Back to Home
Light Mode

Privacy Policy

Assesslytic Privacy Policy

Current version: 2026-08-22

Effective date: August 22, 2026

This policy is a notice about how Assesslytic handles personal information. It is separate from the Terms and Conditions, which is the agreement that governs your use of the service. If you take an assessment through an employer, school, or testing organization, that organization's own privacy notice also applies.

1. About This Privacy Policy

This Privacy Policy explains what personal information Assesslytic collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to the Assesslytic websites, applications, APIs, business workspaces, scheduled assessments, study and training features, certificates, proctored sessions, and AI-assisted features.

We collect personal information when you create or manage an account, use the website or service, take or administer an assessment, upload content, make a payment, or contact us. We also collect technical, analytics, and diagnostic data automatically when you interact with the service, as described below.

This policy is separate from the Assesslytic Terms and Conditions. The Terms are the agreement that governs your use of the service. This policy is a notice about how we handle personal information, and reading it does not waive any right you have under data protection law.

If you access Assesslytic through an employer, school, academy, testing organization, or other sponsoring organization, that organization's own privacy notice also applies to the way it uses your information.

2. Who Controls Your Information

For individual accounts, our public website, our marketing activity, billing, and platform security, Assesslytic decides why and how personal information is processed. In data protection terms, Assesslytic is the controller for that processing.

For business-managed workspaces, the sponsoring organization decides which assessments to run, which candidates to invite, whether proctoring is enabled, what results to review, and how long to keep workspace records. That organization is the controller for that processing and Assesslytic acts as its processor, handling the information on its documented instructions.

If you are a candidate or team member in a business workspace and you want your information corrected or deleted, contact the organization that invited you first. You may also contact Assesslytic and we will route the request to that organization and support it as required by law.

3. Information You Provide

Account information: your first name, last name, email address, and password. Passwords are stored only as a salted one-way hash, never in readable form. We also record whether your email has been verified and which version of the Terms and Conditions you accepted.

Security information: if you enable two-factor authentication, we store an encrypted authenticator secret and the date it was activated. We never store your one-time codes.

Workspace information: business name and workspace settings, team member roles and permissions, invitations you send or accept, and branding you upload.

Assessment and learning content: assessments, questions, prompts, passages, rubrics, schedules, study rooms, training assignments, certificate templates, and any notes, documents, or study materials you upload for assessment generation or private practice.

Billing information: your plan, subscription status, and transaction records. Card numbers and bank details are entered directly with our payment processors and are never stored on Assesslytic servers.

Support information: the content of messages, attachments, and contact details you send when you email support or use a contact form.

4. Information Created When You Use the Service

Session and result data: assessment sessions, start and end times, individual answer events, scores, section and gap analysis results, progress records, issued certificates, and post-assessment survey responses.

Chatbot and generation logs: the prompts and workflow steps produced when you use AI-assisted assessment generation, so that we can deliver the result, diagnose failures, and investigate abuse.

Technical and security data: IP address, browser and device characteristics, approximate location derived from IP, pages and features used, referring pages, sign-in attempts, failed login counts and lockout records, session cookies, and error diagnostics captured when something breaks.

Product analytics data: PostHog receives page views, navigation and interaction events, browser and device data, session or analytics identifiers, feature usage, and product events such as assessment or study workflow identifiers, completion events, question counts, durations, scores, ratings, and subscription activation. When you are signed in, we may associate this analytics data with your name, email address, account type, and plan. PostHog may also receive frontend exception details when an error occurs.

Monitoring and diagnostic data: Sentry receives backend error and exception details, service logs, request diagnostics, traces, performance profiles, and service, environment, and release information so we can investigate failures and monitor reliability. This data may include technical identifiers or other personal information present in the relevant request or error context.

Communication data: delivery and open status for transactional emails such as verification, password reset, invitations, and assessment notifications.

5. Assessment Submissions, Recordings, and Uploads

Where an assessment includes speaking or writing tasks, Assesslytic collects your written response or an audio recording of your spoken response, the duration of that recording, a machine-generated transcript of the audio, rubric scores, AI-generated feedback, any final score, and any score override and reviewer note added by a human reviewer.

Audio recordings, uploaded notes, documents, images, and other files are stored in our object storage infrastructure under access controls, and are made available to you and, for a business-managed assessment, to the sponsoring organization.

Speaking assessments require microphone access, and audio is captured only for the duration of a task you actively start.

Documents you upload as notes, currently PDF, DOCX, PPTX, Markdown, and plain text within your plan's size limit, are processed in two ways. We store the original file in object storage, and we extract the text from it and store that text so it can be reused without re-reading the file. Where you ask for study material or an assessment to be generated from a note, the extracted text is sent to our AI provider as context for that request.

Notes you upload are private to your own account. They are used to generate your own study and assessment material, they are not shown to other users, they are not visible to a business workspace administrator, and they are not used to build assessments for anyone else. Deleting a note removes both the stored file and the extracted text.

You are responsible for what you upload. Only upload documents you have the right to use, and do not upload documents containing other people's personal information unless you have a lawful basis to do so. Please do not upload special categories of data such as health records, biometric data, government identity numbers, or financial account details, because Assesslytic notes are not designed to hold that kind of information.

6. Proctoring, Monitoring, and Integrity Signals

Proctoring is not enabled for every assessment. Where a sponsoring organization enables it, a proctored session may capture webcam video, microphone audio, recorded session chunks uploaded to secure storage, session heartbeats, browser and device telemetry, and integrity events such as face presence, multiple-face detection, motion, tab switching, and window focus loss. Each event is stored with a timestamp and an integrity hash.

This information is used only to support secure assessment delivery, to let an authorized reviewer verify what happened during a session, and to produce integrity signals for review. It is not used for advertising, and it is not used to build biometric identification profiles beyond the integrity checks described here.

Your browser asks for camera and microphone permission before any capture begins, and you can refuse. Refusing a required proctoring step may mean you cannot take a proctored assessment, and the sponsoring organization decides what happens in that case.

Automated integrity flags are decision-support information only. They are not a finding of misconduct and should be reviewed by a person with context before any action is taken.

7. Information From Third Parties

If you sign in with Google, we receive your name, email address, and Google account identifier from Google so we can create or match your account. We do not receive your Google password.

If an organization invites you to a workspace or a scheduled assessment, we receive your name and email address from that organization.

Our payment processors send us confirmation of payment status, subscription events, and limited card metadata such as the last four digits and card brand, so we can service your subscription and support billing questions.

8. How We Use Information

To create and secure your account, verify your email, authenticate sign-in, support two-factor authentication, and protect against credential stuffing and account takeover.

To deliver the service: generate and host assessments, run practice and scheduled tests, grade responses, produce results, gap analysis, study plans, training assignments, and certificates, and make them available to you and to an authorized sponsoring organization.

To review free-response submissions, transcribe audio, synthesize audio for listening or speaking tasks, and generate assessment content using AI-assisted features.

To support secure assessment delivery and integrity review where proctoring is enabled.

To process payments, manage subscriptions and renewals, prevent payment fraud, and meet tax and accounting obligations.

To send transactional messages such as verification codes, password resets, invitations, schedule reminders, and service notices, and to send marketing messages only where you have opted in.

To provide customer support, investigate reports, resolve disputes, and keep records of what we did.

To understand how people use the website and product, measure feature adoption and assessment or study workflow completion, analyze product performance, and improve usability using PostHog.

To detect and diagnose errors, investigate failures, monitor service health and performance, and improve reliability using Sentry.

To detect, investigate, and prevent fraud, abuse, security incidents, assessment misconduct, and violations of our Terms, and to comply with law and respond to lawful requests.

9. Legal Bases for Processing

Where data protection law requires a legal basis, we rely on the following. Performance of a contract, for creating your account, delivering assessments and results, and billing you for a paid plan. Legitimate interests, for security, fraud and integrity protection, service reliability, product improvement, support, and defending legal claims, balanced against your rights and freedoms.

Consent, for optional analytics and advertising storage, for marketing messages, and for camera and microphone access. You can withdraw consent at any time, and withdrawing it does not affect processing that already took place.

Legal obligation, for tax, accounting, and record-keeping duties and for responding to valid legal requests. In a business-managed workspace, the sponsoring organization is responsible for establishing the legal basis and any required notice or consent for the assessments, monitoring, and decisions it runs.

10. AI-Assisted Features and Automated Processing

Assesslytic uses third-party AI services to generate practice and assessment content, review free-response answers, transcribe spoken responses into text, synthesize audio, summarize performance, and surface integrity signals. To do this, the relevant prompt, submission text, audio, or uploaded material is sent to that provider on our behalf and processed under our agreement with them.

AI outputs, including scores, transcripts, feedback, and integrity signals, may be incomplete, inaccurate, or unsuitable for a specific purpose. Assesslytic does not make employment, admission, certification, grading, or disciplinary decisions about you. Where a sponsoring organization uses Assesslytic outputs in such a decision, that organization is responsible for human review, validation, accommodations, and any disclosure the law requires.

Where the law gives you the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, you may ask for human review of an AI-generated score. Contact the sponsoring organization for a business-managed assessment, or contact us using the details below.

11. Cookies and Similar Storage

Assesslytic uses a small number of essential cookies and similar browser storage. The aptitest_session cookie is an encrypted, HTTP-only cookie that maintains your authenticated session and refreshes access securely. The aptitest_session_present cookie is a lightweight, browser-readable cookie used to detect whether a session exists. Essential storage cannot be turned off, because the platform cannot operate securely without it.

We also use local and session storage for your consent choices, theme preference, terms acceptance, and in-product continuity such as assessment progress and scheduling feedback.

When you allow the optional analytics category, PostHog may use cookies and local storage to maintain an analytics identifier and session continuity. It collects the product analytics and frontend exception data described in Section 4 so we can measure use of the service and improve it. PostHog does not initialize before you provide this consent, and turning the analytics category off stops future PostHog capture and disables its analytics persistence.

Optional analytics and advertising measurement uses the Google tag with consent mode. Google analytics storage, advertising storage, ad user data, and ad personalization stay denied until you allow the optional analytics category. You can accept, reject, or change these choices at any time using the cookie settings control on this page.

12. When We Share Information

With your sponsoring organization: for a business-managed assessment, the organization that invited you may access your assessment records, submissions, results, reports, invitation and support history, and any proctoring artifacts and integrity events tied to its workspace.

With service providers: we share information with the vendors listed below, only to the extent needed to run the service, and under contracts that require them to protect it and to use it only for the purposes we specify.

With analytics and monitoring providers: we send the data described in Section 4 to PostHog for product analytics and frontend exception tracking, and to Sentry for backend error monitoring, logs, traces, request diagnostics, and performance monitoring. These providers process the data on our behalf to help us understand use of the service, identify problems, and improve reliability.

For legal and safety reasons: where we reasonably believe disclosure is required by law or valid legal process, or is necessary to investigate fraud, security incidents, or assessment misconduct, to enforce our Terms, or to protect the rights, property, or safety of any person.

In a corporate transaction: if Assesslytic is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a policy that is at least as protective.

We do not sell your personal information for money. Where you have allowed optional analytics, limited identifiers may be shared with Google for advertising measurement, which some laws treat as sharing for targeted advertising. You can switch this off at any time through cookie settings.

13. Service Providers and International Transfers

We currently rely on the following categories of provider: OpenAI for content generation, free-response review, audio transcription, and speech synthesis; Stripe and Paystack for payment processing; our cloud hosting and object storage infrastructure for databases, files, audio, uploads, and proctoring artifacts; our email delivery provider for transactional and support email; PostHog for product analytics, signed-in user and session identification, feature usage measurement, and frontend exception tracking; Sentry for backend error monitoring, service logs, request diagnostics, traces, and performance profiling; Google for optional sign-in and, with your consent, advertising measurement; and our proctoring platform provider for proctored session capture, telemetry ingestion, and integrity analysis.

These providers may store or process information in countries other than the one you live in, including outside the European Economic Area, the United Kingdom, or Nigeria. Where we transfer personal information across borders, we rely on lawful transfer mechanisms such as standard contractual clauses, adequacy decisions, or the transfer conditions permitted by applicable local law, together with contractual and technical safeguards.

We review this list as our infrastructure changes and update this policy when a provider is added or removed.

14. How Long We Keep Information

Account information is kept while your account is active. When an account is closed, we delete or anonymize it within a reasonable period, except where we must keep specific records for legal, tax, audit, security, or dispute-resolution reasons.

Assessment records, submissions, recordings, transcripts, results, and proctoring artifacts in a business-managed workspace are kept for as long as the sponsoring organization requires and instructs, subject to any retention setting it configures and to applicable law.

Notes and documents you upload are kept until you delete them or close your account. There is no automatic expiry, so you stay in control of how long your own material is stored.

Short-lived security records expire automatically. Email verification codes, password reset tokens, invitation tokens, and scheduled assessment access tokens each expire after the period set in our configuration. Login attempt and lockout counters reset after the lockout window ends.

Security logs, error diagnostics, and billing records are kept for the period needed to investigate incidents, meet financial and legal obligations, and defend legal claims. We do not keep personal information for longer than is necessary for the purposes described in this policy.

15. How We Protect Information

We use administrative, technical, and organizational safeguards appropriate to the risk. These include encrypted connections, HTTP-only encrypted session cookies, one-way password hashing, encrypted storage of two-factor authentication secrets, optional two-factor authentication, failed login lockouts, role and permission checks on workspace data, access controls on stored files, integrity hashing of proctoring events, and monitoring for errors and suspicious activity.

No service can be completely secure. Keep your password confidential, enable two-factor authentication where available, and tell us promptly at the address below if you believe your account has been accessed without your permission.

16. Your Privacy Rights and How to Use Them

Depending on where you live, you may have the right to access the personal information we hold about you, to receive a copy in a portable format, to correct information that is inaccurate, to delete information, to restrict or object to certain processing, to withdraw consent you previously gave, to ask for human review of a significant automated decision, and to be free from discrimination for exercising these rights.

You can update your name, password, two-factor settings, and cookie choices directly in the product, and you can delete your account yourself from your profile page. Deleting your account removes your name and email address from our records, deletes the notes and files you uploaded, and signs you out. For anything else, email us at the address below from the email address on your account. We may ask for information needed to verify your identity before we act, and we will respond within the period required by applicable law.

If your information sits inside a business-managed workspace, we will forward your request to the sponsoring organization, because that organization decides what happens to workspace records. We will assist it as its processor.

If you believe we have not resolved your concern, you can complain to your local data protection authority. In Nigeria this is the Nigeria Data Protection Commission. In the European Economic Area or the United Kingdom, it is the supervisory authority for your country of residence.

17. Marketing and Communication Choices

We send transactional messages such as verification codes, password resets, invitations, schedule notices, receipts, and security alerts because they are needed to operate your account. These cannot be turned off while your account is active.

Marketing email is opt-in only. At signup you can tick a separate, optional box to receive product updates and tips, and we record the date you did so. Leaving it unticked, which is the default, means we do not add you to marketing email. Assesslytic is not sending marketing email yet, and when we begin, every marketing message will carry an unsubscribe link and opting out will not affect transactional messages.

18. Children and Student Users

Assesslytic is not directed to children who are below the minimum age of digital consent in their country, and we do not knowingly collect their personal information without the involvement of a parent, guardian, school, or other authorized organization.

Where a school, academy, or testing organization invites students, that organization is responsible for obtaining any parental or guardian consent required for account creation, assessment delivery, recording, and proctoring, and for issuing any notice its own law requires.

If you believe a child has provided personal information to us without the required authorization, contact us and we will investigate and delete it where appropriate.

19. Regional Disclosures

Nigeria: we handle personal data in line with the Nigeria Data Protection Act. You may exercise your rights using the contact details below and may lodge a complaint with the Nigeria Data Protection Commission.

European Economic Area and United Kingdom: the legal bases in Section 9 apply to you, and you have the rights described in Section 16 under the GDPR and UK GDPR, including the right to complain to your supervisory authority. Cross-border transfers are covered in Section 13.

California: you may request to know, delete, or correct your personal information, and you may opt out of sharing for cross-context behavioral advertising by rejecting optional analytics in cookie settings. We do not sell personal information for money and we will not discriminate against you for exercising your rights.

20. Changes to This Privacy Policy

We may update this policy to reflect changes to the product, our providers, or the law. The version and effective date at the top of this page always show the current version.

If a change materially affects how we use your personal information, we will give notice in the product, by email, or by another reasonable method before the change takes effect where the law requires it.

21. How to Contact Us

You can reach us about anything in this policy, including access, correction, deletion, and portability requests, at support@assesslytic.com. Please tell us which account or workspace your request relates to so we can verify and route it correctly.

Privacy questions: support@assesslytic.com