aurate

Privacy Policy

Last updated: 11 May 2026

1. Who We Are

aurate is a trading name of AURATE AI LTD, a company registered in England and Wales (Company No. 17131159), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Throughout this policy, "aurate", "we" and "us" refer to AURATE AI LTD.

We are the data controller for your personal data.

Contact for data protection queries: hello@aurateai.com

ICO Registration: ZC109790 (currently registered under the founder's sole-trader name; update to AURATE AI LTD registration is pending and tracked separately).

2. Privacy-First Design

aurate is designed to keep your personal data tight to what's actually needed to run the service. We don't record audio. We don't sell your data. We don't use your sessions to train AI models. What we do keep is described below — and you can delete almost all of it by deleting your account.

What we retain (and delete when you delete your account):

  • Account data: your email and encrypted password, managed by Supabase Auth.
  • Payment data: managed entirely by Stripe. We never see or store your card details.
  • Session telemetry: scores, session duration, persona choice, interaction counts. No transcript content.
  • Your Vibe Card content: the autopsy report you see on your /autopsy page and Vibe Card — your Vibe Score, feedback bullets, metric evidence, phase summaries, fatal flaw, silver lining, and next step. This is text generated by our scoring engine that quotes and paraphrases what you said in the session.
  • Module summaries: the "strongest response" and "weakest response" the scoring engine extracts from each phase of your session. Also paraphrases of what you said.
  • Action plan: the action plan you talk through near the end of the session, extracted by the scoring engine.
  • Session transcript (beta period only): during this beta period, we retain the full session transcript on our servers to verify the quality of our scoring, resolve disputes, and improve the product. This is an interim measure tied to beta. We'll re-evaluate retention before paid launch and may shorten the period or stop retaining transcripts altogether. Until that re-evaluation, transcripts are tied to your account and deleted when you delete it.
  • CV text and CV summary: when you start a session, we store your CV text and a short summary of it on the session record so the AI can stay coherent across reconnects and grade you accurately at the end. Tied to your account and deleted when you delete it.

What we never retain:

  • Audio recordings of your sessions. Your voice is transcribed in real time by Google Gemini so the AI can respond. The audio stream goes directly from your browser to Google via an ephemeral token. It never passes through our servers and is never stored anywhere we control.

What's cached in your browser:

  • A copy of your CV text — cached in your browser so you don't have to re-paste between sessions on the same device. (This is separate from the server-side CV record described above — both exist; the browser cache is for your convenience and the server-side record is operationally required.) Clear the browser copy any time from the context page using the "Clear saved CV" button, by clearing your browser data, or by deleting your account.

Anonymous progression tracking (not active today)

When we activate sector-level benchmarking — currently disabled and gated by a feature flag (enable_benchmarking_write) — we'll generate a one-way cryptographic hash from your account identifier to track anonymous performance trends across sessions. The hash can't be reversed to identify you. We'll update this policy when this goes live.

3. What Data We Collect

3.1 Data You Provide

DataWhen CollectedPurpose
Email addressAccount creationAuthentication, account management, transactional communications
CV textSession configuration (uploaded, extracted in-browser, or pasted)Personalising the interview. When you start a session, your CV text and a short summary of it (generated by Gemini) are stored alongside the session record so the AI can stay coherent across reconnects and grade you accurately. Both are tied to your account and deleted when you delete it. A copy is also cached in your browser for convenience — clear it any time from the context page.
Session configuration choicesSession setupCalibrating the AI interviewer (role level, industry, persona)
Payment informationStripe CheckoutProcessing payments. We do not store card details — handled entirely by Stripe.

3.2 Data We Generate During Your Session

DataHow GeneratedRetention
Audio (voice)Real-time conversation with the AI interviewerNever stored. Streams directly from your browser to Google via ephemeral token. Never passes through our servers.
Session transcriptTranscribed in real time during the sessionRetained on our servers during this beta period for autopsy verification, dispute resolution, and product improvement. Tied to your account; deleted when you delete it. Will be re-evaluated before paid launch.
AI responsesGenerated by the Gemini API during the sessionStored as part of the session transcript (same row as above) — same beta-period retention and account-deletion behaviour.
Vibe Score, Vibe Card payload, and feedback bulletsGenerated at session end by our autopsy pipelineRetained in your session telemetry as the autopsy report shown on your Vibe Card and /autopsy page — includes your Vibe Score, metric evidence, phase summaries, fatal flaw, silver lining, next step, and feedback bullets. This is LLM-generated text that quotes and paraphrases what you said. Tied to your account; deleted when you delete it.
Module summariesGenerated at phase transitionsRetained as the "strongest response" and "weakest response" the scoring engine extracts from each phase. These quote and paraphrase what you said. Tied to your account; deleted when you delete it.
Action planExtracted at the end of the session by the module-summary LLMStored on your active session record. Tied to your account; deleted when you delete it.
Heartbeat telemetrySent every 60 seconds during active sessionsStored as a timestamp update used for crash detection and session recovery. No transcript content.

3.3 Anonymised Benchmarking Data

(Not active today.) When we activate sector-level benchmarking — currently disabled and gated by a feature flag (enable_benchmarking_write) — we will extract anonymised performance metrics from your results at session end. The data will include your Vibe Score, module-level ratings, session duration, sector tag, persona mode, and response timing patterns. All personally identifiable information will be stripped before storage; your user ID, email, IP address, and session content will never be included. This anonymised data will power our comparative benchmarking engine, and the anonymisation will be irreversible.

Until activation, none of this is happening. We will update this policy in the same PR that flips the flag.

3.4 Data Collected Automatically

DataPurposeRetention
IP addressDispute resolution, fraud prevention, session validationRetained for 90 days, then automatically deleted. Lawful basis: legitimate interest.
Browser/device informationSession compatibility and debuggingNot stored persistently. Used transiently during session establishment.
Consent timestampsLegal compliance — proving you consented to session termsRetained indefinitely as part of the immutable audit log.

4. How We Use Your Data

PurposeLawful Basis (UK GDPR)
Providing the interview simulation servicePerformance of contract (Article 6(1)(b))
Processing payments via StripePerformance of contract (Article 6(1)(b))
Generating your autopsy and performance analysisPerformance of contract (Article 6(1)(b))
Storing consent timestamps for legal complianceLegal obligation (Article 6(1)(c))
Retaining IP addresses for dispute resolutionLegitimate interest (Article 6(1)(f))
Generating anonymised benchmarking data (not active today; flag-gated)Legitimate interest (Article 6(1)(f)) — data is fully anonymised when activated
Crash detection and session recoveryLegitimate interest (Article 6(1)(f))
Sending transactional emailsPerformance of contract (Article 6(1)(b))

We do not use your data for marketing purposes unless you explicitly opt in. We do not sell your data to third parties. We do not use your session content (audio, transcripts) for AI model training.

A note on biometric data (Article 9 UK GDPR)

Your voice is processed by Google Gemini during your session for real-time transcription so the AI can respond. We've architected the audio path so that audio never transits our servers — it goes directly from your browser to Google via an ephemeral token. We are seeking formal legal advice on whether voice processing in this architecture creates Article 9 obligations for us, and we'll update this policy with the outcome.

5. Who We Share Your Data With

We share personal data only with the following service providers, each acting as a data processor on our behalf:

ProviderData SharedPurposeLocation
SupabaseEmail, user profile, session metadata, telemetry, IPDatabase, authentication, session stateEU (Frankfurt)
Google (Gemini API)Audio (in-transit), CV context (in system prompt)AI interview simulationGoogle Cloud (EU)
StripeEmail, payment informationPayment processingEU/UK (contracting entity: Stripe Payments Europe Ltd, Ireland; some processing in the US under the UK Extension to the EU-US Data Privacy Framework)
VercelTransient request data during function executionApplication hosting, autopsy processingEU (eu-west)
UpstashIP addresses, user identifiersRate limiting and abuse preventionEU (Ireland, eu-west-1)
ResendEmail addressTransactional email deliveryUS (UK Extension to the EU-US Data Privacy Framework — "UK-US Data Bridge")
SentryError data (anonymised request metadata)Error tracking and monitoringEU (de.sentry.io)

We do not share personal data with any other third parties.

6. Data Retention Schedule

Data CategoryRetention PeriodDeletion Trigger
AudioNot retained. Never stored.N/A — streams directly from browser to Google
Session transcript and AI responsesAccount lifetime (beta-period retention; will be re-evaluated before paid launch)Account deletion (cascade)
Vibe Card payload, module summaries, action planAccount lifetimeAccount deletion (cascade)
CV text and CV summary (server-side)Lifetime of your active session recordAccount deletion (cascade) plus active-session cleanup
CV text (browser cache)Until you clear it"Clear saved CV" button on the context page, browser data clear, or account deletion
Account data (email, tier, credits)Lifetime of accountAccount deletion
Session telemetry (scores, metadata)Lifetime of accountAccount deletion (cascade)
IP address90 daysAutomatic TTL
Consent timestampsIndefinitely (immutable audit log)Not deleted — required for legal compliance
Anonymised benchmarking dataIndefinite, once active (not active today — enable_benchmarking_write flag is OFF)Not affected by account deletion when active (contains no PII)
Vibe Card sharesLifetime of accountAccount deletion (cascade)
Admin audit logsIndefinitelyNot deleted — required for compliance

7. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate personal data.
  • Right to erasure: Delete your account and all associated personal data using the "Delete my account" button in your profile settings.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Request your data in a machine-readable format.
  • Right to object: Object to processing based on legitimate interest.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw at any time.

Account deletion: Use the "Delete my account" button in your profile settings. Deletion is immediate and irreversible. All identifiable data is permanently removed. When anonymised benchmarking is active (currently disabled and gated by a feature flag), anonymised data (which contains no PII and cannot be linked back to you) will be retained to maintain the integrity of aggregate analytics.

All other rights: Email hello@aurateai.com. We will respond within 30 days.

Complaints: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS/HTTPS on all connections), database-level Row Level Security policies, API key isolation via ephemeral tokens (keys never exposed to client browsers), and immutable audit logging of all administrative actions.

9. Cookies

aurate uses cookies only where strictly necessary. We use Supabase Auth session cookies to keep you signed in — these are first-party, expire when your session ends or when you sign out, and cannot be disabled without breaking sign-in. We do not use advertising cookies, analytics cookies, or cross-site tracking cookies. Most of your client-side state (your CV cache, your tier, your session preferences) is held in your browser's localStorage rather than in cookies, and is cleared by signing out, clearing site data, or deleting your account.

10. Children

aurate is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that a user is under 18, we will delete their account and associated data.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by a prominent notice in the application. The latest version will always be available at this page.

12. Additional Disclosures for US Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. This section supplements the rest of our Privacy Policy for California residents.

Categories of personal information collected

In the preceding 12 months, we have collected the following categories of personal information as described in Section 3 above: identifiers (email address), commercial information (purchase history via Stripe), internet activity information (session telemetry), and inferences drawn from session performance (Vibe Scores).

We do not sell your personal information

aurate does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We have not sold personal information in the preceding 12 months. Because we do not sell personal information, there is no need to opt out — but we honour this commitment unconditionally.

We do not share for cross-context behavioral advertising

aurate does not share your personal information for cross-context behavioral advertising as defined under the CPRA. We do not use tracking or advertising cookies.

Your CCPA rights

  • Right to know: You may request the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information. Use the "Delete my account" button in your profile settings for immediate deletion, or email us.
  • Right to correct: You may request correction of inaccurate personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.

To exercise any of these rights, email hello@aurateai.com. We will verify your identity and respond within 45 days.