Skip to content

Last updated October 8, 2026

Privacy policy

1. Introduction

GenQora (“GenQora”, “we”, “us”) respects your privacy. This Privacy policy describes how we collect, use, share, and protect personal information when you use our website at genqora.com, the GenQora desktop application, and related services (the “Service”).

This policy should be read with our Terms of service and Refund & cancellation policy.

2. Data controller and contact

For privacy questions, data subject requests, or complaints, contact: support@genqora.com.

3. Information we collect

3.1 Account and identity

  • Name, email address, and profile picture from Google sign-in.
  • Internal user ID, account role (for example customer or staff), and sign-in timestamps.

3.2 Billing and payments

  • Plan purchased, amount, currency, payment status, credits granted, subscription status, and transaction references.
  • We do not store full payment card numbers, CVV, or UPI PINs. Stripe and Razorpay process payments under their own privacy policies.
  • Billing address or tax identifiers if required by the payment provider or law.

3.3 Usage and metering

  • Credit balance, consumption events, and whether live Auto AI or related features were active.
  • Feature flags, kill-switch state, and abuse-prevention signals.
  • Desktop app version and basic diagnostic logs needed to operate the Service.

3.4 Session and profile data you provide

  • Interview session metadata you sync (for example company, role, round, difficulty, schedule).
  • Resumes, notes, and settings you choose to store or upload.
  • Referral and affiliate codes you apply.

3.5 Audio, transcript, and screen content

  • During active use, audio from the interview environment and optional screen captures may be sent to our servers and speech and AI providers to produce transcripts and answers.
  • We design the product to focus on interviewer audio; you control when features are active.

3.6 Support and communications

  • Messages you send to support, feedback, and records of how we resolved your request.

3.7 Technical and security data

  • IP address, browser type, device identifiers, and cookies or similar technologies on the website (see Section 8).
  • Server logs for security, debugging, and performance.

3.8 Staff and admin operations

Authorized staff may access account and billing data to provide support, prevent fraud, and operate the platform. Staff actions may be recorded in audit logs.

4. How we use information

We use personal information to:

  • create and manage your account;
  • provide, maintain, and improve the Service;
  • meter credits and enforce plan limits;
  • process payments and send receipts;
  • communicate about the Service, security, and legal notices;
  • detect, prevent, and respond to abuse, fraud, and security incidents;
  • comply with law and respond to lawful requests;
  • analyse aggregated, de-identified usage to improve the product.

Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we rely on: contract (to provide the Service you requested); legitimate interests (security, improvement, fraud prevention); legal obligation; and consent where required (for example optional marketing cookies if we use them).

5. How we share information

We do not sell your personal information. We share data only as follows:

  • Service providers who process data on our behalf under contract, including hosting, database, email, payment (Stripe, Razorpay), authentication (Google), speech-to-text, and AI inference providers.
  • Professional advisers (lawyers, accountants) under confidentiality obligations.
  • Business transfers if we merge, are acquired, or sell assets (with notice where required).
  • Legal and safety when required by law, court order, or to protect rights, safety, and integrity of the Service.
  • With your direction, for example when you connect integrations we explicitly offer.

6. International transfers

We and our providers may process data in countries other than where you live (including the United States and India). Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms.

7. Retention

We keep personal information only as long as needed for the purposes above, including:

  • account data: while your account is active and for a reasonable period after closure for backups and legal compliance;
  • billing records: as required by tax and accounting laws (often 7 years or more);
  • support tickets: typically up to 3 years;
  • security logs: typically up to 12 months unless needed for an investigation.

We may retain anonymised or aggregated data longer.

8. Cookies and similar technologies

On the website we use cookies and local storage for:

  • keeping you signed in (session and authentication tokens via Supabase);
  • remembering referral or affiliate codes you land with;
  • security and abuse prevention;
  • basic preferences.

You can control cookies through your browser settings. Blocking essential cookies may prevent sign-in from working.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), access controls, and least-privilege staff access. No method of transmission or storage is 100% secure; please use a strong Google account password and enable two-factor authentication on Google.

10. Your rights and choices

Depending on your location, you may have the right to:

  • access, correct, or delete your personal information;
  • export your data in a portable format;
  • object to or restrict certain processing;
  • withdraw consent where processing is consent-based;
  • lodge a complaint with a supervisory authority.

To exercise rights, email support@genqora.com. We may verify your identity. You can sign out in the app and ask us to delete your account and synced data; some billing records may be retained as required by law.

India (Digital Personal Data Protection Act)

If you are in India, you may have rights to access, correction, erasure, and grievance redressal. Contact us at the email above; we will respond within timelines required by applicable law.

11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided data and we will delete it.

12. Marketing communications

We may send product updates or offers to your account email. You can opt out of non-essential marketing by replying “unsubscribe” or contacting support. We will still send transactional messages (receipts, security, legal notices).

13. Third-party links

The Service may link to third-party sites (for example Google, payment checkout). Their privacy practices govern those interactions.

14. Changes to this policy

We may update this policy. The “Last updated” date will change. Material changes may be notified by email or a notice on the website. Continued use after the effective date means you accept the updated policy.