Interview Studio
Varidac Inc. · Interview Studio

Privacy Policy

Effective September 25, 2026. How Interview Studio handles your information: what stays on your computer, what passes through our server, and what we keep.

The short version

01

Who we are

Interview Studio is made by Varidac Inc., a Delaware corporation based in Pleasanton, California (“Varidac”, “we”, “us”). We are responsible for the personal information described here. You can reach us at contact@varidac.com.

This policy covers the Interview Studio website, the app at /app, and the information we receive from the checkout linked from them. The checkout itself is run by Link, Stripe's checkout service, under its own privacy policy. This policy should be read with our Terms of Service; by subscribing to or using Interview Studio you confirm that you have read it.

02

What we collect, and why

Before you subscribeWhen you tick Yes, I agree to automatic renewal on our subscribe page and continue, our server stores when you agreed and which version of the wording you saw, under a random reference that is passed to the checkout so the two can be matched. We don't store your IP address or anything else about you with it (to slow down repeated requests, a scrambled form of the IP address is counted separately and deleted within a day). If you don't complete the checkout, the record is deleted after 8 days; if you do, it becomes part of your licence record, and a note of which checkout used the reference (so the same agreement can't be attached to anyone else's purchase) is deleted after 8 days.
When you subscribeCheckout is run by Link, a Stripe company, which sells the subscription as merchant of record and collects your name, email, payment details, billing address and country under its own privacy policy. We never see your card number. When you land on our thank-you page — and, separately, when Stripe notifies our server that the checkout has completed or that your subscription has changed (for example, that you cancelled) — our server looks up your checkout or subscription at Stripe. The details Stripe returns include your name, email, billing details, whether you accepted our terms at checkout, and your subscription. We keep only your email, the checkout reference, the purchase date, whether it was a test or a real purchase, your acceptance of the terms, and your subscription id, status and renewal date (and, if you cancel, the date your access ends and when you cancelled; if it ends, when it ended) — to issue your licence key, confirm you're subscribed, keep a record of your agreement, and handle billing questions and refunds. We don't keep your name or billing address. Providing an email address and payment is necessary to subscribe; without them we can't provide the service.
Your licence recordKept on our server: the licence id; the email and checkout reference it was issued to, whether it was a test or a real purchase, the purchase date, whether you accepted our terms at checkout, when it was first issued, and the version of the Terms you agreed to; your agreement to automatic renewal (when you ticked Yes, I agree, and which version of the wording); a log of cancellations and undos made with the app's buttons (when, and the resulting end date); when we emailed you your copy of the subscription terms; your Stripe subscription id, its status, its renewal date, the date your access ends if you've cancelled (with when you cancelled, as Stripe records it, and when we first saw that cancellation), when it ended if it has (as Stripe records it), when we last checked it with Stripe, and the last time a check with Stripe got no answer; up to three random browser ids (created in your browser — a private window, another browser profile or clearing a browser's site data creates a new one); usage counters — requests per minute and per day for each feature, which expire within two days, and the value of model usage in each calendar month (UTC), for the included monthly allowance. If we switch a licence off, or after your record is deleted, we keep only the bare licence id — with no email or other contact details — so that key can't be used again.
What you put into the appRésumés, job descriptions, transcripts and notes you add, your profile, roles, tailored résumés, practice answers, scorecards and Rehearse recordings are stored in your browser's own storage on your device. We can't see them. They stay until you erase them (Settings → Erase everything) or clear your browser's site data; a browser can also clear a site's storage if the device runs very low on space, so keep an export. You can export them from Settings; voice recordings aren't included in the export.
Text sent to the AI modelWhen you use a feature that needs the model — building your profile, reading a job description, writing a résumé, a cue card, a practice interviewer's turn, a score — the app sends the text that feature needs through our server to Anthropic, which returns the response. Building your profile sends the full text of each résumé, transcript or note you added, including anything other people said in a transcript; other features send the question, what you said, and the parts of your profile or job description they need. Our server passes it through and does not store it or write it to our logs. Anthropic keeps API inputs and outputs for up to 30 days — up to 2 years if its automated safety systems flag a request (with safety classification scores kept up to 7 years), or longer where the law requires — and under its commercial terms does not use them to train its models.
Your voice, and the app's voiceLive, Practice and Rehearse use your browser's built-in speech recognition. Chrome sends the audio to Google and Edge to Microsoft to turn it into text; Safari uses Apple's speech recognition, which may send it to Apple. That processing is covered by your browser provider's privacy terms, not ours. If you switch on on-device recognition in Settings, the audio stays on your computer; if your browser can't do that, voice input doesn't start. We never receive audio. When the app speaks — a practice interviewer's question, a Rehearse prompt, or a cue card you ask it to read aloud — it uses a voice on your computer by default. If you choose an online voice in Settings (Chrome's “Google” voices or Edge's “Online” voices), or your computer has no other English voice, the words being spoken — which can include your first name and lines from your stories — are sent to Google or Microsoft. In Live mode the microphone is meant to hear only you (wear earbuds). Listen to the interviewer (off until you switch it on in a live session) turns the sound of the browser tab or screen you choose to share — the call — into text on your computer only, using your browser's on-device speech recognition; if that isn't available, the feature doesn't start. The interviewer's voice and words are not recorded, not saved, and not sent to us, to Google, Microsoft or Apple, or to the AI model: the app matches the question on your computer, and a card written by the model is based on your own stories and on a question from our own bank or a description of the kind of question — never on what the interviewer said. What was heard is discarded when the session ends. Nothing you say in a live session is saved unless you keep the scorecard, which holds scores, topics, timings and word counts, a one-line coaching note per answer, three fixes, and the role's company and title — not a transcript. A job description you paste to start a live session is saved as a role in your browser. Rehearse records your voice by default so you can play your answers back (you can switch it off before you start); the recordings stay in your browser.
Website fontsOur home page loads its typefaces from Google Fonts, so your browser sends Google your IP address, browser details and the page address when you visit it. Google's privacy policy applies. The app, the thank-you page and these policy pages load nothing from Google.
Technical logsOur hosting provider (Vercel) records request logs — IP address, browser type, time, the address requested (on the thank-you page that includes the checkout reference), the response status and any error messages — so we can run and secure the service. They are kept for up to 30 days. If the AI model provider returns an error, a short error message from it may appear in these logs; the text you sent does not. We use no analytics, advertising or tracking cookies. The app uses your browser's storage only for your licence, a random browser id, your settings and your own data.
If you email usWe keep the correspondence so we can answer you and keep a record of what was agreed (for example, a cancellation or refund).
03

How we use it

  • To provide Interview Studio: issue and check your licence, route requests to the model, and show your remaining monthly allowance.
  • To keep it working and fair: enforce the three-browser limit and rate limits, and prevent sharing, abuse and fraud.
  • To handle billing, cancellations, refunds and support, and to keep a record of your agreement to the subscription terms.
  • To send you notices about your subscription — for example, a change to the price or these terms; a copy of your subscription terms after you subscribe; and confirmations when you cancel, undo a cancellation, or your subscription ends.
  • To keep the records the law requires, such as proof of your agreement to automatic renewal.

We do not sell or rent personal information, share it for advertising, use the content you create to train AI models, build marketing profiles, or make decisions about you by automated means that have legal or similarly significant effects.

04

Who we share it with

Only the companies that run Interview Studio or its checkout, each for the purpose listed:

  • Link (a Stripe company) — sells the subscription as merchant of record; runs checkout, payment, tax, receipts and billing emails; and handles payment and refund support, as an independent company under its own privacy policy. Stripe provides the payment platform, the subscription records we look up and update (when you cancel in the app, our server tells Stripe to stop the renewal), the notifications Stripe sends our server when a checkout completes or a subscription changes, and the subscription page at /billing (its customer portal), where you sign in with your email to cancel; Stripe emails you the sign-in link. You update your card in your Link account.
  • Vercel — hosting and request logs.
  • Redis (Redis Cloud, connected through Vercel) — the database that holds licence records and usage counters.
  • Anthropic — the AI model that generates cards, scores and résumés.
  • Google — typefaces for our home page (see above).
  • Our email provider — for messages you send to contact@varidac.com and our replies.
  • Resend — delivers our service emails: the copy of your subscription terms (which includes your licence key), and confirmations when you cancel, undo a cancellation, or your subscription ends. It receives your email address and the content of those emails.

Google, Microsoft or Apple receive your voice — and, with online voices, the words the app speaks — through your browser's own speech features; that is between you and your browser provider.

No other party collects personal information about your online activities over time and across different websites through Interview Studio.

We may also disclose information if the law requires it, to protect the rights and safety of our users or ourselves, or as part of a merger or sale of the business — in which case this policy continues to apply to it, and we'll tell you.

05

How long we keep it

Licence recordWhile your subscription is active, and for three years after it ends — California law asks us to keep proof of your agreement to automatic renewal, and we need it for billing disputes and refunds. Then it is deleted automatically.
Monthly usage totalsDeleted automatically about 13 months after the month they cover.
Per-minute and per-day countersExpire automatically within two days.
Agreement given before an unfinished checkout, and the note of which checkout used an agreementDeleted automatically after 8 days.
Email send recordsA note of each service email we send — which email, for which licence or subscription (the reference can include the relevant date), when, whether it was confirmed sent or its delivery is unknown, a one-way code used to avoid sending it twice, and Resend's message id; not the content — kept about 13 months so the same email isn't sent twice.
A copy of your subscription terms that couldn't be sent yetYour licence id and checkout reference, and when it was first held back, kept until it is sent or your subscription ends, and at most 30 days.
A confirmation email that couldn't be sent at the timeWhich confirmation it is (a cancellation, an undone cancellation or the end of your subscription), your email address, licence id and subscription reference, and the relevant dates (when your access ends, or when your subscription renews), kept until it is sent, and at most 7 days.
Bare licence idKept without any contact details after a licence is switched off or its record is deleted, so that key can't be used again.
Text sent to the modelNot stored by us. Anthropic: up to 30 days (up to 2 years if flagged).
Request logsUp to 30 days.
Your data in the appIn your browser until you erase it or clear site data.
Email correspondenceAs long as needed to handle your request and keep a record of it.

Link and Stripe keep payment records under their own policies and tax law.

06

Your choices and rights

  • Export your sources, profile, roles, résumés, practice sessions, scorecards and settings to a file: Settings → Export. Voice recordings and your licence key aren't included.
  • Erase everything the app stores in your browser: Settings → Erase everything. Your licence key and browser id stay, so you can keep using the app; it doesn't affect our licence record or anything already sent to the model provider.
  • Access, correct or delete your licence record, or ask what we hold about you: email contact@varidac.com from the address you subscribed with. We'll reply within 30 days. We may keep what the law requires us to keep, such as the record of your agreement to automatic renewal.
  • Do Not Track: we don't track you across websites, and we don't let other companies do so through our site, so we treat every visitor the same whether or not a Do Not Track signal is sent.
  • California: we do not sell or share personal information as the California Consumer Privacy Act defines those terms.

If you are in the EU, the UK or Switzerland

Varidac is based in the United States, and we process your information there. We process it to perform our contract with you (providing the service you bought), for our legitimate interests (keeping the service secure and preventing abuse, and keeping proof of your agreement so we can handle billing questions, refunds and disputes), and to meet legal obligations (such as California's rules on automatic-renewal records). You have the right to access, correct, delete, restrict or object to our processing of your information, to receive it in a portable form, and to complain to your local data-protection authority. Our processors — Vercel, Redis, Anthropic and Resend — may process information in the United States and elsewhere under data-processing agreements that include the EU Standard Contractual Clauses. Link handles your payment as an independent company under its own privacy policy.

If you are in Canada

Varidac's founder is accountable for our privacy practices and can be reached at contact@varidac.com.

07

Security

Connections use HTTPS. The AI model key stays on our server and is never sent to your browser. Licence keys are cryptographically signed. We keep as little on our server as the service needs. No system is perfectly secure; if a breach affects your personal information we will notify you as the law requires.

08

Children

Interview Studio is for adults preparing for job interviews. It is not directed to anyone under 18, and you must be 18 or older to subscribe. If we learn that we hold personal information about someone under 18, we will delete it.

09

Changes to this policy

If we change this policy we'll post the new version here with a new effective date. If a change is material, we'll email subscribers before it takes effect.

10

Contact

Questions or requests: contact@varidac.com · Varidac Inc., Pleasanton, California.