Privacy Notice
Beta • Version 2026-08-13.v1
This notice describes what UmberRook does with your data. It is written in plain language for a beta product and is deliberately specific: where we say we do not keep something, we mean there is no code that keeps it.
This is a beta. We are not claiming certification under any privacy framework, and we are not claiming compliance with the law of every country we might be reachable from. We have tried to build something honest and minimal, and to describe it accurately. If something here matters to you and is not clear enough, ask us before you use the product.
Your voice, and what happens to it
Your microphone audio is sent to OpenAI and converted to text so your answers can be transcribed. The microphone is open only while you are answering a question.
We do not store your audio. It is transcribed as you speak and the recording is never saved to our systems — only the text of your answers is kept. Your speech is streamed to OpenAI for transcription while you answer, and what comes back is text. There is no recording in our storage, no audio file attached to your session, and nothing for us to play back — because it was never saved.
We never ask for your camera. The interview is one-way video: you see the examiner, the examiner does not see you.
Your microphone is open only while you are answering a question. It is muted while the examiner is speaking, so what you say between questions is not captured.
What we store
- Your account — email address, and a display name if you set one.
- The text of your answers — the transcript of what you said, attached to the question you were asked.
- Your practice feedback — the estimated band commentary generated after a session ends.
- Your session history — when a session ran, how long it lasted, which questions it used, and whether it completed.
- Billing records — your credit balance and its history, and a Stripe customer reference. We never see or store your card details.
- Which notices you agreed to — the type, the version, the language you read it in, and when. We do not store your IP address against your consent, or anywhere else.
- Operational records— that a session started, how long the examiner’s video took to appear, whether a step failed. These hold no interview content: no audio, no transcripts, no feedback, no question text.
How long we keep it
We keep the text of your answers, your practice feedback and your session history for as long as your account exists. Operational records of how the software behaved are deleted automatically after 30 days. Billing records are kept as long as the law requires.
To be precise about the part that is automatic: operational records delete themselves after 30 days, on a schedule that runs every fifteen minutes. The rest — your answers, your feedback, your session history — stays until your account is deleted. We are not pretending it expires on its own.
Who processes your data
These are the companies that handle data on our instructions in order for the product to work. We do not sell your personal information, and we do not share it with advertisers or data brokers.
- LiveAvatar— renders the examiner’s video and lip-sync. It receives pre-generated examiner audio. It does not receive your microphone audio, your answers, or anything you say.
- OpenAI — transcribes your speech to text while you answer, and generates your practice feedback from the transcript afterwards. Your audio passes through OpenAI for transcription; we do not permit it to be used to train models.
- Supabase — our database, file storage and sign-in. Your account, transcripts, feedback and history live here.
- Stripe — payments. Card details go to Stripe directly and never reach our servers; we store only a customer reference.
- Vercel — hosting. Serves the application and processes requests.
- Sentry — technical error monitoring, so we can find crashes. It is configured to receive error types and stack traces only: no request bodies, no transcripts, no answers, no question text, no email addresses, and IP collection is turned off.
Getting your data, or having it deleted
You can download everything we hold about you at any time from your account. To have your account and practice history deleted, email us and we will do it.
The export is immediate and includes everything: your account details, every consent you gave, every session with its questions and your answers, your feedback, and your credit history.
Deletion is by request rather than a button, and we would rather say that plainly than offer a control that does not yet work. Email us and we will delete your account and practice history. Billing records that we are legally required to keep are the one exception, and they are retained without your interview content.
Contact: [email protected]. Write to this address for a deletion request, a question about this notice, or anything else about your data.
Changes
If we change what we collect, who processes it, or how long we keep it, we update the version at the top of this page and ask you to read it again before your next session. The version you agreed to is recorded against your account, so what you accepted stays answerable.