Privacy Policy
Last updated 31 July 2026
This policy explains what personal data PracticeDepth (operated by [Your registered legal name]) collects, why, who we share it with, and the rights you have — including how to have your data deleted. We collect as little as we can to run the Service.
1. Who is responsible
The controller of your personal data is [Your registered legal name], [Street address], [Postal code, City], [Country]. For any privacy matter, contact support@practicedepth.com.
2. What we collect
- Account data — your email address, and, if you sign in with GitHub or Google, the basic profile information they share (name, email, avatar). We use email one-time codes and these providers for authentication.
- Practice data — your interview answers (typed or transcribed from voice), the questions asked, feedback, scorecards, study plans, Learn-mode history, and interview history tied to your account. Your Depth Passport (the demonstrated depth per topic and your activity record) is derived from this history when you view it; it is a reading of data you already have, not a separate profile we build about you.
- Public profile data — only if you choose to publish a Depth Passport: the handle you pick and any display name, bio and location you enter, plus the sections you switch on. This is deliberately opt-in and off by default — see section 5.
- Messages — if you use member-to-member contact, we store the messages you send and receive, who they were between, and any block or report you make. See section 6.
- Support requests — questions you put to the in-app support assistant, and emails you send us.
- CV Defense data — when you use CV Defense, we extract a minimal structured summary from your CV (headline, years, roles, skills, claims) and then discard the raw file. We do not store your original CV. Job-description text you provide is used transiently and is not stored long-term.
- Billing data — records of your credit purchases (pack, amount, date). Payments are processed by Stripe; we do not receive or store your full card number.
- Device signal — for visitors who try the product without an account, we compute a device fingerprint to allow one free taste and deter abuse. It is a hashed signal, not your identity.
- Technical data — basic logs and information your browser sends (such as approximate language for currency defaults) needed to operate and secure the Service.
3. Why we use it (legal bases)
Under the GDPR, we rely on the following legal bases:
- Performance of a contract — to create your account, run interviews, meter credits, and process purchases.
- Legitimate interests — to keep the Service secure, prevent abuse of free credits, and diagnose faults so we can improve reliability, balanced against your rights.
- Legal obligation — to keep records we are required to keep (for example, for tax on purchases).
- Consent — where we ask for it: usage analytics, publishing a public Depth Passport, opting in to be contacted by other members, and email notifications. You can withdraw any of these at any time by switching them off in the product.
4. Processors we share data with
We use trusted third-party processors to run the Service. They act on our instructions and only for the purposes below:
- Stripe — payment processing.
- Google (Gemini API) — generating and analysing interview content from your answers.
- Groq — speech-to-text transcription of your voice answers.
- Resend — sending authentication and account emails.
- Sentry — error and performance monitoring, so we can find and fix faults. Reports are processed in the European Union and contain technical diagnostics: the error, where in the code it happened, the page it happened on, and your browser and operating system. We deliberately do not send request bodies, cookies or headers, and we do not record your screen. Your CV text, your interview answers and your email address are never included.
- PostHog — product analytics, so we can see which pages and features are used and where people get stuck. Processed in the European Union. In your browser this runs only if you accept analytics, and it records the pages you visit and a few actions such as reaching your scorecard — never your answers, your CV, anything you type, or the text on the screen. We also record a small number of account milestones from our own servers, such as starting an interview or completing a purchase, identified by your account ID and never by your email address.
- Our hosting and database/cache providers — storing account and practice data, and holding live session state briefly.
Some processors may process data outside your country. Where they do, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. We do not sell your personal data.
5. Your public Depth Passport
Your Depth Passport is private by default. Nothing about your practice is visible to anyone else unless you explicitly publish it.
- You opt in, per section. Publishing requires you to choose a handle and turn it on. You control which sections appear, and your numeric depth index is hidden by default even when your profile is live.
- Public means public. A published page at
/p/your-handlecan be viewed by anyone with the link and may be indexed by search engines or cached by third parties outside our control. - You pick the handle.We only ever suggest one — we don't derive it from your name or number it, so your handle reveals nothing you didn't choose to reveal.
- Unpublishing is immediate.Switching your profile off makes the page stop resolving straight away. We can't remove copies already cached elsewhere.
6. Messages between members
If you publish a passport you may also opt in to being contacted by other members. This is a relay: messages are delivered inside the product and neither side's email address is revealed to the other.
- We store message content so we can deliver it, show your inbox, apply rate limits, and act on reports of abuse.
- If you have email notifications on, we send you a notice that you have a message — it never includes the sender's address or the full thread. You can turn notifications off at any time.
- You can block a member or report a message. We may review reported messages to enforce our Terms.
- Deleting your account deletes the messages you sent and received.
7. How long we keep it
We keep account and practice data for as long as your account is active. Live interview session state is short-lived and expires automatically within hours. Billing records are kept as long as the law requires. When you delete your data (see below), we remove it as described, except where we must keep limited records to meet a legal obligation.
8. Your rights
If you are in the EU/EEA or UK, you have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent. You also have the right to complain to a supervisory authority. To exercise any of these, email support@practicedepth.com.
9. Deleting your data (GDPR erasure)
You have the right to erasure(“the right to be forgotten”). Here is exactly how it works with PracticeDepth:
- In-product — delete your CV data. Go to Settings → Data & privacy and choose “Delete CV data”. This immediately and permanently removes your extracted CV profile, your CV Defense history, and any study plans generated from CV Defense, from our database.
- Full account & data deletion — in the product. Go to Settings → Data & privacy and choose “Delete account”. We email a confirmation link to the address on your account; opening that link deletes everything immediately. Nothing is deleted until you open it, and the link expires after 24 hours. You can also email support@practicedepth.com from your account address if you'd rather we do it for you.
- What we delete. Your account and authentication records, credit balance, interview and defense history, study plans, Learn history, any extracted CV profile, your public passport and handle (the page stops resolving), and the messages you sent and received. Live session state expires on its own within hours.
- Taking your profile offline without deleting.If you only want your public page gone, you don't need to delete your account — unpublish it in the product and it stops resolving immediately.
- One thing we keep on purpose. To stop the free signup credits being farmed by deleting and re-registering, we keep a one-way cryptographic hash of your email address (and, if we had one, your device fingerprint) for 30 days, recording only that a free grant was issued. A hash can't be turned back into your address, it isn't linked to any of your practice data, and it never identifies you to anyone. After 30 days it stops counting, and signing up again works normally — with credits.
- What we may retain.Your purchase records are deleted from our database along with everything else, but our payment processor (Stripe) independently keeps the transaction and receipt for it as long as tax and accounting law requires — we can't erase that, and neither can you. We may also keep anonymised or aggregated data that can no longer identify you. Backups are purged on their normal rotation.
- How long it takes. Deletion in the product is immediate once you open the confirmation link. If you email us instead, we verify the request and delete without undue delay — normally within 30 days— and confirm by email when it's done.
Deletion is permanent and cannot be undone. Any unused credits — including paid ones — are forfeited, so spend them or contact us first if that matters to you.
10. Security
We use appropriate technical and organisational measures to protect your data — keys and secrets are server-side only and never exposed to the browser, payments go through Stripe, and access is limited to what's needed to run the Service. No system is perfectly secure, but we work to keep the risk low.
11. Children
PracticeDepth is not directed at children under 16. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes
We may update this policy. When we make a material change, we'll update the date above and, where appropriate, notify you. Questions? See our contact page.