Legal
Privacy policy
What we collect, why, and how to get it corrected or deleted. Optional analytics, privacy-masked session replay and Reddit conversion measurement stay off unless you choose them. We do not sell personal data.
Last updated: 3 September 2026. Version 2026-09-03.
Who we are
PublicServicePathway is operated by Maebh Collins in Ireland. Maebh Collins is the data controller for the personal data described here. For anything in this policy, email[email protected].
What we collect
- Account data. Your email address and a password hash. Stored in Supabase in the EU (eu-west-1, Ireland). We never see or store your plain-text password.
- Practice history. Your attempts, answers, scores, timings and mock-interview reports. This is the product: it is how your dashboard shows where you are improving.
- Consent records. When you accept the terms and this policy at signup, we record what version you accepted and when.
- Payment status. If you subscribe, Stripe processes the payment and we store your subscription status and Stripe customer reference. Card numbers go to Stripe directly; we never see or store them.
- Server logs. Standard request logs (IP address, timestamp, page requested) kept briefly by our hosting providers for security and debugging.
- Cookie-free aggregate traffic. Cloudflare Web Analytics counts public page views and measures page performance without setting cookies or browser storage. Cloudflare does not log URL query strings in Web Analytics. This reporting does not include application answers, form contents or account email addresses.
- Your examples. The work examples, flashcards and interview plans you write in the app. They are yours: stored against your account only, visible to nobody else, and exportable or deletable by you at any time from your Profile.
- Public HEO example check. If you use the no-account HEO taster, Cloudflare Turnstile first processes browser and network signals to prevent automated abuse. Your example is then sent to Anthropic for that check and is not stored by PublicServicePathway. We keep a one-way browser-identifier hash, a one-way network hash and minimal usage counts for up to 30 days to enforce the single free check and a global daily model limit. We do not put the example text or returned feedback in that usage record.
- Email resources and updates. If you unlock an email-gated worksheet or subscribe for updates, we store the email address, signup time and source form. The form states when the signup includes preparation emails. The downloadable resource is available immediately after a successful request.
- Optional acquisition attribution. If you accept analytics or Reddit conversion measurement, we keep a random journey ID with source, campaign, content, term, competition, grade and landing-page labels for up to 90 days. This connects a consented visit to signup or purchase without storing application text, coach answers, names or contact details in that browser record.
- Feedback and contact messages. If you submit product feedback, we store your answers against your account so we can understand which testing group and product experience they relate to. If you use the public contact form, we collect the name, email address and message you choose to send.
- Optional product analytics. If you consent, Google Analytics counts visits and PostHog records page views, clicks, scrolling and selected product events such as finishing onboarding or completing a practice activity. Signed-in analytics uses your internal account ID, not your email address.
- Optional session replay. If you consent, PostHog can reconstruct the layout, navigation, clicks and scrolling in a visit. All form inputs are masked. Text inside the signed-in app is masked except approved static navigation labels, and URLs are recorded without query strings or fragments. We do not enable console-log, request-header or request-body recording.
- Optional Reddit conversion measurement. If you choose this separate option, the Reddit Pixel measures safe acquisition events such as a landing-page visit, signup or purchase so we can tell whether a Reddit ad worked. It is not loaded inside the application and receives no application text, coach answers, names, email addresses, phone numbers or internal account ID. Automatic email and phone matching is disabled.
Why we're allowed to (lawful bases)
- Contract. Account data, practice history and payment status are needed to provide the service you signed up for.
- Legitimate interest. Server logs, cookie-free aggregate traffic and performance measurement, Cloudflare Turnstile, per-browser and network limits, and the global daily model allowance help us operate and protect the service.
- Your request and our legitimate interest. When you ask for the public HEO example check, processing the text is necessary to return the feedback you requested. The short-lived hashed usage record prevents repeated refreshes from restarting the free allowance.
- Consent. Optional Google Analytics and PostHog analytics/session replay, first-party campaign attribution, the separate Reddit conversion measurement option, and preparation emails run only after you choose them. You can reject optional measurement without losing any app feature. Email-resource forms explain the email permission beside the submit button. You can withdraw either choice at any time.
- Your request and our legitimate interest. We use contact messages to answer you, and voluntary product feedback to improve the service. Giving feedback is optional. A separate checkbox controls whether we may follow up about it.
Cookies, local storage and session replay
Necessary local storage keeps you signed in, preserves app preferences, remembers your privacy choice and gives the public HEO taster a random browser identifier for up to 30 days so refreshing does not restart it. Optional Google Analytics and PostHog storage is not created until you accept analytics. Reddit conversion measurement is a separate choice and its script is not loaded until you accept it. A random first-party journey ID and campaign labels are stored only after you accept at least one optional measurement choice. The Accept and Reject choices are equally available, nothing optional is preselected, and the choice expires after six months. Withdrawing consent stops further collection and clears the optional storage we can access in your browser.
Session replay is used to find dead ends, confusing screens and technical failures. It is not used to evaluate you, your public-service application or the quality of your answers. For the exact storage names, purposes and durations, see the cookie and browser-storage notice. You can.
Who processes your data
- Supabase - database and authentication, hosted in the EU (Ireland).
- Stripe - payment processing. Stripe is the only party that handles your card details.
- Cloudflare - website hosting, security, content delivery, cookie-free aggregate Web Analytics and the Turnstile anti-abuse check on the public HEO taster.
- Google Analytics - optional visit and page-use statistics. Advertising personalisation and Google Signals are disabled in our site configuration.
- PostHog Cloud EU - optional product analytics and privacy-masked session replay, using its EU processing endpoint.
- Reddit - optional ad conversion measurement on selected acquisition pages. Automatic email and phone matching is disabled.
- Anthropic - model-assisted coaching and scoring, under the terms below.
We do not sell your data or share it with anyone else.
How our model uses your text
When you use the public HEO taster, run the coach, score a practice answer, run an application fit, or build a role-specific mock interview, the text you wrote is sent to Anthropic's API for that one analysis and the feedback comes back to your browser or account. Anthropic's API terms do not permit your text to be used to train their models. We do not store your text in the coaching logs - only counts and token usage for rate limiting. Public taster feedback comes back to the browser rather than an account and is not saved by us. Inside the signed-in app, you can switch model-assisted checks off entirely under Profile > Model data controls; everything else in the app keeps working.
For a full mock, the booklet, uploaded PDF or pasted job description is used to extract a role brief, assessed-area map and tailored question plan. We store that extracted plan, not the raw document or pasted source. Your answer transcript is held while the mock is in progress so the final report can consider the whole interview. It is cleared when the report is completed unless you explicitly choose to save it; the report itself stays in your practice history. Model feedback can be wrong and is a development aid, not an official score, a pass prediction or a decision by a real interview board.
If you work in the public service: keep your examples free of classified detail and identifiable citizen data. Describe the work you did, not the file you did it on. The coach never needs names, PPS numbers or case detail to structure your example.
Speaking your answer
Written practice can use your browser's speech recognition instead of typing. In Chrome and Edge, the browser may send audio to Google's speech service; in Safari it may use Apple's service. That happens between your browser and that provider under its privacy terms. We receive only the resulting text and treat it like a typed answer.
A live voice practice panel is different. Your browser sends microphone audio directly to OpenAI over an encrypted WebRTC connection so the panel can respond in real time. PublicServicePathway never receives or stores that audio. We receive the text turns created during the conversation and send the completed text transcript to Anthropic for the final development report. The transcript is deleted after the report unless you chose to save it.
Camera self-view is local only and is never sent to OpenAI, Anthropic or PublicServicePathway. If you choose temporary local recording, your browser records your own camera and microphone into device memory for replay or download. It is never uploaded and disappears when the page closes unless you download it. Typing remains available as the fallback, and a failed live connection before the panel opens does not use one of the monthly mock allowances.
How long we keep it
- Account data, practice history, signed-in feedback and saved mock reports are kept while your account is active. A full-mock transcript is retained only when you choose to save it.
- Public contact-form messages are kept for up to 24 months, unless the conversation needs to be retained longer for an account, legal or security reason.
- Email-resource and update signups are kept until you unsubscribe or ask us to delete the address. You can do either by emailing [email protected].
- PostHog session recordings are kept for no more than 30 days. PostHog product events are kept for no more than 12 months. Google Analytics event-level data is kept for no more than 14 months. Our browser privacy choice expires after no more than six months. Optional Reddit identifiers use Reddit's provider-set duration; measurement stops and identifiers our site can access are cleared when you withdraw consent.
- Signed-in consent records are kept with the account, and may be retained afterwards only where necessary to demonstrate compliance with our legal obligations.
- Accounts inactive for 24 months are deleted, along with all their practice history.
- You can delete your account yourself, immediately, under Profile > Danger zone - every example, flashcard and attempt goes with it, and all we keep is a dated record that an account was erased, with row counts and no personal data. You can also download everything first with Download my data. Prefer email? Ask and it is done within 30 days.
Your rights
Under the GDPR you can, at any time:
- Access - ask for a copy of everything we hold about you.
- Rectification - have anything inaccurate corrected.
- Erasure - have your account and all its data deleted.
- Portability - get your data in a machine-readable format.
- Restriction or objection - ask us to limit processing or object where we rely on legitimate interests.
- Withdraw consent - change your optional analytics or Reddit conversion measurement choices, or unsubscribe from preparation emails, at any time without affecting earlier lawful processing.
Email [email protected] and we will respond within 30 days. If you are not happy with how we handle it, you can complain to the Data Protection Commission at dataprotection.ie.
Changes to this policy
If this policy changes in a way that matters, the version string at the top changes and existing users are told before the change takes effect. The version you accepted at signup is recorded against your account.