Your practice is personal

Privacy & your data

Effective September 10, 2026 · notice version 2026-09-10.1

This notice describes the hosted mockinterview.live service, maintained by the mockinterview project maintainer. Contact the operator privately at makinenitejovardhan@gmail.com, including without an account. Other installations have their own operators, providers and policies.

Accounts and eligibility

We store your email, a password hash, email-verification status, account settings, and the version and time of your terms/privacy acknowledgment and adult declaration. Hosted AI practice is for people aged 18 or older. We do not request a birth date or identity document for signup. If you believe a child has provided data, contact us so we can restrict use and arrange deletion. An age declaration is not identity verification.

For approved testers, we also store an email address and the time it was added to the tester registry to manage unlimited practice access. An operator can add this email before account registration. Tester access takes effect after the matching account verifies its email.

Practice, resumes and AI providers

Your scenario, chosen settings, answers, notes/code/diagram and optional resume context support the AI interview and feedback. The app stores transcripts, workspace revisions and reports with your account. It is a practice tool; it does not make employer hiring decisions or infer your health, identity or emotions from camera footage.

Selecting a resume file immediately uploads it for text extraction and AI parsing, independently of the later “use for this interview” option. Extracted text, filename, parsed details and generated reviews are saved. Review and matching requests send the resume and any supplied job description to the service’s model. The app does not retain the original uploaded binary in this processing path. Use your own permitted material and omit unnecessary contact details, health information, government identifiers, financial credentials, confidential questions and real patient/client records.

The hosted service uses Google Cloud/Firebase for hosting and storage, Google Gemini for platform interviews, resume tools and other AI assistance, and Resend for verification and password-reset emails (your email and a single-use link). The platform Gemini key uses a project with paid billing enabled. Google’s paid-service terms govern its handling of inputs, including safety/abuse processing. Personal-key interviews use the selected provider for interview reasoning and feedback; Gemini supplies native voice. Resume tools still use the platform model.

Review the relevant provider information: Google Cloud, Gemini, Resend, OpenAI, Anthropic, DeepSeek, xAI. Provider policies, account plans and locations differ. A working API key does not prove zero retention or appropriate data handling.

Service-specific processing terms also include the Google Cloud DPA, Google processor terms and Resend DPA. Linking these documents does not certify that every provider arrangement satisfies the laws of your location.

Voice and camera

Device checks are local. Starting a voice interview streams your microphone audio through our API to Google Gemini, and saves a text transcript. The application does not save raw microphone recordings, but provider processing and retention are governed separately. Use a private space and only your own voice. Text interviews require no microphone or camera permission.

Camera self-view starts off and remains in your browser. The current service does not upload camera frames or accept face-analysis samples. It does not use facial geometry, gaze, posture or emotion analysis to score your practice. Legacy analysis records from earlier versions are covered by the retention controls below.

Personal model keys

Your key travels over HTTPS to the service and selected provider for validation and use. It is held in memory in the page and is not intentionally written to browser storage, transcripts, reports or feedback. A temporary encrypted server copy can support reconnection and scoring, with a three-hour expiry and earlier removal after completion. Personal Gemini keys require your declaration that their Google project has paid billing enabled. We cannot independently verify that declaration through a normal connection check.

Feedback and service operation

New interview attempts include a required product-feedback check-in after a started interview ends. Complete it before starting another interview; the check-in is optional for approved testers. Saved reports, history, export, deletion and report retries remain accessible. Each question allows an unable-to-judge answer. Comments and permission to inspect your transcript are optional and do not affect whether you can complete the check-in. An optional section can also record prior use of other interview-practice tools, tool names, a comparison rating and written details for product improvement.

These answers are associated with your account and interview; they are not anonymous. We retain the questionnaire version, answers, optional comment and sharing choice, submission/update times, and relevant interview metadata such as subject, format, selected level, mode and provider. The operator uses aggregate counts and rating distributions to understand usability, interviewer behavior, content and service reliability. The questionnaire does not send your answers to an AI model or change your interview score. It does not enroll you in research or authorize publication of private records.

The separate “Share feedback” and “Report a problem” controls remain optional. Their technical diagnostics and transcript-sharing choices start unchecked. Contact us to withdraw optional sharing or request deletion. Deleting an interview removes its structured check-in; separately submitted problem reports or general feedback remain until removed separately or through account deletion. Account export includes your structured check-ins.

Security and troubleshooting use limited request/usage metadata, such as time, request ID, IP address, browser information and error category in infrastructure logs. We do not intentionally log passwords, resume text, interview content or personal model keys. Authorized operators may access records to provide support, handle your requests, investigate abuse or maintain the service. We do not publish private records as community contributions.

Purposes and legal grounds

Where European or UK data-protection law applies, core account and requested AI processing supports our agreement with you; proportionate security, abuse prevention, service administration and product-quality analysis support legitimate interests, subject to applicable rights and balancing requirements. A required product check-in is not a request for consent to research. Optional diagnostic and transcript sharing for support is based on your consent. You can withdraw that permission by contacting us; withdrawal does not affect earlier lawful processing. Reading this notice is not blanket consent for every use of personal information. We do not request special-category data or use interview content for advertising or our own model training.

Storage, retention and deletion

The hosted application database is in the United States. Providers may process information in other countries. Provider contracts and any applicable international-transfer requirements also matter; US storage alone does not establish compliance in your country.

Account and interview records remain until you delete them or request deletion. A new resume upload replaces the previous upload; older standalone reviews and interview-derived content remain until separately removed. Settings offers account export and deletion; History offers individual interview deletion; Resume offers removal of saved resumes and reviews. Removing resumes does not rewrite existing interview answers or reports that already incorporated them. Delete those interviews separately if needed. Downloads and copies you have shared are outside the app’s deletion controls.

Verification links expire after 24 hours and reset links after 30 minutes. Temporary credentials expire after three hours. A minimal, pseudonymous eligibility record may remain after account/interview deletion until hourly cleanup following seven days from the attempt’s start to enforce hosted limits: it contains a keyed email hash, attempt ID, funding type and start time, without email text, resume or transcript. Hourly maintenance removes expired action/credential/eligibility records and raw legacy camera-analysis samples older than 30 days. Historical aggregate reports remain with their interview until deletion.

Configured ordinary Google Cloud logs retain 30 days, while required infrastructure audit logs retain 400 days. Automated database backups retain seven backup copies; this is a count, not a guaranteed seven-day deletion period. Restricted manual release/recovery backups may also retain deleted records. These copies are not active interview history; complete expiry from every backup is not immediate. Contact the operator about a specific deletion request or backup retention.

Browser storage and tracking

The app uses browser local/session storage for sign-in, preferences, cached resume reviews and recovery of unsaved answers/workspace. Logout and account deletion clear private app caches on the current browser origin. Another device, alternate hostname, downloaded export or browser backup may still hold a copy; clear that site’s storage on shared devices.

We do not sell personal information, use advertising or cross-site behavioral tracking, or embed an analytics SDK in this release. Do Not Track and Global Privacy Control signals do not change these practices; essential sign-in, preference and recovery storage continues to operate. We will explain material changes before introducing additional tracking or new data uses.

Your questions and rights

You may use the account controls or email the operator for access, correction, deletion, withdrawal of optional sharing, or applicable rights to portability, restriction or objection. We may proportionately verify account ownership; do not send identity documents or secrets unless a secure, necessary process has been agreed. Depending on your location, you may complain to your data-protection authority or appeal a decision. Applicable legal response deadlines still apply to requests; support availability does not remove them.

Material notice changes will be dated here and presented for review before further hosted AI use. For private access, accessibility or data questions, see Help & support. Public GitHub issues are visible to everyone and should never include personal records.