⚠ Draft — pending legal review. Placeholder wording; have a lawyer review before publishing.
Legal
Privacy Policy
Last updated: 2026 · HintFlow (hintflows.com)
This policy explains what HintFlow collects, where it goes, and the choices you have. HintFlow is a desktop application for interview practice. We try to collect as little as possible — but we want to be exact rather than reassuring, so this page describes what the software actually does, including the parts that leave your machine.
1. What we collect
- Account details. The email address you sign in with, and a one-time verification code sent to it.
- A device identifier. At registration we record a salted hash of your operating system's machine identifier, used only to stop one person farming the free signup credits (one account may be created per device). It does not gate signing in, and it is not used to track you across the web.
- Practice transcripts and reports — stored on your device and in the cloud. Every practice session is written to your local application data folder. When you are signed in, the app also uploads sessions the cloud does not have yet, so you can read your history from another computer. What is uploaded is the transcript (who said what), the session summary, the generated report and the mock scorecard, together with metadata: start and end time, turn count, report status and size. Bodies are held in a private object-storage bucket under a key that includes your user id; metadata is held in our database. Both are scoped to your account — a request from a different account for the same session id gets a plain "not found".
- Audio, while a session runs. Your microphone and, on the routes that use it, your computer's own audio output (so the app can hear the interviewer) are streamed live through our server to a speech-to-text provider. The stream is relayed, not recorded: we keep no audio file, and only count how much was sent so we can meter the session.
- Billing records. Payment attempts, membership passes and a credit ledger (every grant and every spend) needed to run your account.
- Diagnostics. When a speech-to-text connection drops we record the session id, a connection id, the close code and how long the connection lasted, so we can find out why. Unhandled server errors are logged with the request path and the error message. Neither contains your transcript.
2. What we do not store
- Your résumé. It is never uploaded. No route on our server accepts one; the upload payload is built from a fixed list of allowed fields on both the app side and the server side, so a résumé cannot ride along even by accident; and there is no column or object for it anywhere in our data model. Your résumé stays in your local knowledge folder, and the personalisation that reads it runs on your own machine.
One honest caveat: if the app generates an interview question that quotes a line from your résumé back at you, that question is part of the session — so that quoted fragment can appear in a transcript, and transcripts are uploaded as described above.
- Raw audio. Relayed for transcription, never written to disk on our side.
- Card and payment details. These are entered on the payment provider's own page. We never see or hold them.
3. Screen capture (Solver)
The Solver panel captures your screen only at the moment you press the capture key — there is no continuous recording, and no capture happens while the panel is merely open. A session holds at most seven frames at a time; frames live in memory for the current question and are dropped when the session ends. We do not store captured images on our servers.
Status, stated plainly: screen capture and on-screen reading are still being built. The shipped build refuses to capture and says so rather than pretending. When this ships, a captured frame will be sent to our vision provider (see below) to be transcribed into text; this page will be updated with the specifics before that happens.
4. Third parties that process your data
We use the following processors. They act on our behalf to return a result; we do not authorise them to use your data for their own purposes. Which speech provider is used depends on the route your session runs on.
- Cloudflare — hosting, database and private object storage for transcripts, reports and account records.
- Deepgram — speech-to-text on the international route.
- Volcengine (火山引擎) — speech-to-text on the mainland-China route, and the interviewer's synthesised voice.
- Cerebras — fast answer and hint generation.
- Alibaba Cloud (Qwen) — scoring, follow-up questions and post-session reports.
- Zhipu (GLM) — fallback generation, and reading captured screenshots when the Solver ships.
- Resend — sending your sign-in code by email.
- 虎皮椒 (Xunhu) — processing WeChat Pay / Alipay payments, where payments are enabled.
These providers operate in different countries, so depending on the route your session uses, your audio and text may be processed outside the country you are in — including in the United States and in mainland China.
The application itself holds no third-party API keys. Every provider call is made through our own server, which supplies the credentials.
5. How we use it
To sign you in, run the features you use, keep your practice history available across your devices, prevent abuse of free credits, process payments, diagnose faults, and provide support. We do not sell your personal information and we do not use your transcripts for advertising.
6. Retention
Cloud transcripts and reports are kept for as long as your account exists — they are meant to be a long-term record of your practice, not a temporary cache. Local copies stay in your application data folder until you remove them or uninstall the app. Account and billing records are kept while your account is active and afterwards as long as tax and accounting rules require. Diagnostic records are short operational logs.
7. Your choices
- Consent. You agree to this policy when you create an account and start using HintFlow. Everything described above is data we need in order to run the service you asked for — we do not sell it, and we do not use it for anything outside providing HintFlow.
- Stop uploading. Uploads only happen while you are signed in. Sign out, or use the app without an account, and nothing is sent to our history storage.
- Local copies. You can delete the files in your application data folder, or uninstall the app, at any time.
- Questions. Email [email protected] if you have a question about your data.
8. Security
Traffic is encrypted in transit. The storage bucket holding transcripts and reports is private and has no public address; every read and write is checked against a signed token for your account. We store no third-party keys in the application.
9. Children
HintFlow is intended for job-seeking adults and is not directed at children under 16.
10. Changes
We may update this policy; material changes will be posted on this page with a new date.
11. Contact
Questions about privacy? Email [email protected].