Privacy Policy
Version 1.0 · Effective September 15, 2026 · The French version prevails in case of discrepancy.
Your interview answers stay yours. This policy explains what data Hopali uses, why, how long it is kept, and who it is shared with.
At a glance
- No audio recording is kept. Your voice is streamed live during the interview, then it's gone.
- Your résumé and the job description are deleted once you confirm your brief. Only the details you checked are kept.
- Transcripts are deleted after 90 days.
- Your answers are not used to train AI models, not sold, and not used for advertising.
- No employer ever sees your data, and feedback does not predict any hiring decision.
- You can delete your account and all your data from the app at any time.
1. Controller
Adeo Consulting (company being incorporated) — 147 rue Blomet, 75015 Paris, France. For any question about your data: contact@hopali.app
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account | First name, phone number (SMS sign-in), Apple or Google identifier, language | You, Apple, Google |
| Application brief | Background extracted from your résumé, job title and description, public company facts you confirm | You, public sources |
| Uploaded files | Résumé (PDF, DOCX), job description | You, deleted once you confirm the extraction |
| Interview | Voice streamed live (not recorded), transcript of your answers | You |
| Feedback and exercises | Criteria, quotes from your answers, exercises, progress | Generated by the Service |
| Purchases | Transaction reference, product, amount, date, minute balance, receipt email (web) | Stripe/RevenueCat, Apple |
| Technical and security | IP address, device and browser type, error logs, session timestamps | Your device |
| Usage measurement | Journey events (sign-up, brief ready, interview completed, purchase), never including résumé, job, answer content or company name | Your device |
Hopali does not seek sensitive data such as health or beliefs, so don't include any in your résumé or answers unless it's relevant. Your voice is never used to identify you, and we don't infer emotions, personality or accent from it.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and secure your account, sign you in | Contract |
| Prepare your brief, run the interview, produce feedback and exercises | Contract |
| Handle purchases, minute balance, restores and refunds | Contract |
| Keep transaction records | Legal obligation (accounting) |
| Prevent abuse (multiple accounts, bypassing limits) and keep the Service secure | Legitimate interest |
| Answer support requests | Contract / legitimate interest |
| Measure app usage to improve it | Legitimate interest, which you can object to at any time |
| Website analytics (Google Analytics) and ad campaign measurement (Meta Pixel, attribution) | Legitimate interest, which you can object to at any time via "Manage my choices" |
Account details and a brief are required to use the Service. The microphone is only needed during an interview. Uploading a résumé is optional: you can type your background instead.
4. Automated analysis
Hopali uses AI to prepare questions, run the interview and write educational feedback. This produces no decision with legal or similarly significant effects on you: nothing is sent to any employer, and nothing is decided about your application. It may contain errors, which you can report from the feedback screen.
5. Retention
| Data | Period |
|---|---|
| Audio recording | Not retained |
| Uploaded files (résumé, job description) | Deleted once you confirm the extraction |
| Transcripts | 90 days |
| Briefs, feedback, exercises | Until you delete them or your account |
| Account | Until deleted. After 3 years without sign-in, the account is deleted following an email notice (only if no unused minutes remain) |
| Transaction records | 10 years (accounting obligation), limited to transaction data |
| Technical and security logs | Up to 12 months |
| Backups | Rolling, at most 30 days after deletion |
| Usage measurement events | Up to 25 months |
| Support conversations | 3 years after the last exchange |
6. Recipients and service providers
Your data is only accessible to the publisher and to the service providers strictly necessary to run the Service, who are bound by contract and act on instructions. Your data is never sold.
| Provider | Role | Location |
|---|---|---|
| Supabase | Database, authentication, temporary file storage | EU |
| Render | Website and web app hosting, application server, interview sessions | EU (Frankfurt) |
| OpenAI | Real-time voice, résumé extraction, feedback writing | USA |
| Twilio (via Supabase) | SMS sign-in codes | USA |
| Apple, Google | Sign in with Apple / Google; Apple in-app payments | USA / Ireland |
| RevenueCat | Purchase and balance management | USA |
| Stripe | Web payments | Ireland / USA |
| PostHog | Usage measurement | EU (Frankfurt) |
| Google Analytics | Website and web app analytics | USA / Ireland |
| Meta Platforms Ireland (Meta Pixel) | Measuring Facebook and Instagram ad performance | Ireland / USA |
| Appstack | Attributing installs and purchases to campaigns, with your consent | USA |
OpenAI processes your voice, brief and answers to run the interview and produce feedback. Data sent through the API is not used to train its models. OpenAI may keep it for up to 30 days to monitor abuse before deleting it. Measurement events never contain your résumé, the job description, your answers, your transcripts or the target company name. Transfers outside the EU rely on the EU–US Data Privacy Framework where the provider is certified, or otherwise on the European Commission's Standard Contractual Clauses. Data may also be disclosed where the law requires it.
7. hopali.app and cookies
- PostHog runs in cookieless mode: it counts visits and clicks on the buttons that open the app, with no cookie, no browser storage and no tracking from one visit to the next.
- Google Analytics measures site traffic and sets analytics cookies.
- Meta Pixel measures whether a visit or sign-up follows a Facebook or Instagram ad. It sets
_fbpand_fbccookies shared between hopali.app and the web app. - You can turn this measurement off at any time via "Manage my choices" in the footer: Google Analytics, Meta Pixel and PostHog all stop together.
- The site never sends any résumé, answer, typed text or full URL. Session recording, autocapture and heatmaps are disabled.
In the app, ad attribution (Appstack) is only enabled with your consent. On iPhone, it also follows Apple's tracking setting.
8. Security
All data is encrypted in transit (HTTPS/TLS). Access to data is restricted and enforced on the server, and purchases and feedback access are verified server-side. If a data breach creates a risk, it is reported to the CNIL, and you are informed if the risk is high.
9. Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to its processing. You can withdraw consent at any time without losing what you've purchased, and you can set instructions for what happens to your data after your death.
- Delete your account: Settings → Account → Delete account. If you signed in with Apple, the app shows the final step to complete in your Apple Account settings.
- Any other request: contact@hopali.app, ideally from the phone number or address linked to your account. We reply within one month.
- Complaints: you can contact the CNIL (www.cnil.fr) or the data protection authority where you live.
10. Minimum age
Hopali is for people aged 18 and over. If we learn that an account belongs to a minor, it is deleted.
11. Changes
Material changes to this policy are announced in the app or by email before they take effect. The version date appears at the top of the page.