Skip to content

Privacy Policy

How SchemaLab collects, uses, shares, and protects your information.

Last updated June 20, 2026

Overview

We operate SchemaLab and are the data controller responsible for your information. This policy explains what we collect when you use SchemaLab, why we collect it, the legal basis for it, who processes it on our behalf, and the choices you have. We collect the minimum needed to run the practice and performance loops.

Information we collect

Account information: your email and authentication details, and any profile fields you provide (such as experience level).

Content you create: the data models, submissions, challenge progress, and interview transcripts you generate while using the Service.

Usage data: product analytics events (pages viewed, features used) collected to improve the Service.

Payment information: if you subscribe, billing is handled by Stripe. We do not store full card numbers; we receive limited subscription and status information from Stripe.

Support reports: when you send a report, we collect your message, account email, and any optional screenshot. To help us investigate, the report can also include the current page, app version, browser family, viewport size, and the problem in view. We do not include URL query strings.

How we use your information

To provide and maintain the Service, run deterministic and AI-assisted feedback, manage subscriptions, communicate with you about your account, secure the platform, and improve content and features.

Legal basis for processing

Where the GDPR or similar laws apply, we rely on these bases: contract (to provide the Service you sign up for, run submissions, and manage your subscription); legitimate interests (to secure the platform and improve features via privacy-preserving analytics); consent (where required, for example advertising cookies in regions that require opt-in); and legal obligation (for example retaining payment records). You can withdraw consent at any time where consent is the basis.

Service providers and third parties

We share data with processors that help us operate the Service:

Supabase: database, authentication, and storage.
Stripe: payment processing and subscription billing.
PostHog: product analytics.
Anthropic: AI processing for tutoring, design feedback, and mock-interview evaluation.
Resend: transactional and account email (for example sign-up, password reset, and receipts).
Meta: advertising measurement, where enabled (see Cookies, analytics, and advertising).
Vercel and Railway: application and API hosting.

Each processes data only to provide their service to us, under their own terms. We do not sell your personal information.

AI processing

When you use AI features, the relevant context (such as your current model and the challenge) is sent to our AI provider to generate feedback. We instruct providers not to use your content to train their models, consistent with their commercial terms. AI feedback is assistive and is bounded by our deterministic checks.

Cookies, analytics, and advertising

Essential cookies: we use these for authentication and security (to keep you signed in). They are required for the Service to function.

Product analytics: PostHog and Vercel are configured to be cookieless, without setting tracking cookies or storing an analytics identifier on your device. PostHog events stay anonymous and session-local; we do not send your account identifier to PostHog.

Advertising: where enabled, we use the Meta Pixel to measure and improve our ads, which shares limited event data with Meta. You can opt out at any time through Your Privacy Choices in the footer, and we honor the Global Privacy Control browser signal. In regions that require prior opt-in consent for advertising cookies, we request consent before any such cookie is set.

International data transfers

We are based in the United States and our providers process data there. If you access the Service from outside the United States, your information is transferred to and processed in the U.S. Where required, we rely on appropriate safeguards such as the Standard Contractual Clauses for these transfers.

Data retention and deletion

We retain your account and content for as long as your account is active. You can delete your SchemaLab account and platform-owned content at any time from your account settings, or by contacting us at support@schemalab.dev. Once an in-product request is accepted, account access ends and we continue verified deletion across our systems and applicable service providers in the background. A private status link reports progress and the final deletion receipt without revealing deleted content. De-identified verification receipts that no longer map to your account may remain. Required billing records and copies of support messages already delivered to our external inbox may also remain under applicable retention rules.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the email above. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority.

California privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to access or delete it, to correct it, and to opt out of its “sale” or “sharing.” We do not sell your personal information. Advertising tools like the Meta Pixel may count as “sharing” for cross-context behavioral advertising; you can opt out through Your Privacy Choices in the footer, and we honor the Global Privacy Control signal. We will not discriminate against you for exercising these rights.

Security

We use industry-standard measures including encrypted transport, authentication, and tenant isolation so users can only access their own data. No method of transmission or storage is perfectly secure.

Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

Changes to this policy

We may update this policy from time to time. Material changes will be posted here with an updated date.

Contact

Privacy questions or requests? Email support@schemalab.dev.