Privacy Policy
This policy explains what information UIHero collects, why we use it, when we share it, and the choices available to you.
1. Scope
This Privacy Policy applies to the UIHero website, coding workspace, accounts, and support interactions. It does not apply to third-party services that publish their own privacy notices.
UIHero is responsible for the handling described here. Depending on where you live, we process information to provide the service you request, protect and improve the service, comply with law, and, when required, based on your consent.
2. Information we collect
Information you provide
- Account and profile information: your email address, display name, handle, optional profile image, preferences, and sign-in information. Supabase processes the email and password or social sign-in details needed to authenticate you. We do not receive the password you use with a social sign-in provider.
- Learning information: code, drafts, submissions, test results, problem progress, saved topics, and practice history that you choose to associate with your account.
- Reviews: your display name, optional role, rating, review text, and review status if you choose to submit a learner review.
- Billing and communications: the plan you select, subscription and billing records, and the name, email, topic, and message you provide when you contact us. You provide card details directly to Stripe. We do not receive or store your full card number.
Information collected when you use the service
- Device and activity information: IP address, browser and device type, dates and times, referring pages, pages requested, feature interactions, submission status, and reliability, error, or security events.
- AI and interview information: the code or context you choose to share, interview type and duration, microphone audio during a live interview, transcripts, session events, scorecards, and provider usage information.
- Browser-stored information: theme, editor state, local drafts, coding workspace files, terminal output, and other preferences stored on your device.
Account details are required if you create an account, and billing details are required if you buy a plan. Profile extras, reviews, analytics, and AI or interview features are optional. If you do not provide information required for a feature, we cannot provide that feature.
We do not ask you to provide government identifiers, financial-account credentials, health information, or other sensitive personal information for ordinary practice features. Do not put that information in code, forms, or support messages.
3. Where information comes from
We receive information from you, from your browser when you use the service, and from providers that support the features you choose. These providers may include Supabase for accounts and stored app data, Google, GitHub, or LinkedIn for social sign-in, StackBlitz for browser coding, a grading provider for submissions, OpenAI for requested AI features, Stripe for billing, Resend for email, and Google Analytics after you allow optional analytics.
A social sign-in provider shares only the account and profile information covered by the permission screen you approve. We do not receive the password you use with that provider.
4. How and why we use information
We use information to:
- create, authenticate, and protect accounts;
- provide coding workspaces, previews, tests, submissions, drafts, progress, profiles, interviews, and feedback;
- manage paid plans, confirm billing events, prevent duplicate charges or messages, and provide paid access;
- save preferences and personalize learning features;
- review and, only after approval, publish a learner review you submit;
- respond to support, privacy, feedback, and security requests;
- send necessary account and subscription messages;
- measure reliability, diagnose problems, improve the service, and understand aggregate use when you allow optional analytics; and
- prevent abuse, protect people and systems, enforce our terms, and meet legal obligations.
Legal reasons for processing
We process information to perform our agreement with you when we provide an account, requested feature, or paid plan. We use information for legitimate interests such as securing, supporting, and improving the service, provided those interests do not override your rights. We rely on consent for optional analytics and other uses where the law requires it. We also process information when needed to meet legal obligations or protect legal rights.
AI feedback and interview scores are practice tools. We do not use them to make solely automated decisions that have legal or similarly significant effects on you.
We do not sell personal information or share it for cross-context behavioral advertising. If that changes, we will update this policy and provide any notice or choice required by law before the change takes effect.
5. Code and local preview
When you choose Run, your code is executed in a browser-based coding environment. A preview can make network requests written into your code, and supporting services may receive ordinary request information such as your IP address, browser type, and request time.
Working drafts are stored in your browser for each problem and are not sent to our main database by draft autosave. Leaving a workspace ends its active browser coding session, although your browser or the runtime provider may keep normal caches.
When you choose Submit, the code needed to grade the answer is sent to a separate grading service. We keep the submission record, result, and progress tied to your account. Our main database does not keep a copy of the submitted source after it is sent for grading, although the grading provider may process copies and test artifacts under its own retention controls.
Never include passwords, API keys, personal information, or other secrets in challenge code.
6. AI, billing, and email
When you request an AI code review or interview feature, we send the selected code, prompt, transcript, live audio, or session context needed to provide that feature to our AI provider. Ordinary browsing does not activate your microphone. A live interview starts only after you take an explicit action and allow browser microphone access.
We do not save raw microphone recordings in our main database. We do save interview transcripts, session details, usage information, and scorecards so you can view results and so we can operate usage limits. We do not use interview sessions to infer psychological traits or penalize accent, disability, language background, culturally different speaking styles, or microphone quality.
Stripe processes payment details and sends us the account, plan, subscription, invoice, status, and billing events needed to manage paid access. Stripe may also use transaction and device information for fraud prevention, tax, security, and legal compliance under its own privacy notice.
Resend processes recipient and message information when we send account or subscription email or deliver a contact request to our support inbox. These service messages are not marketing email.
7. Cookies and local storage
We use essential cookies and similar browser storage to keep you signed in, protect the service, operate the coding workspace, and remember choices such as theme and local editor drafts. You can clear this information in your browser, but doing so may sign you out or remove preferences, drafts, and local workspace data.
Google Analytics is optional and does not load until you choose Allow analytics. If allowed, it receives limited page and feature-use information. We do not send editor code, form contents, email addresses, account identifiers, query values, transcripts, or interview and submission identifiers to Google Analytics.
8. How we share information
We disclose information only when reasonably necessary:
- Account and app providers: Supabase supports sign-in, storage, and app records. Google, GitHub, or LinkedIn supports a social sign-in only when you choose it.
- Coding and grading providers: StackBlitz and package providers support browser coding. A separate grading provider receives code only when you choose Submit.
- OpenAI: receives the code or context needed for an AI review, or the audio, transcript, and session context needed for an interview you start.
- Stripe: provides checkout, subscription payment processing, billing events, and customer billing tools.
- Resend: delivers account and subscription email and sends contact requests to our support inbox.
- Google Analytics: receives limited usage information only after you allow optional analytics.
- Public review visitors: may see your display name, optional role, rating, and review text after we approve a review you submit.
- Legal, safety, and business needs: we may disclose information when required by law, to protect rights or safety, or as part of a merger, financing, reorganization, or sale with appropriate protections.
- At your direction: we share information when you ask us to or clearly authorize an integration.
Service providers acting on our behalf process information under our service arrangements. A provider may separately use information for its own legal, security, fraud, or compliance duties, as explained in its privacy notice. We may also use information that has been aggregated or de-identified so it cannot reasonably identify you.
9. Retention
Account, profile, learning, review, and interview records are generally kept while your account is active and for a reasonable period afterward when needed for support, security, or disputes. Local drafts remain in your browser until you replace or clear them. Raw microphone recordings are not kept in our main database.
Billing records are kept as needed for subscriptions, accounting, fraud prevention, disputes, and legal duties. Contact and email-delivery records are kept as needed to answer requests, deliver messages, and show that delivery occurred. Security logs are kept only for the period reasonably needed to investigate and protect the service. Optional analytics follows the retention setting of our analytics account.
After a valid deletion request, we delete or de-identify account information within a reasonable period unless we must keep some records for security, fraud prevention, billing, disputes, legal compliance, or backups. Providers apply their own retention schedules under their notices and our service arrangements. Backup copies are isolated from ordinary use and removed through their normal cycle.
10. Security
We use reasonable technical and organizational safeguards designed for the information we handle, including access controls, protected connections, restricted credentials, and separation between coding environments and production systems. No service can guarantee absolute security. Use a unique password and contact us promptly if you suspect unauthorized access.
11. Your choices and privacy rights
Depending on where you live, you may have the right to know about, access, correct, delete, or receive a portable copy of your personal information. You may also be able to restrict or object to some uses, withdraw consent, appeal a denied request, or complain to your local data-protection authority.
Send a request through our contact form or email support@uihero.dev. We may need to verify your identity. An authorized agent may act for you where the law allows, but we may ask for proof of authorization. We will not discriminate against you for exercising a privacy right. You may also ask us to remove a review linked to your account.
12. Children
The service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 provided personal information, contact us so we can investigate and promptly delete it as required by law. A higher age or parental permission requirement may apply in some places.
13. International transfers
We and our providers may process information in countries other than where you live. When the law requires a transfer safeguard, we use an applicable legal mechanism for that transfer. Privacy laws in those countries may differ from the laws where you live. Contact us to ask which safeguard applies to your information or how to obtain a copy.
14. Changes to this policy
We may update this policy as the service and legal requirements change. We will post the revised policy, update its effective date, and provide additional notice before a material change when required by law.
15. Contact
To ask a privacy question or exercise a privacy right, use our contact form and select Privacy, or email support@uihero.dev. Do not include passwords, private keys, or sensitive code. We may verify your identity before acting on a request.