Privacy Policy
Last updated: 2026-06-19
This Privacy Policy explains how Interview With AI (“we”, “us”, or “Interview With AI”) collects, uses, and protects your information when you use the Interview With AI website and interview-practice application (the “Service”). By creating an account or using the Service, you agree to the practices described here. See our Terms of Service for the terms that govern your use of the Service.
1. Information we collect
- Account information: the email address and password you sign up with (passwords are hashed by our auth provider), and any display name or avatar you provide (e.g. via Google sign-in).
- Interview content you create: the questions, code you write or paste, interview transcripts, behavioral answers, and generated interview reports associated with your account.
- Voice data: if you use voice mode, your microphone audio is streamed in real time to provide transcription/speech. We do not store this streamed audio unless you turn on interview recording.
- Interview recordings (optional, off by default): you can choose to record an interview. When you enable recording, we capture and store both your microphone audio and the AI interviewer’s audio for that session so you can replay and download it from your profile. Recording is off until you turn it on, and you can turn it off at any time in Settings. Recordings are temporary: they are automatically deleted about 24 hours after the interview, so they are available for a short replay/download window and then removed. We use recordings only to let you replay and download your own session — we do not use them to train AI models, we do not analyze them for any other purpose, and we do not sell or share them with third parties (other than the storage provider that holds the files for you).
- Usage and billing information: features you use, usage events, and billing records (Stripe customer id, plan tier, credits) needed to operate paid features.
- Technical data: standard server logs (request time, status, anonymized route) and a server-side audit log of AI model calls (prompts/responses) used for safety, quality, and abuse prevention.
2. How we use your information
- To provide the interview simulation, generate questions/reports, and run your code.
- To operate authentication, account management, and paid features (including checkout and subscriptions).
- To debug, secure, and improve the Service, and to prevent abuse and fraud.
- To communicate with you about your account, important service changes, and legal obligations.
3. Service providers (processors) we rely on
Your data is processed through the following third parties to deliver the Service:
| Provider | What it does | What it may receive |
|---|---|---|
| Supabase | Authentication and database hosting | Account email, hashed password, and all stored interview content listed above |
| OpenAI | AI interviewer responses and evaluation | Interview context needed to respond: transcript, your code, behavioral answers |
| Google (Gemini) | Optional real-time voice mode and scenario research | Transcript/voice stream and scenario context when those features are used; interviewer audio it generates may be stored by us if you enable recording |
| DeepSeek | Authoring practice questions and behavioral scenarios only | Question/scenario prompts (role, topic, difficulty). It does not receive your interview transcripts, your code, your answers, or any other personal data. |
| Deepgram | Voice transcription (STT) and speech (TTS) | Voice audio for transcription, and generated speech; this audio may be stored by us if you enable interview recording |
| Supabase Storage | Stores your interview recordings when you enable recording | The recorded audio files for your sessions, kept private to your account |
| Resend | Sends transactional email (e.g. a link to your recording) | Your email address and the message content (a link to your profile) |
| Stripe | Payment processing | Payment and billing details (we do not store full card numbers) |
| Meta (Facebook) | Conversion measurement — the Meta Pixel and Conversions API count page visits and completed purchases so we can see which plans sell | Anonymous PageView and Purchase events on each visit; on a completed purchase, a SHA-256-hashed (unreadable) copy of your email plus the amount and currency paid. Meta may use this data to measure conversions and to recognise your activity across its own services. |
Each provider processes data under its own terms. We encourage you to review their privacy and data-retention policies, particularly if you are subject to specific data-residency requirements.
We don’t sell your data, and we don’t run advertising campaigns of our own. We never sell or rent your personal data. To understand which of our plans are purchased, we use the Meta Pixel and Meta’s Conversions API (described in the table above) to measure conversions; for that limited purpose, Meta receives a hashed copy of your email and your purchase events, and Meta may use that information to measure conversions and to recognise your activity across its own services. We do not otherwise share your data with third parties for their own commercial purposes. The providers listed above receive your data only as processors acting on our behalf to operate the Service — not as purchasers — and only as necessary to provide the feature you are using. Any use of your data by those providers beyond providing the Service to us is governed by their own published terms, which we encourage you to review.
4. Legal basis (for users in the UK / EU / EEA)
We process your personal data on the following bases: performance of a contract (providing the Service and paid features you requested), our legitimate interests (security, abuse prevention, and product improvement), and compliance with legal obligations. Where we rely on legitimate interests, we balance them against your rights.
5. How we store and secure data
Data is stored in our Supabase database, protected by row-level security so that one user cannot access another user’s records. Access to infrastructure and secrets is restricted. No method of transmission or storage is fully secure, but we apply measures intended to protect your information. Your session is stored in your browser; do not use the Service on a shared or untrusted device.
6. Data retention
We keep different kinds of data for different periods so you can track your progress over time while sensitive raw material does not linger:
- Deleted after 30 days: raw interview transcripts, code snapshots and code-run logs, and our AI audit logs are automatically deleted 30 days after they are created.
- Kept while your account is active (so your history and progress persist): your completed interview sessions’ summary information and your interview reports and scores. Account information (such as your email), billing and entitlement records, and your saved behavioral scenarios are also retained while your account is active.
- Interview recordings: stored only if you enable recording, and automatically deleted about 24 hours after the interview. We keep them for a short replay/download window only; the audio is not retained long-term.
When you delete your account, the data associated with it — including completed sessions and reports — is removed. You can request earlier deletion of specific data at any time by contacting us (see below).
7. International data transfers
Your information, including interview content, may be processed in countries other than your own. To generate interview responses and evaluate your performance, your interview content (transcript, code, and answers) is sent to our AI providers in the United States — OpenAI, Google, and Deepgram. Your interview content is not sent to DeepSeek; DeepSeek (which operates from the People’s Republic of China) is used solely to author practice questions and scenarios from non-personal prompts, and never receives your transcripts, code, or answers. We rely on appropriate safeguards where required, and you consent to these transfers by using the Service.
8. Your rights
Depending on where you live (for example under the UK GDPR, EU GDPR, or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us at info@ai-interviewing.xyz. We will respond within the time required by applicable law. Note that we may need to verify your identity first.
9. Children’s privacy
The Service is not directed to children under the age required by your jurisdiction (typically 13 or 16), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will indicate the “Last updated” date above and, for material changes, provide notice (such as in-app or by email). Continued use after changes take effect constitutes acceptance.
11. Contact us
If you have questions about this Privacy Policy or your data, contact us at info@ai-interviewing.xyz.