Privacy Policy
Last updated: 6 September 2026
This policy explains how MMI Room handles information when you visit mmi-room.com, create an account, practise interviews or subscribe. Contact us at support@mmi-room.com.
1. Information we handle
- Account information: your email address, account identifier, verification status and sign-in information. If you use an available social sign-in option, the provider may supply your name and profile picture. Descope handles password and sign-in processing; MMI Room does not store your password in its application database.
- Payments and access: Stripe customer, subscription and transaction identifiers, payment amounts and currency, subscription status, paid access dates, invitation redemption and owner-access status. Stripe collects the payment and billing details entered into its checkout. Our application does not store full card numbers or card security codes.
- Technical information: hosting and authentication services process information such as IP addresses, browser/device details, request times, requested URLs and errors to deliver and protect the service.
- Support messages: your email address and the information you choose to include when contacting us.
- Practice data on your device: interview history, progress, anecdotes and audio/video recordings, as described below.
2. Recordings, camera, microphone and local storage
The current recording feature uses your camera and microphone only after your browser grants permission. Recordings are saved in this browser’s local database. History, progress and anecdotes are also stored locally. The current application does not upload your practice recordings or anecdotes to MMI Room’s servers, send them to an AI model, or synchronise them between devices.
People with access to your device or browser profile may be able to access locally stored information. Signing out does not erase it. Clearing site data, changing browser or device, or using private browsing may remove it or make it unavailable. We cannot recover local data from our servers. Avoid including identifiable patients, confidential interview material or other people’s private information in your practice or support messages.
3. Why we use information
We use account and technical information to sign you in, verify access, deliver the website, troubleshoot faults and protect against abuse. We use payment records to administer subscriptions, cancellation, refunds and access periods. We record owner-access changes and invitation redemptions for security and administration. We use support messages to respond to enquiries and requests, and retain records where needed for accounting, disputes or legal obligations.
You can read our public pages without an account. If you do not provide the information required for sign-in or payment, those features may not be available.
4. Who receives information, and how
Information is transmitted electronically through HTTPS browser requests and server-to-server connections. The providers involved in the current service are:
- Descope: account creation, email verification, sign-in and session management. Your browser connects directly to Descope; our server validates its session tokens.
- Stripe: hosted checkout, payment processing, subscription management and fraud prevention. Your browser sends payment details to Stripe. Our server exchanges customer/subscription identifiers with Stripe and receives signed payment-event notifications.
- Vercel: website hosting, content delivery and application requests, including operational and security logs.
- Neon / Databricks: database hosting for account-linked payment, entitlement, invitation and administration records.
- Google Workspace: email communications when you contact our support address.
Authorised MMI Room administrators can access the account and billing records needed for support and management. Accounts granted owner privileges can view account identifiers and access status and administer access. This does not give them access to recordings stored only in another user’s browser. We may also disclose relevant information to professional advisers or authorities where necessary for legal obligations or resolving disputes.
We do not sell personal information. The current application does not include advertising pixels or use practice recordings to train AI models. A provider may separately process information for its own payment, security or legal purposes under its applicable terms and notices.
5. Processing outside Australia
Our access database is configured in Sydney, Australia, but this does not mean all processing remains in Australia. Our hosting and authentication services use international infrastructure, including the United States. Providers may also process information in other countries where they and their subprocessors operate. Overseas privacy laws may differ from Australian laws.
Provider information is available from Descope, Stripe, Vercel, Databricks and Google. These notices describe provider practices and do not replace this policy. Contact us if you need further information about a particular transfer.
6. Cookies, browser storage and security
Sign-in services use session-related browser storage and may use cookies. MMI Room uses local storage and a browser database for the practice features described above. Blocking or clearing these can affect sign-in and saved practice data.
Security measures in the current application include HTTPS, server-side validation of sign-in tokens and access permissions, database authentication, signed Stripe webhook verification, hashed single-use invitation codes and invitation-attempt limits. Payment secrets are kept on the server, not in public website files. No online service or personal device is completely secure. Protect your login credentials and device, and contact support if you suspect unauthorised access.
7. Retention and your choices
Account and access records are kept while needed to operate your account. Payment, administration and support records may be retained longer for accounting, security, disputes or legal requirements. Retention also depends on the services holding the records. We do not currently offer automatic deletion after a fixed inactivity period.
You may email support to request access to, correction of, or deletion of information we hold. We may verify your identity first and explain if some records must be retained. Deleting an account is separate from cancelling a paid subscription; request cancellation too if you want future billing stopped. Delete browser-held data through the available app controls or your browser’s site-data settings. Server-side account deletion does not erase copies on your device.
8. Questions, complaints and changes
Send privacy questions or complaints to support@mmi-room.com, with enough detail for us to investigate. We will respond and explain the steps available. If unresolved, you may contact the Office of the Australian Information Commissioner where the complaint falls within its jurisdiction.
We may update this policy when our service or information practices change. The date above identifies this version. Material changes will be brought to users’ attention where appropriate; we will seek additional consent where required by law.