Payments are processed by Stripe. We receive your purchase and billing events; we never receive or store your card number.
- Technical data. Standard server logs (IP address, browser type, timestamps) generated by operating and securing the Service.
2. How We Use Data
- To provide the Service: run scenarios, save your sessions, show your history and scores.
- To power AI features: your code, session context, and chat messages are sent to Anthropic (our AI provider) to generate coaching responses and performance feedback.
- To manage billing, plan limits, and prevent abuse (such as rate limiting).
- To communicate with you about your account (confirmation emails, password resets).
We do not sell your personal data or share it with advertisers.
3. AI Processing
When you use AI coaching or end a session, relevant content (your code, the scenario context, your chat messages, and session activity metrics) is sent to Anthropic's API to generate responses and feedback. Under Anthropic's commercial API terms, API inputs and outputs are not used to train their models by default. Avoid pasting sensitive personal information into the editor or chat; it is not needed for any scenario.
4. Service Providers
We share data only with the processors needed to run the Service:
- Supabase: authentication and database hosting (account data, session history).
- Stripe: payment processing and billing records.
- Anthropic: AI coaching and grading (session content, as described above).
- Vercel: hosting, standard request logs, and privacy-friendly product analytics (see section 5).
- Sentry: error monitoring, so crashes can be found and fixed. Configured not to send personal information and not to record your screen.
- Google: if you choose to sign in with Google, it verifies your identity and provides your email address. We never receive your Google password.
5. Cookies and Local Storage
We use authentication cookies (via Supabase) to keep you signed in, and browser local storage for product preferences such as onboarding state.
We use Vercel Analytics to count how many people reach each step of the product, such as opening a scenario or starting a session. It is cookieless, does not follow you to other sites, and we never attach your email, account id, code, or chat messages to these counts. We also use Sentry to record technical errors, configured not to send personal information and not to record your screen.
We do not use advertising trackers, we do not run cross-site tracking, and we do not sell or share your data with advertisers.
6. Data Retention and Deletion
Account and session data are retained while your account is active. You can request deletion of your account and associated data at any time by emailing divjotmuchhal@gmail.com from your account email; we will delete it within 30 days, except where retention is required for legal or billing-record purposes.
7. Your Rights
Depending on where you live (for example, the EU/EEA under GDPR, India under the DPDP Act, or California under CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these rights, contact us at the email below. We do not discriminate against you for exercising them.
8. Security
Data is transmitted over HTTPS and stored with access controls via our providers. No method of transmission or storage is completely secure; we cannot guarantee absolute security, but we take reasonable measures appropriate to the data we hold.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy as the Service evolves. Material changes will be communicated through the Service or by email. The "Last updated" date above reflects the current version.
11. Contact
Privacy questions or requests: divjotmuchhal@gmail.com