// privacy

Privacy
policy.

What we collect, why, who else sees it, and how long it stays. Written in the same plain language as the rest of this site, because a policy you cannot read protects nobody.

// last updated 2 October 2026

// the short version

If you read nothing else

  • This website sets no cookies and runs no advertising or tracking across other sites. It counts visits, without identifying you.
  • If you use the form on this site, we get your email address and nothing else. It reaches a mailbox, not a marketing tool.
  • For a candidate's interview data, the employer is in charge, not us. We hold it on their behalf and act on their instructions.
  • We keep the code and the transcript from an attempt for 90 days by default, then delete them. The scorecard is kept until the employer asks us to delete it.
  • No machine rejects anyone. A scorecard is evidence for a person, and a person decides.
  • We do not sell personal data, and we never have.
// 1

Who we are

Codesolara is a product of CODESOLARA (OPC) PRIVATE LIMITED, a company registered in India with its registered office at:

D-502, 42 Park ViewKalhar Cross Road, SolaAhmedabad 380060, GujaratIndia

In this policy, "we", "us" and "Codesolara" mean that company. Write to us about anything on this page at privacy@codesolara.com.

// 2

Two different roles, and why it matters to you

Data-protection law separates the party who decides what happens to personal data from the party who only carries out instructions. We are in both positions, depending on whose data it is.

We decide (controller)

For visitors to this website and for the accounts of our customers' staff. We chose to collect that data and we answer for it directly.

The employer decides (processor)

For everything about a candidate and their interview. The organization running the interview chose to assess you, decides how long to keep the result and what it means. We hold and process that data for them, under their instructions and our contract with them.

// practically: if you are a candidate asking to see or delete your interview data, the fastest route is the employer who invited you. Ask us and we will help, but we have to check with them first — we are not allowed to hand out or erase their records on our own judgement.

// 3

If you visit this website

This site is static pages. It sets no cookies, stores nothing in your browser, and loads no advertising pixels or third-party trackers. Nothing follows you off this domain.

What we get

  • The email address you type into the form, if you use it. It is emailed to us and read by a person. It is not added to a mailing list or a marketing automation tool, and we use it only to reply to you about Codesolara.
  • Standard server logs from our hosting provider — IP address, browser user agent, the page requested, and the time. These exist to keep the site up and to spot abuse. We do not use them to build a profile of you.
  • Visit counts, through Umami. Each page you load sends the page address (including any campaign tags in the link you followed), the page you came from, your screen size and your browser language. So do a few actions: requesting a walkthrough, starting the product video, watching it to the end, and clicking one of our email addresses. Your browser also sends its IP address and user agent with the request, as with any request. Umami uses them to count unique visitors and to tell which country a visit came from, without setting a cookie or storing anything on your device. We see totals in a dashboard, never a record of any one person's visit.

Our own fonts, video and images are served from this domain. No page contacts Google or any other third party to load them.

Why we may do this

Under the GDPR our basis is legitimate interest — running and securing a website, understanding which pages people find useful, and answering people who ask us to get in touch. You can ask us to delete your enquiry at any time and we will.

// 4

If you are a customer using the console

When your organization signs up and your colleagues get accounts, we hold what an account needs to work:

  • Name, work email address and role within the organization
  • A password stored as a memory-hard hash — we cannot read your password, and neither can anyone who obtains the database
  • Second-factor enrolment data where it applies, and records of sign-in attempts used to slow down brute-force guessing
  • An audit log of significant actions in your account — who invited a candidate, who opened a submission, who changed a score
  • Billing and usage records: attempts consumed, invoices, and the ledger behind them

Our basis for this is performing our contract with your organization, plus our legitimate interest in keeping the service secure and our legal obligation to keep accounting records.

// 5

If you are a candidate sitting an interview

An interview is a recorded event. You should know the shape of the recording before you start, not afterwards. You never create an account with us — an invite link is a single-use token that opens one session, and that is the whole of your relationship with our systems.

What is stored

  • The email address the employer used to invite you
  • The code you submit
  • Your conversation with the AI assistant, and what it did on your behalf
  • Your answers when the assistant asks before running a command (Allow or Deny), and the plans you approved or rejected
  • The scorecard built from all of the above

What is never stored

  • No camera, no microphone, no screen recording
  • No keystroke logging
  • We never read your clipboard. Text you paste into a file or into a message to the assistant is stored like anything else you type there
  • Nothing from outside the interview tab. We cannot see your other tabs, files or applications

The employer who invited you decides why they are assessing you and what they do with the result. Their own privacy notice governs that decision. We process this data for them.

// 6

AI, and what it does not decide

  • Your work is sent to an AI provider. The assistant beside you in the workspace, and the grading of your submission afterwards, both run on models operated by Anthropic. Your prompts, the assistant's replies and the submitted code are sent there to produce them.
  • It is not used to train models. We use Anthropic's commercial API, under terms that do not permit training on the data we send.
  • No decision is made by a machine alone. A scorecard is evidence assembled for a person: every part of it can be reviewed, disagreed with and overridden by the hiring team, and the original machine score stays visible when they do. Nobody is accepted or rejected automatically, so this is not a decision based solely on automated processing in the sense of Article 22 of the GDPR.
  • Employers carry their own obligations. Laws in some places require notice, bias auditing, or an alternative process when a tool is used in hiring. The organization running the interview is responsible for meeting those where it hires, and we will supply what they need to do it.
// 7

Who else processes this data

We keep the list short on purpose. Each of these is bound by a contract to process data only on our instructions.

ProviderWhat they do for usWhere
Amazon Web ServicesHosting, database, object storage, and email delivery for this siteUnited States
AnthropicThe AI assistant in the candidate workspace, and the AI grading of a submissionUnited States
UmamiVisitor counts for this website — no cookies, no profilesUnited States and European Union
Google WorkspaceOur own email — service notifications to you, and messages you send usUnited States

Beyond these, we disclose personal data only where the law requires it, or where a business transfer makes it necessary — in which case the same protections travel with it. We do not sell personal data and we do not share it for advertising.

Our own platform operators cannot read candidate submissions or scorecards. That is enforced by database privilege rather than by a rule someone has to remember — see how the boundaries work.

// 8

Where your data goes

We are an Indian company and the service runs on Amazon Web Services (AWS) in the United States. So personal data handled by Codesolara is stored and processed in the United States, and is accessible to our team in India.

If you are in the European Economic Area or the United Kingdom, that is a transfer outside your region. We rely on the European Commission's Standard Contractual Clauses, with the UK addendum where it applies, and we will provide a copy on request.

// 9

How long we keep things

  • Interview artifacts — the submitted code and the assistant transcript — are deleted on a retention schedule, 90 days by default. A customer can agree a shorter window with us, and a specific attempt can be deleted on request.
  • The scorecard is not on that schedule. It is kept until the employer who holds it asks us to delete it.
  • Account data is kept while the organization is a customer, and deleted within 90 days of the account closing.
  • Enquiries from this website are kept while the conversation is live and deleted when it is clearly over, or sooner if you ask.
  • The audit log and the billing ledger are append-only, by database privilege — nothing can update or delete a row in them, including us. Deleting an attempt's artifacts therefore removes the code and the transcript, but the record that an action happened remains. We think that is the right trade: an access log you can quietly edit is not a log. These records are kept as long as we are required to keep accounting and security records.
  • Backups are retained on a rolling schedule and overwritten in turn, so data deleted from the live system can persist in a backup for a short period before it ages out.
// 10

How it is protected

Candidate code runs in a container created for one attempt and destroyed with it, holding none of our credentials. Tenants are separated at the database by row-level security that fails closed. Grading runs in a further isolated box with no database or storage credential at all. Data is encrypted in transit and at rest.

The full description, including what we do not yet claim — we hold no SOC 2 or ISO 27001 certification today — is on the security page. No system is perfectly secure; if you find a weakness, please tell us at security@codesolara.com.

// 11

Your rights

Depending on where you live you can ask to see the personal data we hold about you, to correct it, to delete it, to get a copy in a portable form, to restrict or object to how we use it, and to withdraw consent where consent is what we relied on. You can also complain to your data-protection regulator.

  • India (DPDP Act 2023) — you may access, correct and erase your data, nominate someone to exercise your rights, and raise a grievance with us. Our grievance contact is below, and you may escalate to the Data Protection Board of India if we do not resolve it.
  • EEA and UK (GDPR) — the rights above, plus the right to lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA) — rights to know, delete, correct and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, and we will not treat you differently for exercising a right.

Write to privacy@codesolara.com. We will respond within 30 days. We may need to verify who you are before acting, so that someone else cannot obtain or destroy your data by pretending to be you.

// if the request is about an interview you sat, see section 2 — we will pass it to the employer who controls that record and help them answer it.

// 12

Grievance contact

As the DPDP Act requires, a named person answers privacy grievances. Reach them at privacy@codesolara.com, or by post at our registered office above. We acknowledge a grievance within 7 days and aim to resolve it within 30.

// 13

Children

Codesolara is a tool for professional hiring and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data reached us, tell us and we will delete it.

// 14

Changes to this policy

When we change what we do with data, we change this page and move the date at the top. For a change that materially affects our customers, we tell them directly rather than relying on you to notice.

contact us →