Privacy Policy
Your privacy matters. This policy explains how Interview AiBox collects, uses, shares, and protects data across our website, product pages, desktop app, and related services.
01Overview
This policy applies to your access to and use of all services provided by Interview AiBox (the “Services”).
Capitalized terms not defined here have the meaning in our Terms of Service at /terms.
By continuing to use the Services, you acknowledge that your data is handled under this policy.
02Scope and third-party boundaries
This policy covers only services directly operated by us.
Third-party platforms, integrations, and linked websites are governed by their own terms and privacy policies.
03Local-first data handling
Resume content, interview audio, and on-screen context are processed locally on your device by default.
We do not access or upload these contents unless you explicitly opt in to a cloud feature, share, or export through our servers. When cloud processing is enabled, we only process the minimum necessary data and do not retain it longer than required to complete the task unless you choose to save it.
04Information we collect
We collect information necessary to provide, secure, and improve the Services, including:
- Account details (such as email and authentication identifiers).
- Authentication data from sign-in providers (for example Google or GitHub).
- Billing fields required for transactions (for example card type, last four digits, and expiry metadata).
- Data you upload or ask us to process (for example recordings, transcripts, screenshots, and support submissions).
- Log and technical data (for example IP address, browser/device information, request time).
- Usage data (for example feature usage, actions, diagnostics, and error signals).
- Cookie and similar tracking signals.
- Other information you provide in webinars, research, or communications.
05Third-party services and sources
We work with service providers to operate the Services (for example payments, analytics, hosting, fraud prevention, and transcription support).
Sensitive payment data is primarily handled by compliant payment processors under their own privacy policies.
- Payment processors (for example Stripe).
- Identity and authentication providers.
- Cloud, support, logging, analytics, and security providers.
06How we use information
We use collected data for the following purposes:
- Provide, maintain, and improve service quality and user experience.
- Operate account, billing, order, notification, and support workflows.
- Detect, prevent, and investigate fraud, abuse, or security incidents.
- Run internal analytics, reporting, audits, and de-identified product research.
- Send product/service updates and optional marketing communications (with opt-out controls).
07Sharing and disclosure
We do not sell your personal information. We share data only when necessary and under appropriate safeguards:
- With processors/service providers supporting core operations (payments, hosting, analytics, support, security).
- To comply with legal obligations, lawful requests, or regulatory requirements.
- To protect users, public safety, and our legal rights, or prevent serious harm.
- With your consent or at your direction.
- As part of lawful corporate transactions (for example merger, reorganization, or asset transfer).
08Cookies and tracking technologies
We use cookies and similar technologies to keep sessions secure, remember preferences, and measure service performance.
You can control cookies via browser settings and our cookie controls; disabling some cookies may affect functionality.
- Strictly necessary cookies for security, login, and core operation.
- Functionality cookies for language, theme, and UI preferences.
- Analytics cookies for aggregated traffic and reliability insights.
09Consent and permissions
We only access microphone, screen, or other OS-level permissions after you grant them, and only to deliver the features you request.
You can revoke permissions at any time from your system settings, and we will stop processing immediately.
10Security
We use industry-standard safeguards to protect data in transit and at rest, including encryption and strict access controls.
- TLS encryption for network traffic.
- Encrypted storage for any server-side data.
- Restricted access and audit logging for internal systems.
11Data retention
Operational logs are retained only as long as necessary to maintain service quality.
You may request deletion of your account data, and we will complete deletion within 30 days (backups within 90 days where legally required).
12Your rights
Depending on applicable law, you may have rights to:
- Access, correct, update, or delete personal information.
- Export data in a portable format.
- Withdraw consent or object to certain processing activities.
- Manage marketing preferences and unsubscribe.
- File a complaint with a supervisory authority (we encourage contacting us first).
13Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16.
If you believe we collected such information by mistake, contact [email protected] and we will review and remove it as appropriate.
14Region-specific and cross-border processing
Our infrastructure and providers may process data in multiple jurisdictions. By using the Services, you acknowledge required cross-border transfers under applicable law.
For users in regions with specific privacy rights (for example EU/UK or certain U.S. states), we support rights requests as required by law.
We do not automatically change practices based solely on browser Do Not Track signals; privacy controls remain available through account and cookie settings.
15Policy updates
We may update this policy from time to time. Material changes will be announced on this page and, where appropriate, via account email.
Updates take effect when posted. Please review this page periodically.
16Contact us
Questions about this policy, your personal information, or the Services? Contact [email protected].