Privacy Policy
MockRep · Last updated: October 5, 2026
MockRep is a free AI mock-interview and interview-prep tool. This page explains in plain language what data it handles. It describes what the app actually does today. If that changes, this page changes too.
1. What we collect
- If you just use the site (no account): the text you paste or upload (resume, job description, interview answers, salary details) is used to produce your result. Interview and negotiation sessions are kept on our server for up to 2 days so a session can continue, then deleted. We do not keep guest resumes or answers beyond that.
- If you create an account: your email address and a password (stored only as a salted one-way scrypt hash, never in readable form). We also keep what you choose to save to your history (for example a STAR answer, prep pack or review) and your per-skill interview scores over time (scores only, never your answers or resume).
- If you join the Pro waitlist: your email address, the date, and where you signed up. It is used only to tell you when a paid plan is available.
- Share cards: if you choose to create a share card, it contains your score, role, country and the display name you type, plus a date. It never contains your resume. Anyone with the card link can see it.
- Usage counts: see section 4.
- On your device: your browser stores a login cookie (only if you sign in; see the Cookie Policy), your resume-builder draft, voice settings and a "first visit" flag. These stay in your browser. Clear them any time in your browser settings.
2. Why we use it
- To generate your interview questions, feedback, resume reviews, prep packs and other results.
- To let you log in and see your saved history and progress.
- To email you about the paid plan if you joined the waitlist.
- To keep the service secure and within free-use limits (abuse and rate limiting use your network address briefly in memory, not in the database).
We do not sell your data, show ads, or use your resume or answers to train models.
3. Who else handles your data
- Nebius Token Factory (AI processing): the text you submit (resume, job description, answers) is sent to Nebius, which runs NVIDIA Nemotron models, to produce your result. Our Nebius account has Zero Data Retention turned on, which means Nebius is set not to keep prompts or outputs after the response.
- Render (hosting), Cloudflare (network and security) and Neon (database): they host the app and its data and may log technical request data such as IP address as part of running their service.
- Your browser's speech feature: if you use the voice mode, speech recognition is done by your browser (for example Chrome or Safari), which may send audio to its provider under that provider's own policy. We never receive or store your audio.
We do not use advertising or third-party analytics trackers.
4. Analytics
We count visits ourselves. There are no cookies for this, no third-party scripts, and no IP addresses stored. We keep daily totals (page views and how often each feature is used). To count unique visitors, we store a one-way hash made from the day, a server secret, and your network and browser details. It cannot be turned back into an IP address and cannot be linked from one day to the next. Bots and uptime checks are not counted. The aggregate numbers are visible at /stats.
5. How long we keep data and how to delete it
- Guest sessions: up to 2 days.
- Account data and saved history: until you delete it. Logged-in users can remove individual saved items, or choose Delete account, which removes your account, saved history, progress scores and login sessions.
- Waitlist email: until the paid plan is announced or you ask us to remove it (email us below).
- Usage counts: daily totals with no personal information.
- Technical logs kept by our hosting providers follow their own short retention.
6. Your rights
You can ask to see, correct, export or delete the personal data we hold about you, and to withdraw from the waitlist, by emailing the address below. This applies wherever you live, including India (Digital Personal Data Protection Act, 2023) and the US (including California). We will reply within 30 days.
7. Security
Connections use HTTPS. Passwords are hashed with scrypt. Login sessions are random tokens stored hashed in an HttpOnly cookie. Sign-in attempts are rate limited and accounts lock for 30 minutes after repeated failures. No system is perfectly secure, so please do not put sensitive information such as government ID numbers in your resume text.
8. Children
MockRep is for adults and job seekers. It is not meant for children under 16, and we do not knowingly collect their data.
9. Changes
If we change how we handle data (for example when a paid plan launches), we will update this page and the date above.
10. Contact
Questions or requests: ranjitkumarsahoo77@gmail.com