Words used on this page, in plain English
- Controller (in India: data fiduciary)
- The company that decides how your data is used and is responsible for it. For Prepvo, that is us.
- Processor
- A company that handles data for us, only on our instructions and under a contract (for example our hosting provider).
- Subprocessor
- A company that one of our providers uses to help them. The same data-protection rules apply to it.
- Lawful basis
- The legal reason that allows us to use your data, for example because you signed up for the service or because you said yes.
- Legitimate interests
- A lawful basis that means we have a fair, expected reason to use data, weighed against your rights. You can object.
- Merchant of record
- The payment company that sells the plan to you on our behalf. It takes the payment, handles tax and receipts, and its name appears on your bank statement.
- GDPR and UK GDPR
- The data-protection laws of the European Union and the United Kingdom.
- DPDP Act
- India's data-protection law, the Digital Personal Data Protection Act, 2023.
About this page
This policy explains how [Legal entity name], trading as Mithila Labs ("Mithila Labs", "we", "us"), collects and uses personal data when you use our website and Prepvo (the "service"). We are the controller of your personal data (in India, the data fiduciary).
Contact: [privacy@your-domain] · [Registered address]. Grievance Officer (India): grievance@[your-domain].
Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, name (optional), login details, country you are applying in | You |
| Career content | Resumes you upload, job descriptions or links, answers to our follow-up questions, generated resumes and cover letters | You; generated by the service |
| Voice data | Your speech during a mock interview, processed live | You (with consent) |
| Session data | Transcripts, feedback reports, round and difficulty settings, minutes used | Generated by the service |
| Purchase data | Plan, price, currency, billing country, purchase and refund status. We do not receive your full card number. | Our merchant of record |
| Support data | Messages you send us and our replies | You |
| Technical data | IP address, device and browser type, approximate location from IP or timezone (used to show local-currency prices), logs and error reports | Your device |
| Waitlist data | Email address you give us for launch updates | You |
Sensitive information. We do not ask for sensitive data (such as health, religion, ethnicity, sexual orientation or political views). Please leave it out of your resume and answers. If you include it, we process it only to provide the service at your request, and you can delete it any time. Some countries' resume conventions include a photo or date of birth; these are optional.
Other people's data. Resumes can mention referees or colleagues. Only include other people's details if you have their permission.
How we use it and lawful bases
Under the EU GDPR and UK GDPR we rely on these lawful bases:
| Purpose | Lawful basis |
|---|---|
| Creating your account and providing the service (tailoring resumes, cover letters, interviews, feedback) | Performance of a contract |
| Processing your voice to run live interviews | Your consent, given before your first interview; you can withdraw it any time (voice features then stop working) |
| Payments, invoices, tax and accounting records | Contract; legal obligation |
| Showing prices in your local currency | Legitimate interests (showing relevant prices); no profile is built |
| Security, fraud and abuse prevention, enforcing our Terms, debugging | Legitimate interests |
| Improving the service using aggregated, de-identified usage statistics | Legitimate interests |
| Analytics cookies or similar technologies | Consent (cookie banner) |
| Service emails (receipts, renewal reminders, important changes) | Contract; legal obligation |
| Product news and waitlist updates | Consent; unsubscribe any time |
| Handling legal claims and requests from authorities | Legal obligation; legitimate interests |
Where we rely on legitimate interests, you can object (see Your rights). We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. Keyword scores and interview feedback are practice aids for you only; we do not share them with employers.
Voice and recordings
- Before your first voice interview we ask for your consent and your browser asks for microphone permission.
- Your speech is streamed to speech and AI providers to be transcribed and answered in real time.
- Session recordings are stored in your account (audio for voice sessions, video for video sessions) so you can watch or listen again. You can delete any session, including its recording, whenever you like.
- The text transcript and feedback report are saved to your account so you can review them. Delete them any time.
- We do not use your voice to create a voiceprint, identify you biometrically or clone your voice.
- No person listens to interviews live. Staff may view a transcript only if you ask for support or report a problem, or if needed to investigate abuse or meet a legal obligation.
- Your camera is only used if you choose a video session, and only while it runs. The video is streamed live to a third-party AI video provider acting as our processor so the AI interviewer can respond. The recording is kept in your account for replay until you delete it, and we don't use it for face recognition. You can turn the camera off at any time.
AI processing
To generate text and run interviews we send the relevant content (for example your resume, the job description, your answers) to AI, speech recognition and voice providers acting as our processors. They process it only to provide the service to us, under written contracts. We do not sell your data. We do not allow our providers to use your content to train their AI, and we do not use your content to train our own models without your separate opt-in consent.
International transfers
We are based in India. Our providers may process data in India, the United States, the European Economic Area, the United Kingdom and other countries. When we transfer personal data from the EEA, UK or Switzerland to a country without an adequacy decision, we use safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, plus supplementary measures where needed. For transfers out of India we follow the Digital Personal Data Protection Act, 2023 and any restrictions notified under it. Ask us for a copy of the relevant safeguards.
How long we keep it
| Data | Retention |
|---|---|
| Session recordings (audio and video) | Until you delete the session or close your account |
| Resumes, cover letters, transcripts, feedback reports | Until you delete them or close your account |
| Account data | While your account is open; deleted within 30 days of account closure |
| Inactive accounts | We may delete accounts with no sign-in for 24 months, after an email warning |
| Backups | Deleted data is removed from rolling backups within 35 days |
| Purchase and tax records | As long as tax and accounting law requires (typically 8 years) |
| Support messages | 24 months after the conversation closes |
| Security logs | 90 days, longer if needed to investigate an incident |
| Waitlist emails | Until launch plus 6 months, or until you unsubscribe |
Your rights
Depending on where you live, you have some or all of these rights:
- Access a copy of your personal data, and portability (a machine-readable export).
- Correction of inaccurate or incomplete data.
- Deletion (erasure) of your data.
- Restriction of, or objection to, processing, including processing based on legitimate interests and any direct marketing.
- Withdraw consent any time (for example voice processing or analytics), without affecting earlier processing.
- Not to be subject to solely automated decisions with significant effects (we don't make any).
- Complain to a data-protection authority (see Region-specific information).
How to exercise them: most actions (export, edit, delete) are in your account settings. Otherwise email [privacy@your-domain] from your account email. We may need to verify your identity. We reply within one month (GDPR/UK GDPR), 45 days (California) or the time the applicable law sets, and may extend where the law allows, telling you why. Requests are free unless manifestly unfounded or excessive. We will not discriminate against you for using your rights. You may use an authorised agent where the law allows.
Deleting your data
- Delete items: remove any resume, cover letter, transcript or report from your account; it is deleted from our live systems straight away.
- Delete your account: Account settings > Delete account. This cancels any renewal and deletes your content within 30 days, and from backups within 35 days after that.
- By email: write to [privacy@your-domain] with the subject "Deletion request" from your account email (or tell us the email you used). We confirm when it's done.
We keep only what the law requires us to keep (for example purchase and tax records), and we tell you what we keep and why.
Cookies and similar technologies
| Type | Purpose | Consent needed? |
|---|---|---|
| Strictly necessary (cookies and local storage) | Sign-in, security, remembering your cookie choice and selected currency | No |
| Analytics | A privacy-friendly analytics service counts visits and popular pages in total, only if you allow it | Yes, via the cookie banner |
| Advertising | None on this site | Would need consent |
You can change your choice at any time with the "Cookie settings" link in the footer, and you can clear or block cookies in your browser. We honour Global Privacy Control signals where the law requires.
Children
The service is only for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, contact [privacy@your-domain] and we will delete it.
Security
We use encryption in transit (HTTPS), encryption of stored data, access controls with least-privilege access for staff, and reputable providers. No system is perfectly secure. If a personal data breach is likely to put you at risk, we will notify you and the relevant authorities as the law requires (for example within 72 hours to the supervisory authority under GDPR, and to the Data Protection Board of India under the DPDP Act).
Region-specific information
EEA and UK
You can complain to your local supervisory authority, for example your EU member state's data-protection authority or the UK Information Commissioner's Office (ICO). We'd appreciate the chance to help first at [privacy@your-domain].
California (CCPA/CPRA)
In the last 12 months we collected the categories listed in section 1 (identifiers, commercial information, internet activity, audio information, professional or employment-related information, and inferences limited to practice feedback) for the purposes in section 2, and disclosed them to the service-provider categories in section 5. We do not sell or share personal information and do not use sensitive personal information to infer characteristics about you. You have the right to know, delete, correct and opt out of sale/sharing, and not to be discriminated against for exercising these rights.
Australia
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988. Overseas recipients are described in sections 5 and 6. You can access or correct your information and complain to us; if you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC).
India (DPDP Act, 2023)
We process your digital personal data based on your consent or for legitimate uses permitted by the Act. You have the right to access information about processing, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise your rights in case of death or incapacity. Contact our Grievance Officer at [grievance@your-domain]; if unresolved, you can approach the Data Protection Board of India.
Canada
We follow PIPEDA principles. You may contact the Office of the Privacy Commissioner of Canada.
Changes and contact
We will post updates here with a new date and tell you by email or in the app before significant changes take effect. Questions or requests: [privacy@your-domain], or write to [Legal entity name], [Registered address].