Privacy Policy

Last Updated: March 10, 2026

Welcome to Orchestra ("we," "us," or "our"). Orchestra is an AI-powered real-time interview assistant platform designed to help job seekers prepare for and succeed in their interviews. We are committed to protecting your privacy and handling your personal information with care and transparency.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (orchestra.love) and our services (collectively, the "Services"). Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Information We Collect

1.1 Information You Provide to Us

When you create an account, we collect essential account information such as your full name, email address, encrypted password, and professional profile details like your experience level and target roles. To further personalize your experience, you may also choose to provide additional profile and persona information, including your resume, professional background, job descriptions for roles you're targeting, career goals and preferences, educational background, and details about your skills and certifications.

If you subscribe to one of our paid plans, we collect billing-related information such as your billing name and address, payment card details (which are processed securely through trusted third-party payment processors), and transaction history. We also collect communications data when you interact with us, including email correspondence, support ticket details, and any feedback or survey responses you choose to share.

1.2 Information Collected Automatically

We automatically collect usage data about how you interact with our Services to help us operate, improve, and personalize the experience. This includes information related to interview sessions (both practice and real-time modes), feature usage such as Vision View, Combo Mode, Practice Mode, and Multi Screen Capture, as well as the time spent using different features. We also track credit usage and session minutes, pages visited, navigation patterns, and the date and time you access the Services.

In addition, we collect device and technical information such as your IP address, browser type and version, operating system, device identifiers, screen resolution, and time zone settings. We also use cookies, web beacons, and similar tracking technologies to gather information about browsing activities across our Services. For more details on how these technologies are used, please refer to Section 6 (Cookies and Tracking Technologies).

1.3 Information from Third-Party Services

Video Conferencing Platform Integration: When you use Orchestra during interviews on platforms like Zoom, Microsoft Teams, Google Meet, Skype, or other supported platforms, we may access:

  • Screen sharing content you choose to analyze
  • Information you input during sessions

AI Model Providers: We use OpenAI's GPT-4o and GPT-4o mini models. The information you provide during sessions is processed by these AI models in accordance with their privacy practices.

Payment Processors: Our payment processors (such as Stripe or similar services) share transaction confirmation and billing information with us.

1.4 Sensitive Information

Screen Content Analysis: Our Vision View and Combo Mode features may capture and analyze on-screen content during your sessions. This may include:

  • Presentations, code, or documents shared during mock interviews
  • Interview questions and materials
  • Technical challenges or problem sets

You have full control over when these features are activated and what content is shared.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 To Provide and Improve Our Services

  • Creating and managing your account
  • Generating personalized AI personas based on your resume and job descriptions
  • Providing real-time AI assistance during interview sessions
  • Analyzing screen content through Vision View
  • Processing questions and generating responses in Combo Mode
  • Facilitating practice interview sessions
  • Tracking credit usage and session minutes
  • Providing access to features based on your subscription plan

2.2 To Communicate with You

  • Sending account-related notifications
  • Responding to your inquiries and support requests
  • Sending service updates and maintenance notices
  • Providing information about new features and improvements
  • Sending marketing communications (with your consent)

2.3 To Process Payments

  • Processing subscription payments
  • Managing billing and invoicing
  • Preventing fraud and unauthorized transactions

2.4 To Improve and Optimize

  • Analyzing usage patterns to improve our Services
  • Conducting research and development
  • Testing new features and functionality
  • Optimizing AI model performance
  • Improving user experience and interface design

2.5 For Security and Legal Compliance

  • Detecting, preventing, and addressing fraud and abuse
  • Protecting against security threats
  • Enforcing our Terms of Service
  • Complying with legal obligations
  • Responding to legal requests and preventing harm

2.6 With Your Consent

  • Any other purposes disclosed to you at the time we collect your information
  • Any other purposes for which you provide explicit consent

3. Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

AI Model Providers: We use OpenAI's GPT-4o and GPT-4o mini models to power our AI assistance features. Your interview questions, responses, and screen content (when using Vision View or Combo Mode) are processed by OpenAI's services. This processing is subject to OpenAI's privacy practices and data usage policies.

Payment Processors: We use third-party payment processors to handle subscription payments and billing.

Cloud Hosting: We use Supabase and other cloud infrastructure providers to host and store data.

Analytics Providers: We use analytics services to understand how users interact with our Services.

Customer Support: We use customer support tools to manage and respond to your inquiries.

All service providers are contractually obligated to maintain the confidentiality and security of your information and to use it only for the purposes for which it was disclosed.

3.2 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal process (subpoena, court order, or search warrant)
  • Legal claims or disputes
  • Requests from law enforcement or government agencies
  • Situations involving potential threats to the safety of any person

3.4 Protection of Rights

We may disclose information to:

  • Enforce our Terms of Service and other agreements
  • Protect our rights, property, and safety
  • Protect the rights, property, and safety of our users and the public
  • Detect, prevent, or address fraud, security, or technical issues

4. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit using SSL/TLS protocols, encryption of sensitive data at rest, secure authentication and password protection, regular security assessments and audits, access controls and authentication mechanisms, employee training on data protection and privacy, and the use of secure data centers with physical security controls. However, no method of transmission over the internet or electronic storage is completely secure, and while we strive to protect your personal information, we cannot guarantee absolute security; you are responsible for maintaining the confidentiality of your account credentials.

5. International Data Transfers

Orchestra is operated from the United States. If you are located outside the United States, please be aware that information we collect will be transferred to, processed, and stored in the United States and other countries where our service providers operate.

These countries may have data protection laws that differ from those in your country. By using our Services, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.

We take appropriate measures to ensure that your personal information receives an adequate level of protection in accordance with applicable data protection laws.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities and to provide, maintain, and improve our Services.

6.1 Types of Cookies We Use

Essential Cookies: Necessary for the Services to function properly (e.g., authentication, security).

Analytics Cookies: Help us understand how users interact with our Services (e.g., page views, session duration).

Functional Cookies: Remember your preferences and settings.

Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness.

6.2 Managing Cookies

Most web browsers are set to accept cookies by default. You can usually modify your browser settings to decline cookies or alert you when cookies are being sent. However, disabling cookies may affect the functionality of our Services.

You can learn more about managing cookies at: www.allaboutcookies.org

6.3 Do Not Track

Some browsers include a "Do Not Track" (DNT) feature. Our Services do not currently respond to DNT signals.

7. Children's Privacy

Our Services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.

8. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, and services that are not operated by us. This Privacy Policy does not apply to third-party services. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access.

Video Conferencing Platforms: When you use Orchestra with platforms like Zoom, Microsoft Teams, Google Meet, or Skype, you are subject to those platforms' privacy policies and terms of service.

OpenAI Services: Our use of OpenAI's AI models is subject to OpenAI's privacy policy and terms of service. Please review OpenAI's privacy practices at: https://openai.com/privacy

9. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collection, and the categories of third parties with whom we share information.

Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.

Right to Opt-Out: You have the right to opt-out of the sale of your personal information. We do not sell personal information.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, please contact us. We will verify your identity before processing your request and respond within 45 days.

10. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Legal Basis for Processing: We process your personal information based on:

  • Contract performance (to provide our Services)
  • Consent (for marketing communications and optional features)
  • Legitimate interests (to improve our Services, prevent fraud)
  • Legal obligations (to comply with laws and regulations)

Data Protection Officer: For GDPR-related inquiries, you may contact our Data Protection Officer.

Supervisory Authority: You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on our website
  • Updating the "Last Updated" date at the top of this policy
  • Sending an email notification to the address associated with your account (for material changes)

Your continued use of our Services after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically.