Caize

Privacy Policy

Last updated August 23, 2026

This Privacy Policy describes how Caize.ai, operated by MK AI AB, a company registered in Sweden (reg. no. 559577-3010), with its registered office at Kastanjegatan 19C, Lund, Sweden ("Caize.ai," "we," "us," "our"), collects, uses, retains, and shares personal data in connection with the Service, and explains the rights available to you.

1. Data We Collect

When you register for an account, we collect your name, email address, and profile picture, along with profile information you provide such as your university, degree, and language preference, and your responses to onboarding questions about your career direction, degree level and field of study, job-search timeframe, and experience level. Profile pictures are held in publicly accessible storage, meaning anyone with the direct image link can view them. Your password is never stored in plain text; only a one-way cryptographic hash is retained.

If you join our waitlist prior to registering, we keep a separate record of your email address, the source of your signup, and your status, which exists independently of any account you may later create.

When you log in, we automatically record a session token, your IP address, and your browser or device information. Short-lived tokens are also generated for email verification and password reset, and these expire quickly after issuance.

The most sensitive category of data we process relates to your practice sessions. This includes a full text transcript of your spoken answers, produced through speech-to-text conversion; AI-generated feedback, including scores, written evaluations, and references back to your transcript; and metadata such as session length, timestamps, the case completed, and status. Your microphone audio is processed only to produce this transcript and is not retained afterward. If you enable your camera, the video is shown only locally in your own browser during the session — it is never recorded, uploaded, or stored by us, and no facial recognition or biometric analysis is performed. We do not collect any other biometric data, and the animated figure displayed during a session is a static visual unrelated to your appearance. The business case content itself is authored by our team and is not personal data about you.

In connection with paid plans, we retain billing identifiers such as your subscription status and billing period, along with any discount or access code you redeem. We do not receive or store your card number or other full payment credentials, which are held solely by our payment processor. If you use our referral program, we record which signups your invite code brought in and the resulting discount credits: your invitees never see your identity (only the code they used), and you see only counts of invited and active members, never who they are.

We maintain internal records of the artificial intelligence calls made in connection with your use of the Service — including the provider and model used, token volumes, associated cost, and response time — and a cost summary associated with each session. These internal logs are designed not to contain transcript content, and are used solely for cost accounting and operational purposes.

We send only transactional communications, such as account verification and password reset emails; we do not send marketing or newsletter communications. We use a cookie necessary to keep you signed in, a preference cookie remembering your interface layout, and — only if you arrive through an invite link — a referral cookie that remembers the invite code for 30 days so your signup can be attributed to the member who invited you. We do not use analytics, advertising, or tracking cookies or pixels of any kind. Where errors occur, our error-monitoring tooling receives only a bare account identifier, with no name, email address, IP address, cookie data, or query parameters attached.

Our systems include the technical capability to support sign-in through third-party identity providers in the future. This capability is not currently active, and no data of this kind is presently collected. Should this change, we will update this Policy in advance of the feature becoming available.

2. How We Use Your Data

We process your account and profile information to provide and administer your account, under the basis that this is necessary to perform our contract with you. We process transcripts, feedback, and session data for the same reason: to deliver the practice and self-review features you have signed up to use. We process billing identifiers to manage your subscription and to comply with applicable accounting obligations. We process session, device, and error data on the basis of our legitimate interest in keeping the Service secure, reliable, and free of abuse. We process waitlist information on the basis of your interest in registering and our legitimate interest in managing signups, and we process internal cost and usage data on the basis of our legitimate interest in operating and improving the business.

3. Use of Artificial Intelligence

Your interview transcripts are shared with a third-party artificial intelligence provider in order to generate follow-up questions and produce your assessment and feedback. Text and voice data are also shared with a voice-processing provider to enable speech synthesis and transcription. These providers act as our processors under contractual terms that restrict their use of your data to providing services to us. AI-generated feedback informs your own self-assessment and is not used by Caize.ai to make any decision producing legal or similarly significant effects concerning you.

4. Sharing of Data

We share personal data only with service providers engaged to help us deliver the Service, including a payment processor, artificial intelligence and voice-processing providers, an email delivery provider used solely for transactional messages, cloud storage and hosting providers, and an error-monitoring service, each acting under contractual restrictions limiting use of your data to the purpose for which it was shared. We do not sell personal data and do not share it with third parties for their own marketing purposes.

Where any of these providers process data outside the European Economic Area, we rely on legally recognized safeguards, such as the European Commission's Standard Contractual Clauses, to protect that data.

5. Data Retention

We retain your account and profile information for as long as your account remains active, and delete or anonymize it within a reasonable period following account closure, subject to the exceptions below. Session tokens and short-lived verification and reset tokens expire automatically shortly after issuance. Interview transcripts, AI feedback, and session metadata are retained while your account is active and are deleted or anonymized within a reasonable period after closure. Billing records are retained for the duration of your subscription and for a period afterward sufficient to satisfy applicable accounting and tax obligations under Swedish law.

You can act on this yourself at any time from Settings: delete your interview history (permanently removing past sessions, transcripts, and feedback), download a full export of your data, or delete your account entirely. Deleting your account erases your personal data immediately, cancels any active subscription, and deletes your customer record at our payment processor; invoices are retained as required by accounting law.

Internal cost and usage logs are retained indefinitely in anonymized, aggregated form for financial and operational purposes; because this data no longer identifies you once anonymized, it is not affected by deletion of your account. Waitlist records are retained until you register or opt out, or for a limited period following signup if neither occurs.

6. Data Security

We take measures appropriate to the sensitivity of the data we hold, including one-way hashing of passwords, scrubbing of error reports before they reach our monitoring tools, treatment of session audio as transient rather than stored, keeping camera video local to your browser, and reliance on a minimal set of functional cookies rather than persistent tracking identifiers.

7. Your Rights

Depending on your location, you may have the right to access, correct, or delete the personal data we hold about you, to restrict or object to certain processing, to receive a copy of data you have provided to us in a portable format, and to withdraw any consent you have given, without affecting the lawfulness of processing carried out before that withdrawal. You may also lodge a complaint with a data protection supervisory authority, including the Swedish Authority for Privacy Protection or the relevant authority in your own country of residence. To exercise any of these rights, please contact us using the details below.

8. Children

The Service is intended for individuals who are at least 18 years old, or the age of majority in their jurisdiction. We do not knowingly collect personal data from anyone below this age.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The current version will always be available through the Service, and for material changes we will provide reasonable notice before they take effect.

10. Contact

For any question regarding this Policy or to exercise your rights, please contact us at [email protected].