Skip to main content

Privacy Policy

Effective Date: September 21, 2026

1. Introduction

Desk Dojo LLC ("Desk Dojo," "we," "our," or "us"), a company in the United States, operates the Desk Dojo mobile application (the "App") and the website at deskdojo.co (the "Website"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App or our Website.

Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the App.

2. Information We Collect

2.1 Information You Provide

When you create an account, we collect:

  • Email Address: Used for account authentication, password recovery, and important account notifications.
  • Password: Stored in encrypted (hashed) form. We never store or have access to your plaintext password.
  • Display Name (optional): If you choose to set a display name, it is used to personalize completion certificates, and it is attached to feedback you send us from inside the App (Section 2.7). You may change or remove it at any time.
  • Terms you accepted: When you create an account, we record which version of the Terms of Service and this Privacy Policy you accepted (their effective dates) and when, so we can tell you which version you agreed to.

We do not collect your profile photo, phone number, age, or any other personal demographic information.

2.2 Learning Progress Data

To provide our educational services and track your learning journey, we collect:

  • Lesson completion status and scores
  • Quiz and drill performance (attempts, correct answers)
  • Experience points (XP) earned
  • Daily activity streaks
  • Achievement unlocks and timestamps
  • World/course completion records
  • Swipe game scores and statistics
  • Prestige level (for users who reset and replay content)

2.3 Device Preferences (Stored Locally)

The following preferences are stored only on your device. The setting itself never syncs and is never uploaded:

  • Theme preference (light or dark mode)
  • Sound effects enabled/disabled
  • Haptic feedback enabled/disabled
  • Keyboard shortcut platform preference (Windows or Mac)

Changing one of these does send an analytics event naming the setting and its old and new value, so that we can see which options people use. That event carries nothing else. If you turn analytics off in the App's settings, it is not sent at all.

2.4 Automatically Collected Information

When you use the App, we may automatically collect certain information for error tracking and app improvement:

  • Error and Crash Data: When the App encounters an error, we collect crash reports, error messages, and the sequence of actions leading to the error. This helps us identify and fix bugs.
  • Device and App Information: Our error tracking service collects details about your device and the App so we can reproduce and fix errors: device model and maker, operating system and version, app version, screen size, how much memory and storage the device has, battery state, network connection type, language and region setting, time zone, and a random identifier for this installation. Our analytics service collects a smaller set: device type, app version and build, its bundle identifier, and screen size. We do not collect advertising identifiers.
  • Vendor Identifier (iOS): On iOS devices, our subscription management provider (RevenueCat) collects your Identifier for Vendor (IDFV) to validate purchases and prevent fraud. This identifier is specific to our app and cannot be used to track you across other apps.
  • Service Logs: Our servers keep technical logs of requests to our AI features, recording your account identifier, which feature was called, and how many calls you have made that day. When a request fails, the log may also capture technical detail about the failure so we can diagnose it, which can include part of the AI response involved.

Important: Automatic error and crash reports do not include your email address. Email addresses are stripped from error messages before they are sent, and only your anonymous user ID and a random installation identifier are attached. This applies to reports the App sends on its own. Anything you choose to send us yourself is covered in Section 2.7.

2.5 Guest Users

You may use the App as a guest without creating an account. Your guest progress is stored only on your local device and is not uploaded to our servers unless you create an account or sign in, when it is merged into that account so you keep it. If you uninstall the App or clear its data before then, your guest progress will be permanently lost. Guest use is still covered by the analytics and error tracking described above, and a guest can send us feedback as described in Section 2.7. Neither carries your progress, and as a guest there is no account, name, or email address to attach to them. The AI features in Section 2.6 require an account, so a guest does not reach them at all.

2.6 Voice Recordings and AI Processing (Interview Prep)

The Interview Prep features let you record spoken answers to practice questions, mock interviews, and case interviews. When you use them:

  • Voice Recordings: With your permission, we record your spoken answer. The recording is sent securely to our transcription provider (Deepgram) to convert it to text, and is then deleted. We opt out of Deepgram's model improvement program, so your recordings are not used to train its models. We do not store your audio on our servers. The copy on your device is deleted once it has been transcribed. If a recording comes back empty, it is deleted at once, except in the technical rehearsal (called the spoken rehearsal in the consulting track), where we keep it on your device only until your next take or until you leave, so you can play it back and check whether your microphone was working.
  • Transcripts: The text transcript of your answer is sent to our AI provider (OpenAI) to generate practice feedback. The same text is also checked by OpenAI's safety model for signs that you may hurt yourself; what the App does then is on our Safety page. We do not store your transcripts on our servers.
  • The Interviewer's Voice: The questions the interviewer asks you are written by the AI and spoken by our speech provider (Deepgram). Because the interviewer is responding to you, its questions can restate something you said.
  • Practice Feedback, Outlines, and Transcripts: AI feedback, answer outlines, your story bank, and your practice history are stored on your device only. Feedback quotes what you said, and a finished case interview saves its full transcript on your device, where the ten most recent are kept. None of this is uploaded to our servers, and none of it syncs across devices. It is not part of your phone's backup either, so a new phone does not restore it (Section 5.1).
  • No Voice Identification: We do not create voiceprints, and we do not use your voice to identify you. Your voice is used solely to transcribe what you said.
  • Usage Records: To operate fair usage limits, our servers keep counts of your AI feature usage and randomly generated practice session identifiers. Daily counts are pruned as they age. If you use the free AI-graded practice available without a subscription, the count of those is kept for as long as your account exists, because that allowance is a lifetime one. These records never include recordings, transcripts, or feedback.

You can always type your answers instead of speaking, and you can revoke microphone access at any time in your device settings.

2.7 Feedback and Reports You Send Us

The App has two places where you can write to us directly. Both are optional, and both are delivered through our error tracking provider (Sentry), which is where we read them.

  • Send Feedback: the feedback form in your Profile. We receive the reason you picked and the note you wrote. If you are signed in, your display name and the email address on your account are attached, so that we can reply to you. If you are using the App as a guest, there is no account to attach and we receive only your note.
  • Reporting AI feedback: the report link shown alongside AI-generated feedback. We receive the reason you picked, the note you wrote, and which screen it came from. Your email address is not attached, and any email address written inside the note itself is removed before the report is sent.

Whatever you write in these boxes reaches us as you wrote it, so leave out anything you would rather we did not hold.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the App
  • Create and manage your account
  • Track and display your learning progress
  • Sync your progress across devices (for registered users)
  • Send password reset emails when requested
  • Remind you once before a yearly plan renews
  • Identify and fix bugs and errors in the App
  • Improve the App based on usage patterns
  • Respond to your support requests

If you are in the European Economic Area, the United Kingdom, or Switzerland, the law asks us to say which legal basis we rely on for each of these uses:

  • Performing our contract with you: providing and operating the App, creating and managing your account, saving, showing, and syncing your progress, sending the account emails in Section 4.9, providing the paid features you buy, and answering your support requests.
  • Our legitimate interests: keeping the App working and secure (error tracking, Section 4.3), operating the fair-usage limits in Section 2.6, and understanding how the App is used (analytics, Section 4.2). Analytics can be switched off in the App's settings at any time.
  • Your consent: recording your voice for the Interview Prep features, which you agree to in the App before the first recording. You can withdraw that consent at any time by revoking microphone access in your device settings (the mock and case interview rooms also let you type instead); withdrawing does not affect what was processed before.
  • Legal obligations: keeping the record of which Terms and Privacy Policy version you accepted (Section 2.1), and responding to lawful requests.

The only information you must give us is an email address and a password, and only if you want an account. You can use the App as a guest without giving us any (Section 2.5).

4. Third-Party Services

We use the following third-party services to operate the App:

4.1 Supabase (Authentication & Database)

We use Supabase to handle user authentication and store your learning progress data. When you create an account, your email address and encrypted password are stored with Supabase. Your progress data is also stored in Supabase to enable cross-device syncing.

Supabase Privacy Policy: https://supabase.com/privacy

4.2 PostHog (Analytics)

We use PostHog to understand how the App is used, such as which lessons are completed and which features are popular. PostHog receives your anonymous user ID (not your email) and anonymized usage events such as lesson completions, feature interactions, subscription status, and app lifecycle events (such as when the App is opened, backgrounded, installed, or updated), together with your device type, app version and build, its bundle identifier, and screen size. We have disabled location tracking (GeoIP) in PostHog. No personally identifiable information is included in analytics events.

PostHog Privacy Policy: https://posthog.com/privacy

4.3 Sentry (Error Tracking)

We use Sentry to track errors and crashes in the App. Sentry collects error messages, stack traces, and contextual information about how the error occurred. We also collect performance data (such as screen load times and network request durations) to monitor app responsiveness. For reports the App sends on its own, we have configured Sentry not to collect your email address or name: email addresses are stripped from error messages, and only your anonymous user ID and a random installation identifier are attached.

Sentry is also how we receive the feedback and reports you choose to send from inside the App. Those submissions include what you wrote, and a feedback submission from a signed-in account includes your display name and email address. See Section 2.7.

Sentry Privacy Policy: https://sentry.io/privacy/

4.4 RevenueCat (Subscription Management)

We use RevenueCat to manage in-app subscriptions and purchases. RevenueCat receives your anonymous user ID (not your email or name), your purchase and subscription history, and on iOS, your Identifier for Vendor (IDFV). We also store subscription metadata (plan type, subscription status, and billing period dates) in our database to manage your access to premium features. RevenueCat processes transactions through the Apple App Store and Google Play Store.

RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

4.5 Expo (App Platform)

The App is built using Expo, a platform for React Native applications. Expo provides various services including app updates and build infrastructure. To deliver app updates, Expo's update service receives your device's operating system, our project identifier, and a random token that identifies the installation. It does not receive your identity, your email, or your learning progress.

Expo Privacy Policy: https://expo.dev/privacy

4.6 Deepgram (Speech to Text and Text to Speech)

We use Deepgram for both directions of speech in the Interview Prep features. It converts your spoken practice answers to text, and it speaks the interviewer's questions. Deepgram receives the audio of answers you choose to record, and the text of the questions put to you. Because the interviewer is responding to you, that text can restate something you said. We do not enable speaker identification. Audio is processed for transcription and is not retained by us.

Deepgram Privacy Policy: https://deepgram.com/privacy

4.7 OpenAI (AI Interviewer and Feedback)

We use OpenAI to run the AI interviewer and to grade your answers in the Interview Prep features. OpenAI receives the text of your practice answers (transcribed or typed), and returns the interviewer's next question and the written feedback you see. We do not store these exchanges on our servers. OpenAI also runs an automated safety check on each practice answer, looking only for signs that you may hurt yourself (see our Safety page).

OpenAI Privacy Policy: https://openai.com/policies/privacy-policy

4.8 Cloudflare (Website Hosting)

Our Website is hosted by Cloudflare. When you visit it, Cloudflare processes your IP address and the technical details of your request (such as the page requested and your browser type) in its server logs in order to deliver the Website and protect it from abuse. The Website does not set cookies. If you contact us from the Website, you do so by email to [email protected], and we use what you send us to answer you and to fix what you wrote about.

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

4.9 Resend (Email Delivery)

The emails we send you about your account, the confirmation email when you sign up, the password reset email when you ask for one, and a one-time reminder before a yearly plan renews, are delivered by Resend. Resend receives your email address and the content of those emails, including the one-time link inside them, in order to deliver them. We send no marketing email.

Resend Privacy Policy: https://resend.com/legal/privacy-policy

5. Data Storage and Security

5.1 Where Your Data Is Stored

  • Local Storage: Your preferences and, for guest users, all progress data are stored locally on your device, as is the Interview Prep practice data described in Section 2.6. The App keeps that practice and preference storage out of your phone's backups (iCloud and Google), so a new phone does not restore it. We have no access to your phone's backups.
  • Cloud Storage: For registered users, your email and progress data are stored in Supabase's secure cloud infrastructure.

5.2 Security Measures

We implement appropriate technical and organizational security measures to protect your data, including:

  • Encryption of passwords using industry-standard hashing algorithms
  • Secure token storage on iOS and Android (Keychain and Keystore)
  • HTTPS encryption for all data transmitted between the App and our servers
  • Crash and error monitoring in the App (Section 4.3)

5.3 Where Your Data Is Processed

We and the providers in Section 4 process your data primarily in the United States. Our database (Supabase) runs in the US West region in Oregon; our analytics (PostHog) and error tracking (Sentry) use their United States clouds; Deepgram stores data on servers in the United States; OpenAI processes data in the United States and contracts with European customers through OpenAI Ireland Limited.

If you are in the European Economic Area, the United Kingdom, or Switzerland, your data therefore leaves that region. Supabase, PostHog, Sentry, RevenueCat, Cloudflare, and Resend each provide the European Commission's Standard Contractual Clauses (with the UK addendum), and PostHog, Sentry, Cloudflare, and Expo are also certified under the EU-US Data Privacy Framework. Deepgram enters into the Standard Contractual Clauses with its customers, and OpenAI's data processing addendum incorporates the Standard Contractual Clauses as amended by the UK addendum. If you want to know which safeguard applies to a particular provider, email us at [email protected].

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. If you delete your account:

  • Your account and personal data (email, display name, learning progress, achievements, drill statistics, and subscription records) are permanently deleted from our database immediately.
  • Error tracking and performance data (Sentry) associated with your anonymous user ID is automatically deleted by Sentry within 90 days under its retention policy, except that Sentry may keep a downsampled copy of performance data for up to 13 months.
  • Server request logs (Supabase) are kept for up to 90 days depending on our plan. They record technical details of requests to our servers and can include your IP address; they are not linked to your learning data.
  • Account emails (Resend) are kept by Resend under its retention policy; we have not confirmed the period. We send them only when you sign up, ask for a password reset, or have a yearly plan about to renew.
  • Analytics data (PostHog) associated with your anonymous user ID is retained by PostHog for up to seven years under its retention policy unless we delete it sooner. After your account is deleted, this data can no longer be linked to your identity because the association between your user ID and email is permanently removed.
  • Subscription records (RevenueCat) associated with your anonymous user ID may be retained by RevenueCat as required for App Store and Google Play transaction compliance.
  • Voice recordings are deleted immediately after transcription and are never stored on our servers. Your practice data, including AI feedback, outlines, your story bank, and case interview transcripts, is stored on your device only. Deleting the App removes it from that device. Deleting your account removes it from the device you delete from; another device you were signed in on keeps its own copy until you delete the App there. Resetting your progress inside the App removes whatever that reset covers, which depends on the scope you choose.
  • Feedback and reports you send us (Section 2.7) are kept by our error tracking provider so that we can act on them. Deleting your account does not automatically remove a submission you have already sent. Contact us and we will delete it.

Local data on the device you delete from is also cleared upon account deletion, apart from a few small leftovers: the App's own version markers, any progress card image you shared, and working files kept by the analytics and error tracking tools.

7. Your Rights and Choices

7.1 Access and Portability

You have the right to request access to the personal data we hold about you. Contact us at [email protected]to request a copy of your data. You can also export it yourself at any time from the App: Profile, then "Export My Data". The export includes your account details, learning progress, subscription record, interview usage counts, and the interview practice data stored on that device.

7.2 Correction

You may update your display name through the App's settings. To update your email address or make other corrections, please contact us at [email protected].

7.3 Deletion

You have the right to request deletion of your account and associated data. You can do this by:

When you delete your account, your personal data is permanently removed from our database immediately. Third-party service data retention is described in Section 6 above.

7.4 Opt-Out

You may opt out of certain data collection:

  • Cloud Sync: Use the App as a guest to keep all data local to your device.
  • Analytics: Analytics data collection is enabled by default. You can disable it at any time in the App's settings.
  • Error Tracking: Automatic crash and performance monitoring (Sentry) cannot be disabled, as it is essential for maintaining app stability and quality for all users. This automatic monitoring data does not include your email address or name. Feedback you choose to send us is separate and voluntary; what it includes is described in Section 2.7.
  • Voice Features: Type your practice answers instead of speaking, or revoke microphone access in your device settings.

7.5 Automated Feedback

The feedback and grades in the Interview Prep features are generated automatically by AI (Section 2.6). They are kept on your device, and no employer or interviewer sees them. Within a practice session the AI uses how you answered earlier to choose what to ask or suggest next. Beyond that they change nothing: not your account, your subscription, or your access to anything, and nothing outside the App uses them. Our analytics receive counts only (for example, how many checks you passed), never the feedback itself (Section 4.2). If you think a grade or piece of feedback is wrong, use the report link shown with it in the App or email us at [email protected], and a person will look at it.

7.6 Restriction and Objection

If you are in the European Economic Area, the United Kingdom, or Switzerland, you can also ask us to restrict how we use your data while a question about it is resolved, and you can object to any use we base on our legitimate interests (Section 3). Analytics can be switched off directly in the App's settings. Email us at [email protected]for anything else.

7.7 How to Make a Request

Email [email protected] from the address on your account. We reply within one month, or within three months for an unusually complex request, in which case we tell you within the first month. We never charge a fee. If we cannot tell that a request comes from you, we will ask you to confirm it from that address before we act, so that nobody else can read or delete your data. You can also use an authorized agent; we will still confirm the request with you. If you used the App as a guest, we hold no account to match you to; tell us what you sent us (for example, a feedback message) and roughly when, and we will find what we can.

If you are in the European Economic Area, the United Kingdom, or Switzerland and you are not satisfied with our answer, you have the right to lodge a complaint with your local data protection authority (in the United Kingdom, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner). We have not appointed a data protection officer; the contact in Section 11 handles all privacy matters.

8. California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA, as amended by the CPRA). We honor them whether or not the law's size thresholds apply to us:

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you, and how we use and share them. Sections 2 to 6 describe this.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions (Section 7.3).
  • Right to Correct: You can ask us to correct inaccurate personal information (Section 7.2).
  • Right to Opt Out of Sale or Sharing: We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is nothing to opt out of.
  • Right to Limit Use of Sensitive Personal Information: The only sensitive personal information we collect, as the CCPA defines it, is your account log-in (email and password). We use it only to sign you in and never to infer anything about you, so there is nothing to limit. Your voice recordings are used only to transcribe what you said and never to identify you (Section 2.6).
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at [email protected], yourself or through an authorized agent. We confirm requests as described in Section 7.7 and respond within 45 days, in practice within the one month promised there.

9. Children's Privacy

The App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected], and we will delete such information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. You are advised to review this Privacy Policy periodically for any changes.

For significant changes, we may provide additional notice, such as an in-app notification or email (if you have provided your email address). Before a new provider receives your data, we add it to Section 4.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Controller: Desk Dojo LLC
  • Postal address: 2108N N St, Sacramento, California 95816-5712, United States
  • Email: [email protected]
  • Website: https://deskdojo.co
  • Person in charge of the protection of personal information (Canada, including Quebec):the Managing Member of Desk Dojo LLC. Contact: [email protected]. We will confirm this person's identity on request.