Privacy Policy

Last updated: December 29, 2025

1. Introduction

Invert Code Orbit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered career application system.

2. Information We Collect

2.1 Personal Information

We collect the following personal information:

  • Account Information: Name, email address, profile picture (from OAuth providers)
  • Professional Information: Phone number, location, years of experience, education, LinkedIn profile, portfolio links
  • Application Data: Cover letters, remarks, CV/resume files
  • OAuth Data: Provider ID, access tokens (stored securely)

2.2 Interview Data

  • AI interview questions and candidate responses
  • Interview session metadata (start time, duration, completion status)
  • AI-generated evaluations and scores
  • Conversation history and message timestamps

2.3 Technical Information

  • IP addresses (for rate limiting and security)
  • Browser type and version
  • Device information
  • Usage patterns and analytics

3. How We Use Your Information

We use your information to:

  • Facilitate job applications and recruitment processes
  • Conduct AI-powered interviews and assessments
  • Generate evaluation reports and recommendations
  • Communicate with you about your applications
  • Improve our services and user experience
  • Ensure security and prevent fraud
  • Comply with legal obligations

4. AI Processing and Guardrails

4.1 OpenRouter Integration

We use OpenRouter API for AI-powered interviews. Interview questions and responses are sent to OpenRouter for processing. We have implemented strict guardrails to ensure:

  • AI operates in READ-ONLY mode for candidate data
  • AI cannot delete, modify, or access unauthorized information
  • AI cannot execute system commands or perform destructive actions
  • All interview data is stored in our secure database, not shared with third parties

4.2 Data Retention

Interview transcripts and evaluations are stored for:

  • The duration of the recruitment process
  • Additional period as required by law or business needs
  • You may request deletion of your data (see Section 8)

5. Information Sharing and Disclosure

5.1 Within Organization

Your information is shared with:

  • HR managers reviewing your application
  • Interviewers assigned to evaluate your responses
  • Administrators managing the platform

5.2 Third-Party Services

We share limited data with:

  • OAuth Providers: Google, LinkedIn (for authentication only)
  • OpenRouter: Interview questions and responses (for AI processing)
  • Database Provider: MySQL/PlanetScale (for data storage)

5.3 Legal Requirements

We may disclose your information if required by law, court order, or government request.

6. Data Security

We implement industry-standard security measures:

  • Encryption: Data in transit (HTTPS/TLS) and at rest
  • Authentication: OAuth 2.0 with secure session management
  • Access Control: Role-based permissions (RBAC)
  • Rate Limiting: Protection against brute force attacks
  • Security Guardrails: AI cannot perform destructive operations
  • Regular Audits: Security reviews and updates

7. Cookies and Tracking

We use cookies and similar technologies for:

  • Session management (NextAuth.js)
  • Authentication state persistence
  • User preferences
  • Analytics and performance monitoring

You can control cookies through your browser settings, but this may affect functionality.

8. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request deletion of your account and data
  • Portability: Receive your data in a structured format
  • Objection: Object to certain processing activities
  • Withdrawal: Withdraw consent at any time

To exercise these rights, contact us at privacy@invertcode.com

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers.

11. Changes to Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our platform or sending an email.

12. Contact Us

For questions or concerns about this Privacy Policy or our data practices, please contact:

Data Protection Officer
InvertCode
Email: privacy@invertcode.com
Website: www.invertcode.com

13. Compliance

We are committed to compliance with applicable data protection laws, including GDPR, CCPA, and other relevant regulations.