Privacy Policy
This policy explains what information InterviewGym handles when you use our interview-practice and career-preparation service, how we use it, and the choices available to you.
- Effective
- July 25, 2026
- Last updated
- July 25, 2026
1. Overview
InterviewGym (“we,” “us,” or “our”) provides tools for interview practice, career preparation, profile management, and resume feedback. This policy applies to information handled through the InterviewGym website and related account features.
Questions about this policy or our data practices can be sent to contact@interviewgym.app.
2. Information you provide
Depending on the features you use, you may provide:
- your name and email address, plus authentication information handled by Supabase when you create or access an account;
- profile details such as your target role, opportunity type, and onboarding status;
- resume files and related metadata, including the original filename, file type, file size, and storage path;
- organization, cohort, membership, or invitation information when an organization feature applies to your account; and
- contact-form information: name, email, role or request type, organization or program when provided, and your message.
Passwords are handled by Supabase Auth. InterviewGym does not receive or store your Google password.
3. Google Sign-In and Google user data
When you choose Google Sign-In, InterviewGym initiates authentication through Supabase Auth using only the standard OpenID Connect identity scopes: openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile. The application does not request Google Drive, Gmail, Calendar, Contacts, or other Google API access.
These scopes allow Google and Supabase Auth to provide a Google account identifier, email address and verification status, name, and basic profile metadata such as a profile-picture URL. InterviewGym uses the email address to identify and contact the account and uses the name to create or maintain the InterviewGym profile. The application does not display or save a separate profile-table copy of the Google profile picture.
Supabase Auth processes the OAuth exchange and retains the Supabase authentication identity and session. Although Google may return provider credentials during that exchange, InterviewGym does not read, use, or separately persist Google provider access or refresh tokens. No Google API is called after sign-in.
Google identity information is used only to authenticate you, create or maintain your InterviewGym account, and display account identity information when applicable. It is processed by Google, Supabase, and the application hosting infrastructure for those purposes; we do not sell it or share it for advertising. Our use and transfer of Google user data is limited to providing the authentication and account functionality described here.
To request deletion of Google-derived account information, email contact@interviewgym.app. You may also revoke InterviewGym’s access in your Google Account permissions. Revoking Google access does not by itself delete your InterviewGym account or other information already stored with it.
4. Automatically handled technical information
When the service operates, InterviewGym and its infrastructure providers may process authentication cookies, request and error metadata, request timestamps, IP address, and browser or device information ordinarily available to hosting, security, and authentication systems. We do not currently include advertising trackers, behavioral analytics, device fingerprinting, or precise-location tracking in the application.
5. Browser storage and cookies
- Authentication cookies: Supabase session information is stored in cookies so authenticated pages and server requests can recognize your session.
- Recovery and invitation state: short-lived cookies support password-recovery isolation and pending invitation routing.
- Local storage: the recording-mode preference and current mock training progress are stored in your browser. Mock progress is keyed to the authenticated account identifier but is not synchronized to the database.
- Session storage: a pending verification email address may be held temporarily to support the check-email flow.
- Temporary media: recordings and preview URLs are held in browser memory for the active practice flow and are released during cleanup.
Browser-local information may remain until the application removes it, the session ends, or you clear site data in your browser.
6. Resumes and recordings
Resume files are stored in a private Supabase Storage bucket. A related Postgres record stores your user identifier, application-controlled storage path, original filename, MIME type, file size, and timestamps. Row-level and storage access policies restrict users to their own resume. The application supports replacing, downloading, and removing the current resume. Current resume feedback is mock or demonstration output; the service does not currently perform production AI resume analysis.
Current audio and video recording is performed in the browser. Recording blobs and object URLs stay in browser memory and are not uploaded to persistent InterviewGym storage by the current interview submission service. Current transcripts, scores, and feedback are mock or static product content rather than production transcription or AI analysis.
7. How we use information
We use information as reasonably necessary to:
- authenticate users and operate accounts and profiles;
- store, retrieve, replace, and remove resumes;
- deliver contact requests and respond to them;
- protect the application and enforce access controls;
- troubleshoot, maintain, and improve the service; and
- meet applicable legal obligations and resolve disputes.
8. Service providers
- Supabase provides authentication, Postgres data storage, row-level authorization, and private resume-file storage.
- Google provides optional Google Sign-In.
- Vercel hosts and delivers the web application and server routes.
- Resend delivers authentication email and contact-form email.
- Cloudflare provides domain and email-routing infrastructure for the public contact address.
These providers process information only in connection with the services they provide and under their own terms and privacy practices.
10. Retention
We retain account and service information for as long as reasonably necessary to provide the service, maintain accounts, protect security, resolve disputes, and satisfy legal obligations. We do not promise a fixed retention period where the repository and current operations do not establish one.
Browser-local data may remain until you clear browser storage. There is no current self-service account-deletion workflow. To request deletion, email contact@interviewgym.app.
11. Security
We use safeguards supported by the current architecture, including authenticated sessions, private resume storage, user-owned storage paths, database row-level security, and authorization checks. No method of storage or transmission can guarantee absolute security.
12. Your choices and requests
You may update current profile information in the Profile page. You may replace, download, or remove your saved resume through the available controls. Depending on where you live, you may also have rights to ask for access, correction, or deletion of personal information.
Send requests, including questions about Google user data, to contact@interviewgym.app. You can manage InterviewGym’s Google access through your Google Account permissions, but revocation alone does not delete the InterviewGym account.
13. Children’s privacy
InterviewGym has not established a separate child-directed experience or a specific age-eligibility threshold. If you believe information associated with a child has been provided to the service, or you are a parent or guardian with a question, contact us at contact@interviewgym.app.
14. Changes to this policy
We may update this policy as InterviewGym changes. When we make a material revision, we will update the “Last updated” date displayed on this page and provide additional notice when appropriate.
15. Contact
Privacy questions and requests can be sent to contact@interviewgym.app. For general questions, you may also use the Contact page.