Skip to content

Security

Security and privacy by design

Practice conversations can be personal. This page explains the rules the platform is built on. The details are in the privacy policy, terms and data processing agreement.

Isolation

  • Separate workspaces

    Every record belongs to a workspace. Access is checked both in the database and in the application, one never replaces the other.

  • Least privilege

    Roles decide who can edit scenarios, see results or manage billing. Participants see only their own attempts.

  • No client writes to sensitive data

    Scores, access and billing are changed only by the server, never directly from the browser.

Hidden scenario content

The instructions that give a counterpart its private goals and information stay on the server. They are never included in what the participant's browser receives, including in embeds and via the API.

Voice and personal data

  • Voice without recording

    Before the first voice conversation we explain where the voice goes. We do not record it. Only the transcript used for the report is kept.

  • Retention you control

    Transcripts are deleted after a year by default and uploaded recordings after 30 days. A team administrator can set a different period.

  • Not used for model training

    We do not train models on your conversations. OpenAI does not use API data for training, and our voice provider does not record voice and deletes the conversation record after 30 days.

Responsible use of scores

Feedback is meant for development. The platform does not rank people and does not make hiring, promotion or other employment decisions.

Security questions

If your organization needs a security questionnaire or a data processing agreement, we will provide them before launch.