This Privacy Policy explains how The Molly Project ("we," "us") collects, uses, and protects personal information in connection with the SBILT prototype (mollyproject.io). It is intended to comply with Quebec's Act respecting the protection of personal information in the private sector (Law 25) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA).

01 / Identity

Who We Are & Privacy Officer

The Molly Project is a Quebec-based research initiative developing AI-powered interview training tools. It is operated as a sole proprietorship registered with the Registraire des entreprises du Québec.

The person responsible for the protection of personal information (responsable de la protection des renseignements personnels) as required by Law 25 is:

Louis Vaillancourt

Email: info@mollyproject.io

Location: Quebec, Canada

02 / Collection

What We Collect & Why

2.1 Access Requests and Tester Applications

If you ask for access through the short form on our home page, we record your email address and the date of the request. If you complete the full tester application, we also record your name, professional role, experience, the interview types and frameworks you work with, your written answers, your stated time commitment, how you heard about the project, and your signature and date of agreement. This information is used to assess your application, to correspond with you, and — if you are accepted — to issue your credentials. A copy of each application is also delivered to our team mailbox by email. We do not use any of it for marketing.

2.2 Session Transcripts

When you use the SBILT prototype, your practice conversations are recorded as session transcripts on our server. Each transcript contains the full text of the conversation, timestamps, a randomly generated session identifier, interaction measures (rapport, attunement, posture quadrant data), and your login username.

These transcripts are de-identified, not anonymous, and we want to be precise about the difference. The session identifier is random and carries no meaning. But because each transcript stores the username you log in with, and because we hold the record of which username was issued to which person, we are able to link a transcript back to you. No file on the server maps usernames to names — that link exists only in our own credential records — but it exists, and so the transcripts remain personal information. We do not describe them as anonymous.

2.3 Saved Sessions

If you use the save feature, a copy of your session is written to a separate file so you can resume it later using your save code. These files contain the same conversation content as the transcript.

2.4 Research Archive

A selection of session transcripts and saved sessions is placed in a research archive, held separately on the same server, and used to evaluate and improve the tool. Some material is copied there and some is moved there, in which case the archive holds the only remaining copy. Archived material is personal information on the same basis described in 2.2, and is subject to the archive retention period in section 3 rather than the period that would otherwise apply.

2.5 Server Logs

Our web server records standard technical data including IP addresses, browser type, and access times. The application itself does not record IP addresses anywhere — they exist only in the web server's access log, which is used for security and diagnostics and is not used to identify you personally.

2.6 Authentication Credentials

Access to the SBILT prototype requires a username and password issued by us. Passwords are stored as cryptographic hashes, never in readable form. Accounts issued from mid-2026 onward use bcrypt; a number of earlier accounts still use an older Apache hashing algorithm and are being migrated. Authentication attempts are not logged beyond standard security monitoring.

03 / Retention

How Long We Keep Your Information

Type Retention Period
Access request emails6 months from the request
Tester applications12 months from submission
Survey responses12 months from submission
Session transcriptsDeleted 90 days after the last activity in the session
Saved sessionsDeleted 90 days after the session is saved — unless placed in the research archive, in which case the archive period applies
Research archive12 months from the date of each record
Derived research signals — scores and codes only, no transcript text12 months from the date of each record
Server access logs14 days
Authentication credentialsUntil access is revoked or the prototype is discontinued

Deletion at 90 days is automatic and is carried out by a scheduled task on our server. Transcripts are deleted, not anonymized. Where a period is stated, it is the period we actually apply — not an outer limit.

04 / Third Parties

Who We Share Your Information With

We do not sell or rent your personal information. We share it only with the following service providers, as necessary to operate this prototype:

  • OVH Canada Inc. (Québec, Canada) — Server hosting. Your account data, transcripts, and the research archive are stored in Quebec.
  • OpenRouter, Inc. & Google LLC (United States) — AI inference. During practice sessions your conversation content is transmitted to OpenRouter, which routes it to Google's Gemini 2.5 Flash model. This processing takes place outside Canada.
  • Zoho Corporation (Canada) — Hosts our team mailbox (info@mollyproject.io) in its Canadian data centre. Application notifications are sent from our Québec server to this Canadian mailbox; this email does not leave Canada.
  • Anthropic PBC (United States) — Provides the AI assistant (Claude) our team uses for development and tuning. De-identified practice transcripts may be reviewed this way to evaluate and improve the tool. This review is manual; there is no automated pipeline sending transcripts to Anthropic.

05 / Cross-Border Transfers

Transfers Outside Quebec

Your account data, session transcripts, and the research archive are hosted in Canada. Our use of AI involves two distinct cross-border activities, both currently taking place in the United States: (1) real-time inference — during practice sessions your conversation content is transferred to OpenRouter, Inc. and Google LLC to generate persona responses and coaching feedback; and (2) development and tuning — de-identified practice transcripts may be reviewed via Anthropic PBC. Email notifications are sent from our Québec server to our team mailbox hosted by Zoho in Canada, and remain within Canada.

This is an early-stage prototype offered only to a small group of invited testers, who receive a written tester agreement setting out these data flows before they are given access. We rely on our providers' standard data-processing terms for these cross-border transfers, and we are completing our privacy impact assessment under Law 25 as the project matures. We are working to bring both AI activities onto Canadian infrastructure. If you have questions before using the prototype, contact us at info@mollyproject.io.

06 / Your Rights

Your Rights Under Law 25 & PIPEDA

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information (subject to legal retention obligations)
  • Withdraw consent at any time, which may affect your ability to use the service
  • Data portability — request a copy of information you provided, in a structured, commonly used format
  • File a complaint with the Commission d'accès à l'information du Québec (CAI) at cai.gouv.qc.ca, or the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca

To exercise any of these rights, contact info@mollyproject.io. We will respond within 30 days. We maintain a documented internal procedure for locating and removing all records associated with an individual across every system described in this policy.

07 / AI & Automated Processing

Automated Decision-Making

The SBILT prototype uses artificial intelligence — Google's Gemini 2.5 Flash model, accessed via OpenRouter, Inc. (United States) — to generate persona responses and coaching feedback during practice sessions. This AI processing:

  • Is used solely for educational and training purposes
  • Does not make decisions with legal or significant consequences affecting you
  • Does not create profiles used to determine access to services

The prototype scores your practice interviews in order to give you feedback. These scores are a training aid. They are not used to make decisions about your employment, your professional standing, or your access to any service, and we do not provide them to any third party.

08 / Security

Security Measures

We take reasonable technical and organizational measures to protect your personal information, including:

  • HTTPS encryption for all web traffic (TLS via Let's Encrypt)
  • Password-protected access, with passwords stored as cryptographic hashes, never in readable form
  • Server hosted in a Canadian data centre (OVH Canada, Québec)
  • Brute-force protection and firewall hardening on the server

We maintain a confidentiality incident register as required by Law 25. In the event of an incident presenting a risk of serious injury, we will notify the Commission d'accès à l'information and affected individuals.

09 / Cookies

Cookies & Tracking

The SBILT prototype does not use tracking cookies, advertising technologies, or third-party analytics. All fonts and assets are served from our own server, so loading our pages does not disclose your visit to any third party. Practice sessions use browser memory (sessionStorage) to maintain your current session — this is not a tracking cookie and is cleared when you close the tab.

10 / Updates

Changes to This Policy

We may update this policy as the prototype evolves. The revised policy will be posted on this page with an updated date. Where a change materially affects how we handle information already collected, we will notify active testers directly.

11 / Contact

Questions & Rights Requests

For any privacy questions, rights requests, or concerns:

Louis Vaillancourt

Privacy contact: info@mollyproject.io

Website: mollyproject.io

Regulatory authority: Commission d'accès à l'information du Québec (CAI) — cai.gouv.qc.ca