Legal
This Privacy Policy explains how The Molly Project ("we," "us") collects, uses, and protects personal information in connection with the SBILT prototype (mollyproject.io). It is intended to comply with Quebec's Act respecting the protection of personal information in the private sector (Law 25) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA).
01 / Identity
The Molly Project is a Quebec-based research initiative developing AI-powered interview training tools. It is operated as a sole proprietorship registered with the Registraire des entreprises du Québec.
The person responsible for the protection of personal information (responsable de la protection des renseignements personnels) as required by Law 25 is:
02 / Collection
2.1 Access Requests and Tester Applications
If you ask for access through the short form on our home page, we record your email address and the date of the request. If you complete the full tester application, we also record your name, professional role, experience, the interview types and frameworks you work with, your written answers, your stated time commitment, how you heard about the project, and your signature and date of agreement. This information is used to assess your application, to correspond with you, and — if you are accepted — to issue your credentials. A copy of each application is also delivered to our team mailbox by email. We do not use any of it for marketing.
2.2 Session Transcripts
When you use the SBILT prototype, your practice conversations are recorded as session transcripts on our server. Each transcript contains the full text of the conversation, timestamps, a randomly generated session identifier, interaction measures (rapport, attunement, posture quadrant data), and your login username.
These transcripts are de-identified, not anonymous, and we want to be precise about the difference. The session identifier is random and carries no meaning. But because each transcript stores the username you log in with, and because we hold the record of which username was issued to which person, we are able to link a transcript back to you. No file on the server maps usernames to names — that link exists only in our own credential records — but it exists, and so the transcripts remain personal information. We do not describe them as anonymous.
2.3 Saved Sessions
If you use the save feature, a copy of your session is written to a separate file so you can resume it later using your save code. These files contain the same conversation content as the transcript.
2.4 Research Archive
A selection of session transcripts and saved sessions is placed in a research archive, held separately on the same server, and used to evaluate and improve the tool. Some material is copied there and some is moved there, in which case the archive holds the only remaining copy. Archived material is personal information on the same basis described in 2.2, and is subject to the archive retention period in section 3 rather than the period that would otherwise apply.
2.5 Server Logs
Our web server records standard technical data including IP addresses, browser type, and access times. The application itself does not record IP addresses anywhere — they exist only in the web server's access log, which is used for security and diagnostics and is not used to identify you personally.
2.6 Authentication Credentials
Access to the SBILT prototype requires a username and password issued by us. Passwords are stored as cryptographic hashes, never in readable form. Accounts issued from mid-2026 onward use bcrypt; a number of earlier accounts still use an older Apache hashing algorithm and are being migrated. Authentication attempts are not logged beyond standard security monitoring.
03 / Retention
| Type | Retention Period |
|---|---|
| Access request emails | 6 months from the request |
| Tester applications | 12 months from submission |
| Survey responses | 12 months from submission |
| Session transcripts | Deleted 90 days after the last activity in the session |
| Saved sessions | Deleted 90 days after the session is saved — unless placed in the research archive, in which case the archive period applies |
| Research archive | 12 months from the date of each record |
| Derived research signals — scores and codes only, no transcript text | 12 months from the date of each record |
| Server access logs | 14 days |
| Authentication credentials | Until access is revoked or the prototype is discontinued |
Deletion at 90 days is automatic and is carried out by a scheduled task on our server. Transcripts are deleted, not anonymized. Where a period is stated, it is the period we actually apply — not an outer limit.
04 / Third Parties
We do not sell or rent your personal information. We share it only with the following service providers, as necessary to operate this prototype:
05 / Cross-Border Transfers
Your account data, session transcripts, and the research archive are hosted in Canada. Our use of AI involves two distinct cross-border activities, both currently taking place in the United States: (1) real-time inference — during practice sessions your conversation content is transferred to OpenRouter, Inc. and Google LLC to generate persona responses and coaching feedback; and (2) development and tuning — de-identified practice transcripts may be reviewed via Anthropic PBC. Email notifications are sent from our Québec server to our team mailbox hosted by Zoho in Canada, and remain within Canada.
This is an early-stage prototype offered only to a small group of invited testers, who receive a written tester agreement setting out these data flows before they are given access. We rely on our providers' standard data-processing terms for these cross-border transfers, and we are completing our privacy impact assessment under Law 25 as the project matures. We are working to bring both AI activities onto Canadian infrastructure. If you have questions before using the prototype, contact us at info@mollyproject.io.
06 / Your Rights
You have the right to:
To exercise any of these rights, contact info@mollyproject.io. We will respond within 30 days. We maintain a documented internal procedure for locating and removing all records associated with an individual across every system described in this policy.
07 / AI & Automated Processing
The SBILT prototype uses artificial intelligence — Google's Gemini 2.5 Flash model, accessed via OpenRouter, Inc. (United States) — to generate persona responses and coaching feedback during practice sessions. This AI processing:
The prototype scores your practice interviews in order to give you feedback. These scores are a training aid. They are not used to make decisions about your employment, your professional standing, or your access to any service, and we do not provide them to any third party.
08 / Security
We take reasonable technical and organizational measures to protect your personal information, including:
We maintain a confidentiality incident register as required by Law 25. In the event of an incident presenting a risk of serious injury, we will notify the Commission d'accès à l'information and affected individuals.
09 / Cookies
The SBILT prototype does not use tracking cookies, advertising technologies, or third-party analytics. All fonts and assets are served from our own server, so loading our pages does not disclose your visit to any third party. Practice sessions use browser memory (sessionStorage) to maintain your current session — this is not a tracking cookie and is cleared when you close the tab.
10 / Updates
We may update this policy as the prototype evolves. The revised policy will be posted on this page with an updated date. Where a change materially affects how we handle information already collected, we will notify active testers directly.
11 / Contact
For any privacy questions, rights requests, or concerns:
Louis Vaillancourt
Privacy contact: info@mollyproject.io
Website: mollyproject.io
Regulatory authority: Commission d'accès à l'information du Québec (CAI) — cai.gouv.qc.ca