Privacy Policy

Effective date: August 27, 2026 · Contact: [email protected]

MockWise (“we”, “us”) provides AI-powered mock interviews. This policy explains what we collect, why, how it is stored, and your choices. We only collect what is needed to run the service.

Information we collect

  • Account: email, first/last name, password hash (we never store plain passwords), authentication tokens (JWT stored in a cookie/local storage).
  • Resumes: PDF or DOCX files you upload (max 10 MB each, up to 5 stored). We store the file, its filename, and parsed text (skills, experience, education) to personalize questions.
  • Interviews and reports: interview type, duration, messages, transcripts, AI feedback, scores, and reports you generate.
  • Audio: microphone audio you record during interviews. It is sent to our transcription provider (Groq Whisper, whisper-large-v3-turbo) to produce a transcript. Audio is processed transiently and not kept as a permanent recording in our database (see Security).
  • Payments: Razorpay handles card/UPI/wallet details. We store Razorpay order/payment IDs, amounts, currency, and credit balances. Card numbers never touch our servers.
  • Usage and analytics: if you have not blocked analytics, we log GA4 events (page views, CTA clicks, sign-up, interview created/completed, purchases) with approved campaign parameters, referring-site origin, and device category. Sensitive query values and private interview/report identifiers are removed. No resume, job description, answer, transcript, or report content is sent to analytics.
  • Cookies and similar: `accessToken`/`refreshToken` for auth, and GA/Cloudflare cookies for analytics and bot protection.

How we use information

  • To create and manage your account, authenticate you, and enforce credit/subscription limits.
  • To run mock interviews: generate questions from your resume/role, transcribe audio, stream AI responses, and build reports.
  • To process payments and grant credits via Razorpay.
  • To improve the product, debug, and measure conversion (aggregated analytics).
  • To send service emails (verification, password reset, receipts) via SMTP (e.g., Gmail SMTP if configured).

Storage and retention

  • Account, interview, and report data is stored in Postgres; sessions/cache in Redis.
  • Resume files are stored either on local disk (`uploads/resumes/<userId>/`) or in Cloudflare R2 (`mockwise-files` bucket) depending on deployment, under keys like `resumes/<userId>/<uuid>_filename.pdf`. See Security.
  • Resumes are kept until you delete them (via /resumes) or delete your account. Deleting a resume removes the file from storage and the DB row.
  • Interview transcripts and reports are retained while your account exists and are removed if you delete your account. Audio chunks are held in memory only for the duration of transcription and not persisted as long-term recordings.
  • Backups: Postgres/Redis backups follow your infrastructure provider’s retention (disclosed on request).

Sharing and third parties

  • Groq (AI): interview prompts, resume parsed text, and transcripts are sent to Groq (`openai/gpt-oss-120b`, `openai/gpt-oss-20b`) for chat and report generation; audio to Groq Whisper for transcription.
  • Google Gemini: used for reports if `GEMINI_API_KEY` is configured (model `gemini-2.5-flash`).
  • Speechmatics / Kokoro: used for text-to-speech if enabled.
  • Razorpay: processes payments; your payment method details go directly to Razorpay.
  • Cloudflare and hosting: our site is behind Cloudflare (bot protection, CDN) and runs on Docker (EC2) with Postgres/Redis. Their logs may include IPs and request metadata.
  • Google Analytics: GA4 (`G-1LH7256TYY` if configured) for aggregated usage.
  • We do not sell your personal data.

Your choices and rights

  • Access, correct, or delete your account data via /profile or by emailing [email protected].
  • Delete resumes in /resumes; this deletes the file from storage.
  • Object to or restrict certain processing, or request export, by contacting support.
  • Opt out of analytics by using a blocker or disabling cookies (auth will still require cookies).

Security

We use HTTPS (TLS via Cloudflare), BCrypt for passwords, JWT with expiry, and scoped access checks (you can only access your own resumes/interviews). See Security for details. No system is 100% secure, so please use a unique password and keep your device secure.

Children

MockWise is not intended for children under 16.

Changes

We will post updates here with a new effective date. If changes are material, we will notify via the app or email.

Contact

Questions or requests: [email protected]. We monitor this address. For security issues, see Security.