Privacy Policy
Last updated: 30 July 2026
Kaairo AI ("Kaairo", "we", "us", or "our") operates the website www.kaairo.ai and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian law.
Our role. When you use Kaairo directly — for example by creating a candidate account, taking an assessment you found on our platform, or subscribing to our newsletter — Kaairo acts as a Data Fiduciary and determines the purposes and means of processing your personal data. When an employer or organisation uses Kaairo to assess its own candidates or employees, that organisation is the Data Fiduciary and Kaairo acts as a Data Processor, processing personal data on that organisation's instructions for its hiring or learning-and-development purposes. In that case the organisation's own privacy notice also governs how your data is used, and requests to access or delete data held on its behalf may need to be directed to that organisation.
1. Information We Collect
We collect the following categories of personal data:
- Account Data — Name, email address, and authentication credentials when you create an account or sign in via Google OAuth.
- Assessment Responses — Written answers, multiple-choice selections, and situational judgement responses submitted during assessments.
- Voice Interview Transcripts — Real-time voice recordings captured during AI voice interviews, which are transcribed and processed for competency scoring.
- Coaching Session Data — Voice recordings and transcripts from AI coaching roleplay sessions, processed for development scoring and feedback.
- Proctoring Data — If camera-based proctoring is enabled, we capture periodic still snapshots of the camera feed and video feed metadata for face detection, look-away detection, and multiple-person detection. No continuous video is recorded; still snapshots and event-level flags are retained.
- B2B Lead Data — Name, work email, company, designation, mobile number, city, and team size submitted through our business enquiry forms.
- Free Tool Data — When you use one of our free public tools (such as the Competency Framework Generator), we collect the email address you verify, the role title, seniority, industry and any description you enter, and the framework generated for you. We also record your IP address and a browser identifier — both when you search, before the email step, and again when you generate — to enforce usage limits and prevent abuse. If you tick the optional consent box, we additionally record that consent together with the IP address and browser user-agent it was given from.
We derive a small amount of information from what you have already given us, without any external lookup of you personally: the organisation implied by your email domain, an automated lead score and priority band computed from that domain and the role you searched for, how many people from your organisation have used the tool, and whether your organisation already appears in our business-enquiry or customer records. This is used to prioritise our own follow-up. It is not automated decision-making about you, it produces no consequence for you, and it is never shared.
We email you your result. We send you one follow-up about Kaairo only if you explicitly tick the optional consent box — you receive your framework either way, and the follow-up carries a one-click unsubscribe link. Ticking that box also lets you give us a phone number, which is optional, is only stored if you tick, and means we may call you about the role you were working on. Unsubscribing withdraws both permissions and deletes the number. - Newsletter Engagement — Email address, open rates, and click-through data for subscribers who opt in to our newsletter.
- Usage Analytics — Pages visited, device type, browser information, and interaction patterns collected via analytics cookies.
- Sourced Candidate Profiles — Publicly visible professional profile information about people who have not signed up for Kaairo, collected when an employer searches for candidates. See “Sourced candidate profiles” below.
- Business Prospect Data — Work email address, name, company and role details of people at organisations we contact about Kaairo, together with a record of whether we contacted them and whether they replied or asked us to stop. Collected from publicly available sources such as an organisation’s own job posting or website, never from purchased lists. See “Business prospects” below.
Biometric and sensitive data. Voice recordings and transcripts from voice interviews and coaching sessions, and the facial-detection signals used during camera-based proctoring, may constitute biometric or otherwise sensitive personal data. We collect and process this data only with your consent, only for the assessment or coaching purpose described, and we retain it only as set out in Section 5 — camera snapshots are deleted 30 days after capture, or 90 days where the assessment was flagged for a potential integrity concern and the organisation may need to review the evidence before acting on it. Interview and coaching transcripts are kept as part of the assessment record and deleted on verified request. We do not record continuous proctoring video, and we do not use this data for advertising, profiling unrelated to the assessment, or AI model training.
Sourced candidate profiles. This paragraph applies if you have not signed up for Kaairo and have not applied for a role through it, but your professional profile is publicly visible online. When an employer using Kaairo searches for candidates for a role, we search publicly accessible web pages and may store, for each matching profile: your publicly displayed name, your public headline or current role, your publicly stated employer and city, the public address of the profile, and the short text excerpt returned by the search. We collect this only from pages that are accessible without logging in — we do not log in to LinkedIn or any other platform, we do not access anything behind a login or paywall, and we do not buy or licence candidate databases. The purpose is to let the employer decide whether to approach you about a role. Kaairo does not contact you on the employer's behalf: any approach you receive comes from that employer's own recruiter, in their own name. If the employer takes no action on your profile, the details listed above are deleted after 180 days, and we keep only a non-identifying reference so that we can honour a removal request and avoid surfacing you again. You can ask to be removed at any time using the removal page linked from any approach you receive, or by emailing support@kaairo.ai, which removes you from searches across the platform.
Business prospects. This paragraph applies if you have not signed up for Kaairo and have not contacted us, but we have written to you about Kaairo because your organisation published a job posting or a work contact address. We collect only what is publicly available — typically your work email address, your name and role, and details of the posting itself. We do not buy or licence contact lists, and we do not guess or pattern-build email addresses. We may build a demonstration page for the role described in your public posting and send you a private link to it; that page is a demonstration only, is not affiliated with your organisation, and is not a job application. We stop contacting you immediately and permanently if you reply asking us to. We keep the outreach record — your address, the organisation, and whether you were contacted, replied, or asked us to stop — for one operational reason: it is what allows us to honour that request. Deleting it would be the very thing that let us contact you again. We do not add you to a marketing list, a newsletter, or any automated sequence, and we do not sell or share this data. You can ask us to delete it at any time by emailing support@kaairo.ai; where you have asked us to stop contacting you, we retain the minimum needed to keep honouring that request and nothing else.
2. How We Use Your Information
We process your personal data for the following specific purposes:
- Assessment Scoring — Your written responses and interview transcripts are processed by AI models to generate structured scores across defined competency rubrics.
- AI-Generated Reports — Generating personalised thinking reports, competency analyses, strengths, and improvement recommendations.
- Proctoring Integrity — Monitoring assessment-taking conditions to ensure test fairness and detect irregularities.
- Communication — Sending assessment invitations, result notifications, password resets, and newsletter content you have opted into.
- Opportunity Matching — If you have created a candidate account or completed an assessment, we may email you about other relevant job opportunities on the Kaairo platform, including invitations to take assessments or interviews from other organisations hiring on the platform. These invitations do not share your existing scores, assessment responses, or profile data with any other organisation. Any new organisation evaluates you only on the basis of a fresh assessment you choose to take. You can opt out of these emails at any time using the unsubscribe link in each message or by emailing support@kaairo.ai, and opting out does not affect your account, existing applications, or assessment results.
- Platform Analytics — Understanding usage patterns to improve our platform, features, and user experience.
- B2B Enquiry Follow-up — Contacting you about Kaairo services if you submit a business enquiry form.
3. AI & Automated Decision-Making
Kaairo uses artificial intelligence extensively. We believe in transparency about how AI processes your data:
- Assessment Scoring — Your written responses are scored by OpenAI's GPT-4o-mini model using structured rubrics with defined parameters on a 0–100 scale.
- Voice Interviews — Your voice is captured via your microphone, transmitted in real time to OpenAI's Realtime API for transcription and conversation, and the resulting transcript is scored by AI for competency evaluation.
- Content Generation — AI generates assessment content, interview questions, and development recommendations based on competency frameworks.
- Hiring Decision Support — For employers on eligible plans, AI may generate an internal, organisation-only recommendation that summarises your screening, assessment, and integrity signals into a single overridable hiring brief to help a hiring manager prioritise candidates. It is decision-support only, is never shown to candidates, and the employer retains final hiring authority.
Important: No fully automated decisions with significant legal or similarly significant effects are made without human oversight. AI-generated scores are provided as decision-support tools for employers, who retain final hiring and evaluation authority.
We do not sell your personal data, and we do not use your assessment responses, voice or interview transcripts, or other personal data to train our own or any third party's general-purpose AI models. Our AI processors (such as OpenAI) handle your data under their API / business terms, which do not use API-submitted data for model training. Your data is processed only to produce the scores, reports, and features described in this policy.
4. Third-Party Data Processors
We share your personal data with the following third-party processors, strictly for the purposes described:
| Processor | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI scoring, voice transcription, content generation | Assessment responses, voice audio, interview transcripts |
| Supabase | Database hosting and authentication | All stored personal data (encrypted at rest) |
| Vercel | Application hosting and serverless compute | Request/response data in transit |
| SendGrid | Transactional and newsletter email delivery | Email addresses, names |
| Google Analytics | Usage analytics (loaded only with consent) | Anonymised usage data, device information |
| Microsoft Clarity | Marketing-page heatmaps and session analytics (loaded only on public marketing pages; not on /auth, /apply, /interview, /internal, /org, or /admin) | Anonymised marketing-page interaction data |
| Razorpay | Payment processing for paid subscriptions | Name, email, billing contact and payment metadata (card details are handled by Razorpay and are not stored by Kaairo) |
| Google Cloud Translation | Indian-language translation of assessment content and interfaces (Tamil, Telugu, Kannada and Malayalam; other supported languages are translated by OpenAI) | Assessment content and text submitted for translation |
| Serper | Web search for publicly available candidate profiles, where an employer uses our candidate sourcing feature | Search terms only (role title, city, skills). No candidate, employee or assessment data is sent. |
4a. Organisation-Controlled AI Connectors
A hiring organisation on an eligible plan may choose to connect its own AI assistant (for example ChatGPT or Claude) to its Kaairo account through our AI Connectors feature. When an organisation owner or manager authorises such a connection, Kaairo transmits that organisation's own assessment data to the AI provider the organisation has chosen, at that organisation's direction. In this flow the chosen AI provider acts as a processor for the connecting organisation, not for Kaairo.
By default these connections are read-only and pseudonymised: they expose assessment scores, competency bands, rankings, and a stable record identifier, but not candidate names, email addresses, written responses, interview transcripts, reviewer notes, or proctoring signals. The connecting organisation can re-identify a record only inside Kaairo. Access to identifiable candidate data through a connector is not enabled by default and would require separate, explicit authorisation.
Because the organisation selects and controls the AI provider, that provider's own privacy terms and data-handling practices (including whether inputs may be used to train models, and the country in which it processes data) govern the data once it leaves Kaairo. The connecting organisation is responsible for ensuring its use of a connected AI tool complies with applicable law and the consents it has obtained from candidates. Connections can be revoked at any time in the organisation's Kaairo settings or from the AI tool.
5. Data Retention
We retain personal data only as long as necessary for the purposes described:
- Account & Assessment Data — Retained for the duration of your account, and deleted following account closure or a verified deletion request.
- Voice Interview Transcripts — Retained as part of the assessment record, so the organisation that assessed you can review results and reports; deleted on verified request.
- Coaching Session Transcripts — Retained as part of your development record within your organisation's account; deleted on verified request.
- Camera Snapshots — Deleted 30 days after capture. Where an assessment was flagged for a potential integrity concern, the snapshots are kept for 90 days instead, so that the organisation can review the evidence before acting on it and so that you can contest a flag. Raw proctoring event logs are deleted after 90 days. Aggregate integrity indicators (e.g., tab-switch counts, and the number of snapshots taken) are not images, contain no biometric data, and remain part of the assessment record.
- Newsletter Leads — Retained until you unsubscribe. Unsubscribed addresses are excluded from all future sends and deleted on verified request.
- B2B Enquiry Data — Retained while relevant to the enquiry and follow-up, or until you request deletion.
- Free Tool Data — Generated framework pages are public and remain published unless you ask us to remove yours. The email address, contact record and abuse-prevention records (IP address, browser identifier) are retained while relevant to the enquiry, or until you unsubscribe or request deletion. A phone number, if you gave one, is deleted the moment you unsubscribe. We do not currently apply an automatic deletion schedule to the rest of this category; deletion on request is the mechanism.
- Sourced Candidate Profiles — Where an employer has taken no action on a sourced profile, the personal details (name, headline, employer, city, profile address and search excerpt) are deleted 180 days after collection. A non-identifying reference is kept so that a removal request can be honoured and you are not surfaced again in a later search. Deleted sooner on request.
- Business Prospect Data — The outreach record is retained for as long as we operate outreach, because where you have asked us to stop it is what guarantees we do not write to you again. Demonstration pages built for a prospect close after 21 days, and any session data from them is deleted within 30 days of closing. Deleted on verified request, except for the minimum needed to keep honouring an opt-out.
- Analytics Data — Governed by Google Analytics' retention settings (default 14 months).
6. Cookies & Tracking
We use the following types of cookies and tracking technologies:
- Essential Cookies — Authentication session cookies required for the platform to function. These cannot be disabled.
- Analytics Cookies — Google Analytics cookies for understanding aggregate usage patterns and improving the platform. No advertising or personalisation cookies are used.
- Marketing-Page Session Analytics — Microsoft Clarity sets cookies on public marketing pages (homepage, pricing, blog, product tours) for heatmaps and session-replay UX analytics. Clarity is not loaded on /auth, /apply, /interview, /internal, /org, or /admin.
- Newsletter Tracking — Open tracking (1×1 pixel) and click tracking for newsletter emails. You can opt out by unsubscribing from the newsletter.
You can opt out of analytics tracking at any time by using your browser's cookie settings or installing the Google Analytics Opt-out Browser Add-on.
7. Your Rights Under the DPDP Act, 2023
As a Data Principal under the DPDP Act, you have the following rights:
- Right to Access — Request a summary of your personal data and how it is being processed.
- Right to Correction — Request correction of inaccurate or incomplete personal data.
- Right to Erasure — Request deletion of your personal data, subject to legitimate retention requirements.
- Right to Withdraw Consent — Withdraw consent for data processing at any time. Withdrawal does not affect the lawfulness of processing done prior to withdrawal.
- Right to Grievance Redressal — Lodge a complaint with our Grievance Officer or the Data Protection Board of India.
To exercise any of these rights, contact our Grievance Officer at support@kaairo.ai. To withdraw a specific consent, email us with the subject line Withdraw Consent: <type> — for example Withdraw Consent: Voice Interviews or Withdraw Consent: Newsletter. You can also opt out of marketing and opportunity-matching emails using the unsubscribe link in any such email. We will acknowledge your request within 48 hours and respond within 90 days.
8. Children's Data
Kaairo is intended for users aged 18 and above. We do not knowingly collect personal data from children. We do not engage in targeted advertising, tracking, or behavioural profiling of minors. If we become aware that we have collected data from a person under 18, we will delete it promptly.
9. Cross-Border Data Transfers
Your personal data may be processed in the United States by our third-party processors (OpenAI, Vercel, SendGrid). Under the DPDP Act, cross-border transfers are permitted except to countries on the Government's restricted list. The United States is not currently on any restricted list.
We ensure that all processors maintain adequate security measures and process data only for the purposes described in this policy.
Where your organisation enables an AI Connector (section 4a), pseudonymised assessment data may also be processed by the AI provider your organisation has chosen (for example OpenAI or Anthropic) in the regions where that provider operates, under that provider's own terms.
10. Data Security
We implement reasonable security safeguards as required under the DPDP Act:
- HTTPS/HSTS encryption for all data in transit
- Row-Level Security (RLS) policies enforcing data isolation in our database
- Encryption at rest for all stored data (via Supabase/PostgreSQL)
- Input validation and sanitisation across all API endpoints
- Prompt injection protection for AI-processed content
- Consent and audit logging for data processing operations
11. Data Breach Notification
In the event of a personal data breach that is likely to cause harm to Data Principals, we will:
- Notify the Data Protection Board of India within 72 hours of becoming aware of the breach
- Notify affected individuals without unreasonable delay
- Provide details of the nature of the breach, data affected, and remedial actions taken
12. Grievance Redressal
In accordance with the DPDP Act, we have appointed a Grievance Officer to address your concerns:
Grievance Officer
Email: support@kaairo.ai
Response Time: Acknowledgement within 48 hours, resolution within 90 days
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India as established under the DPDP Act.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify registered users via email before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at support@kaairo.ai