1. Introduction
Welcome to WhalePrep (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the WhalePrep mobile application (the “App”) and our website at whaleprep.com (the “Website”). The App and the Website are referred to together as the “Services.”
By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Services.
2. Information We Collect
2.1 Account Information
Accounts exist only in the App. When you create an account, we collect:
- Email address
- Full name
- Password (stored only as a secure hash; we never store or have access to your plaintext password)
- Authentication method (email, Google, or Apple sign-in)
If you sign in via Google or Apple, we receive your name and a unique identifier from the respective service. We do not receive your Google or Apple password.
2.2 Profile Information
During onboarding and App usage, you may provide:
- Professional role (e.g., Data Analyst, QA Engineer, Product Manager)
- Proficiency level (e.g., Junior, Middle, Senior)
- Profile photo (optional)
2.3 Resume / CV Data
You may optionally upload your resume or CV (PDF or DOCX format) to enable personalized interview practice. We extract the text content from your file and store it on our servers. The original binary file is not retained. The extracted text is sent to OpenAI’s API for analysis to generate a structured summary of your skills, experience, and achievements. This summary is then used to create personalized interview questions tailored to your background. You may store up to 5 resumes per account.
2.4 Audio Recordings and Transcripts
During interview practice sessions, the App records your voice responses using your device’s microphone. This audio is:
- Stored locally on your device in the app’s private storage
- Transcribed to text (using on-device speech recognition — Apple Speech Recognition on iOS or Android’s on-device speech recognizer — when available, or server-side transcription via OpenAI Whisper API)
- Uploaded to our servers for AI-powered analysis of your answers
Audio recordings are not stored on our servers. The uploaded audio is processed through OpenAI Whisper for transcription and then immediately discarded. Only the resulting text transcripts and analysis scores are stored on our servers linked to your account.
Recordings on your device are automatically deleted after 30 days of not being accessed (e.g., played back). If you listen to a recording, its retention period resets. All recordings and associated metadata are deleted when you log out or delete your account.
2.5 Interview Performance Data
For each practice session, we collect and store:
- Questions asked
- Your transcribed answers
- Performance scores (overall and per dimension: fluency, grammar, vocabulary, coherence, pronunciation)
- AI-generated feedback and improvement tips
- Session timestamps
2.6 Job Vacancy Data
If you use the custom interview feature, you may provide:
- Job posting links (URLs) or job description text
We analyze this content using AI to generate interview questions and interview stages for that specific job. The extracted job details (title, company, key focus areas) and the generated questions are stored linked to your account.
When you provide a link, we also download the job posting itself and store its text on our servers, so that your interview stages can be generated when you start practising rather than all at once. This downloaded text is deleted automatically 30 days after the target job is created. The target job itself and its questions remain until you delete them or delete your account. If you paste a job description instead of a link, we store the text you pasted.
2.7 Subscription and Purchase Information
We use Apple’s StoreKit (on iOS) and Google Play Billing (on Android) for in-app purchases. We do not collect or store your payment card information. Apple or Google handles all payment processing. We only receive:
- Subscription status (active, trial, expired)
- Plan type (monthly, quarterly, yearly)
- Transaction confirmation
2.8 Device and Technical Information
For technical support. When you submit a support ticket we collect your device model, operating system and version, and the app version and build number.
For fair use of the free tier. Every request the App makes to our servers includes your platform (iOS or Android) and a device identifier provided by the operating system — Apple’s “identifier for vendor” on iOS, or the Android ID on Android. Neither is an advertising identifier, and neither identifies you personally.
We never store the identifier itself. We store only an irreversible cryptographic hash of it, together with the date we first and last saw that device, how many accounts have used it, and which one-time free allowances have been used on it. We use this solely to stop a single device from claiming the same free allowance repeatedly by creating new accounts. It is not used for advertising, profiling, or analytics.
Because it exists to prevent that specific abuse, this hashed device record is kept after you delete your account — see Section 5.3.
2.9 Usage and Analytics Data
We use Mixpanel, a third-party analytics service, to understand how users interact with both the App and the Website, and — on the Website only, and only if you accept analytics cookies — Google Analytics 4. Mixpanel records the product events described below. In the iOS app only, we additionally use Google Analytics for Firebase, which records app lifecycle events — such as the first time the App is opened on a device, and the start of a session — and is used to measure the effectiveness of our advertising; it does not receive your name or your email address. The Android app does not use Google Analytics for Firebase. We track:
- Screen and page views and navigation patterns
- Feature usage (interviews started, completed, abandoned)
- Onboarding progress
- Subscription-related events (paywall views, purchases, renewals, cancellations)
- Permission grant/denial (microphone, speech recognition, notifications) — App only
- Marketing engagement events on the Website (page views, clicks on calls to action, blog and guide reads)
Analytics events from the App are linked to your user ID to provide aggregated insights. Events from the Website are linked to an anonymous device identifier (set via cookie / local storage) unless you are signed in. We do not sell analytics data to third parties.
2.10 Support Information
When you submit a support ticket, we collect:
- Your message topic and description
- Device and app version information
- Optionally, recent error information to help diagnose issues
2.11 Push Notification Data
If you grant notification permissions in the App, we collect and store:
- Notification preferences (stored on your device)
- Last app open date (to schedule relevant reminders)
- A device push token, stored on our servers so we can deliver reminders and other notifications to your device
We deliver notifications in two ways: local notifications scheduled on your device, and remote push notifications sent from our servers through Firebase Cloud Messaging (FCM). On iOS, FCM delivers through the Apple Push Notification service (APNs). Your push token is used solely to deliver notifications to you; it is not used for advertising and is deleted when you log out or delete your account.
2.12 Website Data
The Website does not require an account. Apart from the newsletter form described below, it does not ask you to submit personal information. The following data is collected when you visit:
- Server access logs. Our hosting provider (Railway) automatically logs your IP address, user agent, requested URL, referrer, and timestamp for every request. These logs are used for security, abuse prevention, and debugging, and are retained for a short rolling window.
- Cookies and local storage. The Website stores your cookie-banner choice in your browser’s local storage. If you accept analytics cookies, Mixpanel and Google Analytics 4 additionally store identifiers used to recognise return visitors. We do not use advertising cookies and we do not embed third-party advertising trackers.
- Analytics events (consent-based). If you accept analytics cookies, page views and interactions on the Website are captured by Mixpanel and Google Analytics 4, as described in Section 2.9. If you decline, neither service is loaded and neither stores an identifier on your device.
- Aggregate traffic measurement (Umami). Regardless of your cookie choice, we count page views using Umami, a cookieless analytics service. Each page view sends the page address, page title, referrer, screen size, and browser language. Umami stores nothing on your device and does not identify you personally: it derives an anonymous visitor count server-side from a daily rotating hash of your IP address and user agent. Because it stores no data on your device and creates no persistent identifier, it runs without requiring consent.
- Newsletter subscription (optional). If you submit the newsletter form, we collect the email address you enter and add it to our mailing list, which is hosted by Resend. We also record that a signup happened and on which page, but your email address is never sent to our analytics services. You can unsubscribe at any time — see Section 6.5.
Other than the newsletter endpoint, the Website is statically generated: there is no database, no contact form, and no account login. If we add any of these features later, we will update this Privacy Policy before launching them.
2.13 Marketing Attribution (AppsFlyer)
We use AppsFlyer, a mobile measurement partner, to understand which marketing campaigns bring users to the App, so we can measure and improve our advertising. AppsFlyer collects:
- Device identifiers (Apple IDFV / a unique AppsFlyer ID; on Android, a non-advertising device identifier)
- IP address (used only to derive approximate country/region)
- App install and in-app events (registration completed, interview started, and subscription purchases, including the purchase amount and currency)
We do not collect Apple’s IDFA or Android’s Advertising ID, and we do not use App Tracking Transparency. iOS attribution relies on Apple’s privacy-preserving SKAdNetwork. Attribution data is used solely to measure our own campaigns — it is not used to build advertising profiles about you and is not sold to data brokers.
2.14 Roles You Create
If the profession you want to practise is not in our catalogue, you can type it in and we will build a role for it. When you do:
- The text you type is sent to our AI providers so they can recognise the profession and generate interview stages and questions for it.
- The resulting role is shared. It is added to our catalogue and becomes available to every other user who types the same profession. The role name, its stages and its questions are not private to you, and they remain in the catalogue if you later delete your account, because other users’ practice depends on them.
- The text you typed is stored alongside the role so we can review the quality of what was generated.
- Your own practice — your answers, transcripts and scores — is never shared with other users, and neither is your resume or your target job data.
Submissions are checked automatically before a role is built, and we may decline text that does not describe a profession. If we cannot build a role for what you typed, we keep the text as a record of what people are asking for. When you delete your account, that record is unlinked from your identity.
2.15 Advertising Conversion Measurement (Google, iOS app only)
In the iOS app we use Google’s on-device conversion measurement, which lets Google tell us whether one of our advertisements led to an install or a subscription.
- What happens on your device: when you sign in, Google’s SDK takes the email address on your account and converts it into an irreversible cryptographic hash on your phone. Only that hash is sent to Google. Your email address itself never leaves the device through this feature.
- What Google does with it: Google compares the hash against its own record of people who clicked one of our ads. When it matches, we learn that an advertisement produced a result. We receive counts, never a list of people.
- Conversion events: we also tell Google when a registration or a subscription purchase happens, including the purchase amount and currency.
This exists solely to measure our own advertising. It is not used to build an advertising profile about you, to target advertisements at you inside the App, or to share your details with data brokers. As stated in section 2.13, we still do not collect Apple’s IDFA and still do not use App Tracking Transparency. The Android app does not use this feature.
3. How We Use Your Information
We use the collected information for the following purposes:
| Purpose | Data Used |
|---|---|
| Provide interview practice sessions | Audio recordings, transcripts, profile data |
| Generate personalized questions | Resume/CV data, role, level, job vacancy data |
| Analyze and score your answers | Transcripts, audio files |
| Display your progress and statistics | Interview scores, history, timestamps |
| Manage your account | Email, name, authentication tokens |
| Process subscriptions | Subscription status from Apple |
| Send practice reminders | Notification preferences, last open date |
| Operate and secure the Website | Server access logs, cookies, anonymous device identifier |
| Improve the Services | Aggregated analytics data from App and Website |
| Provide technical support | Device info, support ticket content |
| Prevent fraud and abuse | Authentication tokens, account activity, server logs, hashed device identifier |
| Send newsletter emails you subscribed to | Email address submitted through the Website newsletter form |
| Measure the performance of our marketing campaigns | Device identifier, IP address, app install and in-app events |
4. Third-Party Services
We share data with the following third-party service providers, solely for the purposes described:
4.1 OpenAI
- Data shared: Your audio recordings (for transcription only — not retained by our servers), transcribed answers, interview questions, extracted resume/CV text, and job vacancy descriptions
- Purpose: Speech-to-text transcription (Whisper API); AI-powered answer analysis, scoring, and feedback generation; resume analysis and personalized question generation; job posting analysis for custom interview preparation
- Privacy Policy: https://openai.com/privacy
4.2 ElevenLabs
- Data shared: Interview question text
- Purpose: Text-to-speech generation for interview questions
- Privacy Policy: https://elevenlabs.io/privacy-policy
4.3 Microsoft Azure Speech Services
- Data shared: Audio recordings of your answers and transcribed text
- Purpose: Pronunciation assessment and scoring (accuracy, fluency, prosody)
- Privacy Policy: https://privacy.microsoft.com/privacystatement
4.4 SendGrid (Twilio)
- Data shared: Your email address
- Purpose: Sending transactional emails (password reset codes)
- Privacy Policy: https://www.twilio.com/legal/privacy
4.5 Mixpanel
- Data shared: User ID (App only) or anonymous device identifier (Website), user properties (name, email, role, level — App only), usage events
- Purpose: Product analytics and usage insights across the App and the Website
- Privacy Policy: https://mixpanel.com/legal/privacy-policy
4.6 Google Sign-In
- Data shared: Authentication tokens during sign-in
- Purpose: Account authentication
- Privacy Policy: https://policies.google.com/privacy
4.7 Apple
- Data shared: Authentication tokens (Sign in with Apple), purchase transactions (StoreKit), subscription status notifications (App Store Server Notifications), device push token (Apple Push Notification service)
- Purpose: Account authentication, subscription management, push notification delivery on iOS
- Privacy Policy: https://www.apple.com/legal/privacy
4.8 Google Play Billing
- Data shared: Purchase transactions and subscription status (via Google Play Billing and Real-time Developer Notifications)
- Purpose: In-app purchases and subscription management on Android
- Privacy Policy: https://policies.google.com/privacy
4.9 Firebase Cloud Messaging (Google)
- Data shared: Device push token and notification payloads
- Purpose: Delivery of remote push notifications (reminders and service messages) on iOS and Android
- Privacy Policy: https://firebase.google.com/support/privacy
4.10 Railway
- Data shared: Standard HTTP request data when you visit the Website (IP address, user agent, requested URL, timestamp)
- Purpose: Hosting the Website and storing short-lived server access logs for security and debugging
- Privacy Policy: https://railway.com/legal/privacy
4.11 AppsFlyer
- Data shared: Device identifiers, IP address, app install and in-app events (including subscription purchase amount)
- Purpose: Mobile attribution — measuring the performance of our own marketing campaigns
- Privacy Policy: https://www.appsflyer.com/legal/services-privacy-policy/
- Opt-out: https://www.appsflyer.com/optout
4.12 Resend
- Data shared: The email address you submit through the Website newsletter form
- Purpose: Hosting our newsletter mailing list and delivering newsletter emails
- Privacy Policy: https://resend.com/legal/privacy-policy
4.13 Google Analytics 4
- Data shared: Website page views and interaction events, plus the identifiers and device/browser information Google Analytics collects by default. Loaded only if you accept analytics cookies.
- Purpose: Aggregate Website audience and traffic reporting
- Privacy Policy: https://policies.google.com/privacy
4.14 Umami
- Data shared: Page address, page title, referrer, screen size, browser language, and your IP address and user agent (used only to derive an anonymous, non-persistent visitor hash — see Section 2.12)
- Purpose: Cookieless, aggregate Website traffic measurement
- Privacy Policy: https://umami.is/privacy
We do not sell your personal information to any third party.
4.15 Anthropic
- Data shared: The profession text you type when creating a role, your extracted resume/CV text, job posting text, and interview questions
- Purpose: Generating interview roles, stages and questions, and classifying free-text professions
- Privacy Policy: https://www.anthropic.com/legal/privacy
4.16 Google Analytics for Firebase (iOS app only)
- Applies to: The iOS app. The Android app does not use this service.
- Data shared: App lifecycle events (first open, session start), registration and subscription-purchase events (including the purchase amount and currency), and standard app and device signals (device model, operating system version, language, country, IP address, and an app-instance identifier). No name. Your email address is shared only as an irreversible hash generated on your own device, for conversion measurement — see section 2.15.
- Purpose: Measuring the effectiveness of our advertising
- Privacy Policy: https://firebase.google.com/support/privacy
5. Data Storage and Security
5.1 Where Your Data Is Stored
- On your device: Audio recordings (auto-deleted after 30 days of inactivity), personal information and authentication tokens (encrypted in the iOS Keychain on iOS, or in the Android Keystore / encrypted storage on Android), profile photo (encrypted with platform data-protection), app preferences
- On our servers (App): Account information, interview attempts, transcripts, scores, extracted resume text, target jobs and the downloaded text of linked job postings, roles you have created, support tickets, subscription event history, and hashed device records used for free-tier abuse prevention
- On our hosting provider (Website): The Website is served as static content from Railway. Railway retains short-lived server access logs.
5.2 Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Passwords are hashed using bcrypt before storage
- Personal information (name, email) and authentication tokens are stored in the iOS Keychain on iOS and in the Android Keystore / encrypted storage on Android (hardware-backed where available)
- Profile photos are stored with platform data-protection encryption
- All data transmission uses HTTPS/TLS encryption
- Refresh tokens are stored as SHA-256 hashes on our servers
- Access tokens expire after a short period and are automatically refreshed
- All API endpoints that access personal data require user authentication via Bearer token
- App Store Server Notifications (iOS) are cryptographically verified using Apple’s root certificates, and Google Play Real-time Developer Notifications (Android) are verified, before processing
- Rate limiting is applied to prevent abuse (see Section 5.4)
5.3 Data Retention
We retain your data for as long as your account is active. Audio recordings on your device are automatically deleted after 30 days of inactivity. Password reset codes expire after 10 minutes. Website server access logs are retained for a short rolling window for security and debugging only. Newsletter subscribers’ email addresses are retained until you unsubscribe or ask us to remove you from the list; this is independent of any App account, so deleting your account does not by itself unsubscribe you. The downloaded text of a linked job posting is deleted 30 days after the target job is created; the target job itself and its questions remain.
When you delete your account:
- Your personal information (name, email, profile) is permanently deleted
- Your interview history, transcripts, and scores are permanently deleted
- Your uploaded resumes and extracted text are permanently deleted
- Your job vacancies and associated questions are permanently deleted
- Audio recordings and tracking metadata are deleted from your device
- Support tickets are retained in anonymized form for analytics — your email is replaced with an anonymous identifier and your user ID is removed. Ticket content (topic, message) is preserved but can no longer be linked to your identity.
- Account deletion feedback (if provided) is retained in anonymized form for product improvement
- Roles you created remain in our shared role catalogue, because other users’ interviews depend on them. They are not linked to your identity.
- Requests for roles we could not build are retained as anonymous demand signal — your user ID is removed.
- AI processing cost records are retained for aggregate accounting with your user ID removed, so they can no longer be linked to you.
- The hashed device record described in Section 2.8 is retained, including which one-time free allowances have already been used on that device. This means deleting and re-creating an account does not restore a free allowance. We keep this to prevent abuse of the free tier; it contains no personal information and cannot be reversed to identify your device.
5.4 Rate Limiting
To protect our service and prevent abuse, we apply rate limits to API requests. Limits are applied per authenticated user. If you exceed a rate limit, you will receive a temporary error and can retry after a short wait. Rate limits do not result in account suspension or data loss.
6. Your Rights and Choices
6.1 Access and Control
You can:
- View your profile information and interview history within the App
- Update your profile, role, and level at any time
- Delete individual interview attempts from your history
- Delete your account entirely from the Profile settings
6.2 Account Deletion
You can delete your account at any time through the App (Profile > Delete Account). This will permanently remove your personal data from our servers as described in Section 5.3.
6.3 Permissions
You can revoke the following permissions at any time through your device’s Settings:
- Microphone access — required for interview practice
- Speech recognition — required for real-time transcription
- Notifications — optional practice reminders
6.4 Analytics Opt-Out
Mixpanel respects your device’s ad-tracking / personalization limits (such as “Limit Ad Tracking” on iOS or opting out of Ads Personalization on Android). You may also clear Website cookies and local storage from your browser settings to reset your anonymous identifier, or contact us to request removal of your analytics data. You can also opt out of AppsFlyer attribution at https://www.appsflyer.com/optout.
6.5 Newsletter Unsubscribe
If you subscribed to our newsletter, every email we send includes an unsubscribe link, and you can use it at any time to remove your address from the list. You can also email us at legal@whaleprep.com and we will remove you. Subscribing to the newsletter is entirely optional and is not required to use the App or the Website.
7. Rights for Users in the European Economic Area (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right of access — request a copy of your personal data
- Right to rectification — request correction of inaccurate data
- Right to erasure — request deletion of your data
- Right to restriction — request limitation of processing
- Right to data portability — receive your data in a structured format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw consent at any time
Legal basis for processing:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of contract |
| Interview practice and analysis | Performance of contract |
| Subscription management | Performance of contract |
| Analytics and product improvement (App and Website) | Legitimate interest |
| Website server logs (security and debugging) | Legitimate interest |
| Push notifications | Consent |
| Resume processing | Consent |
| Newsletter subscription | Consent |
| Marketing attribution (AppsFlyer) | Legitimate interest |
| Advertising conversion measurement (Google, hashed email) | Legitimate interest |
| Abuse prevention (hashed device identifier) | Legitimate interest |
| Generating and sharing a role you requested | Performance of contract |
To exercise any of these rights, contact us at legal@whaleprep.com.
7.1 Where Your Data Is Processed
Our application servers are located in the Netherlands, our database is located in Germany, and voice processing is performed within the European Economic Area.
Some of the third-party service providers listed in Section 4 — including OpenAI, Anthropic, ElevenLabs, Mixpanel, AppsFlyer, Google and Twilio — process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one applies, under our agreements with those providers.
8. Rights for California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Delete your personal information
- Opt-out of the sale of personal information (we do not sell personal information)
- Non-discrimination for exercising your privacy rights
To exercise these rights, contact us at legal@whaleprep.com.
9. Children’s Privacy
The Services are not intended for children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The current version is always available at whaleprep.com/legal/privacy. We will notify you of material changes by:
- Posting the updated policy on the Website and within the App
- Updating the “Last Updated” date at the top of this document
Your continued use of the Services after changes are posted constitutes your acceptance of the revised Privacy Policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- General questions: hello@whaleprep.com
- Privacy-specific requests (data access, deletion, GDPR / CCPA rights): legal@whaleprep.com
12. Apple App Store Disclosure
In accordance with Apple’s App Store requirements, the following data types are collected by the App:
Data Linked to You:
- Contact Info (email address, name)
- Photos or Videos (profile photo)
- Audio Data (interview voice recordings)
- Other User Content (interview transcripts, resumes, job vacancy data)
- Customer Support (support ticket content)
- Identifiers (user ID)
- Identifiers (device identifier used for marketing attribution)
- Identifiers (a hashed device identifier used only for free-tier abuse prevention)
- Purchases (subscription history)
- Usage Data (product interaction, analytics events)
Data Not Linked to You:
We do not collect any data that is not linked to your identity.
Data Used for Tracking:
We do not use your data for tracking as Apple defines it. We use Mixpanel and Google Analytics for Firebase for first-party analytics, and AppsFlyer to measure the performance of our own marketing campaigns, as described in Section 2.13. We also use a hashed device identifier solely to prevent abuse of the free tier, as described in Section 2.8. No data is shared with third-party advertisers or data brokers, and the App does not use an advertising identifier (IDFA).
13. Google Play Data Safety Disclosure
For our Android app, the equivalent disclosure is provided through the Google Play “Data safety” section on our Play Store listing. Consistent with the practices described above, the App collects the data types listed in Section 12 to operate the service, encrypts data in transit, does not collect the Google Advertising ID, uses a hashed device identifier solely to prevent abuse of the free tier, shares install-attribution data with AppsFlyer to measure advertising effectiveness, and does not sell personal data or share it with data brokers. You can request deletion of your data in-app (Profile > Delete Account) or by contacting us.