Your data
Privacy and data controls
How nrml handles your interview practice, account information, and saved work.
What we store
We store your account and language preferences, saved code, AI conversations and proposals, test results, interview activity, notes, feedback, evaluations, and provider usage. If you use billing or referrals, we also record your subscription, confirmed payments, referral attribution, and rewards. Student verification stores your school email and verification expiration. Feedback you send from the app is stored with your account, the page you were on, and the time, so we can act on it and follow up. Feedback sent from an interview also includes the interview link. If you report an issue as an invited guest, we store your guest name instead of an account. Product feedback is visible only to nrml administrators and engineers granted feedback access.
Problem discussions
Discussion comments, replies, and likes are linked to your account. Other learners see an anonymous alias for each problem version, rather than your name, email, or profile. Your comment text is visible to learners who have finished that problem version, so avoid including personal information. You can delete your comments; deleting your account also removes your comment text while preserving placeholders for replies. Reports are available to authorized staff, who can investigate abuse and remove comments.
When data leaves nrml
When you ask the assistant for help, the relevant question, code, and conversation context are sent to the configured AI provider. With your own API key, that provider processes the request using your account. Code execution sends your repository to the configured isolated sandbox service. Payments are processed by Stripe, and account emails are delivered by the configured email service. These services apply their own data policies.
Do not put credentials or other sensitive information in practice code or prompts. nrml encrypts saved personal API keys and displays only the provider and last four characters.
AI interview voice and camera
Microphone access starts only when you enable voice. Spoken answers are sent to the configured AI provider for transcription, and the interviewer’s replies are generated as speech. The microphone does not record answers while the AI is speaking. You can mute, stop voice, or use text at any time.
Camera access is optional and off by default. When enabled, a preview shows what is visible, and a still image is sent with each answer for context. nrml does not continuously record video. Camera imagery is not used to infer emotion, personality, identity, or ability from your appearance. Turn the camera off to stop sharing images.
nrml saves the interview transcript for your session and report. Raw audio and camera images are processed for the current turn rather than stored with the session; AI providers apply their own retention policies. Voice and camera stay connected when you switch workspace panels, with call controls visible across the workspace. Access stops when the session pauses or ends, when you switch languages or leave the workspace, or when you explicitly stop the devices.
Notes and administration
Invited interviewers can follow a candidate’s live interview workspace, including open files, code edits, unsent AI prompts, AI responses, and shared note drafts. A notice in the candidate’s workspace explains this visibility. Private notes and other apps are excluded. Live drafts are transmitted temporarily and are not added to saved session history until they are saved or sent.
Private notes are visible only to their author. Shared notes and interviewer feedback are visible to the session’s participants. Authorized administrators can inspect saved code, conversations, shared notes, evaluation results, billing, and operational records to support the service. Administrator inspection does not reveal another person’s private notes.
Retention and deletion
Interview content remains available until you delete the interview or your account. Archiving retains the interview and removes it from your active history and recent list. You can delete interviews from Interview history or delete your account from Settings → Account. Account deletion also removes associated stored workspace snapshots. Billing records and deidentified operational records may remain where needed to reconcile payments and operate the service.
Terminal scrollback and conflicting-file recovery copies remain with the interview. Reliability metrics expire after 90 days. Backups and copies held by providers follow the operator’s backup settings and each provider’s retention policy; deleting nrml data does not immediately erase those copies.
Browser storage
Your browser holds the session cookie needed to sign in, editor preferences, and recovery drafts for code, notes, feedback, and AI prompts. Drafts are removed after successful saving or sending. Notes drafts are separated by account and interview. On a shared device, sign out and clear this site’s browser data when you finish.
A first-party acquisition cookie lasts up to 30 days and remembers only a broad source category, landing-page category, and an approved campaign label. It contains no visitor identifier, full URL, search query, or referral token. This helps us understand which public resources lead to useful practice. Clear site cookies to remove it.
Product and reliability signals
First-party analytics record a limited set of actions, timestamps, and account or resource identifiers to measure use and reliability. They do not contain source code, prompt text, email addresses, or API keys. Error reporting, when enabled by the operator, is filtered to exclude request bodies and credentials.
We count public page views by category and connect a new account’s acquisition category with signup, practice completion, and subscription events. Public page views are not unique-visitor counts, and no third-party analytics script receives this data.
Questions and requests
You can manage your saved interviews, API keys, active login sessions, and account in Settings. For a concern about a specific interview, use its report action so administrators can review the relevant session.
For privacy questions or help with your data, email support@nrml.dev.