Privacy notice
Last updated 31 July 2026 · Applies to the Interview Coach closed beta
Interview Coach is operated by Ash Rigby, who is the data controller for the personal data described here. For anything in this notice — questions, requests, complaints — email ansrigby@gmail.com. These operator and contact details are temporary for the beta and may be updated before public launch; the version of this page on the site is always the current one.
What we collect, and why
- Account details — your email address, your name as entered at registration, and your password, which Supabase (our authentication provider) processes when you sign up or log in and stores only as a one-way hash — a form that cannot be read back as the password itself. Used to sign you in, keep your practice history yours, and contact you about the beta if needed.
- Your answers — the text of each answer you submit for evaluation, including, for spoken answers, the automatic transcript and any edits you made to it, plus the recording's length. Used to generate your feedback and to show you your own attempt history.
- Evaluation results — the scores, written feedback, suggested stronger answer and confidence level the AI evaluator produces for each attempt. Used to show your results and progress over time.
- Practice activity — which questions you attempted and when, and any questions you mark “I don't know” for review. Used to run your dashboard, progress page and needs-review list.
- Usage counts and records — how many evaluations and transcriptions you use per hour and per day, and, for each transcription, a usage record holding the reserved and provider-reported audio duration in seconds and the request's status. Used only to enforce fair-use limits, control the beta's AI costs and monitor for abuse; these are numbers and statuses — never the audio or the transcript itself.
We do not collect payment details (the beta is free), we do not use advertising or analytics trackers, and we do not sell personal data.
Lawful bases
UK data protection law requires a lawful basis for each use of personal data. For this closed beta we rely on:
- Performance of a contract — for delivering the service you sign up for: your account, signing you in, evaluating the answers you choose to submit, transcribing the recordings you choose to make, and showing you your results, history, progress and needs-review list.
- Legitimate interests — for keeping the service secure and affordable: enforcing fair-use rate limits, preventing abuse, and controlling the beta's AI costs (this is what the usage counters exist for). We use these protections in ways we believe do not override your rights.
- Legal obligation — for handling privacy-rights requests and anything else the law requires of us.
This mapping is our proposed approach for the closed beta and will be professionally reviewed before any public launch.
AI processing — what leaves our systems
- Submitted answers go to Anthropic. When you press “Submit answer”, your answer text is sent to Anthropic (the maker of Claude, in the United States) together with the question and its marking guide so the AI can grade it. The app does not attach your name, email or account identity — but the answer text itself is sent as you wrote it, so any personal details you choose to include in an answer are sent with it. Anthropic states that standard Claude API inputs and outputs are not used to train its models and are deleted within 30 days, subject to its stated exceptions — for example policy enforcement, legal requirements, or separately agreed retention arrangements.
- Recorded audio goes to OpenAI. If you record a spoken answer, the audio stays in your browser until you press transcribe; it is then sent to OpenAI's speech-to-text API (the
/v1/audio/transcriptionsendpoint, in the United States) and only the transcript comes back. Interview Coach does not save the recording in its own database — no audio is stored anywhere on our side. The recording itself is sent as spoken, so anything personal you say out loud is part of the audio OpenAI receives. OpenAI's data-controls documentation currently lists this endpoint as having no application-state retention and no abuse-monitoring retention, and states that API data is not used to train its models unless a customer opts in — though providers can make exceptions where legally required or under their policies.
AI-generated feedback can be wrong. Scores and suggestions are produced by a language model against a marking guide; they may contain inaccuracies and are provided for interview practice only — they are not financial, careers or other professional advice, and no score is a promise about real interview outcomes.
Where your data lives
- Supabasehosts our database and login system — your account and everything in “What we collect” is stored there, protected by row-level security so each account can only read its own data. Supabase runs on cloud infrastructure that may be located outside the UK.
- Vercel serves the website. Its server functions for this site run in the United States, so requests you make (including answer submissions in transit) are processed there. Vercel keeps short-lived technical logs (currently about an hour) that do not include your answers.
Because Anthropic, OpenAI and Vercel process data in the United States, your practice data is transferred internationally when you use the service. We keep what is sent to each provider to the minimum the feature needs, as described above. Each provider offers standard data-protection terms for these transfers: Anthropic's data processing addendum (including standard contractual clauses) is incorporated automatically into its API terms; OpenAI's is incorporated into its services agreement; and Supabase's (effective 1 August 2026) forms part of its terms of service, with acceptance of the agreement having the effect of signing the standard contractual clauses. Vercel's addendum expressly covers its paid plans, and we are confirming how it applies to our current setup before any public launch.
How long we keep it
- Your account and practice history are kept while your beta account remains active, so your progress tracking keeps working.
- If you ask us to delete your account (below), we delete it and all of your practice data following a verified request.
- We review inactive beta accounts at least annually and delete those no longer needed. We do not currently have automatic deletion, and we will not pretend otherwise.
- Deletion removes your data from the live application database. Copies may persist temporarily elsewhere: in the AI providers' retention windows described above, in Vercel's short-lived technical logs (currently about an hour), and in provider-managed database backups according to Supabase's current retention processes, which age out on the provider's schedule.
Deleting your account and data
Email ansrigby@gmail.com from the email address your account is registered under and ask for deletion. We will acknowledge your request and complete it — or formally respond if we cannot — without undue delay and at most within 28 days. Deletion removes your login, account details, answers and transcripts, evaluation results, needs-review list, usage counters and usage records. The same address also handles requests for a copy of your data.
Your rights
Under UK data protection law you have rights over your personal data — depending on the circumstances, these include the rights to access it, correct it, delete it, restrict or object to its use, and receive a copy of it. Exercise any of these via ansrigby@gmail.com. If you are unhappy with how a request is handled, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
This notice describes the closed beta and will be revised — including operator details, retention periods and any new processing — before any public launch.