Skip to main content

    Privacy Policy

    Last updated: August 12, 2026

    At Craqly (operated by Fyrosoft Technologies, "we," "us," or "our"), your privacy is a core priority. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our website at craqly.com ("Website"), use the Craqly desktop application ("Desktop App"), and interact with our related services (collectively, the "Services"). By using the Services, you agree to the practices described in this policy. If you do not agree, please do not use the Services.

    Key Privacy Commitments

    • We do not sell your personal data to third parties.
    • We do not use your session data (transcriptions, audio, notes) to train AI models.
    • We never store your audio. Transcription runs over real-time streaming APIs; no recording is created, by us or by our speech providers.
    • We do save your session transcripts and history so you can review past sessions — and you can switch that off at any time, or delete it.

    1. Information We Collect

    1.1 Information You Provide

    • Account Information -- When you sign up, we collect your name, email address, and profile picture (if signing in via Google OAuth). If you use email-based login, we collect your email and a hashed password.
    • Payment Information -- When you subscribe, payment details are collected and processed by our payment partners (Razorpay and PayPal). We do not store your full credit card numbers, bank account details, or UPI IDs on our servers. We receive and store transaction identifiers, subscription IDs, payment amounts, and billing status.
    • Resume Uploads -- If you upload a resume so the AI can tailor its answers to your background, we do not keep the file itself. We do extract the text and store it in your profile, so that it can personalise your answers in every future session without you re-uploading it. That text stays until you replace or remove it from Desktop App settings, and it is kept independently of the "Save session data" setting, which controls session transcripts rather than your profile. Deleting your account removes it.
    • Support Communications -- When you contact us via email or through the Website, we collect the content of your messages, your email address, and any attachments you provide.
    • Prospect Briefing Data -- In Sales Call mode, if you fill in the Prospect Briefing Form, that data is processed locally during the session for AI coaching purposes.

    1.2 Information Collected During Sessions

    • Audio Data -- During an active session the Desktop App captures system audio (what you hear from the video call), and in modes where your own speech matters — Sales, Recruiting and Practice Voice — your microphone as well. Audio is streamed live to our speech providers for real-time transcription. Audio is never recorded, written to disk, or stored on our servers, in any mode. See section 3 for the detail.
    • Session Transcripts & History -- The text transcript, AI responses and any generated notes are saved to your account by default so you can review past sessions. You can switch this off at any time with "Save session data" in Desktop App settings, in which case nothing from the session is written to our servers, and you can delete saved sessions individually or in full.
    • AI-Generated Content -- Responses, summaries, notes and action items generated during sessions. Storage follows the same "Save session data" preference described above.
    • Screenshot Data -- When you use the screenshot feature (e.g. in Coding mode or Analyze Screen), the captured image is sent to the AI provider for analysis and is not stored on our servers unless session saving is enabled.
    • Speaker Identification Data -- In modes that support speaker diarization (Sales, Meeting, Notes, Recruiting), audio characteristics are used to distinguish speakers. This is processed in real-time by our transcription provider and is not stored as biometric data.

    1.3 Information Collected Automatically

    • Device & System Information -- Operating system, app version, platform (Windows/macOS), architecture, and device type.
    • Usage Data -- Features accessed, session durations, modes used, credit consumption, and interaction patterns within the Desktop App and Website.
    • Log Data -- IP address, browser type, referring pages, timestamps, and access logs when you visit the Website.
    • Installation Data -- When you install or update the Desktop App, we collect the app version, platform, architecture, and OS version to track active installations and provide support.
    • Cookies & Similar Technologies -- We use cookies and local storage on the Website for authentication, session management, analytics, and preference storage (see Section 7).

    1.4 Information from Third Parties

    • Google OAuth -- When you sign in with Google, we receive your name, email, and profile picture as authorized by you during the OAuth consent flow.
    • Payment Providers -- Razorpay and PayPal may provide us with transaction status, subscription lifecycle events, and payment failure notifications.

    2. How We Use Your Information

    We use the information we collect for the following purposes:

    • Providing the Services -- To operate, deliver, and maintain the Desktop App and Website, process your sessions, generate AI responses, and manage your account.
    • Billing & Payments -- To process subscriptions, track credit usage, issue invoices, and manage payment lifecycle events (renewals, cancellations, failures).
    • Communication -- To send transactional emails (subscription confirmations, payment receipts, credit alerts), respond to support requests, and provide service-related notifications.
    • Improvement & Analytics -- To analyze aggregate usage patterns, identify bugs, improve service performance, and develop new features. We use anonymized and aggregated data for these purposes.
    • Security & Fraud Prevention -- To detect and prevent unauthorized access, abuse, fraud, and other harmful activities.
    • Legal Compliance -- To comply with applicable laws, regulations, legal processes, or enforceable government requests.

    3. Audio & Transcription Data

    Given the sensitive nature of audio data processed during interviews, sales calls, and meetings, we want to be transparent about how it is handled:

    • Streaming APIs, not file uploads. Transcription uses the real-time streaming APIs of our speech providers. Your microphone and system audio are sent as a live stream over an encrypted WebSocket connection while the session is running, transcribed as they arrive, and the connection closes when the session ends. No audio file is ever created, uploaded, or submitted for batch processing.
    • We never store your audio. Craqly does not record, download, buffer to disk, or archive raw audio on any server we control. There is no audio file to retrieve, export, or hand over, because none is written. This applies to every mode, including when session saving is switched on.
    • Our speech providers do not retain it either. Deepgram and AssemblyAI process the stream in real time and, under the streaming configuration and data-processing terms we use, do not persist your audio after transcribing it and do not use it to train their models.
    • Practice Voice is different, and you should know how. In Practice Voice mode you speak to an AI interviewer rather than a person. That mode uses Google's Gemini Live API, so your microphone audio is streamed to Google in real time to generate the spoken replies you hear. It is still a live stream that we never store, but Google is the processor for that mode rather than Deepgram or AssemblyAI.
    • Transcripts are saved by default — and you can turn that off. Unlike audio, the text transcript, AI responses and meeting notes for a session are saved to your account so you can review sessions later. This is on by default. Switch off "Save session data" in Desktop App settings and nothing from the session is written to our servers — the transcript is discarded when the session ends. You can also delete any saved session at any time.
    • No AI training. Your audio, transcripts and session content are never used to train, fine-tune or improve our models, and we do not permit our providers to use them for training.
    • Speaker labels. Speaker separation is performed by the transcription provider in real time. Labels such as "Speaker 0" and "Speaker 1" are derived from audio characteristics during the session and are not stored as biometric identifiers.

    4. Data Sharing & Third Parties

    We do not sell your personal information. We share information only in the following circumstances:

    Service Providers

    We work with trusted third-party service providers who process data on our behalf to deliver the Services:

    • Supabase -- Database hosting, authentication, and backend infrastructure
    • Razorpay -- Payment processing for users in India (subject to Razorpay's Privacy Policy)
    • PayPal -- Payment processing for international users (subject to PayPal's Privacy Policy)
    • Deepgram -- Real-time streaming speech-to-text and speaker separation. Receives live audio while a session is running.
    • AssemblyAI -- Real-time streaming speech-to-text, including for non-English sessions. Receives live audio while a session is running.
    • Google -- The Gemini Live API powers Practice Voice mode, and Gemini models are available as an AI response provider. In Practice Voice mode Google receives live microphone audio; otherwise Google receives text only.
    • OpenAI -- AI language model processing for generating responses and content. Receives session text and, in Coding mode, screenshots you choose to analyse.
    • OpenRouter -- Routes AI requests to additional model providers (including DeepSeek) when a model outside OpenAI's catalogue is selected or used as a fallback. Receives session text.
    • Anthropic -- Available as an alternative AI response provider. Receives session text when selected.
    • Hostinger -- Website and application hosting, and email delivery infrastructure (SMTP)

    Which AI provider handles a given request depends on the model configured for that feature, so not every provider listed above is involved in every session. Speech providers receive audio only while a session is actively running; every other provider receives text (and, in Coding mode, screenshots you explicitly choose to analyse).

    Each service provider is contractually obligated to process your data only as necessary to perform their services and in accordance with applicable privacy laws.

    Other Sharing Circumstances

    • Legal Requirements -- We may disclose your information if required to do so by law, regulation, legal process, or governmental request.
    • Protection of Rights -- We may share information to protect the rights, property, or safety of Craqly, our users, or the public.
    • Business Transfers -- In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change.
    • With Your Consent -- We may share your information for purposes not described here with your explicit consent.

    5. Data Storage & Retention

    Your account data (name, email, subscription information, credit balance) is retained for as long as your account is active. Session data (transcripts, AI responses, meeting notes) is retained by default so that your session history is available to you, unless you switch off "Save session data" in the Desktop App — and you may delete it at any time.

    • Account Data -- Retained while your account is active and for a reasonable period after account deletion for legal, tax, and audit purposes.
    • Payment Records -- Retained as required by applicable financial regulations and tax laws (typically 5-7 years).
    • Session Data -- Transcripts, AI responses and notes are retained for as long as your account is active so your session history stays available, unless you switch off "Save session data", in which case they are never written at all. You can delete individual sessions or all saved data from your account at any time. Audio is never retained in either case.
    • Usage Analytics -- Aggregated and anonymized analytics data may be retained indefinitely as it cannot be used to identify individual users.
    • Support Communications -- Retained for as long as needed to resolve your inquiry and for quality assurance purposes.
    • Email Logs -- Records of emails sent to you (subscription confirmations, alerts, etc.) are retained for troubleshooting and compliance purposes.

    When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.

    6. Data Security

    We implement reasonable technical, administrative, and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

    • Encryption of data in transit using TLS/SSL protocols
    • Encryption of sensitive data at rest in our database
    • Row-level security (RLS) policies to ensure users can only access their own data
    • Secure authentication via Google OAuth and hashed password storage
    • Regular security reviews of our infrastructure and third-party integrations
    • Access controls limiting employee access to user data on a need-to-know basis

    While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users as required by law.

    7. Cookies & Tracking Technologies

    We use the following types of cookies and similar technologies on the Website:

    • Essential Cookies -- Required for authentication, session management, and core website functionality. These cannot be disabled without impacting the Services.
    • Analytics Cookies -- Help us understand how visitors interact with the Website, which pages are visited most, and how to improve user experience. These collect anonymized, aggregated data.
    • Preference Cookies -- Store your preferences such as theme (light/dark mode) and language settings.

    The Desktop App uses local storage for authentication tokens and user preferences. It does not use tracking cookies.

    You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Website.

    8. Your Rights & Choices

    Depending on your jurisdiction, you may have the following rights regarding your personal information:

    • Access -- Request a copy of the personal information we hold about you.
    • Correction -- Request correction of inaccurate or incomplete personal information.
    • Deletion -- Request deletion of your personal information, subject to legal retention requirements.
    • Data Portability -- Request your data in a structured, commonly used, machine-readable format.
    • Restriction -- Request that we restrict processing of your personal information in certain circumstances.
    • Objection -- Object to the processing of your personal information for certain purposes.
    • Withdraw Consent -- Where processing is based on your consent, you may withdraw consent at any time.

    Data Saving Controls

    The Desktop App provides granular controls over data saving. You can choose to:

    • Enable or disable saving of session transcriptions
    • Enable or disable saving of AI-generated responses and notes
    • Delete individual sessions or all saved data from your account
    • These preferences can be changed at any time in the Desktop App settings

    To exercise any of your rights, contact us at support@craqly.com. We will respond to your request within 30 days.

    9. Regional Privacy Disclosures

    For Users in India

    We comply with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian data protection regulations. You have the right to access, correct, and request deletion of your personal data. For grievances, contact our Grievance Officer at support@craqly.com.

    For Users in the European Economic Area (EEA) / UK

    If you are located in the EEA or UK, the General Data Protection Regulation (GDPR) and UK GDPR apply. Our legal bases for processing personal data include: performance of a contract (providing the Services), legitimate interests (security, analytics, service improvement), consent (where applicable), and legal obligations. You have additional rights under GDPR including the right to lodge a complaint with your local supervisory authority.

    For Users in California

    Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to know what personal information is collected, request deletion, opt out of sales (we do not sell your data), and not be discriminated against for exercising privacy rights.

    10. International Data Transfers

    Your information may be transferred to and processed in countries other than the country in which you reside. Craqly is operated from India, and our service providers — including Supabase, Deepgram, AssemblyAI, OpenAI, Google, OpenRouter and Anthropic — process data in the United States and in other regions where they operate, which may include the European Union and Asia-Pacific. Session audio and text may therefore be processed outside your country of residence. These countries may have data protection laws that differ from your jurisdiction. When we transfer data internationally, we rely on appropriate safeguards, including standard contractual clauses and data processing agreements with our service providers.

    11. Children's Privacy

    The Services are not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with their personal information, please contact us at support@craqly.com.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and may notify you via email or through the Services. Your continued use of the Services after the updated policy becomes effective constitutes your acceptance of the changes.

    We encourage you to periodically review this page for the latest information on our privacy practices.

    13. Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    For privacy-specific inquiries, you can also reach our Data Protection contact at the email address above.