logoInterview Copilot

Privacy Policy

Last updated: February 12, 2026

This Privacy Policy explains how LotsDots Lab, operating as Interview Copilot ("we", "us", "our"), collects, uses, shares, and protects user ("you", "your") information when you visit and interact with our website, services, and software (collectively, "Services"). Please read this Privacy Policy carefully. By using our Services, you consent to the processing of your information in accordance with this Privacy Policy.

Information We Collect

We collect the following categories of information:

  • Account Information: When you register, we collect your email address and authentication credentials. If you subscribe to a paid plan, payment information is collected and processed directly by our payment provider, Stripe — we do not store your full credit card details.

  • Audio Data: When you use our interview assistance features, the Service captures audio from your device (including system/tab audio and microphone input) in real time. This audio is streamed directly to our third-party speech-to-text provider for transcription and is not stored on our servers. Audio data is kept in memory only for the duration of real-time processing and is discarded immediately after transcription. We do not retain, store, or archive any raw audio recordings.

  • Transcript and Session Data: The text transcripts generated from your audio, along with AI-generated answers and session metadata (such as timestamps, question classifications, and session duration), are stored on our servers to provide you with session history and review features. This data is automatically deleted 30 days after creation.

  • Technical and Usage Data: We collect non-personal information such as your IP address, browser type, operating system, device information, and data about how you use our Services (pages visited, features used, session duration). We use PostHog for product analytics.

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our Services, including real-time audio transcription and AI-generated interview assistance.

  • Process your transactions and manage your subscription.

  • Respond to your comments, questions, and support requests.

  • Conduct research, analytics, and product improvements.

  • Send you technical notices, updates, security alerts, and administrative messages.

  • Detect, prevent, and address fraud, abuse, and technical issues.

Third-Party Service Providers

To deliver our Services, we share data with the following categories of third-party providers:

  • Speech-to-Text Providers (Deepgram, OpenAI): Your audio is streamed in real time to Deepgram or OpenAI for transcription. Deepgram is SOC 2 Type II certified; we have opted out of their Model Improvement Partnership Program, meaning your audio is not retained or used for model training. OpenAI's transcription API has a zero-retention policy — audio data is not stored or used for model training.

  • AI Language Model Providers (OpenAI, Anthropic, Google): Transcribed text (not audio) is sent to AI language model providers to generate suggested answers. Data submitted through their APIs is not used for model training. These providers may retain data for up to 30 days for abuse monitoring purposes, after which it is deleted.

  • Payment Processing (Stripe): Stripe processes your payment information. We do not have access to your full payment card details. Stripe is PCI DSS Level 1 certified.

  • Analytics (PostHog): We use PostHog for product analytics to understand how our Services are used and to improve them. PostHog collects anonymized usage data.

Data Retention

We retain your data as follows:

  • Audio Data: Not retained. Audio exists only in memory during real-time processing and is discarded immediately after transcription.

  • Transcripts and Session Data: Automatically deleted 30 days after creation.

  • Account Information: Retained for as long as your account is active. Upon account deletion, your personal data will be removed within 30 days, except where retention is required by law.

  • Payment Records: Transaction records are retained as required by applicable tax and financial regulations.

Sharing of Information

We do not sell, rent, or trade your personal information. We share data with third-party service providers only as described in the "Third-Party Service Providers" section above, and only to the extent necessary to deliver our Services. We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety.

International Data Transfers

Our third-party service providers may process your data in countries outside your country of residence, including the United States. By using our Services, you consent to the transfer of your data to these countries. We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

Data Security

We use appropriate technical and organizational measures to protect the data we collect, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to operate our Services, remember your preferences, and analyze usage patterns. You can control cookies through your browser settings, but disabling cookies may affect the functionality of our Services. We use Google Analytics and PostHog for analytics purposes.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right to access — request a copy of the personal data we hold about you.

  • Right to rectification — request correction of inaccurate or incomplete data.

  • Right to erasure — request deletion of your personal data.

  • Right to restriction — request that we limit how we process your data.

  • Right to data portability — request your data in a structured, machine-readable format.

  • Right to object — object to the processing of your data for certain purposes.

  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at support@interviewcopilot.io. We will respond to your request within 30 days. If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.

Legal Basis for Processing (EEA Users)

If you are in the European Economic Area, our legal basis for processing your personal data depends on the type of data and the context: (a) Contract — processing necessary to provide you with the Services you requested; (b) Consent — where you have given explicit consent, such as for audio processing during sessions; (c) Legitimate Interests — for analytics, fraud prevention, and service improvement, where these interests are not overridden by your rights.

Children's Privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that information promptly.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on our website with a revised "Last updated" date. For material changes, we will make reasonable efforts to notify you via email or through the Services. Your continued use of the Services after changes become effective constitutes your acceptance of the revised Privacy Policy.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: support@interviewcopilot.io

By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.