SECURITY / TRUST

Built carefully.
Explained honestly.

MockAllies handles your voice, your practice sessions and your payment details. Here's plainly how we protect them, who else touches them, and what we deliberately don't do with them.

Protected
in transit and at rest.

Every connection to MockAllies runs over HTTPS/TLS, and your data is encrypted at rest wherever it's stored.

This is standard practice for handling account information, session recordings and payment activity, and it's the baseline we build everything else on top of. It's not a differentiator we're claiming — it's simply what any service handling your voice and your billing details should do as a matter of course.

A short list.
Named plainly.

We don't have a sprawling stack of trackers and resellers. Practice sessions and payments pass through a small, named set of providers, each doing one specific job.

We don't sell your data, and we don't share it with anyone outside this list for their own marketing or training purposes. The full breakdown lives in our Privacy Policy.

We don't train
models on you.

This is the commitment that matters most for a product built on live voice conversations, so we're stating it plainly rather than burying it in a policy.

We do not use your session audio, transcripts or any data you provide to train, fine-tune or improve any AI model — not Google Gemini, not a model of our own, not anything we might build in the future.

We do not perform voice-biometric processing. We don't create voiceprints from your recordings, and we don't run speaker identification or voice-matching against your audio. Your voice is used to run your practice session and generate your feedback — nothing else.

Recordings expire.
On purpose.

Session recordings and transcripts aren't kept forever. They're retained for a defined period so you can replay them and review your feedback, then automatically deleted.

You can download or export a session before it expires if you want to keep it longer. The exact retention window is spelled out in full in our Privacy Policy — we're keeping this page focused on the approach rather than duplicating the fine print.

Found a problem?
We want to know.

If you believe you've found a security vulnerability in MockAllies, please report it to us directly before disclosing it publicly. We'll acknowledge your report, investigate promptly, and keep you updated as we work on a fix.

RESPONSIBLE DISCLOSURE

[SECURITY CONTACT EMAIL] ↗

Please include enough detail to reproduce the issue. We won't take legal action against good-faith security research that follows responsible disclosure.

Growing into
formal certification.

MockAllies is an early, privately funded company. We haven't yet pursued a formal security certification such as SOC 2 — that's a real, resource-intensive process, and we'd rather tell you honestly where we stand than claim compliance we don't have.

As MockAllies grows, pursuing formal certification is a genuine priority, not an afterthought. Until then, this page reflects what we actually do today, and we'll update it as that changes.

KNOWLEDGE INTO INSTINCT

Questions about
how this works?

Get in touch