Privacy policy

Transparent data handling

We treat your interview audio, transcripts, and payment history as confidential customer data. The sections below explain what we collect, why we need it, how long we keep it, and the controls you have over it.

Data we collect

We collect the minimum information required to run interview coaching sessions and to honor your credit purchases. That includes your account profile (email, name, usage preferences), the transcripts and audio of every voice session, metadata about how you use the service (timestamps, browser/device info, question mix), and support correspondence.

  • Session audio & transcripts so the agent can understand your spoken answers and we can generate written feedback.
  • Usage signals such as session duration, on/off ramp activity, and device/browser identifiers used to defend against abuse.
  • Billing and purchase details shared with Stripe, limited to order IDs and amounts; Stripe keeps card information on its own servers.

How we use your data

OpenAI powers the realtime voice agent and the report generator, which means the audio you share and the text of your answers are sent to OpenAI’s models to produce follow-ups, coaching, and structured feedback. We only send the content required for those features and never inject your personal metadata into unrelated prompts.

Session transcripts, plan history, and report data live in Supabase so you can revisit a session later. We also log anonymized metrics to understand product health and to keep the realtime experience performing smoothly.

Payments and third-party processors

Stripe processes all payments and stores your card information securely. We receive only the non-sensitive transaction metadata needed to credit your prepaid minutes and to reconcile audit logs. The README documents which Stripe keys must be configured so that Stripe Checkout events map cleanly to the wallet updates we perform on the server.

We never store raw card numbers, and we only keep payment-related identifiers for as long as necessary to handle refunds or disputes.

Security and retention

We run in a VPC-backed environment with encrypted storage, encrypted database connections, and strict access controls around OpenAI keys, Stripe keys, and Supabase secrets. Access is logged and reviewed regularly.

Transcripts and related analytics are retained for up to 90 days by default for audit and coaching improvement purposes. If you need a transcript deleted sooner, send a request to the address below and we will honor it subject to any legal obligations.

Early-stage focus

The Hiring Room is still evolving. We may test new data flows, alter retention windows, or change analytics tooling as we learn from live usage.

While we take security seriously, the platform is provided as a work in progress, so please evaluate it carefully before relying on any particular feature.

Your choices

You can opt out of marketing emails at any time by clicking the unsubscribe link. You can also request a copy of your data or ask us to delete it by emailing support@thehiringroom.com.

The controls above complement Supabase Auth, so you can also delete your account from the profile settings page and wipe stored transcripts in the process.