Privacy Policy
Last updated August 11, 2026
PlayCISO is built and operated independently — this policy tells you plainly what we collect, why, who else sees it, and how to get it changed or deleted. If anything here is unclear, email us and we'll answer directly.
What we collect
Depending on how you use the site, we may collect:
- Account data — email, name, and authentication details, handled by our identity provider (Clerk).
- Product usage — scenario decisions, scores, chat/interview transcripts, resume content (for the Resume Review tool), and feedback you submit.
- Payment data — handled directly by Stripe; we do not store your card details.
- Site analytics — pages visited, session duration, and, for signed-in users, which pages you visit, via our own logging and Amplitude (see Analytics & session recording below).
- Lead & contact data — if you take the free scorecard, sign up for updates, or we reach you via cold outreach as a B2B contact, we store your email (encrypted at rest) and, where applicable, your consent status.
How AI is used
PlayCISO is built to run largely on its own — scenarios, grading, board-report critiques, and mock interviews are AI-generated and AI-evaluated, not scripted by a human reviewer. Practically, that means:
- Text you enter into War Room decisions, board reports, chat-based games, and the resume review tool is sent to Anthropic (Claude) for generation and grading.
- Live mock interviews and video-based simulations (board pitch, press conference, PCI interview) use Anam.ai for real-time video/audio AI — your camera and microphone stream directly to their service for the duration of that session.
- We don't use your inputs to train third-party models beyond what the provider's own API terms specify (we do not opt in to model training where a provider offers a choice).
Who we share data with
We don't sell your data. We use a small set of processors to run the product:
- Clerk — authentication and account management.
- Stripe — payment processing.
- Anthropic — AI grading and generation (see above).
- Anam.ai — live video/audio AI for interview and simulation features.
- Stream (GetStream) — the in-app chat widget.
- Amplitude — product analytics, including session replay (see below).
- Infobip / Resend — transactional and marketing email delivery.
- Prospeo — used on our side to find publicly-listed business contact details for cold B2B outreach; not a recipient of your data.
Most of these providers are based in the United States. Where required, we rely on their standard contractual safeguards for data transferred out of the EEA/UK.
Analytics & session recording
We use Amplitude for product analytics, which includes session replay — a reconstruction of on-screen activity (not a video/audio recording of you) used to understand how the product is actually used and to fix what's broken. We also run a small ad script and an AI-search answers widget that load on every page.
We do not currently show a cookie-consent banner before these load. If you'd rather opt out of analytics, use your browser's tracking-protection settings, or email us and we'll exclude your account manually while we build a proper consent control.
If you're under 18
Our Youth Cyber Safety section (ages 12–17) is educational content about staying safe online. Some of its interactive games send your typed messages to Anthropic's AI to generate a response, the same as the rest of the product — we do not currently verify age or require parental consent before that happens, and we're actively working to close that gap. We do not knowingly collect a name, email, or other directly-identifying information from anyone using the youth section. Parents or guardians with concerns can contact us directly and we will act promptly, including disabling access for a specific user if asked.
How long we keep data
Behavioral/event data (page-level engagement, funnel events, email send logs) is deleted after 180 days. Account data, and records tied to a product you've used (scorecard results, saved leads), are kept while your account is active or as needed for the purpose you provided them for. We're in the process of building automatic deletion for the tables that don't yet have a retention limit — in the meantime, an email request (below) gets it handled by hand.
Your rights
You can ask us to access, correct, export, or delete your personal data at any time. We don't yet have a self-service button for this — email us and we'll handle it directly, typically within a few business days. If you're in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
To unsubscribe from marketing email, use the unsubscribe link in any message we send, or email us directly.
Security
Lead and scorecard email addresses are encrypted at rest. We use industry-standard practices (TLS in transit, access controls, least-privilege credentials) to protect the rest of your data, but no system is perfectly secure — if you believe you've found a vulnerability, please report it to security@playciso.com.
Changes to this policy
We'll update this page as the product changes and update the date at the top. Material changes that affect how we handle your data will be communicated by email where we have one on file.
Contact
PlayCISO is built and run independently. For anything on this page — access requests, deletion, questions, concerns — reach us at cyber.breach.space@gmail.com. A real person reads and replies to every message.