Skip to main content

Legal · Privacy Policy

Privacy Policy

Last updated: 21 April 2026. Effective date: 21 April 2026.

Vathus (“we,” “our,” “us”) is an independent software studio based in the United Kingdom. This policy describes what personal data we collect when you use our software (including the desktop application Mockingbird), why we collect it, how long we keep it, and the rights you have over it.

The data controller is the natural person operating Vathus as a UK sole trader. For data-subject requests write to privacy@vathus.ai.

1. What data we collect and why

Account details

email address and tier selection you provide at sign-up

Purpose
To identify your account, apply your subscription tier, and send service notifications (billing receipts, security alerts).
Legal basis (UK GDPR Art. 6)
Contract necessity (Art. 6(1)(b))
Retention
For the lifetime of your account and 90 days after deletion.

Billing details

payment method token + last-4 of card (held by Stripe, not us)

Purpose
To charge your subscription and provide statements.
Legal basis (UK GDPR Art. 6)
Contract necessity
Retention
As required by HMRC (6 years).

Anonymous usage counters (telemetry)

event counts, error codes, app version

Purpose
Product health + debugging. Strictly opt-in: off by default, enable in Settings → Telemetry.
Legal basis (UK GDPR Art. 6)
Consent (Art. 6(1)(a))
Retention
12 months or until you disable telemetry / request deletion, whichever is sooner.

Crash reports

stack traces, OS/app version (scrubbed of transcripts, document content, email addresses)

Purpose
Identifying and fixing crashes. Strictly opt-in: off by default, enable in Settings → Crash reports.
Legal basis (UK GDPR Art. 6)
Consent
Retention
90 days.

Data that stays on your device

The core of Mockingbird is local-first. The following categories never leave your computer unless you explicitly opt into a feature that requires a third-party cloud service (e.g. Pro cloud transcription or BYOK Deepgram):

  • Live audio captured from your microphone or system output
  • Transcripts of your sessions
  • Documents you upload (resumes, job descriptions, rubrics, STAR stories, battlecards)
  • Practice Loop reviews, scores, and rewrites
  • Spaced-repetition drill cards
  • BYOK API keys (Anthropic, OpenAI, Deepgram), encrypted at rest via the operating system keychain (macOS Keychain / Windows DPAPI / Linux libsecret)

2. Third parties we share data with

We use the smallest practical set of third-party processors. Each is listed explicitly below.

Stripe, Inc.

What they handle
Subscription billing (card token, address)
Where
United States (EU SCCs)
Their privacy policy
stripe.com/privacy

Clerk, Inc.

What they handle
Authentication (email, session token)
Where
United States (EU SCCs)
Their privacy policy
clerk.com/legal/privacy

Vercel, Inc.

What they handle
Hosting for vathus.ai, webhook endpoints
Where
United States (EU SCCs)

Sentry (Functional Software)

What they handle
Only if you enable crash reports. Stack traces, OS/app version.
Where
United States (EU SCCs)
Their privacy policy
sentry.io/privacy

PostHog, Inc.

What they handle
Only if you enable telemetry. Anonymous event counters.
Where
European Union (hosted in Frankfurt)
Their privacy policy
posthog.com/privacy

We do not sell, rent, or otherwise make your personal data available to data brokers, advertising networks, or any other third party outside of the processors listed above. We do not use analytics or advertising SDKs in the desktop app.

Bring-your-own-key (BYOK) cloud providers

If you paste a third-party API key (Anthropic, OpenAI, Deepgram) into the app’s Account page, that key is used to connect your device directly to that provider. Your transcripts, prompts, and responses travel between your device and the provider using your credentials. Vathus does not act as a proxy and does not see that traffic. Each provider’s privacy policy governs what happens to data you send them; we recommend reviewing them.

3. Your rights under UK GDPR

You have the following rights over your personal data. To exercise any, write to privacy@vathus.ai; we’ll respond within 30 days.

  • Access: a machine-readable copy of every row we hold about you (Art. 15).
  • Rectification: correction of inaccurate data (Art. 16).
  • Erasure: deletion of your account and all associated data (Art. 17). The Mockingbird desktop app exposes a one-click “Delete all my data” button in Settings that drops every row and wipes the keychain.
  • Restriction of processing (Art. 18).
  • Data portability: a machine-readable gzipped JSON bundle (Art. 20). The desktop app exposes this via Settings → Export all data.
  • Object to processing (Art. 21).
  • Withdraw consent: you can disable telemetry and crash reports at any time in Settings.

If you believe we have mishandled your data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

4. International transfers

Some of our processors (listed above) are based in the United States. Where personal data leaves the UK, transfers are protected by the UK Addendum to the EU Standard Contractual Clauses, which each listed US processor has signed.

5. Cookies and similar technologies

The Mockingbird desktop app does not use cookies. The public website at vathus.ai uses only strictly-necessary first-party cookies for session continuity and does not embed advertising, analytics, or tracking cookies. No cookie banner is required for purely strictly-necessary usage, but if this ever changes we will post a banner first.

6. Changes to this policy

We’ll post the new version here and update the “Last updated” date. If a change materially reduces your rights or expands how we use your data, we’ll email registered users before the change takes effect.

7. Contact

For privacy enquiries: privacy@vathus.ai
For general enquiries: hello@vathus.ai

See also: Terms of Service.