Privacy Notice
Last updated: March 2026
This Privacy Notice explains how PrepCall ("we", "us", or "our") collects, uses, and protects your personal data when you use our AI-powered interview coaching platform. It applies under the UK GDPR, EU GDPR, and the Data Protection Act 2018.
1. Data Controller
The controller responsible for processing your personal data is:
PrepCall
4 Brodia Road, London N16 0ES
Represented by: Gideon Bullock
Email: privacy@prepcall.com
2. Data We Collect
Identity & Contact Data
Full name, email address, and authentication credentials (managed via Clerk). Profile information you provide during account setup.
Career & Professional Data
CV documents you upload, LinkedIn profile data and portfolio URLs you provide, job descriptions and role specifications you submit for interview preparation, and target company and role information.
Voice & Behavioural Data
Real-time voice audio during practice sessions (processed via Hume AI), emotional expression data derived from voice analysis (prosody, tone, pace), and session transcripts generated from voice interactions.
AI-Generated Data
Coaching reports and performance assessments, personalised feedback and improvement recommendations, session summaries and progress tracking data.
Technical & Usage Data
IP address, browser type, device information, operating system, pages visited, features used, session duration, interaction patterns, server logs and error reports.
Transaction Data
Subscription status, payment history, and billing information (processed via Stripe). We do not store full payment card details — these are held by Stripe as an independent controller/processor.
Lawful Bases for Processing
We process personal data under the following lawful bases (Art. 6(1) GDPR):
Contract performance (Art. 6(1)(b)) — Identity & Contact Data, Career & Professional Data, AI-Generated Data, and Transaction Data are processed to provide and manage the service you signed up for.
Consent (Art. 6(1)(a)) — Voice & Behavioural Data is processed with your explicit consent, given when you start a practice session. You can withdraw consent at any time, though this will prevent us from delivering coaching reports for that session.
Legitimate interest (Art. 6(1)(f)) — Technical & Usage Data is processed for platform security, fraud prevention, and service improvement. Our interest is balanced against your rights through data minimisation and pseudonymisation where possible.
Legal obligation (Art. 6(1)(c)) — Financial records are retained as required by applicable tax legislation.
3. Recipients of Your Data
To fulfil the purposes described above, your personal data may be disclosed to:
AI Voice Processing — Hume AI, Inc. (USA): Provides the Empathic Voice Interface for real-time voice coaching and emotional expression analysis.
AI Language Processing — Anthropic, PBC (USA): Provides the Claude language model used for coaching report generation, CV analysis, and question generation.
Authentication — Clerk, Inc. (USA): Provides user authentication and identity management.
Payment Processing — Stripe, Inc. (USA): Processes subscription payments and manages billing.
Hosting — Vercel, Inc. (USA): Provides platform hosting and content delivery.
Database — Supabase, Inc. (USA): Provides managed PostgreSQL database services for storing account, session, and application data.
File Storage — Cloudflare, Inc. (USA): Provides R2 object storage for uploaded CV documents.
We require all processors to enter into data processing agreements (DPAs) that comply with Art. 28 GDPR / UK GDPR.
4. International Data Transfers
Some of our service providers are established outside the EEA and the United Kingdom. We ensure appropriate safeguards are in place, including the EU-U.S. Data Privacy Framework, UK International Data Transfer Agreement (IDTA), or Standard Contractual Clauses (SCCs) as applicable.
You may request a copy of the relevant safeguards by contacting us at privacy@prepcall.com.
5. Retention Periods
We retain your personal data only as long as necessary:
When your subscription ends, account data is retained for 90 days to allow reactivation, then deleted or anonymised.
Voice audio from sessions is deleted within 30 days. Session transcripts and coaching reports are retained for the duration of your subscription plus 90 days.
Financial records are retained for the period required by applicable tax legislation (6 years in the UK; up to 10 years in certain EU jurisdictions).
6. Your Rights
Under the GDPR and UK GDPR, you have the right to:
Access (Art. 15): Obtain a copy of your personal data.
Rectification (Art. 16): Have inaccurate data corrected.
Erasure (Art. 17): Request deletion of your data.
Restriction (Art. 18): Restrict processing under certain conditions.
Data Portability (Art. 20): Receive your data in a machine-readable format.
Object (Art. 21): Object to processing based on legitimate interests.
Withdraw Consent (Art. 7(3)): At any time, without affecting prior processing.
Lodge a Complaint (Art. 77): File a complaint with the ICO (ico.org.uk) or your local supervisory authority.
To exercise your rights, contact privacy@prepcall.com. We will respond within one month.
8. AI Processing
PrepCall is a personal practice and coaching tool. It does not make or influence any actual hiring decisions. The AI simulates interview experiences for your personal development — it does not speak on behalf of, or represent, any employer.
No processing constitutes solely automated decision-making that produces legal effects within the meaning of Art. 22 GDPR. All AI outputs are coaching suggestions provided directly to you for your own use.
EU AI Act Transparency
You are interacting with an AI system when using our voice practice feature. The AI analyses your voice for emotional expression patterns to generate coaching feedback. AI-generated reports should be treated as practice guidance, not professional career advice. Our system is classified as limited risk under the EU AI Act with Article 50 transparency obligations.
9. Data Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS/HTTPS) and at rest, access controls, regular security reviews, and incident response procedures in accordance with Art. 33/34 GDPR.
10. Children’s Data
Our platform is designed for adults preparing for professional interviews. We do not knowingly collect personal data from anyone under 16 (UK: 13 under the DPA 2018). If you believe a child has provided us with data, please contact us and we will delete it without delay.
11. Changes to This Notice
We may update this notice to reflect changes in legislation or our practices. Material changes will be communicated by email or a prominent notice on the platform.
12. Contact
For questions about your personal data or to exercise your rights:
PrepCall
4 Brodia Road, London N16 0ES
Email: privacy@prepcall.com
This Privacy Notice was prepared with AI-assisted guidance and does not constitute legal advice. It should be reviewed by qualified legal counsel before publication.