← Home
MockMe
Privacy Policy
Last updated: April 9, 2026
1. Introduction
MockMe ("we," "our," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the MockMe application ("App," "Service"). By using MockMe, you consent to the practices described in this policy. If you do not agree, please discontinue use of the Service.
2. Information We Collect
2.1 Information You Provide:
- Account Data: Name, email address, and password (stored as a salted bcrypt hash) when you create an account
- Profile Data: Display name, avatar preferences, and weekly practice goals
- Resume Data: Resume files you upload for personalized interview preparation (stored encrypted at rest)
- Interview Responses: Your spoken or typed responses during mock interview sessions
- Pitch Deck Content: Pitch deck files and presentation content you upload
2.2 Information Collected Automatically:
- Usage Data: Session duration, interview scores, feature usage, practice frequency, streaks, XP earned, and achievement progress
- Device Data: Device type, operating system version, app version, and browser/WebView information
- Performance Data: Voice analytics (speaking rate, filler word counts, pause durations), body language metrics (processed on-device), and interview performance trends
2.3 Sensitive Data We Process:
- Audio Data: Voice recordings captured during interview practice are transmitted to our servers for transcription and speech analysis. Audio data is processed in real-time and is not permanently stored after transcription is complete.
- Camera Data: Video from your device camera is used for body language analysis. All camera processing occurs entirely on your device using MediaPipe. No video footage, images, or visual data are ever transmitted to or stored on our servers.
3. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To provide AI-powered interview coaching, generate personalized feedback, track your progress, and deliver analytics
- Personalization: To tailor interview questions based on your resume, experience level, and practice history
- Account Management: To authenticate your identity, manage your subscription, and communicate with you about your account
- Service Improvement: To analyze aggregated, de-identified usage patterns to improve our AI models, features, and user experience
- Notifications: To send you practice reminders, achievement notifications, and service updates (which you can disable in Settings)
- Security: To detect and prevent fraud, abuse, and unauthorized access
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
4. AI and Machine Learning
MockMe uses AI and machine learning technologies to provide its core features:
- Large Language Models: Your interview responses and resume context are sent to third-party language model providers under enterprise data processing agreements to generate interview questions, feedback, and coaching. Under these agreements, data sent to these providers is not used to train their models.
- Speech-to-Text: Audio recordings are processed by third-party speech recognition services under the same enterprise data processing agreements. Audio is processed in real-time and not retained by these providers.
- Text-to-Speech: Interview questions are converted to speech using a neural voice model that runs entirely on MockMe's own servers. Text is not sent to any third party for speech synthesis, and no audio is retained after it is streamed back to your device.
- On-Device ML (MediaPipe): Body language analysis runs entirely on your device. No visual data leaves your device.
4.1 Training MockMe's Own Models. To improve the quality of our interview coaching over time, we record the prompts and responses exchanged during your practice sessions and use that data to train and fine-tune MockMe's own coaching models. Before any training data is written to disk, we automatically remove common categories of personally identifiable information (email addresses, phone numbers, street addresses, government IDs such as SSNs, payment card numbers, IP addresses, and authentication tokens) and we strip your account identifier from the persisted record so that training examples cannot be linked back to you. The content of the interview itself — the questions, your spoken responses (as text transcripts), and the coaching feedback — is retained.
4.2 Your Choice. Participation in this training program is opt-in by default and you can turn it off at any time under Settings → Privacy & Security → Help Improve MockMe. When you opt out, new sessions are not recorded for training. Opting out does not affect the functionality of the Service in any way. Disabling training does not retroactively remove examples collected before you opted out; to remove those, use Delete Account or contact us at privacy@chava.codes.
4.3 What We Never Train On. We never train on raw audio, camera video, resume files, payment information, or account credentials. Camera and on-device body language analysis never leaves your device regardless of your training preference.
4.4 No Sale, No Third-Party Training. We do not sell training data, and your individual data is never used to train models owned by any third-party provider. Training is performed only on infrastructure controlled by MockMe.
5. Third-Party Services
We share data with the following categories of third-party service providers, strictly as necessary to deliver the Service:
- AI/ML Providers — Large language model and speech-to-text services based in the United States. Data sent to these providers is covered by enterprise data processing agreements that prohibit training on your content. (Text-to-speech is generated in-process on MockMe's own infrastructure and is not shared with any third party.)
- Supabase (San Francisco, CA) — Database hosting, authentication, and file storage. Data is encrypted in transit (TLS) and at rest (AES-256).
- Apple (Cupertino, CA) — Payment processing for iOS in-app purchases. We do not receive or store your payment card details.
- Railway (San Francisco, CA) — Application hosting and server infrastructure.
We require all third-party providers to maintain appropriate security measures and to process your data only as instructed by us. A current list of sub-processors is available on request at privacy@chava.codes.
6. Data Storage, Security, and Retention
Storage: Your data is stored on servers in the United States using Supabase (backed by AWS). All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.
Security: We implement industry-standard security measures including: password hashing with bcrypt (12 rounds), JWT-based authentication with 7-day expiration, rate limiting on authentication endpoints, input validation and sanitization, and HTTPS-only communication.
Retention:
- Account and profile data: Retained until you delete your account
- Interview transcripts and scores: Retained until you delete your account
- Audio recordings: Processed in real-time and not permanently stored
- Camera/video data: Never transmitted or stored (processed on-device only)
- Resume files: Retained until you manually delete them or delete your account
- After account deletion: All associated data is permanently deleted within 30 days
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data (available via Settings > Delete Account)
- Portability: Request your data in a portable format (available via Settings > Export Data)
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, contact us at privacy@chava.codes. We will respond within 30 days (or as required by applicable law).
8. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland:
- Legal Basis: We process your data based on: (a) your consent; (b) performance of our contract with you; (c) our legitimate interests in improving the Service; and (d) compliance with legal obligations.
- International Transfers: Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard such transfers.
- Data Protection Officer: You may contact our data protection team at privacy@chava.codes.
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.
9. CCPA Compliance (California Users)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected about you
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out: We do not sell personal information. If this changes, we will provide a "Do Not Sell My Personal Information" mechanism.
- Shine the Light: We do not disclose personal information to third parties for their direct marketing purposes
To submit a CCPA request, email privacy@chava.codes with the subject "CCPA Request."
10. Children's Privacy
MockMe is not intended for users under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal information, please contact us at privacy@chava.codes.
11. Cookies and Local Storage
MockMe uses local device storage (localStorage) to store your preferences, authentication tokens, and session data. We do not use third-party tracking cookies or advertising trackers. Authentication tokens expire after 7 days and are removed upon logout.
12. Push Notifications
MockMe may send you local push notifications (daily practice reminders, achievement alerts, and updates). Notifications are scheduled on your device and do not require sharing your device token with external push notification services. You can enable or disable notifications at any time in Settings or through your device's notification settings.
13. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users via email and/or in-app notification within 72 hours of becoming aware of the breach, as required by applicable law. We will also notify relevant regulatory authorities as required.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email. The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of the Service after changes constitutes acceptance of the revised policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
- Privacy inquiries: privacy@chava.codes
- General support: support@chava.codes
- Legal inquiries: legal@chava.codes