Privacy Policy
Draft for legal review. This text has not been reviewed by a lawyer yet, and it will change before Think Aloud opens beyond invited testers.
Who we are
Think Aloud runs mock system-design interviews with an AI interviewer, at app.thinkaloud.dev. It is run by [the operator's legal name and address, to be added at legal review] ("the operator", "we"). Write to [contact email, to be added at legal review] about anything in this policy.
What we keep
Your Account: your email, the Level you picked, the consent version you agreed to and when, when you were invited and last used the app, the minutes you were given and used, and each time you opened Buy minutes.
Signing in: the six-digit code we email you, stored only as a hash and valid for 10 minutes, and a cookie that keeps your browser signed in. We store the cookie's value only as a hash. A sign-in lasts 30 days from your last visit, and a year at most.
Your sessions: the interview, its length and Level; what you say, as a transcript; what you draw and write on the Canvas; what the interviewer and the coach say; how and when the session ended; and its Report.
Your voice goes from your browser straight to OpenAI while the session runs, so the interviewer can hear you. We do not record or keep any audio ourselves.
The Waitlist: the email you leave on the landing page, when you left it and which form it came from.
Your browser keeps your theme and the microphone you picked in its local storage. They are never sent to us. The app loads no analytics or advertising scripts.
Why
To run the interview: the interviewer hears you and reads a text description of your Canvas, and the app follows where the interview has got to.
To write your Report after the session, from its transcript and Canvas.
To sign you in, to count your minutes, and to email you your sign-in codes, your invitation and when a Report is ready.
To fix problems: the operator can read a session and its Report to find out what went wrong. Otherwise only you can open your sessions and Reports.
Who processes it
Cloudflare hosts the app. It stores everything above (your Account, your sessions, their transcripts, Canvases and Reports), sends our email, and keeps logs of the requests the app serves.
OpenAI runs the interviewer. While the session runs it receives your voice, the transcript and a text description of your Canvas, and it reads parts of the transcript to pick out the figures you say. After the session it reads the transcript and the Canvas to help write your Report.
TypeSafe reads the transcript and a text description of your Canvas while the session runs, so the app can follow the interview. After the session it reads them again to help write your Report.
These companies may process your data outside your country. No one else receives it, and we do not sell it.
How long
Your Account, your sessions and their Reports stay until you ask us to delete them.
We ask OpenAI to store each voice session, so a session can resume after a dropped connection, and to keep the requests that read your transcript for figures or write your Report in its logs, so the operator can look into a problem. What OpenAI and TypeSafe keep, and for how long, is set by their own terms.
Your choices
Write to [contact email, to be added at legal review] to ask what we hold about you, or to delete it. Deleting removes your Account, your sessions and their Reports. It does not reach what OpenAI and TypeSafe keep under their own terms, the request logs Cloudflare keeps, or a Waitlist entry.
Changes
When this policy changes in a way that matters, the app shows you what changed and asks you to agree again before your next session.