Hiprup

Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains how Pixobase Solutions ("Pixobase", "Hiprup", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with Hiprup's institution-focused interview-preparation and assessment platform.

It applies to institution representatives, organization administrators, trainers, students, candidates, website visitors, and people who contact us about Hiprup.

1. Our role and the institution's role

Hiprup is generally provided to an institution, company, or training provider (the "Customer"). The Customer decides who may use its organization, which features and content are assigned, who receives administrator access, and how it uses student progress, mock-interview, and proctoring reports.

For personal data processed under the Customer's instructions, the Customer may be the data fiduciary or controller and Pixobase may act as its processor or service provider. Pixobase separately determines how certain data is used for account administration, security, billing, legal compliance, service analytics, and direct support.

The applicable Order or data processing agreement may describe these roles in more detail. If you have questions about an institution's decision—such as your enrollment, batch, access, or its use of a report—please contact that institution first.

2. Personal data we collect

We collect only the data reasonably required to provide, secure, support, and improve Hiprup.

Contact and prospect information

When an institution requests information or pricing, we may collect its name, the contact person's name, work email, phone number, estimated seat requirement, and message.

Account and identity information

We may collect your name, email address, authentication identifier, profile details, role, organization membership, invitation and approval status, and account activity. Authentication is provided through our contracted identity provider.

Organization and administration information

We process organization names, branding, configured domains, administrator permissions, batches, seat assignments, activation status, curricula, and organization-created content.

Learning and preparation activity

We process assigned technologies, questions viewed or completed, completion dates, notes, coding activity, AI-coach conversations, and related progress data.

Mock-interview and assessment information

Depending on the features you use, this may include selected topics, interview questions, typed or spoken answers, transcripts, conversation logs, AI-generated reviews, scores, feedback, session timing, and usage counts.

Camera and proctoring information

During a proctored mock interview, webcam frames are analyzed on your device. Raw webcam video and image frames are not uploaded to or stored by Hiprup.

We receive and store derived events and summary metrics, which may include:

  • whether a face was absent or more than one face was detected;
  • estimated attention or gaze-away time;
  • switching away from the browser tab or window;
  • exiting full-screen mode; and
  • paste activity or similar session-integrity events.

Hiprup does not use these features for facial recognition or identity matching. Hiding the local camera preview does not stop proctoring during an active proctored session.

Voice and audio information

If you use a voice feature, your browser may transmit audio directly to our AI provider using a short-lived credential. In fallback transcription mode, audio may be temporarily uploaded to our storage provider or processed in application memory before being submitted to the AI provider for transcription.

Hiprup stores the resulting text transcript and related mock-interview record. We request deletion of temporary audio objects after they are retrieved for transcription and do not retain a permanent audio recording as part of the user profile.

Billing and transaction information

For institutional orders, we may process Customer billing contacts, tax details, invoice and order references, amount, currency, payment status, and payment-provider transaction identifiers. Payment credentials such as full card or bank-account details are handled by the provider named in the invoice or payment flow and are not stored by Hiprup.

Device, log, and analytics information

We may collect IP address, device and browser type, operating system, pages and features used, timestamps, referring page, diagnostic logs, cookies or local-storage identifiers, and security events.

Support and communications

We process messages, attachments, and related details when you contact support, respond to a survey, or communicate with our team.

3. How we collect data

We collect personal data:

  • directly from you;
  • from the Customer and its Organization Administrators;
  • automatically when you use the website or service;
  • from our authentication, payment, analytics, email, infrastructure, and AI providers; and
  • when another Authorized User lawfully submits content relating to you.

The Customer is responsible for ensuring that data it gives us was collected and disclosed lawfully.

4. Why we use personal data

We process personal data to:

  • respond to institution enquiries and prepare quotations or Orders;
  • create, authenticate, and administer accounts and organizations;
  • provision seats, batches, curricula, content, and institution branding;
  • deliver learning tools, AI coaching, voice mocks, transcripts, reviews, scoring, and proctoring reports;
  • show Authorized Users their activity and provide permitted reports to Organization Administrators;
  • operate billing, invoicing, tax, payment reconciliation, and contractual records;
  • send service, security, invitation, account, and support communications;
  • detect abuse, protect accounts, troubleshoot errors, and maintain service reliability;
  • understand feature usage and improve Hiprup;
  • establish, exercise, or defend legal claims and comply with legal obligations; and
  • carry out another purpose disclosed to you with your consent or at the Customer's lawful instruction.

Depending on the context, processing may be based on performance of a contract, a lawful institutional instruction, consent, compliance with law, protection from fraud or security threats, or another ground permitted by applicable law.

We do not sell personal data. We do not use Customer Content to train our own general-purpose AI model.

5. AI processing and automated output

Prompts, answers, transcripts, question context, and other necessary content are sent to our contracted AI provider to operate coaching, transcription, mock-interview, review, and scoring features.

These systems generate educational assistance and practice feedback. Their output can be inaccurate. Hiprup does not make a final automated hiring, academic, disciplinary, or placement decision about you. Customers must apply appropriate human review before using AI output or proctoring signals in a decision that materially affects a person.

Our AI provider states that business and API data is not used to train its models by default. It may retain or process data for limited periods for safety, abuse prevention, and service operation under its applicable business terms and data controls.

6. What Organization Administrators can see

Depending on their permission level and the Customer's configuration, Organization Administrators may see:

  • your name, email, organization role, batch, join date, and active status;
  • last-active information and learning progress;
  • assigned and completed questions or content;
  • mock-interview usage, session details, answers, transcripts, AI reviews, feedback, and scores; and
  • proctoring summaries and recorded integrity events.

Administrators may activate, deactivate, or remove your institution access and change your batch or assigned curriculum. Customers are responsible for limiting administrator access to authorized personnel and using this information lawfully.

7. When we share personal data

We disclose personal data only as needed for the purposes described in this Policy.

The Customer and its authorized personnel

We share institution-account data with the Customer's authorized administrators, trainers, and reviewers according to their roles and permissions.

Service providers

We use contracted providers for functions such as:

  • identity and authentication;
  • AI generation, realtime voice, and transcription;
  • application hosting, databases, and infrastructure;
  • temporary object storage;
  • transactional email;
  • product analytics and diagnostics; and
  • invoicing and payment processing.

Our current providers include Clerk, OpenAI, MongoDB Atlas, Amazon Web Services, Cloudflare, and PostHog. A payment provider may also be identified in the relevant invoice or payment flow. Providers process data under their own security and contractual obligations and only for the services we obtain from them.

Professional, legal, and corporate disclosures

We may disclose information to auditors, accountants, legal advisers, insurers, regulators, courts, law-enforcement authorities, or other parties where reasonably necessary to comply with law, protect rights or safety, investigate fraud, or complete a financing, restructuring, merger, acquisition, or transfer of business. Any successor must continue to protect personal data consistently with applicable law.

We do not disclose personal data to third parties for their independent advertising.

8. Cookies and analytics

Hiprup uses essential cookies or similar storage for sign-in, session security, preferences, and core functionality.

We also use PostHog to understand page visits, feature usage, and product performance. After sign-in, analytics may be associated with your Hiprup account identifier and profile information such as name or email. PostHog may use cookies and browser local storage to maintain an analytics identifier.

You can restrict non-essential cookies through browser controls or supported consent settings. Blocking essential storage may prevent sign-in or other features from working. Browser privacy signals are handled where required by applicable law and supported by our systems.

9. Data retention

We keep personal data only for as long as reasonably needed for the purposes described in this Policy, the Customer's documented instructions, our contractual obligations, dispute resolution, security, and legal or tax requirements.

Retention depends on the data:

  • prospect and enquiry records are kept while we respond and for a reasonable sales and compliance period;
  • account and organization records are generally kept while the organization or account is active and for a limited period afterward;
  • progress, notes, AI conversations, mock sessions, transcripts, reviews, and proctoring events are generally retained while the Customer requires them or until they are deleted through an available control, subject to contractual and legal restrictions;
  • temporary audio objects are requested for deletion after retrieval for transcription;
  • billing, tax, and transaction records are retained for applicable statutory periods; and
  • logs and backup copies are retained for limited security, recovery, and continuity periods before deletion or overwrite.

When retention is no longer necessary, we delete or de-identify the data. Deletion from backups may occur through normal backup rotation rather than immediately.

10. Security

We use reasonable technical and organizational measures designed to protect personal data, including access controls, authentication, encryption in transit, provider security controls, monitoring, and role-based organization permissions.

No system is completely secure. You should use a strong, unique password, protect your device and email account, and promptly report suspected unauthorized access. Customers should regularly review their administrator list and remove permissions that are no longer required.

If a personal-data breach occurs, we will investigate, take appropriate containment and remediation steps, and notify affected parties or authorities when required by applicable law or contract.

11. International processing

Our service providers may process data in India or other countries where they or their infrastructure operate. These countries may have different data-protection laws.

Where cross-border safeguards are required, we use contractual, technical, and organizational measures designed to protect the transferred data and comply with applicable transfer restrictions.

12. Your choices and rights

Subject to applicable law and the relevant Customer relationship, you may be able to:

  • request access to or a summary of your personal data;
  • ask us to correct inaccurate or incomplete data;
  • request deletion of data that is no longer necessary;
  • withdraw consent where processing depends on consent;
  • object to or restrict certain processing;
  • ask how your data was processed or shared;
  • nominate another person to exercise rights where applicable; and
  • raise a grievance or complain to the relevant data-protection authority.

Some requests relating to an institution account must be handled or authorized by the Customer. We may verify your identity and consult the Customer before acting. Rights can be limited where retention or processing is required by law, contract, security needs, or the rights of others.

You may delete individual mock sessions where that control is available. For account-level requests, contact us using the details below.

13. Children

Hiprup is intended for people aged 18 or older. We do not knowingly offer institution access directly to a child without an approved arrangement with the Customer.

If a Customer intends to provide Hiprup to a person under 18, it must first obtain Pixobase's written agreement and provide legally required notices, verifiable parental or guardian consent, and any other authorization required by law. If you believe a child has used Hiprup without appropriate authorization, contact us so we can investigate.

14. Third-party links

Hiprup may link to external websites or resources. Their privacy practices are controlled by their operators, and this Policy does not apply to them. Please review their policies before submitting personal data.

15. Changes to this Policy

We may update this Policy as our service, providers, or legal obligations change. We will post the revised Policy and update the date above. If a change materially affects how we use personal data, we will provide reasonable notice through Hiprup, email, or the Customer's business contact.

16. Privacy and grievance contact

To exercise a privacy right, report a concern, or raise a grievance, contact:

Pixobase Solutions — Hiprup Privacy and Grievance Contact

Please include your name, institution, account email, the nature of your request, and enough detail for us to investigate. We may ask for information needed to verify your identity and authority.

We will acknowledge a grievance within 48 hours and aim to resolve it within 30 days, or sooner where applicable law requires.