aurate

Privacy Policy

Last updated: 17 June 2026

1. Who We Are

aurate is a trading name of AURATE AI LTD, a company registered in England and Wales (Company No. 17131159), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Throughout this policy, "aurate", "we" and "us" refer to AURATE AI LTD.

We are the data controller for your personal data.

Contact for data protection queries: hello@aurateai.com

ICO Registration: ZC109790

2. Privacy-First Design

aurate is designed to keep your personal data tight to what's actually needed to run the service. We don't record audio. We don't sell your data. We don't use your sessions to train AI models. What we do keep is described below — and you can delete almost all of it by deleting your account.

What we retain:

  • Account data: your email and encrypted password.
  • Payment data: managed entirely by our payment processor. We never see or store your card details.
  • Session telemetry: scores, session duration, persona choice, interaction counts. No transcript content.
  • Your Vibe Card content: the report shown on your Vibe Card and /autopsy page — your Vibe Score, feedback bullets, metric evidence, phase summaries, Biggest Gap, Silver Lining, and Next Step. This is text generated by our scoring engine that quotes and paraphrases what you said in the session.
  • Module summaries: the "strongest response" and "weakest response" the scoring engine extracts from each phase of your session. Also paraphrases of what you said.
  • Action plan: the action plan you talk through near the end of the session, extracted by the scoring engine.
  • Session transcript: we retain the text transcript of your session to generate and verify your performance feedback and to resolve disputes. Transcripts are tied to your account and are deleted when you delete it, or after 18 months, whichever comes first.
  • CV text and CV summary: when you start a session, we store your CV text and a short summary of it on the session record so the AI can stay coherent across reconnects and grade you accurately. Tied to your account and deleted when you delete it.

What we never retain:

  • Audio recordings of your sessions. Your voice is transcribed in real time by our AI provider so the interviewer can respond. The audio stream goes directly from your browser to that provider via an ephemeral token. It never passes through our servers and is never stored anywhere we control.

Clearing or replacing your inputs:

  • You can clear or replace your CV, the job description, and your other inputs on the context page at any time. Clearing an input resets the form so you can build a new interview plan from the edited inputs — it does not erase data we have already stored. A plan you previously generated stays on your account until you delete it. To remove stored data, delete your account (which erases it) or email us to ask us to delete it.

Progression tracking and benchmarking

At the end of each session we store your performance scores alongside a one-way hash of your account identifier. Because that hash is derived from your account, it stays linked to you — so this is pseudonymised data, and we treat it as personal data. It is not anonymised. We use it to give you progression insight across sessions and to maintain aggregate performance benchmarks. It never includes your name, email, or IP address. See Section 3.3 for the detail, and Section 6 for how long we keep it — including that, because these rows carry no name, email, or IP, they are not removed when you delete your account.

3. What Data We Collect

3.1 Data You Provide

DataWhen CollectedPurpose
Email addressAccount creationAuthentication, account management, transactional communications
CV textSession configuration (uploaded, extracted in-browser, or pasted)Personalising the interview and grading your performance. See Sections 3.2 and 6 for storage and retention.
Session configuration choicesSession setupCalibrating the AI interviewer (role level, industry, persona)
Payment informationCheckoutProcessing payments. We do not store card details — handled entirely by our payment processor.

3.2 Data We Generate During Your Session

DataHow GeneratedRetention
Audio (voice)Real-time conversation with the AI interviewerNever stored. Streams directly from your browser to our AI provider via ephemeral token. Never passes through our servers.
Session transcriptTranscribed in real time during the sessionRetained on our servers to generate and verify your performance feedback and to resolve disputes. Tied to your account; deleted when you delete it, or after 18 months, whichever comes first.
AI responsesGenerated by our AI provider during the sessionStored as part of the session transcript (same row as above) — same retention and deletion behaviour.
Vibe Score, Vibe Card payload, and feedback bulletsGenerated at session end by our autopsy pipelineRetained as the report shown on your Vibe Card and /autopsy page — includes your Vibe Score, metric evidence, phase summaries, Biggest Gap, Silver Lining, Next Step, and feedback bullets. This is AI-generated text that quotes and paraphrases what you said. Tied to your account; deleted when you delete it.
Module summariesGenerated at phase transitionsRetained as the “strongest response” and “weakest response” the scoring engine extracts from each phase. These quote and paraphrase what you said. Tied to your account; deleted when you delete it.
Action planExtracted at the end of the sessionStored on your session record. Tied to your account; deleted when you delete it.
Heartbeat telemetrySent periodically during active sessionsStored as a timestamp update used for crash detection and session recovery. No transcript content.

3.3 Benchmarking and Progression Data (Pseudonymised)

At the end of each session we store performance metrics from your results: your Vibe Score and sub-scores (logic, delivery, resilience, synthesis), filler-word frequency, persona, tier, role/sector category, session length, and a per-session counter that lets us see your trend over time. We store these alongside a cohort_id — a one-way SHA-256 hash of your account identifier. Because that hash is derived from your account, these rows stay linked to you: this is pseudonymised data and we treat it as personal data. It is not anonymised, and we do not claim it cannot be traced back to you.

We do not include your name, email address, IP address, or any transcript content in this data. Our lawful basis is legitimate interest (Article 6(1)(f)) — giving you progression insight across sessions and maintaining aggregate performance benchmarks. You can object to this processing at any time (see Section 7).

Because these rows carry only the hashed identifier and your performance numbers — no name, email, or IP — they are not removed when you delete your account. We keep them so our aggregate benchmarks and trend statistics stay intact. If you would like your existing benchmarking rows removed, contact us before deleting your account and we will delete them — after your account is gone we can no longer tell which rows are yours.

3.4 Data Collected Automatically

DataPurposeRetention
IP address (session)Dispute resolution, fraud prevention, session validationRetained for 90 days, then automatically deleted. Lawful basis: legitimate interest.
IP address (account creation)Sign-up fraud and abuse preventionLogged for fraud and abuse prevention. Retained for 90 days, then automatically deleted (or earlier on request); not linked to your account. Lawful basis: legitimate interest.
Browser/device informationSession compatibility and debuggingNot stored persistently. Used transiently during session establishment.
Consent timestampsProving you consented to session termsStored on your account record; deleted when you delete your account.

3.5 Website Analytics

We use Vercel Web Analytics to understand how visitors use aurate (for example, which pages are viewed and how visitors arrive). It is privacy-first and cookieless — it does not use cookies or other persistent identifiers, does not track you across other websites, and does not collect personally identifiable information. It records only aggregated, non-identifying data such as page views, referring sites, approximate country-level location, and device or browser type. Vercel Inc. acts as a processor for this purpose.

4. How We Use Your Data

PurposeLawful Basis (UK GDPR)
Providing the interview simulation servicePerformance of contract (Article 6(1)(b))
Processing paymentsPerformance of contract (Article 6(1)(b))
Generating your autopsy and performance analysisPerformance of contract (Article 6(1)(b))
Storing consent timestampsLegal obligation (Article 6(1)(c))
Retaining IP addresses for dispute resolution and fraud preventionLegitimate interest (Article 6(1)(f))
Storing pseudonymised benchmarking and progression dataLegitimate interest (Article 6(1)(f)) — see Section 3.3
Crash detection and session recoveryLegitimate interest (Article 6(1)(f))
Website analytics — understanding how visitors use the siteLegitimate interest (Article 6(1)(f))
Sending transactional emailsPerformance of contract (Article 6(1)(b))

We do not use your data for marketing purposes unless you explicitly opt in. We do not sell your data to third parties. We do not use your session content (audio, transcripts) for AI model training.

A note on voice data

Your voice is processed by our AI provider during your session for real-time transcription so the interviewer can respond. We've architected the audio path so that audio never transits our servers — it goes directly from your browser to the provider via an ephemeral token, and we never store any audio recording or voiceprint. We retain only the resulting text transcript and the scores derived from it.

We use your interview audio only to transcribe your answers and generate your feedback — never to recognise or identify you by your voice. For that reason we treat this as ordinary personal data under UK GDPR, not as special category 'biometric' data under Article 9.

5. Who We Share Your Data With

We share personal data only with service providers acting as data processors on our behalf, in the following categories:

CategoryData SharedPurpose
Cloud database and authenticationEmail, user profile, session metadata, telemetry, IPDatabase, authentication, session state
AI interview providerAudio (in-transit), CV context (in system prompt)AI interview simulation
Payment processorEmail, payment informationPayment processing
Application hostingTransient request data during function executionApplication hosting, autopsy processing
Website analyticsCookieless, aggregated usage data — page views, referring site, approximate country, device/browser type (no cookies, no personal identifiers)Understanding how visitors use the site
Rate limiting and abuse preventionIP addresses, user identifiersProtecting the service from abuse, fraud, and excessive requests
Transactional emailEmail addressTransactional email delivery
Error monitoringError data (anonymised request metadata)Error tracking and monitoring
Email and productivityEmail correspondence (support and data-protection requests)Receiving and handling your support and privacy emails

When a job description is uploaded, as part of the parsing process, Gemini extracts the Role and company name to increase accuracy ahead of the interview.

Some of these providers process personal data outside the United Kingdom, including in the United States. Where they do, the transfer is protected by an approved safeguard — the UK Extension to the EU-US Data Privacy Framework ("UK-US Data Bridge") or the UK International Data Transfer Agreement. We make the names of our current processors available on request.

We do not share personal data with any other third parties.

6. Data Retention Schedule

Data CategoryRetention PeriodDeletion Trigger
AudioNot retained. Never stored.N/A — streams directly from browser to AI provider
Session transcript and AI responsesAccount lifetime, or 18 months, whichever is shorterAccount deletion (cascade) or scheduled 18-month purge
Vibe Card payload, module summaries, action planAccount lifetimeAccount deletion (cascade)
CV text and CV summaryLifetime of your session recordAccount deletion (cascade) plus session cleanup
Account data (email, tier, credits)Lifetime of accountAccount deletion
Session telemetry (scores, metadata)Lifetime of accountAccount deletion (cascade)
IP address (session)90 daysAutomatic scheduled purge
IP address (account-creation logs)90 days, then automatically deleted (or earlier on request)Automatic scheduled purge (not linked to your account)
Consent timestampsAccount lifetimeAccount deletion (cascade)
Pseudonymised benchmarking & progression dataIndefiniteNot removed on account deletion — rows carry only a one-way hash plus performance scores (no name, email, or IP), retained to keep aggregate statistics intact. See Section 3.3
Vibe Card sharesLifetime of accountAccount deletion (cascade)
Admin audit logsRetained for complianceNot deleted — required for compliance
Payment records (transaction IDs, amounts, tier — no card data)Retained; your user identifier is removed on account deletionAnonymised on account deletion (financial record retained)
Waitlist sign-up email (if you joined the waitlist)Until removal on requestOn request

7. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate personal data.
  • Right to erasure: Delete your account and your associated personal data using the "Delete my account" button in your profile settings (pseudonymised benchmarking rows are retained — see the note below).
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Request a copy of your data in a machine-readable format by emailing us.
  • Right to object: Object to processing based on legitimate interest.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw at any time.

Account deletion: Use the "Delete my account" button in your profile settings. Deletion is immediate and irreversible. Your directly identifying data — profile, session history, telemetry, transcripts, and CV — is permanently removed. Pseudonymised benchmarking and progression rows, which carry only a one-way hash of your account identifier plus performance scores (no name, email, or IP), are retained to keep our aggregate statistics intact (see Sections 3.3 and 6).

All other rights: Email hello@aurateai.com. We will respond within 30 days.

Complaints: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS/HTTPS on all connections), database-level Row Level Security policies, API key isolation via ephemeral tokens (keys never exposed to client browsers), and immutable audit logging of all administrative actions.

9. Cookies

aurate uses cookies only where strictly necessary. We use authentication session cookies to keep you signed in — these are first-party, expire when your session ends or when you sign out, and cannot be disabled without breaking sign-in. We do not use advertising cookies, analytics cookies, or cross-site tracking cookies. Most of your client-side state (your tier and your session preferences) is held in your browser's localStorage rather than in cookies, and is cleared by signing out, clearing site data, or deleting your account.

10. Children

aurate is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that a user is under 18, we will delete their account and associated data.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by a prominent notice in the application. The latest version will always be available at this page.

12. Additional Disclosures for US Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. This section supplements the rest of our Privacy Policy for California residents.

Categories of personal information collected

In the preceding 12 months, we have collected the following categories of personal information as described in Section 3 above: identifiers (email address), commercial information (purchase history), internet activity information (session telemetry), and inferences drawn from session performance (Vibe Scores).

We do not sell your personal information

aurate does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the preceding 12 months.

We do not share for cross-context behavioral advertising

aurate does not share your personal information for cross-context behavioral advertising as defined under the CPRA. We do not use tracking or advertising cookies.

Your CCPA rights

  • Right to know: You may request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information. Use the "Delete my account" button in your profile settings for immediate deletion, or email us.
  • Right to correct: You may request correction of inaccurate personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise any of these rights, email hello@aurateai.com. We will verify your identity and respond within 45 days.