Privacy Policy
How HireInterviewAI collects, uses, and protects organization and candidate data — including interview recordings, transcripts, proctoring signals, and the knowledge fingerprint candidates build from their own assessments.
Last updated: July 2026
Who we are
HireInterviewAI provides live, adaptive, proctored AI technical interviews — voice, an in-browser code editor, and chat — and reports per-concept skill depth across technical and professional domains. This policy explains what we collect, why, and the rights you have over that data. It applies to our website and the interview platform.
Our role depends on the data. For candidate data from employer-initiated interviews, we act as a processor on behalf of the hiring organization, and we are the controller for the account data of the organizations and HR users who use the platform. For candidate accounts, self-assessments, and marketplace profiles, we are the controller (and data fiduciary under India's DPDP Act) and collect the required consent directly from the candidate.
Data we collect
Organization & HR account data
Names, work email addresses, organization name, role, authentication credentials, billing details (processed by our payment provider), and product usage needed to operate accounts, workspaces, and wallets.
Candidate interview & assessment data
When a candidate takes an interview or a self-assessment, we capture the evidence that makes the evaluation defensible:
- Interview transcripts (the conversation between the candidate and the AI interviewer)
- Code the candidate writes and submits in the in-browser editor
- Voice / audio of spoken answers
- Screen recordings of the interview or assessment session
- Proctoring signals and snapshots (e.g. focus changes, anomaly events)
Candidate account & marketplace data
When a candidate signs up for the marketplace, we collect the data needed to run their profile and the job board:
- Account and profile data — name, email, credentials, and profile details such as headline, seniority, location, and availability
- Job applications — the roles a candidate applies to and the profile shared with the employer on apply
- Payment data for the candidate wallet (card/UPI details are handled by our payment provider, not stored by us)
- Discoverability settings — whether talent search is on or off, and related preferences
- The knowledge fingerprint — a per-concept record of depth we derive from the candidate’s own paid assessments; this is derived personal data
How we use data
We use the data above to deliver and operate the interview, generate per-concept skill reports, run proctoring and integrity checks, provide the evidence trail to the hiring organization (and to the candidate via their evidence link), prevent abuse, process payments, and meet legal obligations. We do not sell personal data, and we do not use candidate interview content to train third-party foundation models.
Discoverability
Discoverability is opt-in and off by default. A candidate's profile and fingerprint are private until the candidate turns discoverability on, and it can be turned off again at any time.
When a candidate turns it on, verified employers can find them through talent search and see only their derived knowledge fingerprint and a profile summary — headline, seniority, location, and availability. Employers do not see raw assessment reports, recordings, transcripts, or which organization has interviewed the candidate.
Legal bases
Where GDPR applies, we rely on: contract (to provide the service to organizations, run the interview a candidate has been invited to, and run a candidate's own account and assessments); legitimate interests (security, fraud and integrity, improving the product); consent where required — collected by the hiring organization before an employer-initiated interview, and collected directly from the candidate for self-assessments and discoverability; and legal obligation (tax, accounting, lawful requests). Under India's DPDP Act, processing is carried out for the stated, lawful purposes with notice and the consent obtained either by the organization or directly from the candidate, depending on which applies.
Sub-processors
We use a small set of trusted infrastructure and service providers to run the platform. Each processes data only as needed for the purpose below.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic | AI evaluation of interview answers (LLM) | United States |
| AssemblyAI | Speech-to-text for spoken answers | United States |
| Google Cloud Platform | Application hosting, compute & data storage | United States / India |
| Cloudflare | Edge network, CDN, DNS, WAF & TLS termination | Global edge |
| Razorpay | Payment processing (wallet top-ups — organization and candidate wallets, INR) | India |
Your rights
Subject to applicable law (GDPR and India's DPDP Act), you can exercise the following rights over personal data:
- Access. Candidates can review the evidence captured about them — transcript, submitted code, recordings, and proctoring signals — via the token-authenticated evidence link issued with their interview, and candidates with a marketplace account can review their profile, assessments, and fingerprint directly in the candidate portal. This implements the access right under DPDP §11 / GDPR Art. 15.
- Correction. Ask us to correct inaccurate account information, or edit your profile directly in the candidate portal.
- Export. Candidates can export their profile, assessment history, and knowledge fingerprint from the candidate portal, without routing the request through any hiring organization.
- Deletion. Candidates can delete their account from the portal; deletion purges the account, its aliases, and the derived fingerprint, and removes the candidate from talent search. For data from an employer-initiated interview, we route the request to the hiring organization that controls it and delete on confirmed request; org-owned interview records remain the organization's business records.
Candidates can exercise their account, export, and deletion rights self-serve from the candidate portal. For anything else, or for data collected by a hiring organization (where we may direct you to them as the controller), email hireinterviewai@gmail.com.
Data retention
Account data is retained while the account is active. Billing records are kept as required by law.
Employer-initiated interviews. Candidate interview data — including recordings and proctoring evidence — is retained for the hiring organization's review window and then deleted on the organization's instruction or on a verified deletion request.
Candidate self-assessments. Assessment recordings are retained for 18 months and can be deleted earlier by the candidate. The knowledge fingerprint persists until the candidate deletes it or deletes their account.
International transfers
We host primarily on Google Cloud and route traffic through Cloudflare's global edge. Some sub-processors (e.g. Anthropic, AssemblyAI) are based in the United States, so data may be processed outside your country. Where required, transfers are made under appropriate safeguards such as Standard Contractual Clauses.
Security
Data is encrypted in transit (TLS) and at rest. The platform runs on Google Cloud behind Cloudflare's edge (WAF and TLS), with tenant isolation so each organization's hiring data is scoped to that organization. Candidate fingerprints are visible to employers only when the candidate opts in to discoverability (default off). For the full picture see our Security & Trust page.
Changes to this policy
We may update this policy as the product and our obligations evolve. Material changes will be reflected by an updated date at the top of this page.
Privacy questions?
Contact our privacy team at hireinterviewai@gmail.com.