Privacy Policy
Last updated: December 18, 2025
At Nandaki AI ("Nandaki," "we," "us," or "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered interview assistance platform, including our website and desktop application (collectively, the "Services").
By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Services.
Contents
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, phone number, and password when you create an account
- Profile Information: Profile picture and professional details you choose to add
- Payment Information: Billing details processed securely through Stripe (we do not store your full payment card details)
- Resume and Career Data: Resume uploads, job titles, skills, and career information you provide for personalized assistance
- Support Communications: Information you provide when contacting our support team
1.2 Information Collected Automatically
- Device Information: Device type, operating system, browser type, and unique device identifiers
- Usage Data: Features used, session duration, interaction patterns, and error logs
- IP Address: Your IP address for security and analytics purposes
- Log Data: Server logs including access times, pages viewed, and referring URLs
1.3 Interview Session Data
- Audio Data: Audio captured from your interview sessions through our desktop application
- Transcriptions: Text transcriptions generated from audio during interview sessions
- AI Responses: Questions detected and answers generated during your sessions
- Session Metadata: Duration, timestamps, and performance metrics of your sessions
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- Provide real-time interview assistance and AI-generated responses
- Process audio and generate accurate transcriptions
- Authenticate your identity and manage your account
- Process payments and manage your subscription
- Provide customer support and respond to inquiries
2.2 Service Improvement
- Analyze usage patterns to improve our features
- Debug technical issues and enhance performance
- Develop new features based on user needs
2.3 Communication
- Send important service updates and security alerts
- Provide information about new features and products
- Respond to your support requests and feedback
2.4 Security and Compliance
- Detect and prevent fraud, abuse, and unauthorized access
- Comply with legal obligations and enforce our terms
- Protect the rights and safety of our users and third parties
Important: Nandaki AI does not sell your personal data. We do not use your audio recordings or interview transcriptions to train AI models without your explicit consent.
3. Audio and Transcription Data
Our desktop application captures audio from your video conferencing sessions to provide real-time interview assistance. Here's how we handle this sensitive data:
3.1 Audio Processing
- Audio is captured only when you actively start an interview session
- Audio is streamed in real-time to our transcription service (AssemblyAI) for processing
- We use temporary, short-lived tokens for transcription to enhance security
- Raw audio is not permanently stored on our servers
3.2 Transcription Storage
- Text transcriptions may be stored to provide interview history and analytics
- You can view your past session transcripts in your dashboard
- You can delete your interview history at any time
3.3 AI Response Generation
- Detected questions are sent to AI services (Claude by Anthropic) through our secure backend
- AI API keys are stored only on our servers, never in the desktop application
- Responses are generated in real-time and displayed in your overlay window
4. Data Sharing and Third Parties
We may share your information with the following categories of third parties:
4.1 Service Providers
- AssemblyAI: Real-time speech-to-text transcription services
- Anthropic (Claude): AI-powered response generation
- Stripe: Secure payment processing
- Cloud Providers: Infrastructure and hosting services
- Analytics Providers: Usage analytics and performance monitoring
4.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your information.
We Do Not Sell Your Data: Nandaki AI does not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. Data Retention
We retain your information for as long as necessary to provide our Services and fulfill the purposes outlined in this policy:
- Account Information: Retained while your account is active and for a reasonable period afterward for legal and business purposes
- Interview Session Data: Retained until you delete it or close your account
- Payment Records: Retained as required by tax and accounting regulations
- Usage Logs: Generally retained for up to 12 months for analytics and security
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal compliance.
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data transmitted between your devices and our servers is encrypted using TLS/SSL
- Secure Token Storage: Authentication tokens in our desktop app are encrypted using platform-native secure storage (Electron safeStorage)
- API Key Security: Sensitive API keys are stored only on our backend servers, never in client applications
- Access Controls: Strict access controls limit who can access your data within our organization
- Password Protection: Passwords are hashed using bcrypt with industry-standard salt rounds
- Rate Limiting: Protection against brute-force attacks and abuse
While we strive to protect your information, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and protect your account credentials.
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
7.1 Access and Portability
You can access most of your personal information through your account dashboard. You may request a copy of your data in a portable format.
7.2 Correction
You can update your account information directly through your profile settings, or contact us to correct any inaccurate information.
7.3 Deletion
You can delete your interview history from your dashboard. You may also request deletion of your entire account and associated data by contacting us or using the account deletion feature in settings.
7.4 Marketing Communications
You can opt out of promotional emails by clicking the unsubscribe link in any marketing email or updating your preferences in your account settings.
7.5 Additional Rights for EEA/UK Residents
If you are in the European Economic Area or United Kingdom, you have additional rights including the right to object to processing, restrict processing, and lodge a complaint with your local data protection authority.
7.6 California Residents
California residents have rights under the CCPA, including the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. As stated, we do not sell personal information.
9. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer your information internationally, we implement appropriate safeguards to protect your data in accordance with this Privacy Policy and applicable laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Nandaki AI
Support Team