Last updated: 2026-07-13
Privacy Policy
SpeakUp SD is a system design interview practice product. This policy explains the data we collect, why we collect it, and how users can export or delete their data.
Data We Collect
- Account data such as email address, authentication identifiers, selected level, target company, interview date, plan tier, and credits balance.
- Practice data such as selected questions, transcripts, evaluation scores, AI feedback, whiteboard snapshots, progress history, and feedback usefulness ratings.
- Audio recordings submitted for practice evaluation. Audio is used for transcription, pronunciation analysis, voice metrics, and scoring. Open Practice audio is not submitted to our servers and is used only on the user's device.
- Technical data such as device, browser, crash diagnostics, request identifiers, and privacy-safe support codes.
How We Use Data
We use data to authenticate users, provide practice sessions, generate AI coaching feedback, track progress, manage credits, process payments, protect the service from abuse, and respond to support or privacy requests.
Audio, Transcript, and Whiteboard Retention
If the first speech-to-text result is low confidence, the same audio may be sent once to a configured secondary speech-to-text provider. This retry does not use speaking speed or accent as a rejection signal. Audio is deleted after successful or failed processing. Interrupted transient jobs may retain encrypted audio for cleanup or retry, but never longer than 24 hours. Transcripts, scores, feedback, and whiteboard evidence may be retained as part of the user's practice history unless the user deletes the account.
Third-Party Providers
We use Supabase for authentication, database, and storage; Groq for primary speech-to-text when configured; OpenAI for speech-to-text and conditional secondary transcription of low-confidence audio when configured; other configured AI providers for coaching; PayPal for enabled Web payments; Apple and Google for native purchases; RevenueCat for native purchase verification and restoration; and configured observability, crash-reporting, or analytics providers for reliability and support. Data may be processed in countries other than the user's country of residence. Each provider processes only the data needed for its role under its own terms and security practices.
Export and Deletion
Users can export their account data from Settings. Users can delete their account from Settings or by visiting the account deletion page. Account deletion removes user-owned practice data from the application database and, where configured, requests deletion of linked authentication and observability records. Some payment, security, abuse-prevention, or legal records may be retained where required for compliance, dispute handling, fraud prevention, accounting, or store-platform obligations.
Support and Privacy Requests
For privacy, correction, deletion, grievance, or support requests, use the published support page. If you cannot sign in, use the support page and include the account email, platform, app version, and approximate request time. Do not send API keys, passwords, bearer tokens, raw audio, or full transcripts in support messages.