Skip to main content

Privacy Policy

Last updated: 12 September 2026 · Version: 1.7.0

Introduction

We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our practice platform.

The data controller is CogniPrep Ltd, a company registered in England and Wales. You can reach us about anything in this policy at support@cogniprep.app.

Information We Collect

1. Account Information

  • Name and email address
  • Password (encrypted and hashed; we never store it in plain text)
  • If you sign in with Google or GitHub, the name, email address and profile picture URL that provider shares with us. We never see the password for that account.
  • Plan tier and the products you have unlocked (provider access, Premium, Assessment Centre access, interview credits)
  • Payment information is processed and stored by Stripe. We do not store card numbers or billing addresses. We receive a Stripe customer reference and, after each successful purchase, a card fingerprint: an opaque token Stripe derives from the card so that the same physical card produces the same token. It cannot be turned back into a card number. We use it only to detect the same card being used across more than one CogniPrep account when checking a referral reward (see section 10).
  • Terms of Service and Privacy Policy acceptance timestamps and version
  • Whether email verification has been completed
  • Your email preference: whether you have unsubscribed from non-essential emails
  • Current daily practice streak and personal best score

2. Game Session Data

Each time you complete a game, we store:

  • The full game state, including every trial, your responses, and timestamps, stored as structured data
  • Raw score, normalised score, and percentile ranking
  • Session start and end times, and total duration
  • Game-specific performance metrics (e.g., reaction time, accuracy, error patterns)
  • Performance category (e.g., average, above-average)

3. Feedback Reports

Feedback reports are generated on-demand from your session data and include:

  • Overall score and performance category
  • Identified strengths and areas for improvement
  • Personalised recommendations
  • Detailed insights based on your game metrics

Note: Feedback reports are not stored separately - they are generated dynamically from your session and score data.

4. Technical and Security Information

  • IP address (used for security and audit logging, and for rate limiting on sensitive endpoints such as sign-in, checkout and AI processing)
  • Country derived from your IP address by our hosting provider. We use it to choose the currency prices are displayed in and to decide whether VAT must be charged on a purchase. The two-letter country code is kept in a cookie for 30 days. We do not store your IP address for this purpose.
  • Browser user-agent string (used to identify your device type for display purposes)
  • Device fingerprint (a hash of your user-agent, used only for display in the device list in your account settings)
  • Device session tokens stored as secure cookies (used to enforce the 2-device limit)
  • Error reports and performance traces when something goes wrong or runs slowly (see “Analytics and Error Monitoring” below)

Note: The 2-device limit is enforced using persistent device tokens (cookies), not fingerprinting. The first two devices you sign in on are permanently registered to your account when it is created. This limit is final and cannot be changed or reset, and devices cannot be removed.

5. Product Analytics

We use PostHog to understand how the product is used. While you are signed in, events are linked to your account ID and plan tier so that we can see, for example, whether Premium users use feedback reports. We do not send your name or email address to PostHog. What is recorded:

  • Page views and the path you took through the site
  • Named product events, such as starting a game or opening checkout
  • Page performance measurements (web vitals)
  • For roughly one in ten visits, a session replay: a recording of how the page changed as you used it. Everything you type is masked before it leaves your browser.

PostHog stores its identifiers in your browser's local storage, not in cookies. See our Cookie Policy for details.

6. Interview Practice Data

When you use the Interview Practice feature, we collect and process:

  • Video recordings: your camera and microphone output for each of the five interview questions, uploaded to Cloudflare R2 secure cloud storage
  • Audio transcript: a text transcription of your spoken answers, generated by OpenAI Whisper
  • Content analysis scores: AI-generated scores (0–10) for relevance, clarity, and structure of your answers
  • Non-verbal presentation scores: AI-generated scores (0–10) for eye contact, posture, and confidence, derived from video frames
  • Filler word detection: a list of filler words identified in your speech (e.g. "um", "like")
  • Overall score and summary: a composite score and AI-generated written summary of your performance
  • Interview credit transactions: a ledger of credit grants, purchases, usage, and refunds

Raw video files are deleted from cloud storage automatically as soon as AI processing completes successfully. If processing fails, your credit is refunded and the recording is not analysed; email us and we will remove it. Transcripts, scores, and feedback are retained in your account until you delete the session or close your account.

7. Assessment Centre Exercise Data

When you attempt an assessment centre exercise we store your answers, your score, and, for exercises with written answers, the AI-generated review of what you wrote. Written answers are sent to OpenAI to produce that review (see “Data Sharing and Third Parties”). We keep a count of AI reviews per exercise to enforce the limit described in our Terms.

8. Application Goals (Onboarding)

After you sign up we ask two questions - which company you are applying to, and which role - so we can decide which practice tests to show you first. We store:

  • Employer: the company you are applying to, chosen from our employer list. If they are not listed you can choose “Other” and type the name, capped at 80 characters.
  • Role: the role you are applying for, chosen from a fixed list (for example “Investment Banking”). If it is not listed you can choose “Other” and type the job title, also capped at 80 characters.
  • Sector:the broad area the role belongs to (for example “Banking & Finance”). We are not asking you this - we work it out from the role you picked, and store nothing for a role you typed in yourself.

There are exactly two boxes in the whole flow you can type into: the “Other” employer name and the “Other” role title. Both are trimmed and length-capped when saved, and neither can be attached to an employer or role we already know, so the only free text we can end up holding is a company name and a job title. Please put nothing else in them - no personal details. Everything else is a selection from a list we defined, and both questions offer “Other”, so you never have to state something inaccurate. We no longer ask for your study level; if you answered that question before we removed it, the answer is cleared the next time you save. You can view, change or delete your answers at any time under Settings → Application Goals. We keep them for a maximum of 2 years from the last time you updated them.

Before you sign up, if you arrive on a page for a particular assessment provider or for the assessment centre, your browser remembers that in local storage and in a short-lived cookie so that your dashboard can open on the thing you came for. This is a page name only, and it is cleared once it has been used.

9. Support, Bug Reports and AI Help

  • Support tickets: when you open a ticket we store its subject, category, urgency, the page you were on, your browser user-agent, your email address, and every message in the thread, including replies you send us by email and any attachments in them. Replies arrive through our email provider, Resend.
  • Bug reports: the description you give us, the page you were on and your browser user-agent, sent to us by email.
  • AI help assistant: if you ask the help assistant a question, your question and the last few turns of that conversation are sent to OpenAI to generate an answer. We do not store the conversation, and we do not send your name, email address or account data with it. Please do not put personal details in your question.

10. Referral, Affiliate and Discount Codes

  • Friend referral codes: your referral code, the discount it gives, and a record of each purchase made with it: which product, the list price, the price charged, the reward granted to you, and the result of our automated fraud check (see “Automated Decision-Making”).
  • Affiliate codes: if you join our affiliate programme we store the name you give us, your payout email address, your code, a ledger of the commissions it earns, and a record of each payout we make to you.
  • School and promotional discount codes: a record of each redemption against your account, so per-user and per-year limits can be enforced. Promotional codes we email you after sign-up are tied to your account and can be used only by you.

11. Review Prompt

If you have paid for something and completed a few practice activities, we ask you one time whether you would leave us a review on Trustpilot. There is a skip button, and we ask once per account and never again.

We store one thing: that you were asked, and whether you clicked through or skipped. That single record is what stops the prompt appearing again. We do not store a rating, a score or any comment - we no longer collect satisfaction ratings at all, and any we held previously have been deleted.

If you do write a review, it is posted on Trustpilot under whatever name you give them, governed by Trustpilot's own privacy policy rather than this one. We never see anything about you from Trustpilot that is not already public on your review. Our own record that we asked you is deleted immediately if you delete your data or your account.

How We Use Your Information

We use your personal data for the following purposes:

Service Delivery

  • Provide access to practice games and features
  • Manage your account, plan tier and unlocked products
  • Process payments through Stripe
  • Authenticate and secure your account
  • Enforce the 2-device limit using persistent device tokens (stored as secure cookies)
  • Show prices in a currency that matches the country your visit comes from, and charge VAT where it is legally due
  • Answer your support tickets and bug reports

Personalisation

  • Display your game statistics, scores, and progress charts
  • Order the games dashboard around the employer and role you told us about at signup, and decide which assessment providers to build next based on the aggregate of those answers
  • Show you, on your dashboard, which assessment providers the employer you named actually uses, which of those you have already practised, and which of those you own - so we can point you at the gap. This is worked out when the page loads, from your own answers and your own activity; it is a prompt on screen, not a decision about you (see “Automated Decision-Making” below)
  • Generate personalised feedback reports with strengths and recommendations (generated on-demand from your session data)
  • Calculate your percentile ranking against anonymised population benchmarks
  • Track your daily practice streak and personal best
  • Compute improvement trends across your session history

Analytics and Error Monitoring

  • PostHog receives the product analytics described in section 5 so that we can see which games and features are used and where people get stuck.
  • Sentry receives a report when an error happens in your browser or on our servers, and a performance trace for a small sample of requests. A report includes the error, the page, your browser details, and, if you were signed in, your account ID and email address so that we can follow up on a problem with your account. When an error occurs in the browser, Sentry also receives a replay of the seconds leading up to it, with all text masked and all images and video blocked.

Anonymised Population Benchmarks

Your raw scores are included in aggregated, anonymised calculations to build population statistics (mean, median, standard deviation, percentile distributions) for each game. These statistics are used to calculate your percentile ranking. No individual scores are identifiable in this process.

Communication

  • Send transactional emails required to operate your account (e.g., account confirmations, email verification, security alerts, billing notifications, and a notification when your interview feedback is ready)
  • Send service-related announcements about CogniPrep features and updates
  • In the days after you sign up, if you have not yet bought anything, send a small number of emails offering a discount on a CogniPrep product you have shown interest in. If you have bought something, we may email you once about the friend referral programme. These are about CogniPrep only. Every such email has a one-click unsubscribe link, and using it stops all non-essential email from us.
  • Changes to our Terms, Privacy Policy or Cookie Policy are announced in the app only - we do not email you about policy updates
  • We do not send third-party marketing emails or any emails unrelated to CogniPrep. Emails are delivered through Resend, our email provider.

Legal, Security and Fraud Prevention

  • Maintain a GDPR audit trail of privacy-related actions on your account
  • Comply with legal obligations
  • Prevent fraud and abuse, including rate limiting by IP address and checking card fingerprints when a referral reward is claimed
  • Enforce our terms of service

Interview Practice

  • Process your video and audio recordings through AI systems to generate interview feedback (transcript, content scores, non-verbal scores, filler word detection)
  • Display your interview history, scores, and AI-generated feedback in your account dashboard
  • Manage your interview credit balance, recording purchases, grants, usage, and automatic refunds on processing failure
  • Send you an email notification when your interview feedback is ready

Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract - To provide the services you have signed up for or bought, including payments, support, and the referral and affiliate programmes you choose to take part in
  • Consent - For optional features you actively choose to use, such as recording yourself in Interview Practice and asking the AI help assistant a question
  • Legitimate Interest - To improve our service, monitor errors, prevent fraud, and tell recent sign-ups about our own products with an easy way to opt out. This also covers the two application-goal questions asked at signup and the one-time review prompt: the goal questions are answered from fixed lists, each with an “Other” option where you can type a company name or job title if ours does not cover it; the review prompt records only that you were asked. Neither is shared with employers or used to score you, and you can erase both at any time from Settings.
  • Legal Obligation - To comply with laws and regulations, including tax and accounting rules for payment, commission and payout records

Data Sharing and Third Parties

We share your data only with the following trusted third-party services:

Service Providers

  • Stripe: Payment processing (PCI-DSS compliant). Stripe stores your billing details; we receive a customer reference ID and a card fingerprint (see section 1). For purchases made from the European Union, Stripe may act as the merchant of record, in which case Stripe is the seller for that transaction and applies local VAT based on the billing address you enter at checkout.
  • Supabase: Authentication and database hosting. Your account and game data is stored on Supabase-managed infrastructure.
  • Google and GitHub: Optional sign-in providers. If you choose one, that provider tells us your name, email address and profile picture URL, and processes your sign-in under its own privacy policy.
  • Vercel: Application hosting and CDN. Vercel processes requests to serve the application and derives the country used for currency and VAT from your IP address.
  • Cloudflare R2: Cloud object storage used to temporarily hold your interview video recordings during AI processing. Raw video files are automatically deleted once processing completes.
  • OpenAI:AI models used for interview feedback (Whisper for transcription, a GPT-4o-mini text model for content analysis, and a vision model for non-verbal analysis), for reviewing written answers in assessment centre exercises, and for the AI help assistant. Your audio, video frames, written answers or help question are transmitted to OpenAI's API for processing and are subject to OpenAI's Privacy Policy. OpenAI does not use API inputs to train its models by default.
  • Trigger.dev: Background job processing used to run interview analysis asynchronously. Job payloads include your interview ID and are processed on Trigger.dev-managed infrastructure.
  • PostHog: Product analytics, as described in section 5.
  • Sentry: Error and performance monitoring, as described under “Analytics and Error Monitoring”.
  • Resend: Sends every email we send you, and receives replies you send to our support addresses so that they can be added to your ticket.
  • Upstash: Hosted Redis used for rate limiting. It briefly holds a counter keyed by your IP address or account ID for sensitive endpoints.

We do not sell your personal data to third parties. We do not use your data for cross-context behavioural advertising. Data shared with OpenAI is governed by OpenAI's API data usage policy; by default, OpenAI does not use API inputs to train its models.

Data Security

We implement industry-standard security measures:

  • SSL/TLS encryption for data in transit
  • Encrypted database storage
  • Secure password hashing (bcrypt)
  • Rate limiting on sign-in, checkout and AI endpoints
  • Access controls and authentication
  • Device session management (max 2 active devices)
  • Interview video files stored in private Cloudflare R2 buckets, not publicly accessible, and accessible only via short-lived signed URLs during processing

Data Retention

We retain your data for the following periods:

  • Account data: retained until you delete your account
  • Game sessions and scores: automatically deleted after 2 years, or immediately when you delete your account or request removal
  • Assessment centre exercise attempts (including your written answers and any AI feedback): retained until you delete your account, so we can enforce per-exercise usage limits; removed immediately when you delete your account
  • Interview video recordings: deleted from Cloudflare R2 automatically as soon as AI processing completes successfully (typically within minutes to a few hours of submission). If processing fails, email us and we will remove the recording.
  • Interview feedback, transcripts, and scores: retained in your account until you delete the session or delete your account
  • Interview credit transactions: 7 years (financial record requirement)
  • Application goals (the employer and role you named, and the sector we derived from the role): automatically deleted 2 years after you last updated them, or immediately when you delete your data or your account, or whenever you delete the answers themselves from Settings
  • Review prompt (only the record that we asked you, and whether you clicked through or skipped): retained until you delete your data or your account
  • Support tickets and messages: retained until you delete your account, so that we can refer back to earlier conversations
  • Card fingerprints and referral records: card fingerprints are deleted when you delete your account. Referral, commission and payout ledgers are financial records and are kept for 7 years.
  • Payment records: 7 years (legal requirement)
  • GDPR audit logs: deleted when you delete your account
  • Device session tokens: automatically removed after 30 days of inactivity (safety net to prevent permanent lockouts from lost devices)
  • Error reports: kept by Sentry for up to 90 days. Product analytics events are kept by PostHog; session replays are kept for a limited period set in our PostHog project.

The 2-year automatic deletion of game data and onboarding answers, and the 30-day device session cleanup, are enforced by a daily automated job. You can also delete your data at any time from your account settings.

Your Rights

Under GDPR and other privacy laws, you have the right to:

  • Access - Request a copy of your personal data
  • Rectification - Correct inaccurate data
  • Erasure - Request deletion of your data ("right to be forgotten")
  • Restriction - Limit how we process your data
  • Portability - Export your data in a machine-readable format
  • Object - Object to certain types of processing
  • Withdraw Consent - Revoke consent at any time

To exercise these rights, visit your account settings (export or delete all your data) or contact us at support@cogniprep.app.

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

International Data Transfers

Our providers (Supabase, Vercel, Cloudflare, OpenAI, Trigger.dev, PostHog, Sentry, Resend, Upstash and Stripe) may store and process data in the United States and other countries. We rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission where applicable

Automated Decision-Making

We use automated processing to personalise your experience:

  • Game difficulty is adjusted automatically based on your performance scores
  • Personalised recommendations are generated from your game history
  • Your dashboard compares the employer you named against the assessment providers you have practised and the ones you own, to suggest what to practise next. It only ever surfaces a suggestion to you - it does not gate access, change your scores, or get shared with anyone
  • Performance percentiles are calculated by comparing your scores against aggregated population data
  • Interview feedback and assessment centre written-answer reviews are generated entirely by automated AI systems (OpenAI); no human reviews your video, transcript or answers. These outputs are for personal self-improvement only and do not constitute a professional evaluation.
  • When a friend buys something with your referral code, an automated check decides whether your reward is granted. It looks at whether the same payment card has been used on other CogniPrep accounts and how many rewards you have already earned. If it trips, your friend keeps their discount but you receive no reward, and the reason is recorded so we can review it.

These automated processes do not produce legal or similarly significant effects. You can request human review of any automated assessment or a withheld referral reward by contacting us at support@cogniprep.app.

Cookies

We use cookies to enhance your experience. For detailed information, please read our Cookie Policy.

Changes to This Policy

We may update this privacy policy from time to time. When we do, we:

  • Update the version number and the “Last updated” date at the top of this page
  • Show a notice in your dashboard the next time you sign in, linking to the updated policy

We do not send emails about policy changes. The in-app notice is the only notification, so please read it when it appears.

Contact Us

If you have questions or concerns about this privacy policy:

  • Data controller: CogniPrep Ltd
  • Email: support@cogniprep.app
  • Data Protection Officer: support@cogniprep.app

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information with third parties for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm this.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights

To exercise your California privacy rights, visit your account settings or contact us at support@cogniprep.app. We will respond to verifiable requests within 45 days.

Supervisory Authority

If you're in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. For UK residents, this is the Information Commissioner's Office (ICO) at ico.org.uk. For EU residents, contact your national supervisory authority listed at edpb.europa.eu.