Privacy Policy
ScreenReady ("ScreenReady", "we", "us", "our") operates the website at getscreenready.com and the ScreenReady interview-practice service (the "Service"). This Privacy Policy explains what personal data we collect, why and how we use it, who we share it with, how long we keep it, and the rights you have over it — in particular under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), and, where it applies to you, the EU General Data Protection Regulation ("EU GDPR").
Please read this Policy alongside our Terms of Service, which incorporate it by reference, and our Cookie settings.
At a glance
We've written this Policy in full below, but in short:
- We collect the minimum we need to run the Service: your email, the interviews you practise, and your subscription status.
- Your webcam video and microphone audio never leave your device. Speech-to-text and any body-language coaching happen entirely in your browser. We only ever receive the resulting answer transcript and a small set of non-identifying scores.
- We never see your full card details and we never sell your personal data. With your consent, we do use Google Analytics and Google Ads (including conversion measurement and remarketing of our own Service) — you can decline these via the cookie banner. See Sections 3.6, 7 and 9.
- We may send you occasional marketing emails about your practice, new features, and Pro offers. You can opt out at any time — one click from any such email, or from the "Manage preferences" link in its footer — and we'll still send you essential account emails. See Section 3.8.
- We use a small set of carefully chosen service providers ("sub-processors"), each under a written data-processing agreement, listed in full in Section 9.
- You have strong rights over your data, including the right to a copy of it, to have it deleted, to complain to us directly, and to complain to the regulator. See Sections 13 and 14.
This summary is for convenience only and does not replace the full Policy below.
1. Who we are and how to contact us
ScreenReady is an AI-powered interview-practice platform. For the purposes of UK and EU data protection law, the data controller — the entity that decides why and how your personal data is processed — is:
ScreenReady
A sole trader trading as ScreenReady, operating from Heriot-Watt University, Riccarton, Currie, Midlothian, EH14 4AS.
ICO Registration Number: ZC184347
You can reach us about anything in this Policy, or to exercise your rights, at: [email protected].
We have not appointed a statutory Data Protection Officer, as we are not legally required to do so. The contact above is the correct route for all data-protection matters.
Territorial scope and EU users. ScreenReady is directed at users in the United Kingdom. We do not market or direct the Service to individuals located in the EU/EEA. If you access the Service from the EU/EEA, you do so on your own initiative; we do not consider ourselves to be "offering services to" data subjects in the EU within the meaning of Article 3(2) of the EU GDPR, and on that basis we have not appointed an Article 27 EU representative. If our EU user base or marketing activity changes such that this no longer holds, we will review and appoint a representative accordingly.
The UK supervisory authority is the Information Commissioner's Office (ICO) (being renamed the Information Commission under the Data (Use and Access) Act 2025). References in this Policy to the ICO should be read accordingly.
2. Scope of this Policy
This Policy applies to personal data we process about visitors to getscreenready.com, registered users of the Service, and subscribers to our paid (Pro) tier. It does not apply to third-party websites we link to. Where we act only as a processor on behalf of an organisation (for example, if your employer or university provides ScreenReady to you), the controller is that organisation, and you should consult their privacy notice first; we will direct your request to them where appropriate.
3. The personal data we collect
3.1 Account data
When you sign in we collect and store your email address. We use passwordless magic-link authentication, so we never create, ask for, or store a password.
3.2 Interview data
When you complete a mock interview we store: the role and company you practised for and any job description or CV summary you choose to provide; the questions generated for your session; your transcribed answers (converted from speech to text in your browser); the AI-generated scores and feedback; your overall score and verdict; and a delivery & presence summary when you use camera mode (see Section 3.3).
Your webcam video and raw microphone audio are never uploaded to our servers. Speech-to-text conversion happens entirely in your browser using your browser's built-in Web Speech API. We only ever receive the resulting text transcript.
Please do not enter sensitive personal information — such as details about your health, race or ethnic origin, religious or political beliefs, sexual orientation, or trade-union membership — into your free-text answers, job descriptions, or CV summaries. These fields are processed by our AI scoring (see Section 6). General agreement to these Terms does not, by itself, amount to the explicit consent that Article 9 requires. If you nonetheless choose to type such information into your answer, job description, or CV summary, that specific act is the explicit consent we rely on to process it, and we process it for the sole purpose of generating your practice feedback; you can delete the relevant interview result at any time.
3.3 Delivery & presence analysis (camera mode)
If you choose to practise with your camera on, ScreenReady analyses your body language entirely within your browser to give you delivery coaching — eye contact, posture, and facial expression. This runs on your device using on-device models (the open-source Mediapipe library, which executes locally and sends nothing to Google in this context). Your video frames, facial landmarks, and any biometric features are processed in memory on your own device and immediately discarded. We do not create, store, or upload any facial template, image, recording, or other biometric identifier, and this analysis is never used to identify or authenticate you.
The only things that leave your browser are your answer transcript (see Section 3.2) and, in camera mode, a small, non-identifying numeric summary — a handful of 0–100 scores for eye contact, posture, composure, and overall presence. We store this summary alongside your interview result so you can see your delivery breakdown, and it contributes a small, capped portion of your overall score. If you practise in text-only mode, no camera analysis occurs and none of this data is produced.
3.4 Scoring-research dataset (optional)
If you opt in via our consent banner, we add a pseudonymised copy of your interview answers (transcripts) and their AI-generated scores to an internal research dataset that we use to calibrate and improve our scoring. Before storage, we automatically remove direct identifiers from your transcripts — email addresses, phone numbers, web links, and long number sequences — and these records are not linked to your name, email, or account. Where available, the pseudonymised numeric delivery & presence scores described above are included; no images, video, or biometric data are ever part of this dataset. You may optionally tell us whether an interview led to a job offer, which helps us measure scoring accuracy.
Contributing is entirely optional. If you decline via the banner, nothing is added. You can withdraw at any time by declining in the banner or emailing us. We apply pseudonymisation to minimise the risk of re-identification; because residual risk can never be reduced to zero, we treat these records carefully and process them only on the basis of your consent.
3.5 Payment data
Payments are processed by Stripe. We never see or store your full card number, CVV, or bank details. We store only your Stripe customer ID, your subscription status (Pro / free tier), and the limited billing metadata Stripe returns to us (for example, the country and last four digits associated with a payment, where provided).
3.6 Usage, analytics, and advertising data
With your consent, we use Google Analytics 4 to collect aggregated data about how visitors use the site — pages visited, session duration, referral source, and device type — configured to avoid identifying you personally.
Also with your consent, we use Google Ads for advertising measurement and remarketing. This lets us measure conversions (for example, when a visit to the site leads to a sign-up or purchase) and build remarketing audiences so that we can show you our own ScreenReady adverts on other Google services and partner sites. This may involve setting advertising cookies and sharing conversion and audience data with Google. We use Google Consent Mode: until you accept via the banner, these analytics and advertising tags load in a restricted, consent-denied state — they do not set advertising cookies or use your data to identify you or build advertising audiences, though a limited amount of aggregated, non-identifying information may still be sent to Google. If you accept, analytics and advertising cookies are set and the corresponding data is shared with Google for the purposes described here. You can decline analytics and advertising cookies via the banner and change your choice at any time.
3.7 Error-monitoring data
We use Sentry to capture server-side errors. Error reports may include your session ID, the URL you were on, and a technical stack trace. We use this solely to debug and improve the reliability and security of the Service.
3.8 Communications
If you email us, we process the content of your message and your contact details to respond to you and keep a record of the correspondence. Email sent to [email protected] is routed through Cloudflare Email Routing and forwarded to our inbox, which is hosted on Google's Gmail.
Service (transactional) emails. To operate the Service we send you essential emails — your magic sign-in link, your interview results and reports, and messages about your subscription or account (for example, billing and cancellation confirmations). These are necessary to provide the Service you have signed up for, and you cannot opt out of them while you hold an account.
Marketing communications. We may also send you marketing emails promoting our own Service — for example, reminders about the free mock interviews you have left, tips to improve your practice, new features, and offers to upgrade to Pro (including free-trial and discount offers). We send these to registered users on the basis of our legitimate interests in retaining customers and promoting our own similar services (Article 6(1)(f) UK GDPR), and, for the email channel, in reliance on the "soft opt-in" under Regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR) — we obtained your email when you signed up for the Service, we only market our own similar interview-practice products, and we give you a simple way to refuse this marketing both when we collect your email and in every message.
You can opt out of marketing at any time, with no effect on your account or the service emails above. Every marketing email includes a one-click unsubscribe and a "Manage preferences" link that takes you — without needing to sign in — to a page where you can turn marketing emails on or off. You can also email us at [email protected]. We record your choice and act on it promptly; opt-out requests are actioned as soon as they reach us.
3.9 Cookies and local storage
See Section 7.
3.10 Do you have to provide this data?
Providing your email address and your interview inputs (your answers and any role, company, job-description, or CV details you enter) is necessary to create an account and use the Service; if you do not provide them, we cannot provide the Service to you. Providing camera-mode data, contributing to the scoring-research dataset, and allowing analytics cookies are all optional, and the core Service works without them. Payment information is required only if you choose to subscribe to Pro or buy an interview pack.
4. Special category and biometric data
UK GDPR gives extra protection to "special category" data (Article 9), which includes biometric data processed for the purpose of uniquely identifying a person. As the data controller, we only "process" data that we actually receive — data we never obtain cannot be personal data we control, under Article 4(2)'s definition of processing as an operation performed on data.
We do not receive, and therefore do not process, any biometric data. Camera-mode delivery coaching (Section 3.3) runs entirely inside your own browser, on your own device, using an on-device software library. Your video frames and any facial landmarks it derives are created, used, and discarded in your device's memory — they are never transmitted to us, and we have no access to them at any point. The only outputs of that camera-mode analysis that reach our servers are a small set of non-identifying numeric scores (for example, "eye contact: 72/100"), alongside your answer transcript described in Section 3.2. Those scores:
- cannot be reversed to reconstruct your image, face, or any biometric template;
- are not used, by us or anyone, to identify or authenticate you; and
- are, in isolation, ordinary numeric data — not biometric data — because they carry no capacity for identification.
On this basis, ScreenReady does not hold or process Article 9 special-category biometric data in connection with camera mode. The data that could qualify as biometric — your video frames and any facial landmarks derived from them — is generated, used, and discarded entirely on your own device; it never crosses the boundary onto our servers or into our possession in any form. Because we never receive that data, it never becomes personal data that we, as controller, process — regardless of what analysis takes place locally on your device to produce your delivery scores.
We do not deliberately collect any other special-category data. If you voluntarily include such information in your free-text answers (see the notice in Section 3.2), we process it only to generate your feedback and rely on your explicit consent (Article 9(2)(a)); you can remove it by deleting the relevant result.
5. How and why we use your data, and our lawful basis
We only process your personal data where we have a lawful basis under Article 6 (and, for any special-category data, Article 9):
| What we do | Personal data used | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Provide the interview-practice Service and store your history | Account data, interview data | Contract — Art 6(1)(b) |
| Generate personalised questions and AI scores/feedback | Role, company, job description, CV summary, answers | Contract — Art 6(1)(b) |
| Provide in-browser delivery & presence coaching and factor a capped portion into your score (camera mode) | Numeric delivery scores | Contract — Art 6(1)(b) (you choose camera mode) |
| Send your magic sign-in link and post-interview email reports | Email address, interview results | Contract — Art 6(1)(b) |
| Send marketing emails about our own Service (usage reminders, feature and Pro/offer emails) — you can opt out any time | Email address, subscription status, interviews-used count | Legitimate interests — Art 6(1)(f); PECR reg. 22 soft opt-in for the email channel |
| Manage your subscription and take payment | Stripe customer ID, subscription status | Contract — Art 6(1)(b); and Legal obligation — Art 6(1)(c) for accounting/tax records |
| Calibrate and improve our AI scoring via the pseudonymised research dataset | Pseudonymised transcripts and scores | Consent — Art 6(1)(a) (withdraw any time) |
| Site analytics | Usage/analytics data | Consent — Art 6(1)(a) |
| Advertising measurement and remarketing of our own Service (Google Ads) | Usage/advertising data, conversion events | Consent — Art 6(1)(a) |
| Error monitoring, fraud prevention, and securing the Service | Error-monitoring data, account data | Legitimate interests — Art 6(1)(f) |
| Handle complaints, respond to your emails, and exercise/defend legal claims | Communications, relevant records | Legitimate interests — Art 6(1)(f); Legal obligation — Art 6(1)(c) where applicable |
| Any special-category data you choose to include in answers | Free-text answers | Explicit consent — Art 9(2)(a) |
Where we rely on legitimate interests, we have considered your rights and freedoms and concluded our interest is not overridden by them; you can ask us for more detail or object (see Section 13). Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
6. AI processing and automated decision-making
We use the Anthropic Claude API to generate interview questions and to score and give feedback on your answers. To do this, your role, company, job description, CV summary, and interview answers are sent to Anthropic for processing. Under our commercial terms with Anthropic, your data is not used to train Anthropic's models.
Our AI scoring is for practice and feedback only. It does not make any decision that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of the automated decision-making rules in Articles 22A–22D of the UK GDPR (as amended by the Data (Use and Access) Act 2025). We do not use it to make automated decisions about employment, eligibility, creditworthiness, or any other matter affecting your rights. The scores and verdicts are coaching signals to help you prepare and carry no consequence outside the Service. If you ever have concerns about how a score was produced, you can contact us using the details in Section 1.
7. Cookies and similar technologies
We use the following:
- Authentication cookie — keeps you signed in (a session cookie that expires after 30 days of inactivity). This is strictly necessary to provide the Service, so no consent is required.
- Cookie-consent preference — stored in your browser's
localStorageso we don't show the banner on every visit. - Google Analytics cookies — set only if you accept analytics cookies via the banner.
- Google Ads cookies — set only if you accept via the banner, and used for measuring our own ad conversions and for remarketing our own Service (see Section 3.6).
Our advertising cookies are used only to measure conversions on our own adverts and to remarket our own Service to you; we do not sell your data and we do not use them to let third parties target you with their own advertising. You can manage non-essential cookies via the banner at any time, and you can block or delete cookies through your browser settings (though essential cookies are needed for sign-in to work).
8. Sharing your data
We share personal data only with the sub-processors listed in Section 9, and otherwise only: where you ask or direct us to; to comply with a legal obligation, court order, or lawful request from a public authority; to establish, exercise, or defend legal claims, or to protect the rights, safety, and property of ScreenReady, our users, or others; or in connection with a business reorganisation, merger, or sale, in which case we will ensure your data remains protected and notify you of any change of controller.
We never sell your personal data. With your consent, we share limited conversion and audience data with Google in order to measure and target our own advertising, as described in Section 3.6; we do not otherwise share your data for third parties' advertising.
9. Sub-processors
We use the following service providers ("sub-processors") to deliver the Service. Each is bound by their own standard-form data-processing terms, published and incorporated by reference below, which we accept as part of using their platform; these are the terms that govern exactly how each provider handles the personal data it processes on our behalf. For the full detail of a given provider's safeguards, retention, and security practices, please refer to their own privacy policy and data-processing terms linked in the table.
| Sub-processor | What it does for us | Where data is processed | Transfer safeguard | Privacy policy | Data-processing terms |
|---|---|---|---|---|---|
| Anthropic | AI question generation and answer scoring (Claude API) | USA | EU SCCs / UK Addendum | Privacy Policy | Commercial / DPA terms |
| Stripe | Payment processing and subscription management | USA / EU | EU-US Data Privacy Framework; SCCs / UK Addendum | Privacy Policy | Data Processing Agreement |
| Resend | Email delivery — service emails (sign-in links, results reports) and marketing emails about our own Service | USA | SCCs / UK Addendum | Privacy Policy | Data Processing Addendum |
| Render | Cloud hosting / application infrastructure | USA | EU-US Data Privacy Framework (incl. UK Extension); SCCs / UK Addendum | Privacy Policy | Data Processing Addendum |
| Neon | Managed PostgreSQL database hosting | USA | EU-US Data Privacy Framework (incl. UK Extension); SCCs / UK Addendum | Privacy Policy | DPA · Sub-processors |
| Google (Analytics & Ads) | Site analytics, and advertising measurement & remarketing of our own Service, with your consent | USA / EU | EU-US Data Privacy Framework; SCCs / UK Addendum | Privacy Policy | Ads Data Processing Terms |
| Sentry | Server-side error monitoring | USA | SCCs / UK Addendum | Privacy Policy | Data Processing Addendum |
| Cloudflare | Bot-protection challenge (Turnstile) on sign-in; and email routing — forwarding messages sent to [email protected] to our inbox (a Google Gmail account) | USA / Global | SCCs / UK Addendum | Privacy Policy | Data Processing Addendum |
If you have questions about how a specific sub-processor handles your data beyond what their own policy describes, or want to know which sub-processors are used for a particular feature, contact us using the details in Section 1.
The open-source Mediapipe library is used as an on-device software library for camera-mode coaching (Section 3.3) and is not a data-sharing sub-processor, because no personal data is transmitted to Google through it.
We load the Inter web font via Google Fonts. When your browser requests these font files, your IP address is necessarily transmitted to Google in order to deliver them. We do not use Google Fonts to track or identify you, and it sets no cookies.
10. International data transfers
Our infrastructure and several sub-processors are located in the United States, so your personal data may be transferred to and processed there. Whenever we transfer personal data outside the UK, we ensure an appropriate safeguard recognised under UK GDPR is in place, which may include the recipient's certification under the EU-US Data Privacy Framework and its UK Extension (applicable to Stripe, Render, Neon, and Google) and/or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's Standard Contractual Clauses, together with a transfer risk assessment. For transfers subject to the EU GDPR, we rely on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses. You can ask us for more information about the safeguards applied to a specific transfer.
11. Data retention
| Data | Retention |
|---|---|
| Account data | Kept while your account is active; deleted within 30 days of an account-deletion request. |
| Interview results | Kept for the life of your account so you can view your history. You can delete individual results at any time. |
| Pseudonymised scoring-research dataset | Retained to improve our scoring. As these records are not linked to your account and contain no information identifying you, they may persist after account deletion. |
| Payment records | Retained by Stripe and by us as required by financial and tax law (typically 7 years). |
| Analytics data | Retained by Google Analytics for 14 months. |
| Error logs | Retained by Sentry for a limited period for debugging, then deleted in line with Sentry's defaults. |
| Complaints and email correspondence | Retained for as long as needed to handle the matter and for a reasonable period afterwards for our records. |
| Marketing opt-out (suppression) record | Kept for as long as your account exists so we continue to honour your choice not to receive marketing. |
Where we are required to keep data to comply with a legal obligation or to defend legal claims, we may retain it for the relevant statutory or limitation period.
12. How we protect your data
We apply appropriate technical and organisational measures, including: encryption in transit (TLS); encryption at rest for stored account and interview data; passwordless authentication (no password for us to store or for an attacker to steal); never handling raw card data (payments go directly to Stripe, a PCI-DSS Level 1 provider); keeping webcam and microphone data on your device; and access controls limiting who can access systems holding personal data.
No method of transmission or storage is ever completely secure, and we cannot guarantee absolute security. Please keep the device and email account you use to sign in secure, and contact us immediately if you believe your account has been accessed without your permission.
Personal data breaches. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where required, within 72 hours. Where a breach is likely to result in a high risk to you, we will also notify you without undue delay, in line with Articles 33 and 34 of the UK GDPR.
13. Your rights
Under UK and EU GDPR you have the right to: access a copy of your data; rectification of inaccurate or incomplete data; erasure of your account and associated personal data; restriction of our processing in certain circumstances; portability of certain data in a structured, machine-readable format; objection to processing based on legitimate interests; and to withdraw consent (for analytics cookies and the scoring-research dataset) at any time. You also have an absolute right to object to direct marketing at any time: if you do, we will stop sending you marketing emails — use the unsubscribe or "Manage preferences" link in any marketing email (see Section 3.8), or email us. As explained in Section 6, we do not carry out automated decision-making with legal or similarly significant effects.
To exercise any of these rights, email [email protected]. We may need to verify your identity, and where we need further information to deal with your request we may pause the response period until you provide it. We will respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do. Exercising your rights is normally free, but we may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, as the law permits.
14. Complaints
If you are unhappy with how we have handled your personal data, you have the right to complain directly to us, and we encourage you to do so first so we can put things right. You can complain by emailing [email protected] with the subject line "Data protection complaint", or by using any contact method we make available. In line with the Data (Use and Access) Act 2025, we will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate it, and keep you informed of progress and the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint, helpline 0303 123 1113 — although we would appreciate the chance to resolve your concern first. If you are in the EU/EEA, you may instead complain to the supervisory authority in your country of residence, work, or where the alleged infringement occurred.
15. Children
The Service is intended for adults and is not directed at anyone under 18. We do not knowingly collect personal data from anyone under 18. We ask users to confirm they are 18 or over when they sign up, and we do not require identity verification to do so. If we become aware that someone under 18 has created an account, we will close it and delete the associated personal data. If you believe a person under 18 has provided us with personal data, please contact us and we will delete it.
16. Third-party links
The Service may contain links to third-party websites. We are not responsible for their privacy practices or content. We encourage you to read the privacy notice of any site you visit.
17. Changes to this Policy
We may update this Policy from time to time. Where changes are material, we will notify registered users by email and update the "Last updated" date above. Where a change requires your fresh consent, we will ask for it.
18. Contact
For any privacy-related question, request, or complaint, contact us at [email protected].