Legal

Security

How MagicInterview protects accounts and data: encryption in transit, server-side secrets, session protection, EU hosting and how to report a vulnerability.

Last updated

MagicInterview handles CVs, notes and the words of real conversations, so protecting them is part of the product. This page describes the protections that are in place today, in plain terms. It does not promise more than that.

Where your data lives#

Our servers and database are hosted in Germany, in the European Union. Provider-specific processing outside the EU, and which providers receive what, is listed on the Subprocessors page.

Encryption in transit#

Traffic between your device and MagicInterview uses TLS (HTTPS). The apps for iPhone, iPad, Android and Mac talk to the same HTTPS service as the web app. Our server also sends standard security headers and limits the microphone to our own pages.

Accounts and sign-in#

  • Sign-in uses email and password, handled by Better Auth, a widely used open source authentication library. Passwords are stored only as hashes.
  • Sessions use secure cookies on the web and the device's secure storage in the apps. They expire after 30 days and are renewed while you keep using the app.
  • Password-reset links work for one hour, can be requested only a few times per hour for each address, and the reset page responds the same way whether or not an account exists. Resetting a password signs out every other session.
  • Redirect targets after sign-in are validated, so a crafted link cannot send you to another site.

Secrets stay on the server#

Credentials for our AI, speech, research, email and database providers are held in server configuration and are never shipped to your browser or the apps. The few keys that appear in the web app or the apps, such as the analytics project token and the subscription provider's public key, are public by design and can only send events or read purchase status.

Isolation and access#

  • Each account has its own isolated workspace. Requests are authenticated, and files and conversations are looked up by account, so one person cannot read another's.
  • Features that cost money or reach AI providers are rate limited per account.
  • Diagnostic records redact fields whose names indicate secrets, such as authorization, cookie, password, token and API key.

Connected AI assistants#

An AI assistant can connect to your workspace only after you approve it on a consent screen that lists exactly what it may read and change. Access uses OAuth. Connection tokens you create in Settings are stored as hashes, and you can revoke any connection in Settings.

What we keep, and for how long#

Audio is not stored: speech is turned into text and discarded. A voice sample is stored only as a numeric voice profile, never as a recording. Live practice sessions on our server exist only in memory; the practice conversation saved in your project is kept like your other conversations. Everything else you save lives in your account until you delete it. When you delete your account, your workspace, files, voice profile, subscription records and diagnostic events are removed. The details are in the Privacy Policy.

Payments#

We never see or store your payment card details. Purchases are handled by the Apple App Store and Google Play, and subscription status is confirmed with RevenueCat.

Reporting a vulnerability#

If you believe you have found a security problem, email support@magicinterview.app with Security in the subject. Please include what you found and how to reproduce it, and give us a reasonable time to fix it before you share it publicly. Please do not access other people's data, degrade the service or test with accounts that are not yours. We read every report and reply as soon as we can.

Questions from security teams#

If your organization needs more detail for a review, write to us at the same address. A Data Processing Addendum is available for customers who need one.