Privacy Policy

  • Product: Dawnstep
  • Operator: Dawnstep (operated by Vatsal Solanki)
  • Effective date: October 9, 2026
  • Privacy contact: support@dawnstep.app
  • Governing jurisdiction: Canada (the federal laws of Canada and the laws of the province or territory where Dawnstep’s operator lives)

1. The short version

  • Dawnstep is a tool for practising job interviews out loud. You paste a job description, answer questions by voice or text, and get written feedback.
  • To do this, we send some of your content to outside AI services. We ask for your permission in the app first, separately from our Terms of Use, and you can say no.
  • Your spoken answers are turned into text. The raw recording is deleted 24 hours after it has been turned into text (24 hours after upload if that fails; about 48 hours at the very most). The text stays until you delete the session or your account.
  • We do not sell your data. We do not show ads. We do not track you across other companies' apps or websites. We do not share your results with employers or recruiters.
  • We do not score or comment on your accent. This is a practice tool, not a prediction of whether you will be hired.
  • You can delete your account. Remaining practice credits are lost when you do.
  • The AI providers we use have their own retention and data-use terms, which we do not control. Section 4 sums up what they say.

2. What we collect and why

What Examples Why we need it
Email address and account ID The address you sign in with; an internal user ID To create your account, send sign-in codes, link purchases to you, and reply to support requests
Consent records Which AI-processing consent you accepted, which version, when, and whether you withdrew it To respect your choices and show that we did
Data-request records That a copy of your data was requested for your account, when, how (in the app, or by us after checking it was you), and how many rows it held. Never the content To show that we answered your request
Job text The job description you paste; an optional role or company name; an optional short summary of your own experience, which you can type or fill in by importing the text of a PDF or Word resume file (see below) To understand the role and plan relevant questions
Role summary The AI-generated summary of the role that you review, edit and confirm To base your questions on something you have checked
Questions, answers and corrections Generated questions; your typed answers or transcripts of your spoken answers; any corrections you make To run the practice session and write feedback
Audio recordings Your spoken answers, up to 120 seconds each To turn speech into text
Feedback and summaries AI-generated feedback on each answer and a session summary To show you what to improve
Product-interaction events Short event names such as "practice started" or "feedback viewed", with a few small machine labels or numbers (never your text or recordings), and the time To see which parts of the app work and which do not, and to keep the service reliable. Stored on our own server and linked to your account while it exists. We do not use a third-party analytics service
Anonymous counts before you sign in A count that the Welcome screen or the sign-in screen was shown, or that a sign-in code was requested or refused. Only the name of the step and the date are added to a daily total. No email address, account, device or IP address is stored with it To see where people leave before they have an account, so we can fix it. Not linked to you. We use your IP address only for a short in-memory limit against abuse and do not write it down. Deleted after 30 days
Reports you send A report about a question, feedback or summary: what kind, why, and an optional note of up to 500 characters To find and fix inaccurate or unsafe AI output
Credits and purchases Your credit balance history; which pack you bought, when, and the store's transaction ID To give you the credits you paid for and to recover your balance if you sign in again
Support messages Emails you send us To help you
Technical data IP address, device and operating-system type, app version, request logs, and error reports if we add an error-reporting tool To keep the service running, secure and fixable

What we do not collect: your contacts, location, photos, camera, or advertising ID. We do not build voiceprints and we do not analyse your voice for accent, emotion or personality. To show you plain numbers such as pace, we count the words in your transcript and measure how long each recording is; we keep that length with your answer until you delete the session or your account. We do not receive your card or bank details; the app store handles payment.

Importing a resume file. If you choose to import a PDF or Word (.docx) file to fill in your experience, the app sends the file to our server once. The server reads it in memory to get its text and then discards it: we do not store the file, and we do not keep its name. Before showing you the text we remove email addresses, phone numbers and web links we find (pattern-based, so it may miss some: please check the text). You can edit the text. Only the text you keep and submit is saved, as your experience summary, and it is sent to the AI provider named below like the rest of your job text. Resumes often contain personal details such as your name, past employers and addresses: please delete anything you do not want shared. We do not read other parts of your device, and the app does not ask for access to your photos, files or contacts beyond the single file you choose.

Please do not include sensitive personal information in what you paste or say. This includes health details, immigration status, government ID numbers, financial account numbers, and personal details about other people. Anything you include is processed like the rest of your content, including by the AI providers described below.

3. How we use your data

We use your data to:

  • run practice sessions and produce feedback;
  • keep your account secure and prevent abuse;
  • process purchases and keep your credit balance correct;
  • answer support requests;
  • fix problems and keep the service reliable, including by looking at the product-interaction events described in section 2; and
  • meet legal obligations.

We do not use your practice content to train AI models. If we ever want to use content for evaluation or improvement, we will ask for separate, explicit permission and update this policy first.

We do not read your practice content except where needed to help with a support request you made, investigate abuse or a security problem, or meet a legal obligation.

4. AI providers and other service providers

Your permission for AI processing

Before we send your content to any AI provider, the app asks for your permission. This is separate from our Terms of Use. If you decline, the AI features (role understanding, question planning, transcription, feedback) are not available. Our server also refuses to process your content with AI unless a current permission is on record. You can withdraw permission later in Settings ("Withdraw permission"); this stops future processing and does not delete what is already saved. If we change which providers receive your content, we will ask again.

Who receives what

Provider What it does for us What it receives Retention and data-use terms
Anthropic Understands the job description, plans questions, writes feedback and summaries, and (only when you ask) suggests example wording built from your own answer and experience Job description text, your experience summary, the role summary you confirm, the interview questions made for you, your answers as text (typed, or transcribed from your voice) Says it deletes what we send from its systems within 30 days (longer only where its safety rules or the law require; up to 2 years if its usage policy was broken). Its commercial terms say it may not train models on our data.
OpenAI Converts your spoken answers to text; reads questions aloud Your audio recordings; question text Says it does not use API data to train its models unless the customer opts in (we have not). Abuse-monitoring logs are kept up to 30 days, except that speech-to-text requests are not kept in them; read-aloud requests (the question text, not your voice) are kept up to 30 days.
Supabase Account sign-in, database, private file storage All data we store (sections 2 and 6) Keeps what we store for as long as we do (section 6). Its daily database backups are kept 7 days. Its sign-in service logs sign-in events; we switch off its option to write those logs to the database.
RevenueCat, Apple App Store, Google Play Process and confirm purchases Purchase and transaction information; the stores also hold your payment details RevenueCat says it is a processor of purchase data and deletes it when we ask. Apple and Google keep your payment details under their own terms.
Hosting provider Runs our server Data passing through our server Fly.io runs our server in Toronto, Canada. It keeps its own operational logs for a period it sets; we do not copy them elsewhere.
Resend Sends the email that carries your sign-in code Your email address and the code (which expires after 15 minutes) Keeps email content, delivery status and logs for 30 days.
Error-reporting tool (planned, not yet in use) Would help us find crashes Technical error data only; to be configured so practice content is removed Not used. If we add one, we will say so here first.

Provider retention is not fully under our control. Each provider keeps data for its own period and under its own terms. The summary above comes from each provider’s own published pages, read on 8 October 2026, and those pages can change. We do not promise that a provider has deleted its own copy when you delete your account: copies at Anthropic and OpenAI expire on their own schedule (up to 30 days, and longer only where their rules or the law require), and sign-in emails stay at Resend for up to 30 days.

When you delete your account, we delete the data we hold and we ask RevenueCat to delete its record of your purchases. We cannot make the AI providers delete their copies sooner than their own schedules. See section 9.

5. Audio, transcripts and typed answers

  • Recording happens only when you start it, and each answer is limited to 120 seconds.
  • The recording is sent to our server, which checks it and stores it in private storage linked to your account, and sends it to OpenAI for transcription. The app cannot read or write that storage directly; only our server can.
  • The raw recording is deleted 24 hours after it has been transcribed. If transcription fails, it is deleted 24 hours after upload, which leaves time to retry. If you retry late and it then succeeds, the 24 hours start again, so in the worst case a recording is kept for about 48 hours after upload. A cleanup job does the deleting; it runs every 15 minutes on our server.
  • You can also delete your recordings yourself, right now. In Settings, “Delete my recordings now” removes every saved recording of your voice immediately instead of waiting for the 24 hours. Your typed text, transcripts and feedback stay until you delete the session or your account.
  • Free rehearsal does not send your voice anywhere. The “Rehearse common questions” practice uses a fixed list of questions on your phone. What you say is recorded only so you can listen back, stays on your phone, is not sent to us or to any provider, and is deleted when you move to another question or leave the screen. The app only counts, without any content, that a rehearsal was started.
  • The transcript is kept until you delete the session or your account. You can correct a transcript before you submit it for feedback. Once feedback has been produced for an answer, that answer's transcript cannot be changed.
  • Transcripts can be wrong, especially with background noise or unfamiliar words. Check them.
  • You can type an answer instead of recording one. Typed answers are treated like transcripts.
  • Question text is sent to OpenAI to produce spoken audio.

6. How long we keep data

Data How long
Raw audio recordings Deleted 24 hours after successful transcription (24 hours after upload if transcription fails; about 48 hours at the very most if a late retry succeeds)
Transcripts, answers, corrections, feedback, session summaries Until you delete the session or your account
Job text, experience summary, role summary Until you delete the last session built from them, or your account. They cannot be deleted on their own: if you start a job but never begin a session they stay until you delete your account
Account and profile Until you delete your account
Consent records Deleted with your account
Data-request records Kept for up to 6 years after you delete your account, with the link to your account removed, to show that requests were answered. They hold no content
Credit and purchase records Kept for up to 6 years (the period Canadian tax law asks businesses to keep financial records), also after you delete your account, for accounting, tax and dispute purposes. They are kept without your name, email or account ID: when your account is deleted, your account ID is removed from our internal reference keys on these records
Product-interaction events and technical job logs Product-interaction events are deleted after 90 days and technical job records after 180 days, with the link to your account removed when you delete your account. Event names, model names, token counts, timing and error codes only; no practice content
Reports you send Deleted with your account
Record of a deletion request Kept for up to 6 years. It keeps the old account ID and which deletion steps finished, so we can show the request was handled
Support emails Kept for up to 12 months after the conversation ends, then deleted.
Technical logs Server logs carry event codes and a shortened account reference, never the text of your answers or your recordings, and our host keeps them only for a short period. We aim to keep practice content out of logs.
Backups Daily backups are kept for 7 days. Deleted data may remain in backups until they expire.
Copies held by AI and other providers Set by each provider; not controlled by us

7. What we do not do

  • We do not sell your personal data.
  • We do not share your data for advertising. There are no ads, and the app does not track you across other companies' apps and websites.
  • We do not share your results, answers or recordings with employers, recruiters or job boards. We do not tell anyone you used the app. Employers cannot buy access to your sessions.
  • We may disclose data if the law requires it, to protect people's safety, or as part of a business transfer. If ownership of the service changes, we will tell you.

8. Your choices

  • Correct transcripts before feedback.
  • Withdraw AI-processing permission in Settings.
  • Delete your saved recordings at any time in Settings (“Delete my recordings now”), without deleting anything else.
  • Delete a single practice session in the Sessions tab, or your whole account in Settings ("Delete my account…"), or ask us to delete the account by email if you cannot get into the app. See the Delete Account page.
  • Get a copy of your data. In the app, open Settings and choose "Download my data": it gives you a text file with what you entered and what we generated for you (your job details, answers and transcripts, feedback, credits, purchases and passes). If you cannot get into the app, write to support@dawnstep.app from the email address of your account and we will send you the same file after checking that it is you. It does not include recordings (deleted about 24 hours after they are turned into text), copies held by our AI providers, or records held by the app store and RevenueCat.
  • Ask us a privacy question or make a complaint at support@dawnstep.app.

We will check that a request really comes from you before acting on it, usually by confirming that you control the account's email address. We will not ask for your password, a sign-in code, or card details. We aim to respond within 5 business days.

Your legal rights depend on where you live. We are based in Canada and are guided by the principles of Canada’s federal privacy law (PIPEDA): consent, limiting what we collect and use, safeguards, and access. If you live elsewhere, your local law may give you more rights, and we will respect them where they apply.

9. Deleting your account

You can delete your account in the app (Settings, "Delete my account…", then type DELETE to confirm), or ask us to. Deleting your account removes your profile, sign-in, consent records, job texts, sessions, answers, transcripts, feedback, reports you sent, and any recordings still stored.

  • Remaining practice credits are lost and cannot be restored or refunded by us.
  • What we keep after deletion, as described in section 6: credit and purchase records (without your name, email or account ID); product-interaction events and technical job logs with the link to your account removed; and a record that the deletion was requested. Their retention periods are in the table in section 6.
  • Deleted data may remain in backups until they expire.
  • Copies held by AI providers and by Resend are governed by their own terms (section 4 gives the periods); they expire on their own schedule, and we cannot delete them sooner.

Details are on the Delete Account page.

10. Children

Dawnstep is for adults. You must be 18 or older. At sign-in the app asks you to tick a box saying you are 18 or older and agree to the Terms and this policy; we do not verify your age. It is not designed for children and we do not knowingly collect their data. If you think a child has created an account, contact us and we will delete it.

11. Where data is processed

Our providers may process data in countries other than the one where you live, including the United States. Our server runs in Toronto, Canada, and our database is hosted in Canada (Montreal).

12. Security

We use measures designed to protect your data, including:

  • access controls so each account can read only its own data, and so the app cannot write to our database directly (changes go through our server, which checks them);
  • private storage for recordings (no public links, and no direct access from the app);
  • AI and payment keys kept on our servers, not inside the app; and
  • a design that keeps practice content out of server logs and error reports.

No system is completely secure. If a breach affects you, we will tell you as the law requires.

13. What this tool is, and is not

Dawnstep is a practice tool. AI feedback can be wrong, incomplete or unhelpful, and transcripts can contain mistakes. The app does not predict whether you will be hired, does not verify your qualifications, and does not score your accent. Please see the Terms of Use for more.

14. Purchases

You can buy consumable practice packs (see Practice packs). There is no subscription. The app store processes your payment and shows the price in your local currency. We receive confirmation of the purchase and a transaction ID, not your card number.

15. Changes to this policy

If we make a material change, we will tell you in the app before it takes effect. If a change affects which providers receive your content, we will ask for your permission again.

16. Contact

Dawnstep (operated by Vatsal Solanki)
support@dawnstep.app
Dawnstep is run online and has no public street address. Please contact us by email.