Privacy Policy
SlayJobs: Mock Interview & Job Coach — Last Updated: September 2026
Definer Technology Limited (“we,” “us,” “our,” or the “Company”), a company registered and based in Hong Kong, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SlayJobs application and website (collectively, the “App”).
By using SlayJobs, you acknowledge that you have read and understood this Privacy Policy and agree to our data handling practices.
1. Information We Collect
1.1 Information You Provide Directly
- Account: your email address, a display name, an optional profile picture, and either a Google account identifier or a password we store only as a hash. You may also record a self-declared English level.
- Your CV: the CV text you paste or the document you upload, which we keep on your profile so you do not have to paste it again.
- Interview material: the job description you practise against, your answers as transcribed text, and the scores, critique and model answers generated from them.
- Payment: we never receive your card number. Card details are entered directly with Stripe; we store only the Stripe customer and subscription identifiers, your plan and your billing period.
- Support messages, if you use the in-app chat. That conversation is held by the chat service, not by us.
1.2 Information Collected Automatically
- Sign-in records: your IP address and browser user-agent string are stored with each sign-in session.
- Feature counters: which feature was used, on which day, and how many times. Used to enforce plan limits.
- Product analytics: a small set of named events describing your progress through the product — landing, starting setup, pasting a job description, signing up, viewing a report, reaching the paywall, checking out. Each event carries a random identifier generated in your browser, plus the campaign parameters, referring site and landing page of the visit that brought you here. If you later create an account, events recorded before you signed up are linked to it. See section 3 for how long these are kept.
- Stored in your browser, not on our servers: your sign-in tokens, your language preference, and the analytics identifier and attribution described above. These use localStorage, not cookies.
- Audio, when you answer a question by speaking. It is transmitted for transcription and is not stored — see sections 3.2 and 9.
- Server logs, which may contain your email address, account identifier, IP address and the request path.
We do not use cookies for tracking, do not collect mobile advertising identifiers, do not request your precise location, and do not record video or perform any facial analysis.
2. How We Use Your Information
2.1 To Run the Service
- Generating interview questions from your CV and the job description, and producing the scores, critique and model answers for your answers.
- Checking your CV and reporting what would stop software reading it correctly.
- Managing your account and subscription, and sending the emails that go with them — password resets, receipts, plan changes.
2.2 To Keep It Working and Improve It
- Error and application logs, to find and fix defects.
- Feature counters, to enforce the limits on your plan.
- Product analytics, to see where people abandon the flow — the events named in section 1.2, and nothing else.
We do not train AI models on your data. We do not train models at all: the analysis is performed by the third-party providers listed in section 4.2, and what they may do with the data they receive is governed by their own terms, not by us. We also do not run A/B tests on you, and there is no setting to opt out of either, because neither happens.
2.3 Legal and Safety
- Rate limiting and quota checks, to prevent abuse of the AI endpoints.
- Complying with valid legal process, and enforcing our Terms.
3. Data Retention
3.1 What We Store and How Long We Keep It
This table describes what actually happens today. Where something stops working but is not yet erased, it says so rather than implying deletion.
| Data Category | Retention |
|---|---|
| Account information — email address, display name, profile photo, your self-declared English level, and either a Google account identifier or a hashed password | Kept while the account exists |
| CV text saved to your profile | Kept until you change it, clear it, or delete your account |
| Interview sessions — job title, job description, the CV text used for that session, experience level, language and practice settings, and the overall score | Kept while the account exists |
| Interview answers — the question you were asked and its category, how long you spoke, the transcript, the scores, the written critique, and the model answers and coaching notes generated for it | Kept while the account exists |
| Shared report links — a stored copy of the report contents served at a public URL, together with the identifier of the account that created it | A link created since we introduced the 90-day limit stops working 90 days after it was created. Links created before that do not expire on their own — email us and we will remove one. In both cases the stored copy is erased when you delete your account. |
| Sign-in sessions — session and refresh tokens, IP address, and browser user-agent string | The token stops being accepted 7 days after sign-in. The record itself, including the IP address, is kept until you delete your account. |
| Password reset tokens | Stop being accepted 1 hour after the request, or as soon as they are used. The record is kept until you delete your account. |
| Feature usage counters — which feature was used, on which day, and how many times | Deleted 120 days after the day recorded. Counters that enforce a one-time free allowance are kept while the account exists, because deleting them would silently reissue the allowance. |
| Subscription records — plan, billing period, and the Stripe customer and subscription identifiers | Kept while the account exists |
| Promotional code redemptions | Kept while the account exists |
| Stored in your browser, not on our servers — your sign-in token, refresh token, and language preference (held in localStorage) | Until you sign out or clear your browser data |
| Application and error logs — may contain your email address, account identifier, IP address and the request path, and, when an AI response fails to parse, a short excerpt of the text being processed | Held by our hosting provider under its own log retention window, not queried or used for profiling |
| Support conversations, if you use the in-app chat | Held by the chat service at email.hobbyland-group.com under its own retention policy |
| Product analytics events — a named step in the funnel, a random identifier generated in your browser, and the campaign parameters, referring site and landing page of that visit. Once you create an account, events recorded before you signed up are linked to it. | Deleted 180 days after the event. Events already linked to an account are also erased when you delete it; events from visits that never became an account are not linked to you and expire on the same 180-day clock. |
| Guest practice counters — which feature an unregistered visitor used, on which day, against a random key from their browser | Deleted 7 days after the day recorded |
We never receive or store your card number. Card details are entered directly with Stripe, our payment processor, which keeps its own transaction records for as long as tax and accounting law requires.
We do not use cookies for tracking, do not collect mobile advertising identifiers and do not request your precise location.
3.2 Audio of Your Answers
When an answer is analysed from audio, the recording is transmitted to the AI providers listed below for transcription and analysis. It is not written to our database: there is no audio or video column in our data store, and no recording is saved to disk. What we retain is the resulting text — the transcript, the scores and the critique.
The providers that may receive your audio, transcript or interview text are Google (Gemini), OpenAI (transcription and speech synthesis), Anthropic (Claude), OpenRouter (which routes requests to these models), and ElevenLabs (speech synthesis). Each processes the request under its own terms and, in some cases, retains it briefly for abuse monitoring. See section 9.
3.3 Inactive Accounts
We do not delete accounts or their contents automatically because of inactivity. If a paid account goes unused for an extended period we may send a reminder email — to do that, your email address, name and plan status are sent to the email service at email.hobbyland-group.com — but nothing is erased. Your data stays as it is until you delete your account or ask us to delete it.
3.4 Deleting Your Account
You can delete your account yourself at any time from your profile page. Deletion runs immediately, as a single database transaction, and cannot be undone. It removes:
- your account record, including your email address, name and sign-in credentials;
- every interview session, and every answer, transcript, score and critique within it;
- the CV text saved on your profile;
- your subscription record and any promotional codes you redeemed;
- your sign-in sessions and any outstanding password reset tokens;
- your feature usage counters; and
- every shared report link you created — any URL you previously sent to someone else stops working immediately.
Because deletion is immediate and complete, there is no reactivation window and nothing can be restored afterwards. Two things it does not do: it does not cancel an active paid subscription, and it does not reach into the AI providers’ or the chat service’s own records. If you hold a paid subscription, cancel it first, or contact us so we can stop the billing for you.
3.5 Right to Deletion by Request
If you would rather not use the in-app control, or you cannot sign in, email [email protected] and we will delete your account and its data within 30 days. The exception is records we are legally required to keep, such as Stripe’s transaction history for tax and accounting purposes.
4. Data Sharing and Disclosure
4.1 We Do NOT Share Your Data With:
- Third-party advertisers or data brokers.
- Social media platforms.
- Third-party analytics or tracking services. Our product analytics are first-party: the events go to our own servers.
4.2 Service Providers
These are the companies that process your data on our behalf, and what each one receives:
- Railway (application hosting) and Supabase (database, Seoul region) — everything described in section 3.
- Google — Gemini receives your audio, CV text, job descriptions and answers for analysis; Google Sign-In receives your email address and name if you sign in that way.
- OpenAI — transcription of your audio, and speech synthesis for the live interviewer.
- Anthropic — your transcripts, CV text and job descriptions, for analysis and question generation.
- OpenRouter — routes some of the requests above to those models.
- ElevenLabs — the interviewer’s speech, synthesised from our text, not from yours.
- Stripe — payment processing. Your card details go to Stripe directly and never reach us.
- Resend — delivery of password-reset and account emails.
- Hobbyland Group (email.hobbyland-group.com) — the in-app support chat, and the emails we send about your account.
4.3 Sharing You Initiate
Creating a share link publishes a read-only copy of that report at a public URL: anyone holding the link can read it, without signing in. Delete your account to remove every link you created, or email us to remove one.
4.4 Legal Requirements
Law enforcement or regulatory bodies, when required by valid legal process.
5. Where Your Data Is Held
Our database is hosted by Supabase in South Korea (Seoul), and the application by Railway. We are a Hong Kong company, so your data is handled from Hong Kong and stored in South Korea.
The service providers listed in section 4.2 process data in their own regions, which for several of them means the United States. Where that transfer is subject to GDPR or UK data protection law, it relies on the transfer mechanisms in those providers’ own data processing terms, and the data is encrypted in transit throughout.
6. Security
- In transit: TLS on every connection, including to each provider in section 4.2.
- At rest: encrypted by our database host.
- Passwords: stored only as a bcrypt hash. We cannot read your password, and neither can anyone with database access.
- Password reset links: only the SHA-256 hash of the token is stored, so a copy of the database does not let anyone reset your password.
- Card details: never reach our servers. Stripe collects them directly.
No system is perfectly secure, and we do not claim otherwise. If you believe your account has been accessed by someone else, email [email protected].
7. Your Rights and Choices
- Access: email [email protected] for a copy of the data listed in section 3. We do not yet offer a self-service export.
- Correction: your name, CV and English level are editable in the app at any time.
- Deletion: delete your account yourself from your profile page — see section 3.4 for exactly what that removes — or email us.
- Marketing email: use the unsubscribe link in any such email.
- Analytics: clearing your browser storage for this site removes the analytics identifier and attribution, and a new random identifier is generated on your next visit. Blocking storage entirely also works; the app degrades to an in-memory identifier that is discarded when you close the tab.
8. Your Rights by Region
The rights below come from different laws, but the way you exercise them here is the same, so this section says plainly which are self-service and which are not.
8.1 How to exercise any of them
- Erasure is immediate and self-service: delete your account from your profile page. Section 3.4 lists exactly what it removes. Nothing is queued for later review.
- Correction is self-service: your name, CV and English level are editable in the app.
- Access, portability, restriction and objection are by email to [email protected]. There is no self-service export yet. We answer within 30 days.
- Analytics can be reset by clearing this site’s browser storage, which discards the identifier described in section 1.2.
8.2 Why we are allowed to hold your data
- To provide the service you asked for — your account, CV, interviews and their feedback. Without this data there is no product.
- Because you chose to — your microphone is used only when you answer by speaking, and you can practise entirely by typing instead.
- To run and protect the service — sign-in records, feature counters and product analytics, so we can keep it working, enforce plan limits and see where people get stuck.
- To meet legal obligations — Stripe’s transaction records, kept for tax and accounting.
8.3 Automated processing
The product scores and critiques your CV and your answers automatically. That is the service, and it is advisory: it produces feedback for you, and no decision is made about you that has legal or similarly significant effects. Nothing is passed to an employer. If you want a human to look at a result, email us.
8.4 Sensitive information
We never ask for health, ethnicity, religion, political opinions, sexual orientation or trade union membership. A CV is free text, so it may contain such details if you choose to include them; where it does, they are processed only as part of the CV itself, and never used to profile or target you.
8.5 EU and UK (GDPR)
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting processing already carried out. Section 5 describes where your data is held and that several providers process it outside the EU and UK. You may lodge a complaint with your national supervisory authority; you do not need to contact us first.
8.6 California (CCPA/CPRA)
You have the right to know what we collect and why, to delete it, to correct it, and not to be treated differently for exercising any of those rights. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. Our analytics are first-party: the events go to our own servers, not to an advertising network.
8.7 Hong Kong (PDPO)
We are a Hong Kong company, so the Personal Data (Privacy) Ordinance applies to us directly rather than as a regional add-on. You may make a data access or data correction request under DPP 6 by emailing us; we answer within the statutory 40 days. If you are not satisfied you may complain to the Privacy Commissioner for Personal Data.
9. Audio
- Only when you start it: the microphone is used only during a mock interview you have begun, and only if you choose to speak rather than type.
- Not stored: your audio is transmitted to the providers named in section 4.2 for transcription and analysis, and is not written to our database. There is no audio or video column in our data store. What we keep is the resulting text.
- No video: the camera preview during setup is rendered in your browser and never uploaded. We do not record video and do not perform facial analysis of any kind.
- No biometric templates: we do not derive or store a voiceprint, a faceprint or any other biometric identifier. Your voice is transcribed to text and the audio is discarded.
- Never used for tracking and never shared with other users.
10. Children’s Privacy
SlayJobs is for adults preparing for work. You must be at least 18 years old to use it, as stated in section 2 of the Terms and Conditions. The service is not directed at children, we do not knowingly collect personal data from anyone under 18, and nothing in the App is designed or marketed for them.
We do not ask for a date of birth. Age is a condition of use you accept when you use the App, not another piece of personal data for us to hold — collecting one to enforce the other would work against the data minimisation this policy commits to everywhere else.
If we become aware that we hold personal data belonging to someone under 18, we will delete it and close the account. If you are a parent or guardian and believe your child has provided us with personal data, email [email protected] and we will delete it, typically within 14 days.
11. Contact Information
For all privacy-related inquiries or to exercise your data rights:
Email: [email protected]
Mailing Address: Definer Technology Limited, Hong Kong
Response Time: Typically within 14 days.
By using SlayJobs, you acknowledge that you have read and understood this Privacy Policy.