Privacy Policy
Last Updated: October 17, 2025
This Privacy Policy describes how Prepair ("we," "us," or "our") collects, uses, and shares your personal information when you use our interview preparation mobile application (the "App").
1. Information We Collect
1.1 Information You Provide
- Account Information: When you create an account, we collect your email address and password through Supabase authentication services
- Profile Information: Name, current job title, company, career level, years of experience, industry, target role, work experiences, education history, technical skills, and soft skills
- Interview Practice Data: Your interview responses, practice session recordings (audio/video if enabled), session transcripts, scores, and feedback
- Career Information: Job applications you track, career goals, and custom interview questions
- Communication: Messages you send through our career coach feature or support channels
1.2 Automatically Collected Information
- Usage Data: App features used, session duration, practice frequency, and performance metrics
- Device Information: Device type, operating system version, unique device identifiers, and mobile network information
- Audio Recordings: Voice recordings during interview practice sessions (with your explicit permission)
- Video Recordings: Video recordings during video interview practice (with your explicit permission)
1.3 Information from Third-Party Services
- Payment Information: Processed securely through RevenueCat and Apple's in-app purchase system. We do not store your payment card details
- Authentication Data: Account verification through Supabase
2. How We Use Your Information
We use your information to:
- Provide Core Services: Enable interview practice, generate personalized feedback, track your progress, and provide career coaching
- Personalization: Customize interview questions based on your role, industry, and experience level
- Speech Processing: Convert your spoken responses to text using AssemblyAI's speech-to-text service
- Response Generation: Generate interview questions and provide feedback using Grok AI
- Voice Synthesis: Convert AI-generated text to speech using Google's Gemini TTS service
- Image Processing: Generate professional headshots using Google's Nano Banana CV model (if you use this feature)
- Analytics: Analyze your practice patterns to show meaningful progress metrics and improvement areas
- Subscription Management: Process and manage your premium subscription through RevenueCat
- Customer Support: Respond to your questions and provide technical assistance
- App Improvement: Identify bugs, improve features, and enhance user experience
- Legal Compliance: Comply with applicable laws and enforce our Terms of Service
3. Third-Party Service Providers
We share your information with the following trusted third-party services to operate our App:
3.1 Grok AI (xAI)
- Purpose: Generate interview questions, provide coaching feedback, and power the career coach feature
- Data Shared: Your interview responses, profile information, and career questions
- Privacy Policy: https://x.ai/legal/privacy-policy
3.2 AssemblyAI
3.3 Google Gemini TTS
3.4 Google Nano Banana CV Model
- Purpose: Generate professional AI headshots
- Data Shared: Photos you upload for headshot generation (only when you use this feature)
- Privacy Policy: https://policies.google.com/privacy
3.5 Supabase
- Purpose: User authentication, account management, and data storage
- Data Shared: Account credentials, profile information, and app data
- Privacy Policy: https://supabase.com/privacy
3.6 RevenueCat
- Purpose: Subscription management and in-app purchase tracking
- Data Shared: Subscription status, purchase history, and device identifiers
- Privacy Policy: https://www.revenuecat.com/privacy
4. Data Storage and Security
4.1 Data Storage
- Your data is stored securely using Supabase's cloud infrastructure
- Interview recordings are stored on your device and optionally backed up to secure cloud storage
- All data transmissions are encrypted using industry-standard SSL/TLS protocols
4.2 Data Retention
- Account Data: Retained for as long as your account is active
- Interview Sessions: Stored indefinitely unless you delete them manually
- Deleted Data: Permanently removed from our systems within 30 days of deletion request
- Third-Party Processing: Audio/text processed by AI services is not retained by those services after processing
4.3 Security Measures
- Encryption of data in transit and at rest
- Secure authentication through Supabase
- Regular security audits and updates
- Limited employee access to personal data
- Secure API connections to all third-party services
5. Your Rights and Choices
5.1 Access and Control
- Access: View your profile information and interview history within the App
- Edit: Update your profile information at any time through Settings
- Delete: Remove specific interview sessions or delete your entire account
- Export: Request a copy of your data by contacting support
5.2 Permission Controls
- Microphone: Required for interview practice; can be managed in device settings
- Camera: Optional for video interview practice; can be disabled anytime
- Notifications: Can be disabled in App settings or device settings
5.3 Marketing Communications
- You can opt out of promotional emails by clicking the unsubscribe link
- Service-related communications (account updates, security alerts) cannot be opted out
5.4 Account Deletion
To delete your account:
- Go to Settings → Profile → Delete Account
- Or email us at karoljaworsky@gmail.com
- All your data will be permanently deleted within 30 days
6. Biometric Data
IMPORTANT - BIOMETRIC DATA COLLECTION: Prepair collects and processes biometric information, including voice recordings and facial characteristics from video recordings. Please read this section carefully before using these features.
6.1 What Biometric Data We Collect
When you use our interview practice features, we may collect:
- Voice Biometrics: Audio recordings of your voice during practice interviews, including voiceprints and speech patterns
- Facial Biometrics: Video recordings that may capture facial features, expressions, and movements (only when you enable video interview mode)
- Behavioral Patterns: Speech cadence, tone, pause patterns, and other communication characteristics
6.2 How We Use Biometric Data
Your biometric data is used solely for the following purposes:
- Speech-to-Text Conversion: Your voice recordings are processed by AssemblyAI to transcribe your interview responses
- Performance Feedback: Analyzing your speech patterns to provide feedback on communication skills
- Practice Review: Allowing you to review your own recordings to improve your interview performance
- Progress Tracking: Measuring improvements in your interview delivery over time
We do NOT use your biometric data for:
- Identifying or tracking you outside the App
- Sharing with employers or third parties (except as disclosed below)
- Marketing or advertising purposes
- Selling to any third party
- Training AI models (unless you explicitly opt-in to a research program)
6.3 Your Consent
By using voice or video interview features, you provide your explicit, informed, and voluntary consent to:
- Collection and storage of your biometric data
- Processing of your biometric data for the purposes described above
- Sharing your voice recordings with AssemblyAI for speech-to-text processing
You can withdraw consent at any time by:
- Stopping use of voice/video interview features
- Deleting your recordings in the App (Settings → Interview History → Delete)
- Deleting your account (all biometric data will be permanently deleted)
- Emailing us at karoljaworsky@gmail.com to request immediate deletion
6.4 Biometric Data Storage and Retention
- Storage Location: Recordings are stored locally on your device and optionally in encrypted cloud storage via Supabase
- Retention Period: We retain your biometric data for as long as you keep the recordings in your interview history
- Automatic Deletion: Recordings are automatically deleted when you:
- Manually delete individual interview sessions
- Delete your account (within 30 days)
- Request deletion via karoljaworsky@gmail.com
- Third-Party Processing: AssemblyAI processes your voice recordings but does NOT retain them after transcription is complete (as per their privacy policy)
6.5 Biometric Data Security
- All biometric data is encrypted in transit using TLS/SSL encryption
- Cloud-stored recordings are encrypted at rest
- Access is restricted to your account only
- We use secure authentication via Supabase to protect your data
- Regular security audits are performed on our systems
6.6 Third-Party Sharing of Biometric Data
We share your biometric data only as follows:
- AssemblyAI: Voice recordings are sent for speech-to-text transcription. AssemblyAI does not retain recordings after processing. See their privacy policy: https://www.assemblyai.com/legal/privacy-policy
- No Other Sharing: We do not share, sell, or disclose your biometric data to any other third parties except as required by law
6.7 Illinois Biometric Information Privacy Act (BIPA) Compliance
For Illinois residents, we comply with BIPA by:
- Providing this written policy publicly available on our website
- Obtaining your informed written consent before collecting biometric data
- Disclosing the specific purpose and length of time biometric data is collected, stored, and used
- Not selling, leasing, trading, or profiting from your biometric data
- Storing and transmitting biometric data using reasonable security measures
- Destroying biometric data when the initial purpose is satisfied or within 3 years, whichever occurs first
6.8 Your Biometric Data Rights
You have the right to:
- Access: Request a copy of your biometric data
- Delete: Request immediate deletion of your biometric data at any time
- Opt-Out: Choose not to use voice/video features (you can still use text-based interview modes)
- Portability: Download your recordings in a standard format
- Withdraw Consent: Revoke your consent to biometric data processing at any time
To exercise any of these rights, contact us at karoljaworsky@gmail.com. We will respond within 30 days (or as required by applicable law).
7. Children's Privacy
Our App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at karoljaworsky@gmail.com.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our App, you consent to the transfer of your information to the United States and other countries where our service providers operate.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights:
- Right to Know: Request disclosure of personal information collected
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of personal information (Note: We do not sell your personal information)
- Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at karoljaworsky@gmail.com.
9. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under GDPR:
- Right to Access: Obtain confirmation of data processing and access your data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Restrict processing of your data
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing of your data
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights or file a complaint with a supervisory authority, contact us at karoljaworsky@gmail.com.
11. Cookie Policy
11.1 What Are Cookies
Cookies are small text files stored on your device. Our App and website may use cookies and similar tracking technologies.
11.2 Cookies We Use
- Essential Cookies: Required for authentication and basic functionality (e.g., keeping you logged in)
- Analytics: We may use analytics to understand app usage patterns (aggregated and anonymized)
- Preference Cookies: Remember your settings and preferences
11.3 Third-Party Cookies
Our third-party service providers may set their own cookies:
- Supabase: Authentication and session management
- RevenueCat: Subscription tracking
11.4 Your Cookie Choices
- You can manage cookies through your device settings
- Disabling essential cookies may limit App functionality
- Analytics cookies can be disabled without affecting core features
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email or in-app notification
- Require you to accept the new policy before continuing to use the App
Continued use of the App after changes constitutes acceptance of the updated policy.
13. Do Not Track
Our App does not respond to "Do Not Track" signals. We do not track users across third-party websites or apps.
14. Contact Us
← Back to Legal Documents