Privacy Policy
Effective date: 4 May 2026 Last updated: 4 May 2026
1. Who we are#
CaptainReady is operated by Jason Jones, trading as CaptainReady, a sole trader established in the United Kingdom.
- Data controller: Jason Jones, trading as CaptainReady
- Registered address: Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA
- Contact email: support@captainready.app
- Website: https://captainready.app
For the purposes of UK GDPR and the Data Protection Act 2018, Jason Jones is the data controller for any personal data you provide to or generate through CaptainReady.
2. What this policy covers#
This policy explains what personal data we collect when you use CaptainReady, why we collect it, how long we keep it, who we share it with, and the rights you have over it. It applies to use of the CaptainReady website and associated services (together, "the Service").
3. The data we collect#
We collect the following categories of personal data.
Account data. Your name, email address, and any profile details you supply (such as target airlines, licence type, or hours logged) when you create an account or update your profile.
Authentication data. Sign-in metadata handled by our authentication provider, Clerk, including login timestamps and session tokens. Passwords, if used, are stored and handled by Clerk and never reach our systems in plaintext.
Payment data. Subscription and billing information. Card and banking details are collected and held by Stripe, our payment processor. We do not see, store, or have access to your full card number at any time. We retain a Stripe customer identifier and summary information such as subscription status, plan, and billing period.
Session data. The content of your mock interview sessions, including the questions posed by our AI interviewer and the answers you provide, plus the scores, feedback, and competency ratings generated for each session.
Usage data. Technical information necessary to operate the Service: timestamps, IP address during authentication, device type, browser type, and basic diagnostic logs.
Analytics data. If you consent, we use a privacy-respecting product-analytics tool (PostHog) to understand how visitors move through the site and where they drop off, so we can improve it. Analytics are off by default and collect nothing until you accept the analytics banner. When enabled, we record pages viewed, clicks, and a small number of product events (for example, starting signup, or completing a session) associated with a random identifier and, once you have an account, your account identifier. We do not send the content of your sessions to our analytics provider, we do not record your screen, we anonymise IP addresses, and we never use this data for advertising. You can decline, and you can withdraw consent at any time.
4. Why we collect it (lawful basis)#
Under UK GDPR we rely on the following lawful bases.
Performance of a contract. We process your account, authentication, payment, and session data because it is necessary to deliver the Service you have signed up for.
Legitimate interests. We process minimal usage and diagnostic data to keep the Service secure, investigate incidents, and improve quality. We have assessed that this is proportionate and does not override your interests.
Legal obligation. We retain certain financial records (invoices, payment confirmations) for six years to comply with HMRC requirements.
Consent. Where we rely on consent — for example, optional product analytics, or optional features or communications — we ask you for it clearly and you can withdraw it at any time. Analytics are only collected after you accept the analytics banner.
5. How long we keep it#
We retain personal data only for as long as necessary.
Session transcripts, scores, and account data — retained until you delete your account. When you delete your account, we purge all associated personal data within 30 days, except where law requires otherwise.
Financial records (invoices, payment confirmations, VAT records where applicable) — retained for 6 years after the end of the tax year to which they relate, in line with HMRC requirements.
Diagnostic logs and security audit records — retained for up to 90 days, then deleted or anonymised.
Backups — may contain copies of your data for up to 35 days after deletion, after which backup rotation permanently overwrites them.
6. Who we share your data with#
We do not sell your personal data. We do not share it for marketing purposes. We do share it with the following categories of service provider, who act as our data processors under contract and are only permitted to use the data to provide services to us.
- Clerk (authentication) — account identifiers and authentication metadata. Data processed in the United States under Standard Contractual Clauses.
- Stripe (payment processing) — payment details, billing information. Data processed in the United States under Standard Contractual Clauses.
- Anthropic (AI inference) — the content of your session messages is sent to Anthropic's Claude API to generate interviewer responses and scoring. Anthropic processes this data as a service provider to us and does not use it to train their models. Data processed in the United States under Standard Contractual Clauses.
- OpenAI (embeddings) — small text excerpts from your messages are sent to OpenAI's embeddings API to support the knowledge retrieval component of the Service. OpenAI does not use this data to train their models when accessed via the API. Data processed in the United States under Standard Contractual Clauses.
- Neon (database hosting) — all Service data is stored in a managed Postgres database hosted by Neon. Data is stored in the European Union.
- Inngest (background job processing) — event identifiers and session identifiers for scoring workflows. Data processed in the United States under Standard Contractual Clauses.
- PostHog (product analytics, only with your consent) — pageview, click, and product-event data associated with a random identifier or, once you have an account, your account identifier. No session content. Data is processed in the European Union.
We may disclose personal data to regulators, law enforcement, courts, or other authorities if required by law or to defend our legal rights.
7. International transfers#
Some of the service providers listed above are based outside the United Kingdom, principally in the United States. Where we transfer personal data outside the UK or European Economic Area, we rely on Standard Contractual Clauses approved under UK GDPR to ensure your data continues to receive an equivalent level of protection.
8. Your session content and AI training#
We do not permit our AI service providers to use the content of your sessions to train their models. Your transcripts are used only to generate responses and scoring for your own sessions. We do not pass user session data to any third-party AI training pipeline.
9. Cookies#
CaptainReady uses strictly necessary cookies for:
- Authentication — cookies set by Clerk to keep you signed in for the duration of your session.
- Security — cookies used to protect against cross-site request forgery and similar attacks.
With your consent, we also use analytics cookies and local storage set by PostHog, our privacy-respecting product-analytics provider, to measure how the site is used. These are off by default: we show a consent banner and set no analytics cookies until you accept. If you decline, no analytics cookies are set. You can change your choice at any time, and we will honour it. We remember your decision so we do not ask again.
We do not use advertising cookies or advertising trackers, and we do not record your screen.
10. Your rights#
Under UK GDPR you have the following rights in relation to your personal data.
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your data, subject to any legal retention obligations.
- Right to restrict processing — ask us to limit how we use your data in certain circumstances.
- Right to data portability — request your data in a structured, machine-readable format.
- Right to object — object to processing based on our legitimate interests.
- Right to withdraw consent — where we rely on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email us at support@captainready.app. We will respond within one month and, in most cases, without charge.
11. Automated decision-making#
Your mock interview sessions produce automated scores generated by AI. These scores are intended as training feedback to help you prepare for real airline interviews. They do not produce legal or similarly significant effects on you — they do not determine eligibility for employment, licensing, or any external decision. If at any time we introduce automated decision-making that does have such effects, we will inform you and provide the safeguards required under UK GDPR.
12. Security#
We take reasonable technical and organisational measures to protect your personal data, including encryption in transit, encryption at rest for database storage, role-based access controls, and routine security review of our service providers. No internet service can be perfectly secure, but we aim to meet or exceed the standards expected of a small SaaS operator handling the categories of data described above.
If we ever experience a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it and, where required, notify affected individuals directly.
13. Children#
CaptainReady is not directed at children. You must be 18 or older to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, email support@captainready.app and we will delete it.
14. Complaints#
If you are unhappy with how we have handled your personal data, please contact us first at support@captainready.app so we can try to resolve the matter. You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Web: https://ico.org.uk
15. Changes to this policy#
We may update this policy from time to time. If we make material changes, we will notify you by email and post the updated policy at https://captainready.app/privacy with a new effective date. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
16. Contact#
Questions about this policy or about how we handle your personal data should be sent to:
Email: support@captainready.app Post: Jason Jones, trading as CaptainReady, Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA