Privacy Notice
Last updated: July 2026. Questions? sharhongkong@gmail.com
Short version: Callback is designed to work with as little data as possible. Your voice, video, and CV never leave your device. The only personal data we collect is your name and email when you sign up — used only to let you know about product updates.
What we collect
- Stored Name and email address — collected when you create a free account. Stored in your browser's localStorage and, if a collection endpoint is active, sent to a form processing service (currently Formspree). Used only to communicate Callback updates to you.
- Stored Interview session data — your session history (job title, interview type, readiness score, date) is stored in your browser's localStorage only. It never leaves your device unless you export it.
- Stored Preferences — voice settings, interview intensity, and your OpenRouter API key (if you use BYOK) are stored in localStorage on your device only.
What we do NOT collect
- Local only Voice and microphone input — your spoken answers are transcribed by your browser's built-in Speech Recognition API. This processing happens on-device (or via your browser's cloud service per its own privacy policy). Callback never receives your audio.
- Local only Camera / video — the self-view feature uses your camera as a mirror only. No frames are captured, recorded, or transmitted anywhere. The camera feed never leaves your browser tab.
- Local only CV / resume — if you upload or paste your CV, it is read by your browser and included in the interview prompt sent to the AI model. It is not stored by Callback. Once your session ends, the CV data is cleared from memory.
- Not collected Usage analytics — we do not currently run any tracking pixels, cookies, or third-party analytics scripts.
AI model calls
Interview questions and coaching are generated by AI models accessed through OpenRouter. When you start an interview, your prompt (job title, job description summary, CV excerpt, and conversation history) is sent to OpenRouter's API. This data is subject to OpenRouter's own privacy policy and the policies of the underlying model provider.
If you use your own OpenRouter API key (BYOK), your key is stored in your browser's localStorage only and sent directly to OpenRouter in the Authorization header. Callback never receives or stores your API key server-side.
Data retention
All data stored by Callback lives in your browser's localStorage. You can delete it at any time by clearing your browser's site data for this domain, or by using the "Clear key" button in the app. We have no server-side copy of your session data.
Your rights under PDPO (Hong Kong)
Under the Personal Data (Privacy) Ordinance (Cap. 486), you have the right to access, correct, and request deletion of your personal data. To exercise these rights or ask any privacy question, contact us at sharhongkong@gmail.com. We will respond within 40 days as required by law.
Changes to this notice
We may update this notice as the product evolves. Significant changes will be noted at the top of this page with a revised date. Continued use of Callback after a change means you accept the updated notice.
Contact
Callback is built and operated by Sharv Ghadge, Hong Kong.
Email: sharhongkong@gmail.com