Privacy Notice
Version 2026-09-03.v6
This notice describes what UmberRook does with your data. It is written in plain language and is deliberately specific: where we say we do not keep something, we mean there is no code that keeps it.
We are not claiming certification under any privacy framework, and we are not claiming compliance with the law of every country we might be reachable from. We have tried to build something honest and minimal, and to describe it accurately. If something here matters to you and is not clear enough, ask us before you use the product.
Your voice, and what happens to it
Your microphone audio is sent to OpenAI and converted to text so your answers can be transcribed. The microphone is open only while you are answering a question.
Your recording is stored temporarily in private, non-public storage and sent to our transcription provider to turn it into text. We delete it after transcription; if that deletion does not succeed, automated cleanup retries it. We keep the text of your answers as part of your practice history, not the audio. The two kinds of practice reach that outcome differently, and the difference is worth stating. In IELTS practice your speech is streamed to OpenAI while you answer and what comes back is text, so no recording is written down at all. In Job Interview practice each answer is recorded, placed in private storage, sent for transcription, and then deleted; if a deletion does not succeed, a daily automated cleanup removes it. Either way, what we keep afterwards is the text, and there is no audio attached to your session for us to play back.
We never ask for your camera. The interview is one-way video: you see the examiner, the examiner does not see you.
Your microphone is open only while you are answering a question. It is muted while the examiner is speaking, so what you say between questions is not captured.
What we store
- Your account — email address, and a display name if you set one.
- The text of your answers — the transcript of what you said, attached to the question you were asked.
- Your practice feedback — the estimated band commentary generated after a session ends.
- Your session history — when a session ran, how long it lasted, which questions it used, and whether it completed.
- Billing records — your credit balance and its history, and a Stripe customer reference. We never see or store your card details.
- Which notices you agreed to — the type, the version, the language you read it in, and when. We do not store your IP address against your consent. The one IP-derived thing we keep anywhere is a keyed one-way code — never the address itself — used to limit the anonymous homepage demo, and it is deleted within 30 days.
- Operational records— that a session started, how long the examiner’s video took to appear, whether a step failed. These hold no interview content: no audio, no transcripts, no feedback, no question text.
Job Interview practice
Job Interview practice works differently from IELTS practice, because you choose how much to tell it. This section describes what happens to that information. Everything here is a statement about code that exists.
For Job Interview practice you choose what to provide — the role and experience level, an optional company name, an optional job description and an optional CV. The role, experience level, job description and the text read from your CV are sent to our AI provider to work out what to ask you; the company name is sent when you give one. Your CV is uploaded over a private one-time link, contact details are removed before it is read, and the file is deleted once it has been read. You see what was extracted and can remove anything you do not want used before you confirm it — anything you remove is not used in the interview that follows. Please leave out anything you do not need for practice.
In Job Interview practice, after your answer is transcribed we may use its text to generate one relevant follow-up question about what you said. The follow-up's text is sent to our speech provider so the interviewer can speak it. If we can't generate a suitable follow-up, the interview simply continues.
What you provide, and what we do with it
- The role you are practising for— job title, experience level, an optional company name, the kind of interview you want and which regional interview conventions to follow. The regional setting changes the style of question you are asked. It is not used to guess your nationality, ethnicity or any other characteristic, and nothing in the product infers one.
- An optional job description— sent to our AI provider so the questions can be about the actual role rather than generic.
- An optional CV— only for a Full Mock, and only when you choose one. It is uploaded over a private, one-time link into private, non-public storage. We read the text out of it, remove contact details before anything else looks at it, and then delete the file. The text we read is sent to our AI provider along with the job description. We do not keep the file. A Pressure Test never reads a CV, and the setup form says so where you choose the file.
- What was extracted— you are shown the specific points the AI drew out, and you can remove any of them before you confirm. Removed points are excluded from the interview that follows. They were read in order to be extracted, so removing one takes it out of what happens next rather than undoing that it was processed.
- Your spoken answers— each answer is recorded, uploaded to private storage, transcribed, and the recording is then deleted. We keep the transcript, not the audio.
Practice across several rounds
A multi-round process keeps the context you reviewed and reuses it for every round, so you do not enter it again, and it links the rounds’ reports together so feedback can refer to more than one interview. We also keep a record of which questions you have already been asked, so later practice does not repeat them. That record holds question wording and identifiers — not your answers and not your CV.
What the feedback is
Practice feedback, produced after the interview from your transcript. It is not a hiring decision, not an employer’s assessment, and not a measure of your employability. It does not analyse your appearance, your accent or your emotions, and there is no code that does.
Deleting it
Deleting your account removes your job interview sessions, the context you reviewed and everything extracted into it, your transcripts, your reports, the links between rounds, and any file still in staging. Billing records are kept as long as the law requires, as described above.
How long we keep it
We keep the text of your answers, your practice feedback and your session history for as long as your account exists. Operational records of how the software behaved are deleted automatically after 30 days. Billing records are kept as long as the law requires.
To be precise about the part that is automatic: operational records delete themselves after 30 days, on a schedule that runs daily. The rest — your answers, your feedback, your session history — stays until your account is deleted. We are not pretending it expires on its own.
Who processes your data
These are the companies that handle data on our instructions in order for the product to work. We do not sell your personal information, and we do not share it with advertisers or data brokers.
- LiveAvatar— renders the examiner’s video and lip-sync. During practice interviews it receives only pre-generated examiner audio — never your microphone audio, your answers, or anything you say. The optional 60-second live demo on our homepage works differently: there, your speech is sent to LiveAvatar to generate the reply, exactly as the demo’s own consent screen says before you start, and UmberRook records and keeps nothing from it.
- Cloudflare — sits in front of the website, routing traffic and filtering abuse, and runs the human-check (Turnstile) before the homepage live demo. Like any network provider it processes request data such as your IP address to do this; it does not receive your answers, transcripts or feedback.
- OpenAI — transcribes your speech to text while you answer, and generates your practice feedback from the transcript afterwards. Your audio passes through OpenAI for transcription; we do not permit it to be used to train models.
- Supabase — our database, file storage and sign-in. Your account, transcripts, feedback and history live here.
- Stripe — payments. Card details go to Stripe directly and never reach our servers; we store only a customer reference.
- Vercel — hosting. Serves the application and processes requests.
- Sentry — technical error monitoring, so we can find crashes. It is configured to receive error types and stack traces only: no request bodies, no transcripts, no answers, no question text, no email addresses, and IP collection is turned off.
Getting your data, or having it deleted
You can download everything we hold about you at any time from your account, and delete your account and practice history yourself from your billing page. If you would rather email us, we will do it for you.
The export is immediate and includes everything: your account details, every consent you gave, every session with its questions and your answers, your feedback, and your credit history.
You can delete your account and practice history yourself: the delete control is on your billing page, and it asks you to sign in again and type a confirmation before anything happens. If you would rather ask us, email works too and we will do it for you. Billing records that we are legally required to keep are the one exception, and they are retained without your interview content.
Contact: [email protected]. Write to this address for a deletion request, a question about this notice, or anything else about your data.
Changes
If we change what we collect, who processes it, or how long we keep it, we update the version at the top of this page and ask you to read it again before your next session. The version you agreed to is recorded against your account, so what you accepted stays answerable.