Legal
Privacy policy
Plain words about what we collect, what we never record, and why. Written for the two groups of people this affects: the companies that use Sphinque, and the candidates they assess.
Effective 1 June 2026
01Who this covers
This policy covers this website and the Sphinque assessment platform. It applies to two groups: company users, the people at a hiring company who create assessments and read reports, and candidates, the people a company invites to take an assessment.
When a company assesses a candidate, the company decides why the assessment exists and what happens with the result. Sphinque processes the candidate's data on that company's instructions.
For candidate data, the company is the controller and Sphinque is its processor. For company users' account data, and for anything sent to us through this website, Sphinque is the controller. We do not yet publish a standard data processing agreement; a company that needs one can raise it with us before it invites candidates.
02What we collect from company users
- Account details: name, work email, company name, and the role you hold there. Accounts are created by Sphinque or by an invitation from a colleague; there is no self-serve sign-up.
- Sign-in data: password hashes, session tokens, and if you use Google sign-in, the identifier Google returns. OAuth tokens are encrypted at rest.
- What you put into the product: job descriptions, blueprint approvals, assessment settings, and the decisions you record on reports.
- Operational logs: the IP address and browser used for requests, and an audit trail of significant actions on your account.
If you request a walkthrough through this website, we collect the name, work email, company, role and team size you enter, and we use them to reply. Nothing else.
03What we collect from candidates
Candidates do not have accounts. An invitation link identifies the assessment session. During the session we retain exactly what the evidence notice says, and the candidate acknowledges that notice before the environment is provisioned and again before the interview begins:
“We retain your written plan and the files you open while planning, your submitted code, the tests you ran and their results, Git and terminal history, assessment activity, AI-assistant interactions — including what you ask Claude Code in the workspace, what it runs and what it edits — and the interview transcript for hiring review. The interview is recorded: your screen, your camera and your microphone. The coding session is not recorded as video. A recording is only watched by the hiring team — it is never used to score you.”
In more detail, that is:
- The plan written before coding, and which files were opened while planning.
- The code in the workspace and a git history of how it changed, snapshotted every 30 seconds.
- Terminal command history inside the assessment environment.
- The results of running tests, both the ones visible to the candidate and the hidden ones run after submission.
- Assessment activity: when the session started, ended and changed phase; tab switches and focus changes; paste events in the assistant panel; and the IP address and browser on each request.
- Every exchange with the in-assessment AI assistant, if the company enabled one, including questions the assistant declined to answer.
- The written transcript of the interview.
- The candidate's name and email as provided by the company that invited them.
04What we record, and what we do not
The interview is recorded: the candidate's screen share, their camera and their microphone, as one video file. It is recorded so the hiring team can watch the conversation themselves rather than take our summary of it.
The coding session is not recorded as video. What we keep from it is the work itself — the code, a git history snapshotted every 30 seconds, the commands run, and every exchange with the AI assistant — which a reviewer can search, compare and quote. A screen recording of the same hour would show less and reveal more.
A recording is never used to score anyone. Scoring reads the written transcript alone: how a candidate looks, sounds, or phrases an answer reaches no model and no verdict. That separation is enforced in code and asserted by a test, not left to policy.
One function in the platform is the only authority on what is captured, and the candidate acknowledges the current version of that notice before the environment is provisioned and again before the interview begins. When what we capture changes, the policy and the notice change first and the acknowledgement is requested again.
05Why we process it
- To run the assessment: provision the environment, run tests, prepare and conduct the interview, and produce the report the company reads.
- To answer integrity questions honestly. Activity data is used to prepare interview questions, not to produce an automated verdict.
- To operate and secure the service: rate limiting, abuse prevention, debugging.
- To communicate with company users about their account and with website visitors who asked us to.
We do not sell personal data. We do not use candidate data to advertise to anyone.
06AI systems and sub-processors
Sphinque uses third-party AI models to generate assessment material, to assist evaluation, and to conduct the spoken interview. Candidate code, assistant conversations and interview speech are sent to those providers for processing during the session. Scoring of the interview is computed from the text transcript only.
We also use infrastructure providers to host the platform, run isolated assessment environments, carry the interview in real time, store its recording, and send email. These are the providers that process personal data for us:
- Anthropic: AI models for generating assessments, evaluating submissions, the interview and the workspace assistant.
- OpenAI: AI models for the spoken interview.
- Amazon Web Services: the AI model behind Claude Code in the candidate's workspace (Bedrock).
- Deepgram: speech recognition during the interview.
- ElevenLabs: the interviewer's voice.
- LiveKit: the interview's real-time audio and video, and its recording.
- E2B: the isolated machines candidates work in and tests run on.
- Cloudflare: storage for interview recordings, and the network in front of this website.
- Railway: hosting for the platform.
- Resend: email delivery.
- Stripe: billing.
- Google: sign-in with Google for company users who choose it, and the mailbox enquiries are delivered to.
07Retention
- Interview recordings are deleted automatically 180 days after the interview.
- Other assessment data — the code, its history, test results, transcripts and reports — is kept while the hiring company's account is active, so it can document its hiring decision. It is not yet deleted on a schedule.
- A company can ask us in writing to delete its assessment data, or a candidate's, at any time, and we delete it.
08Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, have it deleted, restrict or object to its processing, or receive a copy in a portable format.
Candidates: because your data is processed on behalf of the company that invited you, that company is usually the right first contact. You can also write to us and we will help route the request.
Contact: [email protected].
09Security
- Data is encrypted in transit. Sign-in tokens are short-lived and rotated. Accounts lock after repeated failed sign-in attempts.
- Candidate environments are isolated virtual machines whose only outbound route is to our own model proxy, destroyed after the session.
- Hidden tests and reference solutions never enter the candidate's environment.
- Invitation links are single-use tokens that expire, seven days by default, and are never written to browser history after the first visit.
10Cookies and local storage
This website sets no tracking cookies and stores nothing in your browser. The platform uses cookies and local storage that are strictly necessary for signing in and for keeping a candidate session attached to its invitation, and remembers a light-or-dark theme choice where it offers one: in the signed-in product and in a candidate’s coding workspace.
11Changes to this policy
When this policy changes, the effective date above changes with it. Material changes that affect candidates are reflected in the evidence notice they acknowledge, which is versioned. See also the terms of service.