Back to Home
Legal

Privacy Policy

Your privacy matters. Here's how we handle your data with care and transparency.

Effective: June 22, 2026Last Updated: June 22, 2026

No Data Sales

We never sell your personal information

Encrypted

All data encrypted in transit and at rest

You Control It

Delete your data anytime, no questions

1. Introduction

Welcome to Plyphr ("we," "us," "our," or the "Company"), a service operated by León Allende. We operate the web application available at plyphr.vercel.app (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.

By accessing or using Plyphr, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account and use our Service, we collect the following categories of information:

  • Account Information: Name, email address, and encrypted password.
  • Profile and Career Data: Resume/CV content, professional skills, work experience, education history, and career goals that you input into the platform.
  • Interview Data: Company names, job descriptions, role details, and interview-specific information you provide for coaching sessions.
  • AI Interaction Data: Your responses during mock interviews, practice sessions, and any text or voice inputs during coaching exercises.
  • Feedback Data: Ratings, thumbs up/down feedback, and any comments you provide about the Service's outputs.
  • Payment Information: When you subscribe to a paid plan, payment processing is handled entirely by Paddle.com (Paddle.com Inc.), our Merchant of Record. We do not store your credit card number, CVV, or full billing details on our servers. We only receive confirmation of your subscription status and a truncated card identifier for your reference. Paddle's handling of your payment data is governed by its own buyer terms.

2.2 Information Collected Automatically

When you access the Service, we automatically collect:

  • Usage Data: Pages visited, features used, session duration, and interaction patterns within the application.
  • Device and Technical Data: Browser type, operating system, IP address, device identifiers, and general location (country/region level only).
  • Log Data: Server logs including access times, error logs, and API request metadata.

2.3 Information Generated by the Service

Our AI systems generate the following data based on your inputs:

  • Intelligence reports, battle plans, predicted interview questions, and personalized answers.
  • CV rewrites, LinkedIn optimization suggestions, follow-up email drafts, and salary negotiation guidance.
  • Performance scores, speech analytics, and debrief summaries from practice sessions.

2.4 Camera, Microphone & Biometric Data (Live Sessions)

During a live interview session, and only with your consent, Plyphr accesses your device's camera and microphone to provide real-time, voice- and video-based coaching:

  • Facial analysis (on your device): We analyze facial landmarks and geometry on your device using Google MediaPipe to generate delivery feedback (such as engagement and expression cues). This analysis runs locally in your browser. We do not create, store, or use a facial template ("faceprint") to identify you, and raw video is not uploaded to or stored on our servers.
  • Voice & audio: Your microphone audio is processed in real time to produce a speech-to-text transcript and delivery analytics (pace, filler words, pauses). Depending on your session configuration, transcription is performed in your browser or by our speech-processing provider. We do not create a voiceprint to identify you, and we do not retain raw audio after the session ends. The resulting transcript and computed metrics are saved to your session history.

Facial-geometry and voice data can be considered "biometric" or "sensitive" information under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington law (RCW 19.375 and the My Health My Data Act), and the CCPA/CPRA. We treat this data as sensitive: we obtain your affirmative, opt-in consent before the camera or microphone is activated; we use it only to deliver the interview-coaching service you requested; we never sell, lease, trade, or otherwise profit from it; and you can withdraw consent and request deletion at any time. These outputs are communication and delivery feedback — they are not medical, mental-health, or emotional-state diagnoses.

Retention & deletion. On-device facial analysis is ephemeral and is not stored. Session transcripts and delivery metrics are retained as part of your account data and are deleted when you delete the related session or your account. In any event, any biometric-related data is destroyed when the purpose for which it was collected is satisfied or within one year of your last interaction, whichever is first (see Section 7 for our retention schedule).

3. How We Use Your Information

  • Service Delivery: To provide AI-powered Plyphr coaching, generate personalized content, and deliver the core features of the platform.
  • AI Processing: To send relevant portions of your data to our AI providers (Anthropic Claude API, OpenAI Embeddings API) strictly for generating coaching outputs. These providers process data according to their enterprise API terms and do not use your data to train their models.
  • Service Improvement: To analyze aggregated, anonymized usage patterns to improve our algorithms, features, and user experience.
  • Account Management: To manage your account, authenticate your identity, and communicate with you about your account or the Service.
  • Security: To detect, prevent, and address fraud, abuse, security incidents, and technical issues.
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes.

4. Data Minimization

We follow the principle of data minimization — we only collect and process the minimum amount of personal data necessary to provide the Service. Specifically:

  • We only send to AI providers the specific portions of your data relevant to the current coaching task, not your entire profile.
  • We do not collect demographic data beyond what is needed for account creation.
  • Temporary processing data (e.g., intermediate AI outputs) is discarded after the final result is delivered to you.

5. We Do NOT Share Your Personal Data

Plyphr does not sell, rent, trade, or otherwise share your personal information with third parties for their own purposes.

  • We do not sell your data to advertisers, data brokers, or any third party.
  • We do not share your data with marketing companies.
  • We do not allow third parties to access your personal data for their independent use.
  • We do not use your data for targeted advertising by third parties.

5.1 Limited Service Providers

We use the following service providers strictly to operate the Service. These providers act as data processors under our instruction and are contractually obligated to protect your data:

ProviderPurposeData Processed
Anthropic (Claude API)AI-powered coaching generationRelevant portions of profile and interview data
OpenAI (Embeddings API)Semantic search and content matchingText snippets for embedding generation
SupabaseDatabase hosting and authenticationAccount and application data
VercelApplication hosting and deliveryTechnical/request data
Paddle.com (Merchant of Record)Payment processing, billing & refundsPayment and subscription data
Speech-processing providerReal-time speech-to-text during live sessionsSession audio (transient; not retained)

These providers only process data as necessary to provide their services to us and are prohibited from using your data for any other purpose.

6. Data Storage and Security

6.1 Storage

Your data is stored on secure servers provided by Supabase (AWS infrastructure). All data is stored in encrypted databases with access controls.

6.2 Security Measures

We implement industry-standard security measures including:

  • Encryption of passwords using bcrypt hashing.
  • HTTPS/TLS encryption for all data in transit.
  • Rate limiting to prevent abuse (30 requests per minute).
  • Input validation and sanitization at all system boundaries.
  • Access controls and authentication for all API endpoints.
  • Regular security reviews and monitoring.
  • Automatic session expiration after periods of inactivity.

6.3 Security Limitations

While we take commercially reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information. In the event of a data breach that affects your personal data, we will notify you and the relevant authorities as required by applicable law.

7. Data Retention

  • Account Data: We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except as required by law.
  • AI-Generated Content: Plyphr coaching outputs are retained as part of your account data and are deleted when you delete your account.
  • Live Session Media & Biometric Data: On-device facial analysis is ephemeral and is never stored; raw audio is not retained after a session. Session transcripts and delivery metrics are deleted with the related session or your account, and any biometric-related data is destroyed when its purpose is satisfied or within one year of your last interaction, whichever is first.
  • Usage Logs: Anonymized usage and technical logs may be retained for up to 12 months for security and service improvement purposes.
  • Payment Records: Transaction records are retained as required by financial regulations (typically up to 7 years), even after account deletion.

8. Your Rights

8.1 General Rights (All Users)

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated personal data.
  • Data Export: Request a portable copy of your data in a commonly used format (JSON or CSV).

8.2 European Economic Area (EEA) / UK Residents — GDPR

If you are located in the EEA or UK, you additionally have the right to:

  • Restrict or object to certain processing of your data.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data protection authority.
  • Request information about automated decision-making processes that affect you.

Legal Basis for Processing: We process your data based on: (a) performance of a contract (providing the Service), (b) legitimate interests (security, service improvement), and (c) your consent where applicable.

8.3 California Residents — CCPA/CPRA

If you are a California resident, you have the right to:

  • Know / Access: the categories and specific pieces of personal information we collect, the sources, the purposes, and the categories of third parties with whom we share it.
  • Delete: request deletion of your personal information.
  • Correct: request correction of inaccurate personal information.
  • Opt out of the sale or sharing of personal information — including honoring the Global Privacy Control (GPC) browser signal.
  • Limit the use and disclosure of sensitive personal information (SPI).
  • Non-discrimination for exercising your privacy rights.

Sensitive personal information (SPI): CCPA/CPRA treats biometric information processed to identify a consumer as SPI. As described in Section 2.4, our facial-landmark analysis runs on your device and is not used to identify you, and we do not create a faceprint or voiceprint. We use any sensitive information solely to deliver the interview-coaching service you requested — a permitted business purpose — and not for advertising, profiling, or other secondary purposes.

We do not sell or share your personal information (including biometric or sensitive information) for money or for cross-context behavioral advertising. Because we do not sell or share, and because we use sensitive information only for the permitted purpose of providing the Service, no "Do Not Sell or Share" or "Limit the Use of My Sensitive Personal Information" action is required — but you may still exercise any of the rights above by contacting us.

8.4 How to Exercise Your Rights

To exercise any of these rights, contact us at: plyphr.chile@gmail.com

We will respond to verified requests within 30 days (or within the timeframe required by applicable law).

9. Cookies and Tracking Technologies

We use the following cookies and similar technologies:

  • Essential Cookies: Required for authentication and basic functionality (session tokens, CSRF protection).
  • Functional Cookies: To remember your preferences and settings within the application.

We do not use third-party advertising cookies or cross-site tracking technologies.

Do Not Track Signals

Our Service respects "Do Not Track" (DNT) browser signals. Since we do not engage in cross-site tracking, no additional action is taken when a DNT signal is detected.

10. Children's Privacy

Plyphr is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us immediately.

11. International Data Transfers

Your data may be processed in the United States (where our servers are located). If you are located outside the United States, by using the Service you consent to the transfer of your data to the United States. We ensure appropriate safeguards are in place for international data transfers as required by applicable law, including Standard Contractual Clauses (SCCs) where required by GDPR.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website with a new "Last Updated" date.
  • Sending an email notification to the address associated with your account (for material changes).

Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

This Privacy Policy is provided for informational purposes. For specific legal advice, consult a qualified attorney in your jurisdiction.