1. Introduction

Welcome to WhalePrep (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the WhalePrep mobile application (the “App”) and our website at whaleprep.com (the “Website”). The App and the Website are referred to together as the “Services.”

By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Services.

2. Information We Collect

2.1 Account Information

Accounts exist only in the App. When you create an account, we collect:

If you sign in via Google or Apple, we receive your name and a unique identifier from the respective service. We do not receive your Google or Apple password.

2.2 Profile Information

During onboarding and App usage, you may provide:

2.3 Resume / CV Data

You may optionally upload your resume or CV (PDF or DOCX format) to enable personalized interview practice. We extract the text content from your file and store it on our servers. The original binary file is not retained. The extracted text is sent to OpenAI’s API for analysis to generate a structured summary of your skills, experience, and achievements. This summary is then used to create personalized interview questions tailored to your background. You may store up to 5 resumes per account.

2.4 Audio Recordings and Transcripts

During interview practice sessions, the App records your voice responses using your device’s microphone. This audio is:

Audio recordings are not stored on our servers. The uploaded audio is processed through OpenAI Whisper for transcription and then immediately discarded. Only the resulting text transcripts and analysis scores are stored on our servers linked to your account.

Recordings on your device are automatically deleted after 30 days of not being accessed (e.g., played back). If you listen to a recording, its retention period resets. All recordings and associated metadata are deleted when you log out or delete your account.

2.5 Interview Performance Data

For each practice session, we collect and store:

2.6 Job Vacancy Data

If you use the custom interview feature, you may provide:

We analyze this content using AI to generate interview questions and interview stages for that specific job. The extracted job details (title, company, key focus areas) and the generated questions are stored linked to your account.

When you provide a link, we also download the job posting itself and store its text on our servers, so that your interview stages can be generated when you start practising rather than all at once. This downloaded text is deleted automatically 30 days after the target job is created. The target job itself and its questions remain until you delete them or delete your account. If you paste a job description instead of a link, we store the text you pasted.

2.7 Subscription and Purchase Information

We use Apple’s StoreKit (on iOS) and Google Play Billing (on Android) for in-app purchases. We do not collect or store your payment card information. Apple or Google handles all payment processing. We only receive:

2.8 Device and Technical Information

For technical support. When you submit a support ticket we collect your device model, operating system and version, and the app version and build number.

For fair use of the free tier. Every request the App makes to our servers includes your platform (iOS or Android) and a device identifier provided by the operating system — Apple’s “identifier for vendor” on iOS, or the Android ID on Android. Neither is an advertising identifier, and neither identifies you personally.

We never store the identifier itself. We store only an irreversible cryptographic hash of it, together with the date we first and last saw that device, how many accounts have used it, and which one-time free allowances have been used on it. We use this solely to stop a single device from claiming the same free allowance repeatedly by creating new accounts. It is not used for advertising, profiling, or analytics.

Because it exists to prevent that specific abuse, this hashed device record is kept after you delete your account — see Section 5.3.

2.9 Usage and Analytics Data

We use Mixpanel, a third-party analytics service, to understand how users interact with both the App and the Website, and — on the Website only, and only if you accept analytics cookies — Google Analytics 4. Mixpanel records the product events described below. In the iOS app only, we additionally use Google Analytics for Firebase, which records app lifecycle events — such as the first time the App is opened on a device, and the start of a session — and is used to measure the effectiveness of our advertising; it does not receive your name or your email address. The Android app does not use Google Analytics for Firebase. We track:

Analytics events from the App are linked to your user ID to provide aggregated insights. Events from the Website are linked to an anonymous device identifier (set via cookie / local storage) unless you are signed in. We do not sell analytics data to third parties.

2.10 Support Information

When you submit a support ticket, we collect:

2.11 Push Notification Data

If you grant notification permissions in the App, we collect and store:

We deliver notifications in two ways: local notifications scheduled on your device, and remote push notifications sent from our servers through Firebase Cloud Messaging (FCM). On iOS, FCM delivers through the Apple Push Notification service (APNs). Your push token is used solely to deliver notifications to you; it is not used for advertising and is deleted when you log out or delete your account.

2.12 Website Data

The Website does not require an account. Apart from the newsletter form described below, it does not ask you to submit personal information. The following data is collected when you visit:

Other than the newsletter endpoint, the Website is statically generated: there is no database, no contact form, and no account login. If we add any of these features later, we will update this Privacy Policy before launching them.

2.13 Marketing Attribution (AppsFlyer)

We use AppsFlyer, a mobile measurement partner, to understand which marketing campaigns bring users to the App, so we can measure and improve our advertising. AppsFlyer collects:

We do not collect Apple’s IDFA or Android’s Advertising ID, and we do not use App Tracking Transparency. iOS attribution relies on Apple’s privacy-preserving SKAdNetwork. Attribution data is used solely to measure our own campaigns — it is not used to build advertising profiles about you and is not sold to data brokers.

2.14 Roles You Create

If the profession you want to practise is not in our catalogue, you can type it in and we will build a role for it. When you do:

Submissions are checked automatically before a role is built, and we may decline text that does not describe a profession. If we cannot build a role for what you typed, we keep the text as a record of what people are asking for. When you delete your account, that record is unlinked from your identity.

2.15 Advertising Conversion Measurement (Google, iOS app only)

In the iOS app we use Google’s on-device conversion measurement, which lets Google tell us whether one of our advertisements led to an install or a subscription.

This exists solely to measure our own advertising. It is not used to build an advertising profile about you, to target advertisements at you inside the App, or to share your details with data brokers. As stated in section 2.13, we still do not collect Apple’s IDFA and still do not use App Tracking Transparency. The Android app does not use this feature.

3. How We Use Your Information

We use the collected information for the following purposes:

PurposeData Used
Provide interview practice sessionsAudio recordings, transcripts, profile data
Generate personalized questionsResume/CV data, role, level, job vacancy data
Analyze and score your answersTranscripts, audio files
Display your progress and statisticsInterview scores, history, timestamps
Manage your accountEmail, name, authentication tokens
Process subscriptionsSubscription status from Apple
Send practice remindersNotification preferences, last open date
Operate and secure the WebsiteServer access logs, cookies, anonymous device identifier
Improve the ServicesAggregated analytics data from App and Website
Provide technical supportDevice info, support ticket content
Prevent fraud and abuseAuthentication tokens, account activity, server logs, hashed device identifier
Send newsletter emails you subscribed toEmail address submitted through the Website newsletter form
Measure the performance of our marketing campaignsDevice identifier, IP address, app install and in-app events

4. Third-Party Services

We share data with the following third-party service providers, solely for the purposes described:

4.1 OpenAI

4.2 ElevenLabs

4.3 Microsoft Azure Speech Services

4.4 SendGrid (Twilio)

4.5 Mixpanel

4.6 Google Sign-In

4.7 Apple

4.8 Google Play Billing

4.9 Firebase Cloud Messaging (Google)

4.10 Railway

4.11 AppsFlyer

4.12 Resend

4.13 Google Analytics 4

4.14 Umami

We do not sell your personal information to any third party.

4.15 Anthropic

4.16 Google Analytics for Firebase (iOS app only)

5. Data Storage and Security

5.1 Where Your Data Is Stored

5.2 Security Measures

We implement appropriate technical and organizational measures to protect your data:

5.3 Data Retention

We retain your data for as long as your account is active. Audio recordings on your device are automatically deleted after 30 days of inactivity. Password reset codes expire after 10 minutes. Website server access logs are retained for a short rolling window for security and debugging only. Newsletter subscribers’ email addresses are retained until you unsubscribe or ask us to remove you from the list; this is independent of any App account, so deleting your account does not by itself unsubscribe you. The downloaded text of a linked job posting is deleted 30 days after the target job is created; the target job itself and its questions remain.

When you delete your account:

5.4 Rate Limiting

To protect our service and prevent abuse, we apply rate limits to API requests. Limits are applied per authenticated user. If you exceed a rate limit, you will receive a temporary error and can retry after a short wait. Rate limits do not result in account suspension or data loss.

6. Your Rights and Choices

6.1 Access and Control

You can:

6.2 Account Deletion

You can delete your account at any time through the App (Profile > Delete Account). This will permanently remove your personal data from our servers as described in Section 5.3.

6.3 Permissions

You can revoke the following permissions at any time through your device’s Settings:

6.4 Analytics Opt-Out

Mixpanel respects your device’s ad-tracking / personalization limits (such as “Limit Ad Tracking” on iOS or opting out of Ads Personalization on Android). You may also clear Website cookies and local storage from your browser settings to reset your anonymous identifier, or contact us to request removal of your analytics data. You can also opt out of AppsFlyer attribution at https://www.appsflyer.com/optout.

6.5 Newsletter Unsubscribe

If you subscribed to our newsletter, every email we send includes an unsubscribe link, and you can use it at any time to remove your address from the list. You can also email us at legal@whaleprep.com and we will remove you. Subscribing to the newsletter is entirely optional and is not required to use the App or the Website.

7. Rights for Users in the European Economic Area (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

Legal basis for processing:

Processing ActivityLegal Basis
Account creation and managementPerformance of contract
Interview practice and analysisPerformance of contract
Subscription managementPerformance of contract
Analytics and product improvement (App and Website)Legitimate interest
Website server logs (security and debugging)Legitimate interest
Push notificationsConsent
Resume processingConsent
Newsletter subscriptionConsent
Marketing attribution (AppsFlyer)Legitimate interest
Advertising conversion measurement (Google, hashed email)Legitimate interest
Abuse prevention (hashed device identifier)Legitimate interest
Generating and sharing a role you requestedPerformance of contract

To exercise any of these rights, contact us at legal@whaleprep.com.

7.1 Where Your Data Is Processed

Our application servers are located in the Netherlands, our database is located in Germany, and voice processing is performed within the European Economic Area.

Some of the third-party service providers listed in Section 4 — including OpenAI, Anthropic, ElevenLabs, Mixpanel, AppsFlyer, Google and Twilio — process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies, under our agreements with those providers.

8. Rights for California Residents (CCPA)

If you are a California resident, you have the right to:

To exercise these rights, contact us at legal@whaleprep.com.

9. Children’s Privacy

The Services are not intended for children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The current version is always available at whaleprep.com/legal/privacy. We will notify you of material changes by:

Your continued use of the Services after changes are posted constitutes your acceptance of the revised Privacy Policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

12. Apple App Store Disclosure

In accordance with Apple’s App Store requirements, the following data types are collected by the App:

Data Linked to You:

Data Not Linked to You:

We do not collect any data that is not linked to your identity.

Data Used for Tracking:

We do not use your data for tracking as Apple defines it. We use Mixpanel and Google Analytics for Firebase for first-party analytics, and AppsFlyer to measure the performance of our own marketing campaigns, as described in Section 2.13. We also use a hashed device identifier solely to prevent abuse of the free tier, as described in Section 2.8. No data is shared with third-party advertisers or data brokers, and the App does not use an advertising identifier (IDFA).

13. Google Play Data Safety Disclosure

For our Android app, the equivalent disclosure is provided through the Google Play “Data safety” section on our Play Store listing. Consistent with the practices described above, the App collects the data types listed in Section 12 to operate the service, encrypts data in transit, does not collect the Google Advertising ID, uses a hashed device identifier solely to prevent abuse of the free tier, shares install-attribution data with AppsFlyer to measure advertising effectiveness, and does not sell personal data or share it with data brokers. You can request deletion of your data in-app (Profile > Delete Account) or by contacting us.