Privacy Policy
Interview Assistant AI is built so that the most sensitive things it touches — your screen, your microphone, your interview — stay on your machine. This policy explains, in plain language, the limited personal data we do handle, why we handle it, who else is involved, and the rights you have over it.
LAST UPDATED · EFFECTIVE ·
1. Summary
The short version, before the detail:
- We do not run an account system. There is no username, password, or profile to create.
- The desktop app has no analytics, no telemetry, and no crash reporting that sends data to us.
- Screen captures and audio are processed in memory on your device. Captured frames and audio chunks are never written to disk.
- When you ask for an answer, your device sends the request directly to the AI provider you configured (OpenAI or Anthropic) using your own API key. It never passes through a server of ours.
- We handle a small amount of personal data to sell you a licence, validate it, and answer your emails — and we never sell it.
- This website sets only the cookies it needs to work, unless you choose to accept optional cookies.
2. Who we are and scope
"Interview Assistant AI", "we", "us" and "our" refer to the operator of the Interview Assistant AI software and the website at interviewassistant.app. For the purposes of the EU and UK General Data Protection Regulation (GDPR), we are the controller of the personal data described in this policy, except where we state that we act on your instructions or that a third party is an independent controller.
This policy covers: (a) the website interviewassistant.app and its subpages; (b) purchasing a subscription or lifetime licence; (c) licence activation and validation; (d) the Interview Assistant AI desktop application; and (e) communications with us, such as support and security emails.
It does not cover third-party services you choose to use alongside the app — most importantly the AI provider whose API key you enter, the call or video-conferencing software you use, and the platforms that host our downloads and process payments. Those services have their own privacy policies, which we link to below where relevant.
3. Personal data we collect
We collect only what each part of the service needs. Broken down by where it comes from:
| Context | Data | Source |
|---|---|---|
| Visiting the website | IP address, browser and device type, pages requested, referring URL, date and time of the request | Automatically, via our hosting provider's standard server logs |
| Cookie preferences | Your consent choice and the date you made it; your language preference | Set in your browser when you make a choice or change language |
| Purchasing a licence | Name, email address, billing country and postal code, plan purchased, transaction ID, amount, and payment status | You, via our payment processor. We never receive your full card number |
| Licence activation and validation | Licence key, app version, the IP address of the request, and the date and time of each check | The desktop app, at activation and periodically afterwards |
| Support and security emails | Your email address, name if you give it, and anything you choose to include in your message or attachments | You |
| Software updates | IP address and the requested file, as part of an ordinary download | The desktop app, when it checks for or downloads an update from GitHub |
We do not ask for, and ask you not to send us, special-category data (such as health information) or the contents of your interviews.
4. How the desktop app handles your data
The app is designed to be local-first. In practice, that means:
- Screen capture: the app captures only the window or display you select, and only after you explicitly start capture. Each captured frame exists in memory for the length of a single analysis request and is then discarded. Frames are never written to disk and never sent to us.
- Audio: the microphone and system audio are captured only while listening is switched on, with a persistent on-screen indicator. Audio is sent in short chunks to the transcription endpoint of the provider you configured, then discarded. Only the resulting text transcript is kept, in memory, bounded in length, and cleared when you quit or clear it yourself.
- Context: a short text excerpt of recent answers is kept in memory as context for follow-up questions. It is not written to disk.
- Settings: non-secret settings and window preferences are stored in small files under your user profile on your device.
- API keys: your OpenAI or Anthropic key is encrypted at rest using your operating system's credential protection and is never sent to us. The app's sandboxed interface layer never has access to it.
None of the above data is transmitted to us. We cannot see your screen, your audio, your transcripts, your prompts, or the answers you receive.
5. Your AI provider (OpenAI or Anthropic)
Interview Assistant AI works on a "bring your own key" basis. When you request an answer, the app sends the relevant screen frame, transcript text, and prompt directly from your device to the provider you configured, authenticated with your own API key. Your relationship with that provider — including how it processes, retains, or uses API inputs and outputs — is governed by your agreement with them and their privacy policy, not by us.
We encourage you to review the provider's API data-usage and retention terms before use: OpenAI (openai.com/policies/privacy-policy) and Anthropic (anthropic.com/legal/privacy). Spending limits, usage logs, and data controls for your API account are managed in your provider's dashboard.
6. Other people in your calls
When listening is on, the app can process the speech of other participants in a call, and screen capture can include content shared by others. You are responsible for using the app lawfully. Recording and transcription laws differ between countries and US states — some require the consent of every party — and an employer or interviewer may have its own rules about assistive tools. Please check what applies to you before you use these features.
7. Why we use personal data, and our legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Selling you a licence, delivering your licence key, and handling refunds | Performance of a contract with you |
| Validating your licence and preventing licence-key abuse and fraud | Performance of a contract; our legitimate interest in protecting the software from unauthorised use |
| Keeping the website secure, available, and protected against attacks | Our legitimate interest in operating a secure service |
| Answering support requests and vulnerability reports | Performance of a contract, or our legitimate interest in responding to people who contact us |
| Sending essential service messages, such as purchase receipts and licence or security notices | Performance of a contract |
| Keeping tax and accounting records | Compliance with a legal obligation |
| Setting optional (non-essential) cookies, if we introduce any | Your consent, which you can withdraw at any time |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects. We do not send marketing emails unless you have opted in, and every marketing email will include a one-click unsubscribe link.
8. Who we share data with
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We share it only with service providers that help us run the business, under contracts that restrict their use of it to providing their service to us:
- Payment processor — to process purchases, issue receipts, calculate sales tax or VAT, and handle refunds and chargebacks. Depending on how a purchase is made, the processor may act as an independent controller or merchant of record under its own privacy policy.
- Licensing provider — to issue and validate licence keys.
- Website hosting provider — to serve this website and keep its server logs.
- GitHub — hosts the installer and update files. Downloads are subject to GitHub's privacy statement.
- Email provider — to send and receive email.
We may also disclose personal data if required to by law, to respond to valid legal process, to protect the rights, safety, or property of our users, ourselves, or others, or as part of a merger, acquisition, or sale of assets, in which case we will tell you before your data becomes subject to a different privacy policy.
9. International transfers
Our service providers may process personal data in countries other than the one you live in, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on an adequacy decision or on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. You can ask us for more information about these safeguards using the contact details below.
10. How long we keep data
We keep personal data only for as long as we need it for the purposes above:
- Purchase and transaction records: for as long as required by tax and accounting law, which is typically up to seven years after the transaction.
- Licence records: for as long as your licence is active, plus a reasonable period afterwards to deal with renewals, reactivations, and disputes.
- Licence validation request data: only as long as needed for validation, fraud prevention, and troubleshooting.
- Support and security emails: up to two years after the conversation ends, unless we need them longer to resolve a dispute.
- Website server logs: kept by our hosting provider for a limited period, after which they are deleted or anonymised.
- Cookie consent choice: six months, after which we ask again.
Data held only on your device — settings, encrypted API keys — stays there until you delete it or uninstall the app. In-memory data such as transcripts and context is gone when you quit.
11. How we protect data
We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS) for every network request the website and app make, OS-level encryption of API keys at rest, a sandboxed interface layer with no filesystem or network access of its own, and access to business systems limited to the people who need it. The most effective protection is not to collect data in the first place, which is why the app sends nothing to us beyond licence validation.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to [email protected]. We reply within two business days. If a personal-data breach occurs that is likely to put your rights at risk, we will notify you and the relevant authorities as the law requires.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct personal data that is inaccurate or incomplete.
- Delete your personal data, subject to records we are legally required to keep.
- Restrict or object to our processing, including processing based on legitimate interests.
- Data portability — receive data you gave us in a structured, machine-readable format.
- Withdraw consent at any time, where we rely on consent. This does not affect processing that already took place.
- Lodge a complaint with your local data-protection authority — for example, your EU member state's supervisory authority or, in the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, email [email protected]. We will respond within one month (or within the period your local law requires), and may need to verify your identity first — usually by asking you to write from the email address used for your purchase. We will not discriminate against you for exercising your rights.
13. Additional information for US residents
Residents of California and other US states with comprehensive privacy laws have the right to know what personal information we collect, to request its deletion or correction, and to opt out of its "sale" or "sharing". In the last 12 months we have collected the categories described in section 3 — identifiers (such as name, email, and IP address), commercial information (purchase history), and internet activity (server logs) — for the business purposes in section 7. We have not sold or shared personal information, and we do not knowingly sell or share the personal information of consumers under 16.
We honour Global Privacy Control (GPC) browser signals as a request to opt out of optional cookies on this website. You may use an authorised agent to make a request on your behalf; we may ask for proof of their authorisation.
14. Children
Interview Assistant AI is intended for adults preparing for and taking part in job interviews. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the product or the law changes. The "last updated" date at the top of this page always shows when it last changed. If we make a material change — for example, introducing a new category of data or a new purpose — we will give notice on this website, and, where you have a licence, by email, before the change takes effect.
16. Contact us
For any question about this policy or your personal data, email [email protected]. For security issues, email [email protected].
Related
- Cookie Policy
Every cookie this site sets, and how to change your choice.
- Security & privacy model
The technical detail behind what the app touches and keeps.
