Legal
Privacy policy
Last updated 2026-07-23. Applies to all visitors, candidates, and recruiters using SkillBricks.
Who we are
SkillBricks is a product brand of Mockif LTD, a company registered in England and Wales. Mockif LTD is the data controller for all personal data described in this policy. Contact the privacy team at privacy@skillbricks.ai.
What data we collect
We collect only what the service needs to operate. Categories depend on whether you are a candidate, a recruiter, or a visitor.
Candidates
- Account: email, verified non-VoIP phone number, full name, optional display name, city, and country.
- Assessment: session metadata, command logs, examiner dialogue, agent observations, tier and score outputs. If you turn on the optional voice interview, your spoken answers are transcribed to text and the audio is discarded (no recording is kept); the transcript is treated like any other examiner dialogue. See the how-it-works page for what happens during a session.
- Linked identities: optional GitHub login, used only for display-only context. GitHub activity never influences your tier or score.
Recruiters
- Account: work email (free-mail domains are blocked), full name, job title, company name, company LinkedIn URL.
- Payments: Stripe customer and payment-method references. We never store card numbers, CVCs, or expiry dates; Stripe handles card data under PCI DSS Level 1.
- Usage: credit transactions, unlocks, in-platform messages, subscription history, VAT number and billing address where provided.
All visitors
- Analytics: anonymous page views and interaction events via our self-hosted PostHog. EU/UK visitors are only tracked after explicit consent in the cookie banner.
- Technical logs: request metadata sent to our self-hosted Loki with personal data scrubbed at ingestion. IP addresses are truncated before storage.
Why we process it (lawful basis)
- Contract (UK GDPR Article 6(1)(b)). Account data and assessment data are required to deliver the service you signed up for.
- Legal obligation (Article 6(1)(c)). Payment and invoicing records are retained under UK tax law.
- Legitimate interest (Article 6(1)(f)). Fraud prevention signals (Turnstile, phone-carrier check, duplicate-account blocking) and platform security. Balancing assessment on file.
- Consent (Article 6(1)(a)). Marketing emails, JD match digests, and non-essential analytics. You can withdraw consent at any time without affecting the service itself.
We do not sell personal data. The only special-category data we process under Article 9 is described in the identity-verification section below, and only ever with your separate, explicit consent.
Identity verification (biometric data)
Where visual identity verification is offered, and only if you explicitly consent, we process biometric data to confirm that the person completing assessments is the account holder. A short camera capture is converted into an encrypted numerical face template that is stored on our own infrastructure, never shared with third parties, and used solely to compare against captures taken during your assessment sessions. Camera frames are processed in memory and are not retained, with one exception below. This is special-category data under Article 9; our lawful basis is your explicit consent (Article 9(2)(a)), requested separately at the point of capture. Verification is optional at signup; it is required only if you choose to take verified assessments.
Separately and optionally, you can choose to let us keep one frame from your enrollment capture as a profile photo, shown to a recruiter only at the moment your identity is revealed to them. This has its own consent checkbox, off by default; declining it never affects verification. Withdrawing it in Settings deletes the stored photo. Recruiters who already saw your photo before withdrawal may have viewed it, but it is not served to anyone after withdrawal.
Your face template is kept for as long as your verification enrollment is active. Revoking verification in Settings deletes the template and any stored photo, and account erasure removes both. You can withdraw either consent as easily as you gave it, at any time, from Settings. A small number of authorised staff can access verification data for support and fraud review; all access is logged. Questions or objections: privacy@skillbricks.ai.
Automated decision-making
Your tier is computed algorithmically from your assessment outputs. Under Article 22 you have the right to request human review of any tier decision. Email privacy@skillbricks.ai and we will respond within 30 days. We do not use your tier for any decision outside SkillBricks.
How long we keep it
Retention windows below are the runtime source of truth, pulled live from the platform's configuration so the policy cannot drift from the purge jobs.
| Data class | Retention |
|---|---|
| Raw live-task events (commands, keystrokes summary) | 3 months |
| Session metadata summaries | 1 years |
| Aggregate scores, wall, and brick proof trail (the product) | indefinitely |
| Payment records and VAT invoices | 7 years |
| Administrative audit log | 7 years |
| Authentication events | 2 years |
| Access logs (hot / cold) | 1 months hot, 3 months cold |
“Indefinitely” means until you delete your account or request erasure. The aggregate wall is the product; we keep it so you can take your proof trail with you across your career.
Subprocessors and international transfers
We rely on a small set of third-party processors. The full list, their purpose, location, and transfer safeguards lives on the data-processing page. Highlights:
- Supabase (US) hosts our database, authentication, storage, and realtime channel.
- Stripe (US / EU) processes recruiter payments.
- Resend (US) sends transactional and marketing email.
- Twilio Verify (US) checks phone numbers against VoIP carriers at signup.
- Cloudflare (US) provides Turnstile anti-abuse and CDN.
- Anthropic (US) hosts the Claude models used for the AI examiner, agent, and challenge generation.
- OpenAI (US) provides speech-to-text and text-to-speech for the optional voice interview, if you turn it on. Your spoken answer is transcribed and the audio is then discarded; no voiceprint is created, and the examiner is still Claude.
- Hetzner (Germany) provides the infrastructure where our self-hosted services run.
- GHCR (GitHub) (US) hosts the container images we deploy from.
Transfers outside the UK rely on the UK International Data Transfer Addendum combined with Standard Contractual Clauses. Supplementary measures include encryption at rest, TLS 1.3 in transit, and PII scrubbing before any data leaves the App Cluster for observability.
Your rights
Under UK GDPR (and EU GDPR where it applies) you can ask us to:
- Confirm whether we process your data and give you a copy (subject access).
- Correct inaccurate data.
- Delete your data (erasure), subject to records we must keep for tax or legal reasons.
- Export your data in a machine-readable format (portability).
- Restrict or object to specific processing.
- Not be subject to a decision based solely on automated processing with legal or similarly significant effects (see “Automated decision-making” above).
- Withdraw consent for marketing or non-essential analytics at any time.
Data export and account erasure are self-service at /settings/data: download a machine-readable copy of your data (subject access and portability) or delete your account there. You can also email privacy@skillbricks.ai. We respond within 30 days. You can also complain to the UK Information Commissioner's Office; we would prefer to hear from you first.
Security
We run production-grade infrastructure from day one: row-level security on every user-data table, mTLS between internal services, self-hosted Vault for all secrets, gVisor-isolated candidate sandboxes on a separate Execution Cluster, append-only audit logs with an immutable offsite copy. Full detail on the security page.
Breach notification
In the event of a personal data breach we notify the UK ICO within 72 hours of becoming aware of it, and affected users without undue delay where the risk to their rights and freedoms is high.
Children
SkillBricks is not directed to children under 16. We do not knowingly process children's data. If we discover a minor has signed up we will close and delete the account.
Changes to this policy
Material changes are announced 30 days in advance by email to account holders and by banner on the site. The “last updated” date at the top of this page reflects the most recent revision.
Contact
Mockif LTD - Privacy Team
privacy@skillbricks.ai