Privacy
PoisePath processes selected audio, typed questions, optional screen captures, and evidence you provide to create interview-practice or permitted coaching suggestions. Raw audio is streamed for transcription and is not recorded or stored by the app. Transcript and answer text stay in app memory for the current session unless a future, separately consented feature changes that default.
| Service | Data sent | Purpose |
|---|---|---|
| Deepgram | Audio from the input device you select | Streaming speech-to-text |
| OpenAI | Transcript/question, answer controls, and optional labeled evidence; coding screenshots only after a user action | Generate answer suggestions |
| Supabase | Account identity, plan, credit/usage ledger, request-id billing metadata, provider token counts and price estimate, opt-in crash fingerprints, and explicitly submitted aggregate mock-session metrics | Authentication, metering, reliability, and controlled-beta evaluation |
| Stripe | Email, customer/subscription identifiers, and checkout/payment records | Sandbox billing today; live billing is disabled |
| Crash reporting | Only after opt-in: category, surface, app version, sanitized platform, and a one-way fingerprint | Diagnose app failures without transcript or answer content |
| PostHog | Anonymous public-page visits, referrer and campaign parameters, device/browser context, coarse location derived by PostHog, and bounded demo, beta-interest, application-start, or application-submit actions with a page location or application path | Measure website discovery and controlled-beta interest; form answers, email addresses, session replay, broad click capture, and identified visitor profiles are excluded |
BYO provider keys are kept in app memory and cleared when the process closes. Resume, role, project evidence, and preferences are stored locally until you clear the app's local data. Use the in-app clear control to remove the current transcript and answers immediately.
Website analytics use a random browser identifier stored in local storage. PoisePath does not call PostHog's identify API, collect names or email addresses through analytics, or load website analytics inside the browser demo, authentication, billing, or password-reset pages. Web-vitals, dead-click, and survey collection are also disabled. A browser's Do Not Track preference is respected.
Controlled-beta reports are optional and account-only. They contain readiness booleans, duration, failure and reconnect counts, answer-rating counts, latency percentiles, and per-model character counts for cost estimation. The report endpoint does not accept transcripts, answers, screenshots, raw audio, paths, stacks, or free text.
Terms
PoisePath provides generated suggestions that may be incomplete or wrong. You are responsible for verifying every suggestion and for the statements you make. Do not rely on PoisePath for legal, medical, financial, safety-critical, or other high-stakes professional advice.
Sandbox purchases have no real monetary value. Production pricing, refunds, cancellation mechanics, and billing terms must be finalized before live payments are enabled.
Security
Account-mode provider credentials stay on trusted backend services. The desktop uses short-lived transcription credentials and content-bound request identifiers for metering retries. Screen-content protection is best-effort and depends on macOS and the capture path; test the exact meeting and screen-sharing setup before use.
No product can guarantee invisibility from cameras, device monitoring, policy enforcement, or every screen-capture implementation. Report security concerns through the project's support channel before public beta.
Permitted use
Not permitted
- Misrepresenting generated content as experience, qualifications, or results you do not have.
- Using the app where outside assistance is prohibited.
- Attempting to bypass proctoring, monitoring, security, or policy controls.
- Recording or processing another person's audio without the notice or consent required by applicable rules and law.