Version: 2026-07-08

Privacy Policy

Effective date: 2026-07-08 · Version marker: 2026-07-08

Who we are. InterviewerAI is operated by KwantumLabs, Inc., a Delaware corporation (United States). Privacy contact: privacy@interviewerai.app.

The one-paragraph version. If you have an InterviewerAI account (you build and run research studies), we are the controller of your account data — Part A. If you took a survey or interview that runs on InterviewerAI, the organization that invited you controls your data and we process it on their behalf — Part B. We run no advertising trackers anywhere, and the survey experience itself sets no cookies at all — Part C. We never sell personal information.


Part A — Customers and account data (InterviewerAI is the controller)

This part applies to people who create or use an InterviewerAI organization account (researchers, team members, billing contacts).

A.1 What we collect, why, and on what legal basis

Data Source Purpose Legal basis (GDPR Art. 6)
Name, work email You, at signup/invite Account creation, login (magic links), team management Contract (Art. 6(1)(b))
Login security data (session tokens, MFA enrollment, hashed backup codes) Generated Authenticating you, protecting your account Contract; legitimate interest (security)
Billing details (plan, purchases, invoices) You / payment processor Charging for the service Contract; legal obligation (tax/accounting)
Support correspondence You Resolving your requests Contract; legitimate interest
Product usage telemetry (dashboard features used, API/agent tool calls, usage meters) Generated Operating, securing, improving, and billing the service Legitimate interest; contract (metering)
Audit log entries (administrative actions in your organization) Generated Security, accountability, compliance Legitimate interest; legal obligation

We send transactional email (login links, operational notices) through our email subprocessor. Payment processing (Stripe) is upcoming: card data will be handled by the payment processor and will never touch our servers; this policy and the subprocessor list will be updated before it launches. Product analytics (PostHog) is likewise planned for the customer dashboard only; if enabled, it will never run on survey/respondent pages, and this policy and the subprocessor list will be updated first.

A.2 Retention (account data)

Account data is retained for the life of the organization account plus up to 24 months after closure, except billing/tax records retained as required by law and audit logs retained per our security policy.

A.3 Your rights (account holders)

You may access, correct, export, or delete your account data, object to or restrict processing, and complain to a supervisory authority. Contact privacy@interviewerai.app.


Part B — Survey respondents (your survey's organizer is the controller)

This part applies to people who take a survey or interview hosted on InterviewerAI.

B.1 Who is responsible

The organization that invited you to the survey (our customer) is the data controller. It decides what the survey asks, why, and on what legal basis. InterviewerAI is its processor: we host the survey and process your data only on that organization's instructions, under a Data Processing Agreement. For questions about the survey's purpose or to exercise your rights, your first point of contact is the organization that invited you — it is identified in the survey's consent screen. We will help route requests that reach us instead (B.5).

B.2 What is processed when you take a survey

B.3 AI processing — disclosed plainly

Surveys on this platform are AI-moderated. Depending on how the organizer configured the survey, your responses may be processed by AI subprocessors to:

Our AI subprocessors are engaged under agreements that prohibit using your data to train their generalized models. The full list, with regions and links to each vendor's own privacy policy, is at /subprocessors. Processing occurs in the United States — see B.6.

Automated decision-making (GDPR Art. 22). The AI decides only conversational matters — which follow-up question to ask next — and produces quality flags. It does not make decisions with legal or similarly significant effects about you. Where an automated quality check affects whether your response is accepted for the study (and any associated reward), the survey organizer can review and override that outcome — contact the organizer, or the panel that invited you, to contest a decision.

B.4 Rewards, panels, and who pays you

If you reached the survey through a research panel (e.g., Prolific, Dynata, Cint), your relationship — including your reward — is with that panel under its own privacy policy (linked at /subprocessors). Panels receive only completion-status signals and the pseudonymous IDs they issued — never your response content. If the survey organizer offers rewards directly through the platform's incentive integration (Tremendous), the reward is funded and directed by the survey organizer; Tremendous processes the data needed to deliver your reward under its own terms.

B.5 Your rights (respondents)

You can, at any time:

If you contact us and we can identify the controller, we forward your request to them without undue delay.

B.6 Where your data is processed

Hosting, storage, and AI processing take place in the United States (see /subprocessors for the per-vendor list). For respondents in the EEA/UK/Switzerland, transfers from your survey organizer to us are protected by the EU Standard Contractual Clauses incorporated in our Data Processing Agreement, plus technical safeguards: application-layer AES-256-GCM encryption of interview transcripts and session metadata, pseudonymous IDs, and salted-hash IP storage. We do not currently offer EU data residency.

B.7 Retention (respondent data)

Respondent data is kept only as long as the research purpose requires:

Category Retention
Survey responses (text answers and transcripts) For the duration of the research project. Deleted when the survey organizer deletes the project, when a retention window set for the project elapses after the study closes (where the organizer has configured one), or on your individual erasure request.
Audio recordings — completed sessions Deleted 90 days after session completion
Audio recordings — test/terminated sessions Deleted after 30 days
Test sessions (researcher dry-runs) Deleted in full after 30 days
Export artifacts (files generated for the organizer) Deleted after 7 days
Panel provider event payloads Anonymized after 180 days
Consent records Retained as proof of lawful processing
Audit logs (administrative/security events; no response content) Retained per our security policy

If you withdraw consent (including audio consent) during a study, audio recordings already collected are deleted promptly on withdrawal rather than held to the standard audio window (see B.5 for how to withdraw).

Deletion is enforced by the platform's retention engine, which runs automatically (daily by default) and removes the stored files themselves, not just database references.

B.8 Security

Security measures apply to every plan equally and include: TLS for all transmissions; application-layer AES-256-GCM encryption of interview transcripts and session metadata at rest (in addition to disk-level encryption); HMAC-SHA256 tamper-evidence on answer and audit records; strict per-organization data isolation enforced in code and regression-guarded in CI; multi-factor authentication available for staff accounts; and a tamper-evident audit log of administrative actions. If we become aware of a personal-data breach affecting respondent data, we notify the affected survey organizers without undue delay so they can meet their own notification duties (GDPR Art. 33/34).


Part C — Cookies and similar technologies

Survey/respondent pages (/s/…, /start, interview pages): no cookies. No third-party analytics, no advertising trackers, no fingerprinting. Your browser's local/session storage is used solely for functional purposes during your interview: remembering your place if the page reloads, your chosen audio output device, and your chosen interviewer speaking speed. These are strictly necessary/functional for the service you are actively using and are not used to track you across sites.

The one possible exception is bot protection: if a survey organizer enables a CAPTCHA challenge at the entry page, that security provider may set its own cookie and analyze the request solely to tell humans from bots. This applies only at entry, never during the interview, and only when the organizer turns it on.

Customer dashboard: one first-party, essential session cookie (iai_session; httpOnly, secure, SameSite=Lax, 7-day lifetime) used to keep you logged in. This session cookie is exempt from consent under the ePrivacy Directive (Art. 5(3)) because it is strictly necessary to provide the service you requested — keeping you signed in; no advertising or cross-site tracking cookies are set. If dashboard product analytics (PostHog) launches, this section and the subprocessor list will be updated before it is enabled, and it will remain dashboard-only.


Children

InterviewerAI is a business research platform and is not directed at children. Accounts may only be created by adults acting for an organization. Where a survey organizer researches minors, the organizer is the controller and is responsible for the lawful basis and any parental-consent requirements in its jurisdiction, as required by our Acceptable Use Policy; the platform does not knowingly collect children's data for its own purposes. If you believe a child's data was submitted to us in error, contact privacy@interviewerai.app and we will assist the controller with deletion.


US state privacy rights

Depending on your state of residence (e.g., under the California Consumer Privacy Act as amended), you may have rights to know, access, correct, and delete personal information, and to non-discrimination for exercising them. We do not sell personal information and do not share it for cross-context behavioral advertising. For respondent data we act as a "service provider"/processor — direct requests to the survey organizer (see B.5), and we will assist; for account data contact privacy@interviewerai.app. We do not use or disclose sensitive personal information for purposes other than providing the service.


Changes, contact, complaints

We will post changes here with a new effective date and version; material changes to respondent processing are also notified to customers (controllers) in advance. Contact: privacy@interviewerai.app — KwantumLabs, Inc., United States. You may also lodge a complaint with your supervisory authority (B.5).