Legal

Privacy Policy

Last updated August 11, 2026

PlayCISO is built and operated independently — this policy tells you plainly what we collect, why, who else sees it, and how to get it changed or deleted. If anything here is unclear, email us and we'll answer directly.

What we collect

Depending on how you use the site, we may collect:

  • Account data — email, name, and authentication details, handled by our identity provider (Clerk).
  • Product usage — scenario decisions, scores, chat/interview transcripts, resume content (for the Resume Review tool), and feedback you submit.
  • Payment data — handled directly by Stripe; we do not store your card details.
  • Site analytics — pages visited, session duration, and, for signed-in users, which pages you visit, via our own logging and Amplitude (see Analytics & session recording below).
  • Lead & contact data — if you take the free scorecard, sign up for updates, or we reach you via cold outreach as a B2B contact, we store your email (encrypted at rest) and, where applicable, your consent status.

How AI is used

PlayCISO is built to run largely on its own — scenarios, grading, board-report critiques, and mock interviews are AI-generated and AI-evaluated, not scripted by a human reviewer. Practically, that means:

  • Text you enter into War Room decisions, board reports, chat-based games, and the resume review tool is sent to Anthropic (Claude) for generation and grading.
  • Live mock interviews and video-based simulations (board pitch, press conference, PCI interview) use Anam.ai for real-time video/audio AI — your camera and microphone stream directly to their service for the duration of that session.
  • We don't use your inputs to train third-party models beyond what the provider's own API terms specify (we do not opt in to model training where a provider offers a choice).

Who we share data with

We don't sell your data. We use a small set of processors to run the product:

  • Clerk — authentication and account management.
  • Stripe — payment processing.
  • Anthropic — AI grading and generation (see above).
  • Anam.ai — live video/audio AI for interview and simulation features.
  • Stream (GetStream) — the in-app chat widget.
  • Amplitude — product analytics, including session replay (see below).
  • Infobip / Resend — transactional and marketing email delivery.
  • Prospeo — used on our side to find publicly-listed business contact details for cold B2B outreach; not a recipient of your data.

Most of these providers are based in the United States. Where required, we rely on their standard contractual safeguards for data transferred out of the EEA/UK.

Analytics & session recording

We use Amplitude for product analytics, which includes session replay — a reconstruction of on-screen activity (not a video/audio recording of you) used to understand how the product is actually used and to fix what's broken. We also run a small ad script and an AI-search answers widget that load on every page.

We do not currently show a cookie-consent banner before these load. If you'd rather opt out of analytics, use your browser's tracking-protection settings, or email us and we'll exclude your account manually while we build a proper consent control.

Cookies

We use a small number of cookies:

  • Authentication cookies set by Clerk, required to keep you signed in.
  • A lead-attribution cookie (pc_lead) that links your visit to a referring email link, for up to 30 days.
  • An anonymous, randomly-generated cookie that limits how many free plays a browser gets on metered arcade games — it is not derived from anything that identifies you.

If you're under 18

Our Youth Cyber Safety section (ages 12–17) is educational content about staying safe online. Some of its interactive games send your typed messages to Anthropic's AI to generate a response, the same as the rest of the product — we do not currently verify age or require parental consent before that happens, and we're actively working to close that gap. We do not knowingly collect a name, email, or other directly-identifying information from anyone using the youth section. Parents or guardians with concerns can contact us directly and we will act promptly, including disabling access for a specific user if asked.

How long we keep data

Behavioral/event data (page-level engagement, funnel events, email send logs) is deleted after 180 days. Account data, and records tied to a product you've used (scorecard results, saved leads), are kept while your account is active or as needed for the purpose you provided them for. We're in the process of building automatic deletion for the tables that don't yet have a retention limit — in the meantime, an email request (below) gets it handled by hand.

Your rights

You can ask us to access, correct, export, or delete your personal data at any time. We don't yet have a self-service button for this — email us and we'll handle it directly, typically within a few business days. If you're in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.

To unsubscribe from marketing email, use the unsubscribe link in any message we send, or email us directly.

Security

Lead and scorecard email addresses are encrypted at rest. We use industry-standard practices (TLS in transit, access controls, least-privilege credentials) to protect the rest of your data, but no system is perfectly secure — if you believe you've found a vulnerability, please report it to security@playciso.com.

Changes to this policy

We'll update this page as the product changes and update the date at the top. Material changes that affect how we handle your data will be communicated by email where we have one on file.

Contact

PlayCISO is built and run independently. For anything on this page — access requests, deletion, questions, concerns — reach us at cyber.breach.space@gmail.com. A real person reads and replies to every message.

Privacy Policy — PlayCISO · PlayCISO