SECURITY / TRUST
Built carefully.
Explained honestly.
MockAllies handles your voice, your practice sessions and your payment details. Here's plainly how we protect them, who else touches them, and what we deliberately don't do with them.
↓01 / ENCRYPTION
Protected
in transit and at rest.
Every connection to MockAllies runs over HTTPS/TLS, and your data is encrypted at rest wherever it's stored.
This is standard practice for handling account information, session recordings and payment activity, and it's the baseline we build everything else on top of. It's not a differentiator we're claiming — it's simply what any service handling your voice and your billing details should do as a matter of course.
02 / WHO ELSE TOUCHES YOUR DATA
A short list.
Named plainly.
We don't have a sprawling stack of trackers and resellers. Practice sessions and payments pass through a small, named set of providers, each doing one specific job.
- Google Gemini APIPowers the AI voice buyer personas you practice with. Your session audio is processed to generate the buyer's real-time responses. See Section 05 for exactly what we've committed Google's API will not do with it.
- StripeHandles all payment processing. We never see or store your full card number — Stripe's secure systems handle that directly.
- [HOSTING PROVIDER]Hosts the application and stores your account data, session recordings and transcripts.
We don't sell your data, and we don't share it with anyone outside this list for their own marketing or training purposes. The full breakdown lives in our Privacy Policy.
03 / YOUR VOICE, NOT A DATASET
We don't train
models on you.
This is the commitment that matters most for a product built on live voice conversations, so we're stating it plainly rather than burying it in a policy.
We do not use your session audio, transcripts or any data you provide to train, fine-tune or improve any AI model — not Google Gemini, not a model of our own, not anything we might build in the future.
We do not perform voice-biometric processing. We don't create voiceprints from your recordings, and we don't run speaker identification or voice-matching against your audio. Your voice is used to run your practice session and generate your feedback — nothing else.
04 / HOW LONG WE KEEP THINGS
Recordings expire.
On purpose.
Session recordings and transcripts aren't kept forever. They're retained for a defined period so you can replay them and review your feedback, then automatically deleted.
You can download or export a session before it expires if you want to keep it longer. The exact retention window is spelled out in full in our Privacy Policy — we're keeping this page focused on the approach rather than duplicating the fine print.
05 / SEE SOMETHING? TELL US
Found a problem?
We want to know.
If you believe you've found a security vulnerability in MockAllies, please report it to us directly before disclosing it publicly. We'll acknowledge your report, investigate promptly, and keep you updated as we work on a fix.
RESPONSIBLE DISCLOSURE
[SECURITY CONTACT EMAIL] ↗Please include enough detail to reproduce the issue. We won't take legal action against good-faith security research that follows responsible disclosure.
06 / WHERE WE'RE HEADED
Growing into
formal certification.
MockAllies is an early, privately funded company. We haven't yet pursued a formal security certification such as SOC 2 — that's a real, resource-intensive process, and we'd rather tell you honestly where we stand than claim compliance we don't have.
As MockAllies grows, pursuing formal certification is a genuine priority, not an afterthought. Until then, this page reflects what we actually do today, and we'll update it as that changes.
KNOWLEDGE INTO INSTINCT