Privacy Policy
Lailani.ai and PlayCV.ai — Operated by PlayCV, Inc.
Last Updated: July 14, 2026
In Short
- We provide AI-powered communication coaching and professional development tools.
- We do not make hiring, admissions, employment, legal, medical, psychological, financial, or other significant decisions about you.
- We do not sell your personal information.
- Because our Services may analyze video, audio, speech, facial expression, eye contact, posture, gestures, and other communication signals, some information may be considered biometric or sensitive personal information under applicable law. Where legally required, we obtain consent before collecting or analyzing it.
- We do not use facial recognition to identify you, conduct surveillance, perform lie detection, diagnose medical or psychological conditions, or make employment or admissions decisions.
- We do not use your identifiable User Content to train general-purpose third-party AI models unless we disclose this to you and have a lawful basis.
- You may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. Contact privacy@playcv.ai.
1. Introduction
This Privacy Policy applies to Lailani.ai, PlayCV.ai, and any related websites, applications, platforms, products, tools, AI features, software, and services operated by PlayCV, Inc. (collectively, the “Services”).
PlayCV, Inc. (“PlayCV”, “we”, “us”, or “our”) is a Delaware corporation with its registered address at 1111B South Governors Avenue, STE 40089, Dover, DE 19904, United States. We provide AI-powered communication coaching and practice, presentation support, and professional development tools designed to help users understand, practice, and improve how they communicate.
This Privacy Policy explains how we collect, use, store, disclose, retain, and protect personal information, and it explains your rights and choices. It should be read together with our Terms of Service and our Cookie Policy. Additional consent notices, feature-specific disclosures, enterprise or institutional agreements, or customer-specific terms may also apply depending on how you access or use the Services. This Privacy Policy should be read together with our Terms of Service, including its Limitation of Liability, Arbitration Agreement, and Renewal, Cancellation, and Refunds sections, and our Cookie Policy.
Defined terms used in this Privacy Policy, including Account, AI Features, Services, Subscription, and User Content, have the meanings given in the Terms of Service unless otherwise defined here.
2. Our Role
For individual users who create and use their own accounts, PlayCV generally acts as the data controller responsible for determining how personal information is processed.
Where the Services are provided through an employer, university, school, accelerator, company, government body, nonprofit, or other organization, PlayCV may act as a processor, service provider, contractor, or subprocessor on behalf of that organization. In those cases, the organization may determine certain purposes and means of processing, and its own privacy notice, internal policies, contracts, or consent processes may also apply. If you are unsure whether PlayCV is acting as a controller or processor, contact privacy@playcv.ai.
3. Key Privacy Commitments
- We do not sell your personal information.
- We do not use the Services to make hiring, admissions, employment, or other legally significant decisions about you.
- We do not use facial recognition to identify or authenticate you, or create permanent identity templates, unless we clearly introduce and disclose such a feature in the future and obtain any consent required by law.
- We process video, audio, behavioral, communication, and biometric-like information only for disclosed purposes connected to communication coaching, service delivery, security, legal compliance, customer support, and service improvement.
- We do not use biometric information for surveillance, lie detection, medical diagnosis, psychological assessment, or employment screening.
- We aim to collect only the information reasonably necessary to provide, secure, support, maintain, and improve the Services.
- We provide rights and choices over personal information, including access, correction, deletion, portability, objection, restriction, and consent withdrawal where applicable.
4. Definitions
- Account: a registered account used to access the Services.
- AI Features: features that use artificial intelligence, machine learning, large language models, computer vision, speech analysis, audio analysis, avatar technology, or related technologies to provide coaching, feedback, analysis, summaries, recommendations, simulations, or outputs.
- Biometric Information: information that may be considered biometric identifiers, biometric information, biometric data, biometric-like data, sensitive personal information, or special category data under applicable law, including certain facial, voice, eye, gaze, movement, or behavioral characteristics where legally recognized as biometric information.
- Communication Analysis Data: information generated from analyzing how a user communicates, including speech pace, tone, fluency, verbal structure, eye contact, facial presentation, posture, gestures, response timing, confidence indicators, delivery style, and similar communication signals.
- De-identified Data: information processed so that it is not reasonably capable of identifying an individual, provided we maintain reasonable measures designed to prevent re-identification.
- Personal Information: information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable person.
- Processing: any operation performed on personal information, including collection, recording, storage, organization, use, analysis, disclosure, transfer, deletion, and destruction.
- Sensitive Personal Information: personal information treated as sensitive under applicable law, which may include biometric information, account credentials, payment information, government identifiers, health-related information, precise geolocation, or other legally protected information.
- User Content: any content, data, or materials you submit, upload, record, generate, transmit, or otherwise provide through the Services, including videos, audio recordings, transcripts, CVs, resumes, cover letters, LinkedIn profiles, written responses, prompts, messages, documents, presentations, and communication materials.
5. Information We Collect
We collect information you provide directly, information generated through your use of the Services, information collected automatically, and information received from third parties.
5.1 Account and Contact Information
- Name, email address, and username.
- Password or authentication credentials.
- Phone number, if provided.
- Account settings, preferences, and profile information.
- Organization or institutional affiliation, where applicable.
- Subscription status and support communications.
5.2 Professional, Educational, and Career Information
You may choose to provide:
- CVs, resumes, cover letters, and professional bios.
- LinkedIn profiles or profile links.
- Education and work history.
- Skills, interests, and career goals.
- Job descriptions, role materials, and practice questions.
- Presentation materials, written responses, development goals, and communication scenarios.
5.3 User Content
We may collect and process User Content, including video and audio recordings, transcripts, written responses, uploaded documents, prompts and instructions, practice answers, presentation scripts, chat messages, role-play responses, AI-generated feedback associated with your account, session history, and coaching notes. You remain the owner of your User Content, subject to the permissions granted in our Terms of Service so that we can provide, secure, support, maintain, improve, and develop the Services.
5.4 Video, Audio, and Communication Data
Because the Services provide AI-powered communication coaching, we may process video, audio, speech, transcript, and related communication data, which may include:
- Speech pace, tone, clarity, rhythm, fluency, and structure.
- Vocabulary, filler words, hesitation, pauses, and response timing.
- Voice energy, delivery patterns, facial expressions, and emotional presentation.
- Eye contact, gaze direction, and visual engagement.
- Posture, gestures, body language, and physical presence.
- Conversation flow, persuasiveness, communication style, turn-taking, and message clarity.
- Progress over time and performance trends.
This information is used to provide communication coaching, personal development insights, and feedback. It is not used to diagnose, medically assess, psychologically evaluate, rank, or make employment decisions about you.
5.5 Biometric and Biometric-Like Information
Some video, audio, facial, voice, eye, gaze, movement, or behavioral analysis may constitute Biometric Information under certain laws. Where our processing constitutes Biometric Information under applicable law, we will provide notice and obtain any consent required by law before collecting or analyzing it.
We do not use Biometric Information to identify or authenticate you, conduct surveillance, perform lie detection, assess mental health, determine credibility, create permanent identity templates, or make decisions about your eligibility for employment, education, housing, credit, insurance, immigration, legal rights, or other significant opportunities.
5.6 Payment and Transaction Information
Payments may be processed by third-party payment processors, such as Stripe, LemonSqueezy by Stripe, or other providers we may use from time to time. We do not store complete payment card numbers. Payment processors may collect and process payment card details, billing details, transaction history, fraud-prevention information, tax information, and subscription status, governed by their own terms and privacy policies.
5.7 Technical Information
We may automatically collect IP address, device type, browser type, operating system, device and session identifiers, log data, crash and error reports, performance data, security logs, access records, and approximate location derived from IP address.
5.8 Usage Information
We may collect information about how you use the Services, including pages viewed, features used, buttons clicked, navigation patterns, session duration and frequency, interaction history, preferences, referral source, product engagement, subscription usage, and AI feature usage.
5.9 Cookies and Similar Technologies
We use cookies, pixels, local storage, SDKs, web beacons, and similar technologies to operate, secure, personalize, analyze, improve, and market the Services. These may include:
- Strictly necessary cookies: for login, authentication, fraud prevention, security, and core functionality.
- Functional cookies: for preferences and settings.
- Analytics and performance cookies: to understand usage and improve the Services.
- Advertising and marketing cookies: set by third-party advertising partners to measure the effectiveness of our marketing and show you relevant content about the Services on other platforms. These are used only with your consent where required by law, and you can opt out at any time.
- Security technologies: to detect abuse, unauthorized access, and technical issues.
For full details, including the categories of cookies we use, our advertising partners, and how to manage or withdraw your cookie preferences, see our Cookie Policy. You may also control cookies through your browser settings, although some features may not work properly if strictly necessary cookies are disabled. We currently do not respond to browser “Do Not Track” signals. Where legally required, we will honor applicable consent, opt-out, or preference signals, including the Global Privacy Control.
5.10 Information from Third Parties
We may receive information from payment processors, authentication providers, enterprise or institutional customers, third-party integrations you connect, analytics, monitoring, customer support, and security providers, publicly available sources where lawful and relevant, and referral or business partners where permitted.
6. How We Use Information
The table below summarizes our principal processing activities, the data involved, our legal basis under the GDPR (where applicable), and applicable retention periods. The narrative that follows provides further detail.
| Purpose | Data Categories | Legal Basis (GDPR) | Retention |
|---|---|---|---|
| Account management & authentication | Identifiers, credentials, contact details | Performance of contract, Art. 6(1)(b) | Active account + generally 12 months after closure |
| AI communication coaching & feedback | Video, audio, transcripts, Communication Analysis Data, biometric-like data | Consent / explicit consent, Art. 6(1)(a) & 9(2)(a) | Generally up to 24 months, or until deletion |
| Payment processing | Billing and transaction data (via processors) | Performance of contract, Art. 6(1)(b) | Held by payment processors per their policies |
| Service improvement & development | De-identified, aggregated, or anonymized data | Legitimate interests, Art. 6(1)(f) | Indefinitely (anonymized) |
| Security & fraud prevention | IP address, device data, access logs | Legitimate interests, Art. 6(1)(f) | Generally 12–24 months |
| Support & communications | Contact details, account and support history | Performance of contract, Art. 6(1)(b) | Active period + generally 12 months |
| Legal & regulatory compliance | Relevant categories as required | Legal obligation, Art. 6(1)(c) | As required by law |
6.1 To Provide and Operate the Services
To create and manage accounts, authenticate users, provide access to features, record and process communication sessions, generate AI-powered feedback, provide coaching insights, track progress, store preferences, deliver functionality, process subscriptions and payments, and provide support.
6.2 To Provide AI-Powered Communication Coaching
We may use video, audio, transcripts, prompts, written responses, uploaded documents, and Communication Analysis Data to analyze communication style; assess clarity, structure, tone, pace, and delivery; provide feedback on verbal and non-verbal presentation; generate personalized recommendations; simulate communication scenarios; help users practice and improve; and build personalized development roadmaps.
6.3 To Improve and Develop the Services
To improve performance, fix bugs, develop new features, improve user experience, evaluate AI output quality, reduce errors and bias, monitor performance, improve coaching methodologies, conduct internal research and analytics, and develop new capabilities. Where possible and appropriate, we use aggregated, anonymized, or de-identified information for these purposes.
6.4 To Maintain Security and Prevent Abuse
To detect fraud, abuse, spam, or unauthorized access; protect accounts; investigate suspicious activity; prevent misuse of AI features; monitor system integrity; enforce rate limits and usage restrictions; and protect users, PlayCV, and third parties.
6.5 To Communicate with You
To send account notices, security alerts, billing notices, service updates, legal notices, support responses, product updates, coaching tips, and marketing communications where permitted. You may opt out of marketing emails at any time; you cannot opt out of essential service, billing, legal, or security communications.
6.6 To Comply with Legal and Contractual Obligations
To comply with laws, regulations, court orders, and lawful requests; meet tax, accounting, and corporate obligations; resolve disputes; enforce our Terms of Service; protect legal rights; respond to regulatory inquiries; and support audits, compliance reviews, and investigations.
7. Legal Bases for Processing
- Performance of contract: to provide, operate, and support the Services you request.
- Consent: for certain optional processing, biometric processing where required, non-essential cookies where applicable, and marketing communications where required.
- Explicit consent: for special category data or biometric processing where required by law.
- Legitimate interests: for security, fraud prevention, service improvement, analytics, product development, business operations, legal protection, and preventing misuse, where not overridden by your rights.
- Legal obligation: to comply with applicable laws, regulations, court orders, and tax, accounting, and regulatory requirements.
- Vital or public interest: where necessary in rare circumstances permitted by law.
You may withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that occurred before withdrawal. If you withdraw consent for biometric or communication analysis necessary for certain Services, those Services may no longer be available to you.
8. AI Processing
The Services use AI systems to provide coaching, simulations, feedback, summaries, analysis, recommendations, and related outputs. These systems may process prompts, instructions, written responses, uploaded documents, video and audio recordings, transcripts, Communication Analysis Data, professional and educational information, session history, feedback history, and user preferences.
AI outputs may be incomplete, inaccurate, biased, or unsuitable for your particular circumstances, and are provided for informational, educational, and coaching purposes only. The Services do not provide medical, psychological, legal, financial, immigration, employment, or other professional advice. You are responsible for how you interpret and act on AI-generated outputs.
9. AI Providers and Subprocessors
We may use third-party providers to support AI processing, cloud hosting, payments, analytics, monitoring, customer support, security, email delivery, database operations, storage, and infrastructure. These may include cloud hosting providers; AI model providers; speech, video, audio, or avatar technology providers; payment processors; analytics, monitoring, and observability providers; customer support platforms; security and fraud-prevention providers; email and communications providers; and database, storage, and infrastructure providers. Our current AI processing providers may include, for example, OpenAI (natural language processing and analysis), Anam.ai (interactive avatar technology), and Google (cloud-based AI infrastructure and processing). Our providers may change over time as the Services evolve.
Where providers process personal information on our behalf, we require them to process it only according to our instructions, maintain confidentiality, implement appropriate security measures, assist with privacy requests where required, and not use personal information for their own independent purposes unless permitted by law and disclosed to you.
10. AI Training, Product Improvement, and Model Development
We do not use your identifiable User Content to train general-purpose third-party AI models unless we disclose this to you and have a lawful basis to do so.
We may use de-identified, aggregated, or anonymized information to improve, evaluate, test, secure, and develop the Services, including to improve AI feedback quality, reduce errors, evaluate model performance, improve coaching recommendations, test new features, improve reliability, develop new functionality, and conduct internal research and analytics. Where information has been anonymized so that it can no longer reasonably identify you, it may be retained and used for research, analytics, product development, and service improvement. If we introduce new uses of identifiable User Content for AI training or model development, we will provide appropriate notice and obtain consent where required by law.
11. Human Review
Access to User Content, video, audio, session data, and personal information is restricted. Authorized personnel may review limited information where necessary to provide customer support, investigate bugs or technical issues, maintain security, prevent abuse, improve quality assurance, review AI output quality, comply with legal obligations, enforce our Terms of Service, or support enterprise or institutional deployments where contractually permitted. Human review is limited to personnel or authorized contractors with a legitimate need, subject to confidentiality, access-control, and security obligations.
12. Biometric and Behavioral Data
12.1 Purpose of Collection
Where we collect or analyze Biometric Information or biometric-like information, we do so to provide communication coaching and related Services requested by you, including feedback on verbal and non-verbal communication.
This analysis is the core service you request from Lailani.ai — not a hidden or secondary use. When you start a session, you are explicitly seeking AI-powered feedback on your verbal and non-verbal communication, which necessarily involves analyzing how you speak and present. Your consent to this analysis is freely given, specific, informed, and unambiguous: you voluntarily seek out the service, we explain what we analyze and why, and you actively consent knowing the analysis is required to provide the coaching you request. You may withdraw consent at any time; because this analysis is the core service, withdrawal means we cannot provide certain coaching and feedback features.
12.2 Notice and Consent
Where required by law, before collecting or analyzing Biometric Information, we will:
- Provide clear notice and explain the purpose of collection.
- Explain the duration of retention.
- Obtain written, electronic, express, or explicit consent as required.
- Provide information about your right to withdraw consent and your deletion rights.
12.3 What We Do Not Do
We do not use Biometric Information to identify or authenticate you, conduct surveillance, perform lie detection, diagnose health or mental health conditions, assess psychological traits for clinical purposes, make hiring, admissions, employment, or similar decisions, create permanent biometric identity templates, or sell, lease, trade, or otherwise profit from biometric identifiers or Biometric Information.
12.4 Retention of Biometric Information
We retain Biometric Information only for as long as reasonably necessary for the purposes disclosed, unless a longer period is required by law, needed for legal purposes, or requested by you where available. Unless otherwise disclosed or legally required, video, audio, and associated biometric-like session data are generally retained for up to 24 months or until you request deletion, whichever occurs earlier.
12.5 Deletion of Biometric Information
You may request deletion of Biometric Information by contacting privacy@playcv.ai. Following a valid request, we will delete or de-identify applicable information from active systems within a reasonable period, subject to identity verification and legal exceptions. Backup copies may persist until overwritten through ordinary backup cycles.
13. No Automated Decisions with Legal or Similarly Significant Effect
The Services provide feedback and recommendations; they do not make automated decisions that produce legal or similarly significant effects about you. We do not use AI outputs to determine hiring outcomes, university or school admissions, employment eligibility, promotion, termination, disciplinary decisions, credit, housing, insurance, immigration outcomes, legal rights, or access to public benefits or essential services. If this changes in the future, we will provide appropriate notice and comply with applicable law.
14. How We Share Information
We do not sell your personal information. We may share personal information in the following circumstances:
14.1 Service Providers
With vendors, subprocessors, contractors, and service providers that help us operate, host, secure, support, analyze, and improve the Services.
14.2 Enterprise, Educational, and Institutional Customers
If you access the Services through an employer, university, school, accelerator, company, government body, nonprofit, or other organization, information may be shared with that organization depending on the applicable agreement, product configuration, administrator settings, consent flow, and legal requirements. We will not share individual session recordings, Biometric Information, or detailed performance analytics with an employer, recruiter, university, or institution for decision-making purposes unless clearly disclosed, contractually authorized, legally permitted, and subject to any required consent.
14.3 With Your Direction or Consent
Where you choose to export, download, publish, connect, send, or share information with another person, platform, or service.
14.4 Legal, Safety, and Enforcement Purposes
Where reasonably necessary to comply with law, legal process, or government requests; respond to lawful requests from public authorities; enforce our Terms of Service; protect legal rights; investigate fraud, abuse, or illegal activity; protect the safety, rights, or property of PlayCV, users, or others; or detect and respond to security incidents.
14.5 Business Transfers
If PlayCV is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to applicable law.
15. International Data Transfers
PlayCV is based in the United States. Our data is currently stored on secure cloud infrastructure provided by Google Cloud Platform in the United States (Iowa data center). Personal information may be processed in the United States and other countries where we or our service providers operate. Where required by law, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, the UK International Data Transfer Addendum, data processing agreements, adequacy decisions, or other lawful transfer mechanisms.
If regional hosting, data localization, or specific transfer arrangements are required by applicable law or an enterprise agreement, we may provide region-specific arrangements where available. By using the Services, you understand that your information may be transferred to and processed in countries that may have privacy laws different from those in your jurisdiction.
16. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Retention depends on the type of information, whether your account is active, whether the information is needed to provide the Services, security and fraud-prevention needs, legal and compliance obligations, dispute resolution needs, your deletion requests and consent choices, and contractual obligations with enterprise or institutional customers. Typical retention periods include:
- Account information: while your account is active, plus generally 12 months after closure.
- Video and audio session data: generally up to 24 months unless deleted earlier or legally required to be retained.
- Biometric or biometric-like data: generally up to 24 months unless deleted earlier or legally required to be retained.
- Support communications: the active period plus generally 12 months for support and compliance.
- Security logs: generally 12 to 24 months unless needed longer for security, fraud, abuse-prevention, or legal reasons.
- Payment records: handled primarily by payment processors and retained according to their policies and legal obligations.
- Legal and compliance records: as long as necessary to comply with applicable law.
- Anonymized or aggregated data: may be retained indefinitely.
17. Deletion Requests
You may request deletion of your account or personal information by contacting privacy@playcv.ai. When we receive a valid request, we will delete or de-identify personal information from active systems within a reasonable period, subject to identity verification and legal exceptions. Some information may be retained where necessary for legal, tax, accounting, or regulatory obligations; fraud prevention and security; dispute resolution; enforcement of agreements; protection of legal rights; and backups or disaster recovery systems until overwritten through normal backup cycles.
18. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect personal information, which may include encryption in transit and at rest, access controls, role-based permissions, multi-factor authentication for administrative access, logging and monitoring, vendor security review, confidentiality obligations, security incident response procedures, data minimization practices, periodic access reviews, secure cloud infrastructure, backup and disaster recovery controls, and internal policies and training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials secure and notifying us promptly of suspected unauthorized access.
19. Data Breach Notification
If we become aware of a security incident affecting personal information, we will investigate and respond in accordance with applicable law. Where required, we will notify affected users, customers, regulators, or supervisory authorities within applicable legal timelines.
20. Your Privacy Rights
Depending on your location, you may have rights to access, correct, and delete personal information; restrict or object to processing; withdraw consent; receive a portable copy of your information; opt out of the sale or sharing of personal information and opt out of targeted advertising and certain profiling; limit the use of sensitive personal information; and lodge a complaint with a supervisory authority. To exercise rights, contact privacy@playcv.ai. We may need to verify your identity before responding, and we will not discriminate against you for exercising privacy rights.
21. EEA, UK, and Swiss Users
If the GDPR, UK GDPR, or Swiss data protection law applies, you may have the rights of access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent, the right not to be subject to automated decision-making with legal or similarly significant effect, and the right to lodge a complaint with a supervisory authority. Where Biometric Information is processed for the purpose of uniquely identifying a person or otherwise qualifies as special category data, we will rely on an appropriate Article 9 condition, such as explicit consent, unless another lawful condition applies.
22. California Residents
If you are a California resident, you may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We may collect the following categories of personal information for the purposes described in this Privacy Policy:
- Identifiers.
- Customer records information.
- Commercial information.
- Internet or electronic network activity information.
- Audio, electronic, visual, or similar information.
- Professional or employment-related information.
- Education information.
- Inferences.
- Sensitive personal information, where applicable.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising unless clearly disclosed and unless applicable opt-out rights are provided. Our use of third-party advertising cookies is disclosed in our Cookie Policy, and you may opt out at any time via the cookie preferences described there or through an opt-out preference signal such as the Global Privacy Control. We use sensitive personal information only for purposes reasonably necessary to provide, secure, support, and improve the Services, or as otherwise permitted by law. California residents may contact privacy@playcv.ai with “California Privacy Request” in the subject line.
23. Illinois and Other Biometric Privacy Laws
Where biometric privacy laws apply, including the Illinois Biometric Information Privacy Act, we will comply with applicable notice, consent, retention, protection, and deletion requirements. Where required, we will:
- Provide written notice before collection.
- Explain the purpose and duration of collection.
- Obtain written or electronic consent.
- Maintain a retention and destruction schedule.
- Protect Biometric Information using reasonable safeguards.
- Refrain from selling, leasing, trading, or otherwise profiting from biometric identifiers or Biometric Information.
- Delete Biometric Information when the initial purpose has been satisfied, within the period required by law, or when otherwise required by applicable law.
24. Other US State Privacy Rights
If you reside in a US state with a comprehensive consumer privacy law not otherwise addressed above, you may have rights to access, correct, delete, and obtain a portable copy of your personal information; to opt out of the sale of personal information, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to designate an authorized agent to exercise these rights on your behalf, where permitted by applicable law. To exercise these rights, contact privacy@playcv.ai. We will respond within the time period required by the law of your state of residence.
25. Australian Users
Where the Australian Privacy Act applies, we handle personal information in accordance with the Australian Privacy Principles to the extent applicable. Australian users may contact us to access or correct personal information, make a privacy complaint, or ask questions about how their information is handled.
26. Children and Minors
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. The Services are intended for users aged 16 and older. Users under 16 must not create an account or use the Services unless we have implemented an appropriate consent process and such use is permitted by law. If you are between 16 and 18, you should use the Services only with permission from a parent or guardian where required by law. If we become aware that we have collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it. Parents or guardians may contact privacy@playcv.ai.
27. Marketing Communications
We may send service-related communications, including account notices, security alerts, billing updates, support messages, and legal notices. Where permitted, we may also send product updates, newsletters, coaching tips, and marketing communications. You may opt out of marketing emails at any time by using the unsubscribe link or contacting us; you cannot opt out of essential service, legal, billing, or security communications.
28. Third-Party Links and Integrations
The Services may contain links or integrations with third-party websites, platforms, or services. This Privacy Policy does not apply to third-party services we do not control, and we are not responsible for their privacy practices, security, content, or data handling. You should review third-party privacy policies before using those services.
29. Data Accuracy
We take reasonable steps to ensure that personal information we hold is accurate, complete, and up to date where necessary for the purposes for which it is processed. You may update certain information through your account settings or contact privacy@playcv.ai to request correction.
30. Data Minimization
We aim to collect and retain only the personal information reasonably necessary for the purposes described in this Privacy Policy. We may periodically review the information we hold and delete, de-identify, or anonymize information that is no longer needed, subject to legal, security, contractual, and operational requirements.
31. Law Enforcement and Government Requests
We may disclose information in response to lawful requests from courts, law enforcement, regulators, government authorities, or other public bodies. Where legally permitted and appropriate, we may seek to narrow requests or notify affected users before disclosure. We do not voluntarily provide government authorities with direct access to user accounts or systems.
32. Business Customers and Enterprise Features
If the Services are used by or through an organization, the organization may have access to certain information depending on the applicable contract, administrator settings, product configuration, and user disclosures, which may include account status, usage information, participation information, completion information, organization-level analytics, and aggregated reporting. We will not provide employers, recruiters, universities, or institutions with individual biometric session data, raw recordings, or detailed performance analytics for decision-making purposes unless clearly disclosed, contractually authorized, legally permitted, and subject to any required consent.
33. De-identified, Aggregated, and Anonymized Information
We may create and use de-identified, aggregated, or anonymized information for analytics, benchmarking, research, product development, security, and service improvement. Where we maintain de-identified information, we will take reasonable measures designed to prevent re-identification and will not attempt to re-identify it except where permitted by law, such as to test the effectiveness of de-identification measures. Anonymized information that no longer identifies or reasonably relates to an identifiable person may be used and retained without restriction, subject to applicable law.
34. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice where required by law, such as by email, in-app notice, or prominent website notice. The “Last Updated” date indicates when this Privacy Policy was last revised. Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.
35. Contact Us and Supervisory Authorities
For privacy questions, requests, or complaints, contact:
- PlayCV, Inc. Privacy Team — privacy@playcv.ai
- Legal inquiries — legal@playcv.ai
- Support inquiries — support@playcv.ai
- Privacy Contact: Jacky Hazan — dpo@playcv.ai
Registered Address: PlayCV, Inc., 1111B South Governors Avenue, STE 40089, Dover, DE 19904, United States.
Supervisory Authorities
If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority:
- EEA: European Data Protection Board — https://edpb.europa.eu/about-edpb/about-edpb/members_en
- United Kingdom: Information Commissioner’s Office — https://ico.org.uk/
- California: California Attorney General — https://oag.ca.gov/privacy
- Illinois: Illinois Attorney General — https://www.illinoisattorneygeneral.gov/
- Australia: Office of the Australian Information Commissioner — https://www.oaic.gov.au/
