This explains what Question Proof collects, why, who touches it, and how to get rid of it. No dark patterns, no "we may share with partners".
Who we are
Question Proof is run by Avitan Shulkin, an individual sole trader in Israel. We are the controller of the personal data described here.
Privacy contact: legal@questionproof.com
We are not required to appoint a Data Protection Officer, under either GDPR Article 37 or Israeli law. Under the GDPR a DPO is needed by public authorities, by controllers whose core activity is large-scale systematic monitoring, and by controllers processing special category data at large scale — we're none of those, and as explained below your voice here isn't special category data. Under Israel's Privacy Protection Law as amended by Amendment 13 (in force 14 August 2025), a DPO is mandatory for public bodies, for data brokers holding data on more than 10,000 people, for controllers doing systematic monitoring, and for controllers processing highly sensitive data at significant scale. Again, none of those. For the same reason our database does not need to be registered with the Israeli Privacy Protection Authority — registration after Amendment 13 is limited to data brokers and public bodies. If that ever changes, this page changes with it.
What we collect, why, and on what legal basis
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Setup details — company, position, interview date | To research the company and shape the interview; to set your access window | Performance of a contract |
| Job description you paste in | To generate questions that match the actual role | Performance of a contract |
| Your resume, if you add one | So Dana can ask about your own history | Performance of a contract |
| Session recordings — your audio | So you can listen back, and so we can produce the transcript and scorecard | Performance of a contract |
| Transcripts | To score the session and show you what you actually said | Performance of a contract |
| Scores — clarity, concision, structure, confidence, vocabulary, biggest problem | To give you the scorecard and track change between sessions | Performance of a contract |
| Email address | To send your access link, your scorecard, and receipts | Performance of a contract |
| A hash derived from your IP address | To stop one person burning the free 90-second session a thousand times. We store the hash, not the IP | Legitimate interests — keeping a free, no-signup service usable |
| Analytics events — which screens got used, whether a session finished, error counts | To find out what's broken and what nobody uses. First-party only, no third-party trackers, no ad networks | Legitimate interests — running and improving the product |
We don't ask for your date of birth, your address, your ID, or your payment details. We never see your card. Paddle takes the payment; we get a transaction reference and your email.
Please don't put health details, ID numbers, or other people's personal information in a job description or resume. We don't need any of it and we don't want it.
About your voice: it is not biometric data here
Your recordings are personal data. They are not special category biometric data under GDPR Article 9, and we want to be exact about why.
Article 4(14) defines biometric data as data produced by "specific technical processing" that allows or confirms the unique identification of a person. Recital 51 makes the same point about photographs: they only become biometric data when processed through a specific technical means allowing unique identification or authentication. The ICO puts it the same way — biometric data becomes special category data when it's processed for the purpose of uniquely identifying a natural person.
We never do that. We do not build a voiceprint. We do not run speaker recognition or speaker identification. We do not match your voice against any other voice, any database, or any previous session. We do not use your voice to authenticate you. Your audio is transcribed and the transcript is scored on how you speak — pace, filler words, structure, hedging, vocabulary — not on who you are.
If we ever built anything that identifies a person by voice, we would need your explicit consent first, and we would ask for it in plain words before we built it.
About the scorecard: it is not an automated decision about you
The scorecard is feedback for you, produced at your request, about your own practice. It doesn't decide anything. Nothing legal or similarly significant happens to you as a result, so GDPR Article 22 (automated decision-making) doesn't apply.
Question Proof also isn't a hiring tool. The EU AI Act's high-risk employment category covers systems intended to be used for the recruitment or selection of people — to analyse and filter job applications and evaluate candidates. That is, systems an employer or recruiter uses to screen people. We don't screen anyone for anyone. No employer receives a scorecard. No employer can. The only person who ever sees your score is you.
We also don't run emotion recognition. Under the AI Act, an emotion recognition system is one that identifies or infers emotions or intentions on the basis of biometric data, and Recital 18 is explicit that picking up readily apparent things — a raised voice, a whisper, a gesture — is not emotion recognition unless it's used to infer an emotion. Your confidence score is not a reading of how you feel. It's built from what's in the transcript and the timing of it: filler words, hedging language, how long you take to get to the point, how steady the pace is. We don't claim to know your emotional state, and we don't build a biometric template to guess at one.
And Dana is an AI. We tell you that before the first session starts, on the page, and again here — which is also what the AI Act's Article 50 transparency rule requires, and has required since 2 August 2026.
Who processes your data, and where
We use four companies. Each one only gets what it needs.
OpenAI — runs Dana and the company research.
Your browser connects directly to OpenAI's Realtime API over WebRTC using a short-lived ephemeral key our server mints for that one session. Your live audio goes from your browser to OpenAI. It does not pass through our servers. Company research runs through OpenAI's Responses API with web search over public sources.
OpenAI acts as our processor under its Data Processing Addendum. Customers in the EEA and Switzerland contract with OpenAI Ireland Ltd; everyone else with OpenAI OpCo, LLC. Transfers rely on Standard Contractual Clauses, with the UK Addendum for UK data.
OpenAI does not train its models on API data by default, and we have not opted in. OpenAI may retain API inputs and outputs for up to 30 days to run the service and detect abuse.
Cloudflare — stores your recordings (R2) and your transcripts and scores (D1), and serves the site.
Cloudflare acts as our processor under its Data Processing Addendum. For transfers out of the EEA, Switzerland and the UK it relies on Standard Contractual Clauses and is certified under the EU–U.S. Data Privacy Framework, the Swiss–U.S. DPF and the UK Extension.
Resend — sends our emails: your access link, your scorecard, and service notices.
Resend acts as our processor. Customer data is hosted in the United States. Transfers rely on Standard Contractual Clauses with the UK Addendum, and Resend is certified under the EU–U.S. Data Privacy Framework.
Paddle — sells you the product and takes the money.
Paddle is our merchant of record, not our processor. Under Paddle's Data Sharing Addendum, Paddle and we are independent controllers: Paddle runs the sale under its own privacy policy and shares back your name, email, purchase history and transaction analytics. Depending on where you buy, your contract is with Paddle.com Market Limited (England and Wales), Paddle.com Inc. (US) or Paddle.com (Canada) Ltd.
Nobody else. We do not share your data with employers, recruiters, advertisers, ad networks, or data brokers. Ever. We don't sell it. There is no third-party analytics script on the site.
We'd only hand anything over to a court or regulator if we were legally compelled, and we'd tell you unless we were forbidden from telling you.
International transfers
We're in Israel. The European Commission has recognised Israel as providing an adequate level of data protection, and reconfirmed that decision in January 2024, so personal data can move from the EEA to us without extra safeguards.
Onward transfers to our processors are covered by the Standard Contractual Clauses, UK Addendum and Data Privacy Framework certifications listed above. Ask legal@questionproof.com if you want copies of anything.
How long we keep things
Recordings and transcripts are deleted 30 days after the interview date you gave us. Automatically. You don't have to ask.
Ask sooner and they go immediately.
Your scorecards and your account row (email, purchase reference, access window) stay until you delete everything, which is one tap in Settings. Rate-limit hashes roll off within days. Aggregate analytics that can't be tied back to you may be kept.
Paddle keeps its own transaction and tax records under its own policy — we can't delete those, and neither can you, because tax law requires them.
Your rights
Wherever you are, you can ask us to:
- See what we hold on you
- Correct anything wrong
- Delete everything
- Export it — recordings, transcripts, scorecards
- Restrict or object to processing, including anything we do on legitimate interests
- Port it to another service in a machine-readable form
- Withdraw consent where we relied on consent
Export and delete-everything are one tap each in Settings. For anything else, email legal@questionproof.com. We answer within 30 days, free.
If you're in the EEA or the UK, you can complain to your national data protection authority. In Israel, you can complain to the Privacy Protection Authority. We'd rather you emailed us first, but it's your call.
Cookies
Two things, both ours:
- A session cookie that keeps you signed in.
- An anonymous id that ties a no-signup session to its scorecard so you can come back and find it.
Both are strictly necessary to deliver the thing you asked for, so there's no consent banner. There are no third-party cookies, no advertising cookies, no tracking pixels, and no third-party analytics. Analytics events are counted on our own servers.
Children
Question Proof is for adults. You must be 18 or over. We don't knowingly collect data from anyone under 18. If you think a minor has used it, email legal@questionproof.com and we'll delete everything.
Security
Traffic is encrypted in transit. Recordings and transcripts sit in Cloudflare storage that only our application can reach. The ephemeral key your browser uses for a voice session is short-lived and single-purpose, and cannot be used to read your stored data. Access to the production data is limited to the person who runs Question Proof.
No system is perfect. If there's a breach that puts your rights at risk, we'll tell you and the relevant regulator without undue delay.
Changes
We'll post the new version with a new "last updated" date. If a change materially affects how we handle your data and you have an open access window, we'll email you at least 14 days before it takes effect.
Contact
legal@questionproof.com — privacy, data, rights requests, anything on this page.