Last updated 28 July 2026
Privacy Policy
NorthAssay runs hiring assessments, which means we handle two very different kinds of data: ordinary account data for the recruiters who use the product, and sensitive assessment data — video, transcripts, and in some cases an identity photo — belonging to candidates who may never have chosen to use us at all. This policy is written for both readers, and it is specific about which is which.
Scope, and who controls what
This policy covers northassay.com and the NorthAssay application. It describes two relationships that carry different obligations, and conflating them is the most common way a policy like this misleads people.
- Recruiters and their accounts. We decide what account data we need and why, so for that data NorthAssay is the controller. This policy is our commitment to you directly.
- Candidates and their assessments. A recruiter chooses to assess you, decides what to ask, and decides what your results mean. For assessment data the recruiter is the controller and NorthAssay is a processor acting on their instructions. We are still accountable for handling it securely and for the limits described below — but if you want your assessment withdrawn from consideration, the recruiter is the party who decides that.
If you are a candidate and you do not know who to ask, write to us at hello@northassay.com with the assessment link you were sent and we will route your request to the recruiter who issued it, and act on it ourselves where we are able to.
What we collect
The table below is the complete inventory, not a summary. It is derived from the application's database schema and object storage rather than written from memory.
| Data | Who it belongs to | Why we hold it |
|---|---|---|
| Email address, name, and sign-in identifiers (including OAuth provider identity if you sign in with Google) | Recruiters and candidates | Authentication and account identity. Held by our authentication provider, not in our own database. |
| Role descriptions, required skills, seniority, and the assessments and questions generated from them | Recruiters | This is the product. Recruiter-authored content used to build and run assessments. |
| Invitation records: the candidate email and name a recruiter enters, an invitation token, its expiry, and how the invitation was shared (direct email, open link, or access code) | Candidates, entered by recruiters | To deliver the assessment to the right person and to bind a private link to the email it was sent to. |
| Assessment answers, scores, per-question score breakdowns, and the written rationale for each score | Candidates | The assessment result, and the explanation a recruiter needs in order to defend a hiring decision. |
| Video interview recordings and the text transcript of the conversation, with speaker labels and timestamps | Candidates | Only for assessments of the video interview type, and only after the candidate starts the interview. |
| An identity photo (a single still image), plus the timestamp of consent and of capture, or a record that the candidate declined | Candidates | Only when a recruiter has enabled the identity check. See §03 — this is the most sensitive data we hold. |
| Assessment integrity signals (see §04) | Candidates | Advisory context for the recruiter about how an assessment was taken. |
| Recruiter score overrides and the note attached to them | Recruiters, about candidates | So a human decision that departs from the AI score is recorded as such. |
| An email address submitted to the guide request form on our landing page | Prospective users | To send the requested guide and, if you later sign up, to know where you came from. |
| Product analytics: pages visited, and which product actions were taken | Recruiters, and anonymous site visitors | To understand which parts of the product are used. See §05. |
We do not ask for or store payment details. NorthAssay is free during early access and there is no payment processor in the product.
Identity photos, video, and what we do not do with them
Some jurisdictions — Illinois under BIPA, and the EU and UK under GDPR Article 9 — treat facial images as a special category of data with its own consent requirements. We treat them that way everywhere, and the specific limits below matter more than any general assurance.
- We do not run facial recognition. No biometric template, faceprint, embedding, or other mathematical representation of your face is generated, stored, or compared. The identity photo is stored as an ordinary image file and shown to the recruiter, who looks at it. There is no matching against any database, including our own.
- The photo is never a decision. It is recorded as one of three states — photo on file, photo declined, or identity self-asserted — and shown to the recruiter as context. Declining is a supported path that does not block you from taking the assessment or from being hired.
- Consent comes first, and declining is real. The capture screen explains what the photo is for and how long it is kept before the camera is enabled, and the timestamp of that consent is recorded alongside the photo. If you decline, no image is captured or transmitted.
- Video and transcripts exist only for video interviews. No assessment records audio or video unless it is an interview-type assessment, and recording starts when you begin the interview, not when the page loads. We do not access your camera or microphone outside of an interview you have started.
Recordings and identity photos are held in private object storage with no public access. Every read is served through a short-lived signed URL issued by our server to an authenticated recruiter, or to you.
Assessment integrity signals
While an assessment is open, the page records a small set of events about how it was taken. This is the part of the product candidates are most entitled to know about, so here is the complete list rather than a category.
- That the browser tab was hidden or became visible again, and for how long.
- That focus moved to another window or application while the tab stayed visible.
- That text was pasted or copied, and how many characters — never the content of your clipboard.
- That full-screen mode was exited.
- A best-effort record of a screenshot key combination being pressed. We cannot and do not capture your screen.
- How long was spent on each question.
- That the assessment was reached through an open link or access code rather than a private invitation, which means identity is self-asserted, and whether a repeated or duplicate join looked automated.
- Whether an identity photo was captured or declined.
No signal ever rejects you automatically
Integrity signals and identity checks are advisory evidence shown to a human. Nothing in NorthAssay uses them to filter, rank down, or reject a candidate without a person deciding. This is enforced in the product, not just promised here: there is no automated rejection path. A recruiter can also override any AI score outright, and the override is recorded as a human decision.
We do not read your clipboard, keystrokes, files, other browser tabs, or anything on your device beyond the events listed above. We do not install anything, and we do not use proctoring software.
How we use it, and how we do not
- To run the product: generate assessments, deliver them, score submissions, and show results to the recruiter who requested them.
- To send transactional email: candidate invitations, submission confirmations, and recruiter notifications.
- To keep the service working and secure: error diagnosis, abuse and rate-limit enforcement on shared links, and capacity work.
- To understand product usage in aggregate.
We do not train AI models on your data
Your role descriptions, rubrics, candidate answers, transcripts, and scores are not used to train, fine-tune, or improve any AI model — ours or a provider's. They are sent to a model provider only as the input to a single request whose output goes back to you, and we use those providers under terms that exclude training on submitted content.
We do not sell or share your data for advertising
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There are no advertising or marketing trackers on the application. Our analytics runs with session replay switched off, so no recording of a candidate's screen or interaction is ever captured, and anonymous visitors to the marketing site do not get a profile.
How long we keep it
Identity photos: 30 days
Identity photos are automatically deleted after 30 days (or sooner on request). A daily automated job deletes both the image and its database record once it passes that age. This is the same window the consent screen shows you before the photo is taken, resolved from the same setting, so the two cannot disagree.
For everything else we are going to be straight with you rather than publish a schedule we do not yet enforce. Assessment answers, scores, transcripts, and video recordings are retained for as long as the recruiter's account holds them, because they are the recruiter's hiring record and only the recruiter knows when a role is closed. There is no automated expiry on them today. Invitation links themselves do expire, and an expired link cannot be used to take an assessment.
We delete on request — see §07 — and we will publish a defined retention schedule for assessment data, with automated enforcement behind it, rather than adding a clause here that nothing implements.
Your rights, and how to actually use them
Depending on where you live you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent you previously gave. We honour these requests regardless of whether your local law compels us to.
To make a request, email hello@northassay.com from the address the request concerns, or include the assessment link you were sent. We will confirm receipt and respond within 30 days. We do not charge for a request and we will not treat you differently for making one.
- Deleting an identity photo is something we can always do immediately, on your request alone, without asking the recruiter.
- Withdrawing an assessment from consideration is the recruiter's decision, because it is their hiring record. We will pass your request on, tell you who we passed it to, and delete our copy where we are permitted to.
- Access and portability are handled manually today: we will assemble your data and send it to you in a machine-readable format. There is no self-service export button in the product yet, and we would rather say so than imply otherwise.
- If you are unhappy with our response, you can complain to your local data protection authority. In the EU that is your national supervisory authority; in the UK it is the Information Commissioner's Office.
Who else processes your data
We use a small number of infrastructure providers. Each one is listed with what it actually touches, so you can assess the exposure rather than trust a count.
| Provider | What it processes | Where |
|---|---|---|
| Clerk | Authentication: email, name, sign-in identity, session | United States |
| Supabase (PostgreSQL) | The application database: accounts, assessments, answers, scores, transcripts, integrity signals | United States (us-east-2) |
| Cloudflare R2 | Private object storage: video interview recordings and identity photos | United States |
| Vercel | Application hosting and compute; request logs | United States |
| Google (Gemini) | AI processing: generating assessments, scoring submissions, and conducting video interviews in real time | United States |
| Resend | Transactional email delivery: recipient address and message content | United States |
| Upstash (Redis) | Rate limiting and shared-link abuse protection: short-lived counters keyed to a link or address | United States |
| PostHog | Product analytics: page and event data. Session replay is disabled | United States |
Our AI provider is configurable, and Anthropic and OpenAI are also supported by the application. Google is the provider in use today; if we change it we will update this table, because a change of AI provider is a change of subprocessor and you are entitled to know about it.
Where your data is held
NorthAssay and every provider above operate in the United States, so if you are outside the US your data is transferred there. Where that transfer needs a legal basis — for personal data from the EU, UK, or Switzerland — we rely on the European Commission's Standard Contractual Clauses in our agreements with these providers, together with the UK Addendum where it applies. We do not currently offer an EU-resident deployment.
Security
Encryption, access control, and the specifics of how recordings and identity photos are isolated are covered on our security page, which is written for a reader doing vendor due diligence.
Children
NorthAssay is a tool for assessing candidates for paid work and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has been assessed through NorthAssay, tell us and we will delete the record.
Changes to this policy
The date at the top of this page is the date the text below it last changed, and it is verified automatically — a change to this policy that left the date untouched would fail our build. For a change that materially reduces your rights or expands what we collect, we will email account holders before it takes effect, and we will not apply it retroactively to data already collected under an earlier version.
Contact
Privacy questions, requests, and complaints all go to hello@northassay.com. A person reads it. NorthAssay is an early-access product operated by a small team, and we have not yet appointed a data protection officer or an EU representative; if you need a named contact for a formal request, ask and we will give you one.