Privacy Policy

Last updated September 15, 2026

1. About Orava

Orava is an AI-powered interview preparation platform designed to help job seekers practice and improve their interview skills through realistic mock interviews and personalized feedback. This Privacy Policy explains how we collect, use, and protect your personal data when you use our services. We are committed to protecting your privacy and handling your data transparently.

2. Who We Are

Orava is created and operated by Richard Judge. For the purpose of the General Data Protection Regulation (GDPR), Nextfem Leaders School, trading as Orava, is the data controller for your personal information.

3. Information We Collect

When you create an account, we collect your email address and name to set up and manage your profile. During practice interviews, your text and audio responses are linked to your account so you can review them later. You may also upload your resume and paste job descriptions to personalize your sessions.

You can answer one practice question before creating an account. That answer stays in your browser, and each answer you give is sent once to Google's Gemini AI service so the interviewer can ask you a follow-up. We send nothing else with it — no resume, no job description, and no account, because you do not have one yet. We do not store the answer on our servers unless you go on to create an account, and we never store raw microphone audio. We do record that a follow-up was generated, and what it cost us to generate, never its content and never your answer.

You can also compare your resume to one job description before creating an account. Both documents and the resulting comparison stay in your browser for 24 hours; the documents are sent once to Google's Gemini AI service to produce the comparison, and we do not store them or the result on our servers unless you go on to save the comparison to an account. We record that a comparison was generated and what it cost us, never the documents, your target role, or the result.

When you upload a resume during a practice session, it is processed in-memory to generate personalized interview questions. If you save your resume in your prep workspace, it is stored securely in our database so you can reuse it across sessions, and you can delete it at any time from your account. All uploads are protected during transit using SSL/TLS encryption.

If you use Case Study Prep, we store your Case title, employer brief, notes, presentation plan, rehearsal transcripts, panel answers, and AI feedback with your account. We do not store raw microphone audio.

If you use Technical Questions, we store your tailored practice sets, spoken-answer transcripts, answer durations, and AI feedback with your account. We do not upload or store raw microphone audio.

When you create an account, we record how you arrived: the page you landed on, the referring site, any campaign parameters in the link, the country inferred from your network address, and whether you signed up on a phone or a computer. This helps us understand where candidates come from. We do not store your IP address, and this record is never shared with analytics.

We also process limited technical information needed to operate, secure, and improve the service. Optional product analytics is described separately below and remains off unless you accept it.

4. Analytics and device storage

Orava is the controller for optional product analytics. PostHog is our sole analytics provider, and we use its EU cloud ingestion and processing environment. Analytics processes personal usage data only after you accept: minimized page routes, named feature events, device and browser information, language, time zone, screen and viewport information, and network information such as the IP address received by the ingestion service. We do not send your email, name, resume, job description, interview answers, transcripts, story text, company names, or other free-form candidate text.

For signed-in candidates, PostHog receives only the internal Orava user ID, account type, and subscription tier. Anonymous activity from this browser may be connected to that internal ID after signup or sign-in so we can understand the path from a public page or guide to signup and product activation. This makes the analytics personal and linked to the account. After you accept, PostHog also records application errors: the error message, the code location it came from, and the minimized page route, so we can find and fix what broke. Error reports never include what you typed. Autocapture, session replay, surveys, feature flags, and performance capture are disabled.

The necessary localStorage recordorava_analytics_consent stores your accept or reject choice, the policy version, decision or migration timestamp, and six-month expiry. If you accept, localStorage also holds PostHog persistence namedph_<project-key>_posthog. PostHog cookies are not used.

Analytics is strictly default-off. Acceptance and rejection both last six months on this browser and device. We ask again only when the receipt expires or the analytics purpose, provider, or disclosure changes materially. The choice is not synchronized to your account or other devices.

You can change your choice at any time through Cookie settings in the public footer or authenticated user menu. Rejection stops new collection immediately and clears PostHog identifiers and legacy PostHog or Google Analytics storage and cookies where the browser permits.

Orava's policy caps identifiable event-level analytics at 14 months. Genuinely anonymized aggregate reports that can no longer be linked to a person or device may be retained longer.

5. How We Use Your Information

Under GDPR, we must have a valid legal basis to process your data. We use your interview data and preferences to deliver the core mock interview functionality (contractual necessity). We monitor technical information to prevent misuse, protect our services, and ensure everything runs smoothly (legitimate interest).

We use optional product analytics only with the consent and safeguards described in the Analytics and device storage section. We only send marketing communications if you have explicitly opted in, and you can change that at any time from your account page. Service messages about your own account and activity — such as sign-up confirmation — are sent separately and are not marketing.

6. Data Sharing and Third Parties

We do not sell, trade, or rent your personal data. We only share data with trusted third-party services that help us operate our platform, under strict confidentiality agreements.

Vercel and Supabase host our website, store your account data, and manage authentication. Google processes Case Study Prep, Technical Questions, mock interview, resume-to-role comparison and pre-account practice content through its Gemini AI service, and generates the interviewer's voice, to produce practice questions and feedback. Your browser's speech-recognition service converts microphone input into text; its provider varies by browser. With your consent, PostHog processes the minimized product analytics described above in its EU environment. Stripe securely processes payments for paid plans and handles your payment information directly — we do not store your card details.

We may also disclose information if required by law or in the event of a business transfer, where you would be notified.

7. Your Data Rights

Under GDPR, you have the right to access, rectify, or delete the personal data we hold about you. You can also object to processing for certain purposes, request restriction of processing, and request your data in a portable, machine-readable format. You can exercise these rights from the Account page or by contacting us.

8. Data Retention & Security

We keep your personal data for as long as your account is active. You may delete your account and associated data at any time from the Account page. When you delete your account, all personal data is removed from our application systems; we retain only a minimal timestamp record for audit purposes. Stripe retains billing information where required for legal, tax, fraud-prevention, and accounting purposes. Analytics retention is described in section 4.

We use encryption in transit (SSL/TLS) and at rest, along with strict access controls to protect your data.

9. International Data Transfers

Some of our third-party providers are based outside the European Economic Area (EEA). When we transfer your data to these countries, we ensure it receives a similar degree of protection by using legal mechanisms like Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Policy Updates

We may update this policy periodically. All changes will be posted on this page with a revised "Last updated" date. We will notify you of any significant changes.

11. Contact Us

For any questions, data requests, or privacy concerns, please reach out at support@getorava.com. We are committed to addressing your concerns promptly and transparently.