Version 2026-07-05 · Effective July 5, 2026

Privacy Policy

Fynvic, Inc. ("Fynvic," "we," "us") provides AI-assisted interview practice and verified technical screens for software engineers. This Privacy Policy explains what personal data we collect, why we use it, who we share it with, how long we keep it, and the choices you have. This policy applies to fynvic.com, our candidate and business apps, and related services.

Not legal advice. This document is written for transparency. If anything here conflicts with applicable law, the law controls.

1. Data we collect

Fynvic offers two session types: Practice (private rehearsal, not shareable as a credential) and Verified (consented recording with a tamper-evident report you may share). Both use the same technical artifacts; verified sessions additionally store share links, integrity hashes, and dispute metadata.

  • Account data: name, email address, password hash, profile photo (optional), and account preferences.
  • Practice session data: microphone audio (and optional camera preview during device check), transcripts, code submissions, timing metadata, and practice feedback. Practice sessions are not published as verified credentials and cannot be shared via Fynvic share links.
  • Verified session data: same interview artifacts as practice, plus sealed report metadata, optional share tokens, integrity hashes, and dispute flags. We do not perform live government-ID or biometric identity checks in V1.
  • Payment data: plan purchases, amounts, currency, and invoice references processed by our payment provider (Dodo). We do not store full card numbers.
  • Technical data: session cookies for authentication, IP address and user agent on security-sensitive actions, and service logs with PII minimization practices.

2. Why we use your data

  • Provide and improve interview practice and verified screens.
  • Generate transcripts, feedback, and tamper-evident reports.
  • Process payments and maintain tax/audit records where required.
  • Send service emails you opt into (score ready, digest, product updates).
  • Protect platform integrity, prevent abuse, and comply with law.

We do not use your interview content to train general-purpose AI models. Our LLM and speech providers are used under API terms that do not train on your content by default.

3. Processors and cross-border transfers

We use subprocessors to run the service. Personal data may be processed in the United States and other countries where these providers operate. If you access Fynvic from India or the EU, your data may leave your country to reach our infrastructure and processors.

  • Infrastructure: Railway, Vercel (hosting, US regions)
  • Realtime & recording: LiveKit (session media egress to our storage)
  • Storage: Amazon S3 (recordings and artifacts, encrypted at rest)
  • Speech & AI: Deepgram (transcription), OpenAI (interview dialogue and scoring assistance — session context only, minimized fields)
  • Payments: Dodo (checkout and invoicing)
  • Email: Resend (transactional email)

4. Cookies

We use strictly necessary cookies for authentication and session security. We do not use advertising cookies. If we add analytics cookies in the future, we will request consent before they load.

5. Retention

  • Recordings & transcripts: retained according to your account settings (default 90 days for video, 365 days for transcripts) unless you delete them sooner or we purge them automatically when expired.
  • Reports: remain in your account until you delete them or close your account, subject to lawful retention exceptions.
  • Payment records: retained for tax and accounting purposes (typically 7+ years in India) even after account deletion. When you delete your account, we anonymize profile data and purge interview content, but we may retain payment rows (amount, date, plan, payment-provider references, and an anonymized internal identifier) to meet legal obligations under Indian tax and GST law.
  • Audit logs: security and compliance logs retained per our internal schedule (currently up to 24 months unless law requires longer).

6. Your rights

Depending on your location, you may have the right to:

  • Access and export your data (Settings → Download my data).
  • Delete recordings or your entire account.
  • Correct profile information.
  • Withdraw consent where processing is consent-based.
  • Dispute a verified report you believe is materially wrong (in-app or email legal@fynvic.com with your session ID). We acknowledge within 5 business days and aim to resolve within 15 business days. Corrections may supersede the prior report with a new report ID; original rows are not silently edited.
  • Lodge a complaint with your local data protection authority.

Contact privacy@fynvic.com for requests. We respond within applicable deadlines (typically 30 days).

7. Children

Fynvic is not directed to anyone under 18. At signup you must confirm you are at least 18; we do not collect date of birth in V1. We do not knowingly collect data from minors. If you believe a minor registered, contact us to delete the account.

8. Security

We use encryption in transit (TLS), encrypted storage for recordings, access controls, webhook signature verification for payments, and least-privilege internal access. No system is perfectly secure; report concerns to privacy@fynvic.com.

9. Changes

We may update this policy. Material changes will be posted here with a new version date. Continued use after notice may require re-acceptance where required by law.

Questions: privacy@fynvic.com