How AI Interview Gym Handles Your Data
Last updated: September 19, 2026
| Data | Where it goes | Why | Current storage |
|---|---|---|---|
| Onboarding answers | Your browser | Personalize your path | Browser local storage |
| Email you submit | AI Interview Gym server | Access/lead administration and requested updates | Server-side access/lead records |
| Social sign-in identity | Your chosen provider + AI Interview Gym server | Create/find your account and restore eligible access | Provider name, provider-specific subject ID, and provider-returned email/name/avatar or verification signal where supplied |
| Account session | Your browser + AI Interview Gym server | Keep you signed in | Opaque HttpOnly cookie in your browser; SHA-256 hash, account ID, and session timestamps on the server |
| Raw résumé file | AI Interview Gym server | Temporary parsing/extraction | Intended to remain in memory only |
| Extracted résumé facts | Returned to your browser | Risk Map and personalized practice | Browser only if you choose to save |
| Recorded practice audio | Your browser for AI Interview Gym | Playback/rehearsal | Not intentionally uploaded to our server |
| Browser transcript | Your browser / browser speech service | Speech analytics | Attempt history may be stored locally |
| Strict Simulation camera frames | Your browser / MediaPipe visual-analysis runtime | Face-presence and visual-attention coaching | Not intentionally uploaded to or stored by the AI Interview Gym server |
| Strict Simulation summary | Your browser | Review environment discipline, timing, and visual-attention coaching signals | Browser local storage; raw camera frames are not included |
| Optional Account Sync telemetry | AI Interview Gym PostgreSQL after explicit opt-in | Merge paid training progress across signed-in devices | Question ratings/attempt counters, delivery metrics, and Strict Simulation summary metrics; excludes résumé data, target-workspace snapshots, transcripts, raw audio, and raw video |
| Human Review submission | AI Interview Gym server + authorized human reviewer | Provide the Mastery Human Review service | Submitted response/transcript, optional context/session summary, review status/timestamps, written feedback, and exact pointers |
| Affiliate referral identifier | Your browser → AI Interview Gym checkout → Lemon Squeezy | Preserve approved referral attribution and, when enabled, the referral promotion | Short-lived first-party HttpOnly cookie for up to 30 days; affiliate/referral records are administered by Lemon Squeezy |
| Payment credentials | Lemon Squeezy | Checkout and payment processing | Not stored by AI Interview Gym |
| Order recovery data | AI Interview Gym server | Grant, restore, revoke, or account-link paid access | Purchase email, Order #/identifier mapping, variant, entitlement/account link, and status |
| Outcome survey | AI Interview Gym server | Aggregate efficacy analysis | Hashed anonymous browser ID, reported outcome, practice counts, optional comments |
Before uploading a résumé
Remove information not needed for interview preparation, such as full street address, personal identification numbers, banking details, passwords, or unrelated reference contact information.
Résumé consent control
Resume Lab requires an acknowledgment before analysis. The server also requires a matching privacy-acknowledgment header for résumé-processing requests.
No model-training claim
AI Interview Gym does not currently send Resume Lab uploads to an external AI/LLM API. If that architecture changes, the privacy notice and this page should be updated before the change is available to users.
Human Review
Human Review is deliberately human-delivered. When a Mastery customer submits a response, an authorized reviewer can read that submitted content and any optional focus notes or session-summary data sent with it. The reviewer’s feedback is stored with the request so it can be shown back to the matching purchase session. One review is available per verified Mastery purchase.
Outcome survey privacy
The outcome survey is optional and does not require your email. The random browser ID is hashed on the server before storage. Survey data is intended for aggregate product evaluation, not for identifying candidates.
Social sign-in
Social login requests only identity-oriented permissions needed for authentication. AI Interview Gym does not intentionally persist social-provider access or refresh tokens after login. The provider-specific subject identifier is used as the durable external identity key; display names are never used as an account-linking key.
Strict Simulation and visual analysis
Strict Simulation requests camera and microphone access only after you start its system check. Camera frames are processed in the browser for coaching signals such as face presence, multiple-face detection, head position, and sustained visual-attention drift. The current implementation loads MediaPipe Face Landmarker code/model assets from third-party hosting. MediaPipe's package documentation states that usage or performance metrics may be sent to Google. AI Interview Gym does not intentionally upload raw simulation video to its own server and does not use these signals for biometric identification or to declare that a user cheated.
Browser data and cross-device access
You can remove browser-stored Resume Lab plans, onboarding choices, progress, attempt history, and Strict Simulation summaries by using product reset tools or clearing site data in your browser. Account login can restore account-linked access on another device. For active paid accounts, Account Sync is optional and off by default; after explicit opt-in it can merge question progress, delivery metrics, and Strict Simulation summaries across signed-in devices. Résumé Lab facts/plans and Mastery target-workspace snapshots remain browser-local in the current version. Turning sync off stops future transfers while retaining the existing cloud copy; the Account Sync control also provides a separate delete-cloud-data action.