Security
Security and privacy by design
Practice conversations can be personal. This page explains the rules the platform is built on. The details are in the privacy policy, terms and data processing agreement.
Isolation
Separate workspaces
Every record belongs to a workspace. Access is checked both in the database and in the application, one never replaces the other.
Least privilege
Roles decide who can edit scenarios, see results or manage billing. Participants see only their own attempts.
No client writes to sensitive data
Scores, access and billing are changed only by the server, never directly from the browser.
Hidden scenario content
The instructions that give a counterpart its private goals and information stay on the server. They are never included in what the participant's browser receives, including in embeds and via the API.
Voice and personal data
Voice without recording
Before the first voice conversation we explain where the voice goes. We do not record it. Only the transcript used for the report is kept.
Retention you control
Transcripts are deleted after a year by default and uploaded recordings after 30 days. A team administrator can set a different period.
Not used for model training
We do not train models on your conversations. OpenAI does not use API data for training, and our voice provider does not record voice and deletes the conversation record after 30 days.
Responsible use of scores
Feedback is meant for development. The platform does not rank people and does not make hiring, promotion or other employment decisions.
Security questions
If your organization needs a security questionnaire or a data processing agreement, we will provide them before launch.