Draft: business details in src/config/legal.ts are still placeholders. Fill them in before submitting for payment-provider approval.

Privacy Policy

What we collect, why, who else sees it, and what we deliberately do not do.

Last updated: 3 August 2026

The short version

  • We run no analytics, no advertising trackers and no third-party pixels. There is no cookie banner because we set no tracking cookies.
  • We never sell, rent or share your data, and we do not use your interview answers to train AI models.
  • We store your name, email and profile photo from Google Sign-In — and, importantly, the answers you write during interview sessions, because the service cannot score them otherwise.
  • Your answers are sent to Google's Gemini API to generate your feedback.
  • Voice is processed entirely in your browser. We never receive audio — only the text you submit.
  • If you paste a resume, we never store it. It is read once to tailor your questions, then discarded — only an anonymised summary of your technical background is kept.
  • You can ask us to delete everything, at any time, and we will.

1. Who we are

InterviewGPT is operated by [[ YOUR LEGAL NAME OR REGISTERED BUSINESS NAME ]], [[ YOUR BUSINESS ADDRESS, CITY, STATE, PIN, INDIA ]]. For anything in this policy, contact avinash.ranjan21@gmail.com. We are the data controller for the personal data described here.

2. What we collect

a. Account details, from Google Sign-In

When you sign in with Google we receive your name, email address and profile photo URL. We never receive or store your Google password. We also record when you last signed in.

b. Interview content

This is the most significant category, so we want to be plain about it. We store the job role, focus area, experience level and session length you choose, the full text of every answer you write, the questions generated for you, and the AI-produced score and written feedback for each answer.

Please avoid putting confidential information into your answers — your employer's non-public details, another person's personal data, or anything under NDA. Practice answers do not need it, and we would rather you did not store it with us.

c. Your resume, if you paste one — read once, never stored

A resume carries far more personal data than an interview answer, so we handle it differently from everything else on this page.

  • We do not store your resume. It is held in memory only for as long as it takes to work out what to ask you, then discarded. It is never written to our database.
  • What we keep instead is a short, de-identified summary of your technical background — the kinds of systems you have built and technologies you have used. It deliberately excludes your name, contact details, employers, dates and education.
  • The resume text is sent to Google's Gemini API once, to produce that summary and your question plan.
  • You are welcome to strip your name and contact details before pasting. The questions do not need them.

d. Voice — transcribed, never stored

If you answer by microphone, your browser records that answer and sends it, together with the answer, over an encrypted connection to Google's Gemini API, which turns the speech into text. We use the audio for this one purpose: an accurate transcript of what you said.

  • We do not store audio. The recording exists in your browser's memory until you submit the answer, is transcribed in a single request, and is not written to our database or any file. Only the transcript is kept, as your answer.
  • Google processes the audio under the Gemini API terms for paid services, which do not permit using it to train their models. We do not pass it to anyone else.
  • While you speak, your browser also shows a rough live transcript using its built-in speech recognition. If transcription fails, that text is used instead, so an answer is never lost.
  • Voice is entirely optional and off-limits until you grant microphone permission. Typing your answers sends no audio at all. The interviewer's voice is generated on your device by your browser.

e. Purchase records

We store which credit pack you bought, when, how many credits it granted and its expiry date. We never see or store your card details — payment is handled entirely by Dodo Payments, which acts as merchant of record and collects billing information on its own systems.

f. Technical logs

Our hosting and serverless infrastructure (Google Cloud) automatically generates operational logs that include IP addresses, timestamps and error traces. These are a byproduct of running the service securely, not a profile we build about you, and they age out on Google Cloud's standard retention schedule.

3. What we do not do

  • No analytics or tracking. No Google Analytics, no Meta pixel, no session recording, no heatmaps, no advertising or marketing trackers of any kind.
  • No tracking cookies. We set none, which is why you see no consent banner.
  • No selling or sharing. We do not sell, rent, trade or share your personal data with advertisers, data brokers or anyone else for their own purposes.
  • No AI training on your answers. Your answers are used to generate your feedback and nothing else.
  • No profiling or automated decisions with legal effect. Session scores are practice feedback. They are never shared with employers and have no bearing on any real hiring decision.

4. Local storage we do use

Two pieces of browser storage keep the site working. Neither tracks you across sites, and both are strictly necessary rather than optional:

  • Sign-in session — Firebase Authentication keeps your login token in your browser's IndexedDB so you are not asked to sign in on every page.
  • Theme preference — your light or dark choice is saved in localStorage.
  • Voice preference — whether the interviewer speaks, and which voice you picked, saved in localStorage.

Clearing your browser storage removes both and signs you out.

5. Why we process your data

  • To perform our contract with you — creating your account, generating questions, scoring answers, tracking credits and their expiry.
  • Our legitimate interests — keeping the service secure, preventing fraud and duplicate-account abuse, and diagnosing faults.
  • Legal obligations — retaining transaction records for tax and accounting purposes.

6. Who else processes your data

We use a small number of processors, each for a specific purpose. We do not give any of them permission to use your data for their own ends.

  • Google Cloud / Firebase — authentication, database, serverless functions and hosting. Stores your account and session data.
  • Google Gemini API — receives your chosen role and level, the generated questions, the answers you write, and the audio of answers you speak (transcribed, not stored), in order to return a score and feedback.
  • Dodo Payments — merchant of record for purchases. Collects your name, email and billing details directly; we receive only a confirmation that payment succeeded.

7. Monitored candidate interviews

Employers and recruiters can invite candidates to a monitored interview through a shared link. If you take an interview via such a link, two things differ from a normal practice session — and the invite page tells you before you start:

  • Your results go to the person who invited you — your answers, AI scores and feedback, and the integrity signals below are delivered to the interview's creator. They are the ones deciding what happens next, and they act as the controller of that data once delivered.
  • Integrity monitoring runs in your browser. You are asked to share your entire screen and stay in full screen. We never record, upload, screenshot or inspect the content of your screen — the browser only tells us metadata: that sharing is on, which kind of surface was shared, whether the tab lost focus, whether full screen was exited, whether extra displays are attached, and whether a paste was attempted. Only those events, with timestamps, are stored and shared with the interview's creator. Repeated violations end the interview.

Personal practice sessions are never monitored and their results are never shared with anyone but you.

8. International transfers

Our infrastructure runs in Google Cloud's United States region, so your data is stored and processed outside India and outside the EEA. Where data originates in the EEA or UK, transfers rely on the safeguards our processors maintain, including Standard Contractual Clauses.

9. How long we keep it

  • Account and session data — for as long as your account exists, so your history stays available to you.
  • On deletion request — account details and interview sessions are removed within 30 days.
  • Transaction records — retained as long as tax and accounting law requires, even after account deletion. These contain purchase amounts and dates, not interview content.
  • Operational logs — kept on Google Cloud's default retention schedule, typically a matter of weeks.

10. Your rights

Depending on where you live — including under the EU/UK GDPR and India's Digital Personal Data Protection Act, 2023 — you have the right to:

  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted;
  • receive your data in a portable, machine-readable format;
  • object to or restrict certain processing;
  • withdraw consent where processing relies on it.

Email avinash.ranjan21@gmail.com from your account address and we will respond within 30 days. We do not charge for this.

If you are in the EEA or UK and think we have handled your data badly, you may complain to your local data protection authority. We would appreciate the chance to fix it first.

11. Security

Sign-in is handled by Google, so we never hold a password of yours. All traffic runs over HTTPS. Database rules restrict every session record to the account that created it, and entitlement fields such as your credit balance cannot be modified from the browser at all. Secrets and API keys are held in a managed secret store and never shipped to the client.

No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify you and the relevant authority as the law requires.

12. Children

InterviewGPT is not intended for children. You must be at least 16, or the age of digital consent where you live, whichever is higher. If we learn we hold a child's data, we will delete it.

13. Changes to this policy

If we add a feature that changes what we collect — voice recording, for example — we will update this policy and change the date above before that feature goes live. Material changes will be notified to you where reasonably possible.

14. Contact

[[ YOUR LEGAL NAME OR REGISTERED BUSINESS NAME ]]
[[ YOUR BUSINESS ADDRESS, CITY, STATE, PIN, INDIA ]]
avinash.ranjan21@gmail.com