This policy explains how Answerflix Ltd, trading as Career1 ("Career1", "we", "us"), handles personal data on career1.ai and in the Career1 product. It covers four groups of people: job seekers who create a Career1 profile, applicants who apply to a company's job through Career1, company users who use Career1 on behalf of an employer, and visitors to our website. It describes how Career1 works today. If anything here does not match what you see, tell us at hello@career1.ai and we will correct whichever of the two is wrong.
1. Who we are
Career1 is a trading name of Answerflix Ltd, a company registered in England and Wales under company number 15968747, with its registered office at 44 Church Street, Stoke-on-Trent, ST4 1BL, United Kingdom. You can reach us about anything in this policy at hello@career1.ai or by post at the registered office.
2. When we decide, and when a company does
Data protection law calls whoever decides why and how personal data is used the controller, and a business that handles it on the controller's instructions a processor. Which one Career1 is depends on who you are.
- Job seekers, visitors, people who write to us, and company users: Career1 is the controller.
- Applicants: the company whose job you applied to is the controller of your application, your resume, your answers to its questions, your interview and its report. Career1 processes them on the company's behalf and on its instructions, under our Data Processing Addendum. The company's own privacy notice applies too. Requests about an application are best sent to the company; if you send them to us, we pass them on and help it answer.
- The Career1 account an applicant gets: when you apply, Career1 also creates a Career1 account in your name, so you can take the interview and follow the application. That account (your name, email address and sign-in details) is ours, and for it Career1 is the controller.
- Companies that find you in the talent pool: a company that views or receives a job seeker's profile becomes a controller of what it receives, responsible in its own right for how it uses it.
3. What we collect
Job seekers
- Your account: name, email address and password, which we store only as an irreversible hash. If you sign in with Google or GitHub, the identifier and profile details that service sends us, such as your name, email address and picture.
- Your resume: the file you upload, the text we read from it, and the structured profile our AI builds from it: headline, skills, technologies, industries, years of experience and a summary. If your resume contains a LinkedIn address, we keep that too.
- What you add: your availability and the rate you expect. If you connect GitHub, your GitHub username, the location on your GitHub profile, and a summary of your public repositories, which companies can see. We do not keep your GitHub access token.
- Your interviews: for the vetting interview, the recording (video with audio), the transcript and the report with your score. For practice interviews, the transcript and the written feedback. Practice is never recorded on video.
- Search data: so that companies can search the pool, we index your name, headline, location, skills and the start of your resume, including a numerical representation of that text (an "embedding") created by OpenAI.
- Status: when you were verified, your verification score, and whether your profile is visible to companies.
Applicants
- The application form: name and email address, and, if the company's form asks for them, phone number, city and the answers to the company's own screening questions.
- Your resume: the file and the text we read from it.
- The interview: the recording (video with audio), the transcript and the AI report described in section 5.
- Progress: the stage of your application, its history, and your interview invitation, whose link works for seven days.
- Scheduling: if the company books a call with you through its Google Calendar, your email address goes on the invitation.
- A Career1 account: in your name and email address. It has no password until you choose one. If your email address was new to Career1, the browser you applied from is signed in to it straight away. An application never adds you to the talent pool.
Company users
- Your account: name, work email address, password (as a hash), your role in the workspace, and invitations you send or receive.
- Signing up: your name, company name, email address, password hash and IP address, held for up to 24 hours while we wait for you to confirm the address.
- Your workspace: the company profile, logo, careers page and job posts, and any voice note you record to draft a job description, which OpenAI transcribes.
- Billing: your plan, the subscription's status and the references Stripe gives us. Card details go to Stripe and never reach Career1.
- Google Calendar: if you connect it, the access tokens (stored encrypted) and the events you create through Career1.
- Activity: sign-ins, with the IP address and browser, and actions such as moving an application to another stage, downloading a resume or watching a recording, which we keep as an audit trail.
Visitors
- Visit records: our own server records each page request: the address, the time, the response, your browser's user-agent string (and the device, browser and operating system read from it), the referring site, any campaign tags in the link, your IP address, the approximate country and city that IP address points to, and a daily visitor key (a salted one-way hash of the IP address, user-agent and date). The private token in a link such as an interview or password-reset link is replaced by a placeholder before the address is stored. This uses no cookies. The Cookie Policy explains it in full.
- Web server logs: like any web server, ours keeps an access log of each request: the IP address, the time, the full address requested and the browser.
- Analytics, only if you accept them: Google Analytics, and a replay of how you used our public pages. Both are described in the Cookie Policy.
The help assistant and messages to us
- The help assistant asks for your email address before it starts. We keep that address, your name if you give it, the conversation, whether you are asking as a company or a job seeker, and your IP address and browser. If the conversation is passed to a person, we also keep a short summary and a category. The messages, without your email address, are sent to OpenAI to write the replies.
- Email you send us, and our replies.
- Older enquiries sent through a contact form this site no longer has: name, work email, company, team size and message.
The free tools
Text or a resume you give one of the free tools is sent to OpenAI to produce the result, and Career1 does not save it. The page request itself is recorded like any other.
Sensitive information
We do not ask about health, ethnic origin, religion or beliefs, sexual orientation, political opinions, trade union membership or criminal records, and none of them is part of what an interview report scores. If you mention something like that in an interview, it becomes part of the transcript and the recording; tell us, or the company you applied to, if you want it removed. We do not use recordings to recognise anyone by face or voice, and nothing in Career1 analyses faces, expressions, tone of voice or accent.
4. How we use it, and our legal bases
Each use of personal data needs a legal basis under the UK GDPR and the EU GDPR. These are ours.
| What we do | Whose data | Legal basis |
|---|---|---|
| Run your profile, practice interviews, the vetting interview, its report and your dashboard | Job seekers | Contract: it is the service you signed up for (Article 6(1)(b)) |
| Show your verified profile to companies searching the talent pool | Job seekers | Contract: being found is what the pool is for. You can hide your profile at any time. |
| Receive an application, run the interview and write the report for the hiring company | Applicants | The hiring company's own legal basis; we act as its processor (see the DPA) |
| Create a Career1 account for someone who applies, so they can take the interview and follow the application | Applicants | Legitimate interests: giving you a way back to your interview and application without a password (Article 6(1)(f)) |
| Run company workspaces, seats and subscriptions | Company users | Contract |
| Keep billing and tax records | Company users | Legal obligation (Article 6(1)(c)) |
| Send sign-in, confirmation, invitation and interview emails | Everyone with an account; applicants | Contract; for applicants, the hiring company's instructions |
| Keep Career1 secure: sign-in records, rate limits, blocking abusive traffic, the audit trail | Everyone | Legitimate interests: protecting accounts, candidates' data and the service |
| Count visits on our own server, and tell people from automated traffic | Visitors | Legitimate interests: understanding how the site is used and keeping abuse out |
| Google Analytics and session replay on our public pages | Visitors who accept analytics | Consent (Article 6(1)(a)), which you can withdraw at any time in cookie settings |
| Answer the help assistant and your emails | Anyone who writes to us | Legitimate interests: answering you; contract, where it is about your account |
| Produce a free tool's result | Anyone using the tools | Legitimate interests: giving you the result you asked for |
| Deal with legal claims and lawful requests from authorities | Anyone concerned | Legal obligation, or legitimate interests in establishing and defending legal claims |
Where we rely on legitimate interests, you can object, and we will stop unless we have a compelling reason that outweighs yours. We do not send marketing email, and we do not use personal data for advertising.
5. AI scoring and automated decisions
Career1 uses AI to interview people and to assess what they said. This section says what is scored, how the scores are used, who sees them, and how to have a person look again.
What is scored
- An interview for a company's job: a language model reads the transcript, your resume and the job, and writes a report for the company: a match percentage for that job, an overall score out of 100, a recommendation (strong hire, hire, maybe or no hire), scores for technical depth, communication, problem solving, experience fit and culture fit, a list of the skills you claimed set against what the conversation showed, with quotes, and strengths, risks and missing skills.
- The vetting interview: a score out of 100, a written summary, strengths, areas to grow, and a skill-by-skill record of what the conversation demonstrated.
- Practice interviews: written feedback only. There is no score.
- Talent pool search: an AI model reads a company's search and ranks profiles by how well they match it.
Assessments are made from the words of the conversation and the resume. Nothing scores your face, expressions, voice, accent, background or camera.
How scores are used
- A company sees its applicants for a job ordered by match percentage. Career1 moves an application on by itself only to record progress: to the interview stage when the invitation goes out, and to "review" when the interview is finished. Nothing rejects anyone automatically. Every decision after that, including a rejection, is made by a person at the company, and the hiring company makes the decision.
- Finishing the vetting interview verifies your profile and adds it to the talent pool whatever the score. There is no pass mark. Searches rank profiles by relevance, with the score deciding ties, and a company can choose to see only profiles above a score it sets.
Career1 does not itself make decisions about people that have legal or similarly significant effects based solely on automated processing, within the meaning of Article 22 of the UK and EU GDPR. The scores do shape which candidates a hiring team reads first, and a company that filters by score may not see a profile at all, which is why the rights below exist.
Who can see what
- Job seekers see their whole vetting report, the transcript and the recording on their dashboard, and their practice feedback.
- Applicants see the stage their application is at, not the score or the report. You can ask the company for a copy of what it holds about you, or ask us to pass the request on.
- The hiring company's team sees its applicants' reports, transcripts, recordings, resumes and answers.
- Any company with a Career1 workspace, including one on the free plan, can see a pool profile's name, headline, location, skills, summary, expected rate, GitHub summary and verification score. A company on a paid plan or trial can also see the contact details, resume, full report, transcript and recording. None of this applies to a profile you have hidden.
- Nobody at a company ever sees a practice interview, or that one happened.
Having a person look again
You can ask for a person to review an assessment, give your side of it, and contest it. For an application to a company, the company decides, so ask the company; you can also write to us and we will pass the request on and help. For your vetting report, write to us: a person at Career1 will compare the report with the transcript and the recording, and correct the report where it misstates what you said.
The laws that cover AI in hiring
Career1 is an automated employment decision tool as New York City Local Law 144 defines one: it produces scores and recommendations that are used in hiring. Under the EU AI Act, AI systems used to recruit or select people, including to filter applications and evaluate candidates, are high-risk (Annex III), and Career1 is one of them. Career1 has not commissioned an independent bias audit, and we do not claim to have completed the conformity assessment the AI Act will require of high-risk systems as its obligations take effect. An employer that uses Career1 for jobs in New York City must have a bias audit and tell candidates beforehand; our Terms set out what falls to employers.
6. Interview audio, video and transcripts
- Live audio: during an interview, the sound from your microphone streams from your browser directly to OpenAI, which runs the voice interviewer, and the interviewer's voice streams back the same way. To set up that connection, your browser contacts a Google server, which sees your IP address.
- The recording: in an interview for a company's job and in the vetting interview, your browser also records video from your camera together with the audio of both sides, and uploads it in pieces to Career1, which stores it on Amazon S3 in the EU. Video is never sent to OpenAI.
- The transcript: OpenAI transcribes the conversation, and Career1 stores the transcript and uses it to write the report.
- Who sees them: for a company's job, the company's team; for the vetting interview, you, and companies as described in section 5.
- Practice: uses your microphone only, and no video is recorded. The transcript and feedback are stored so you can read them, OpenAI processes the conversation to run it and write the feedback, and Career1 staff with administrator access can see them. They are never shown to any company.
7. Cookies and similar technologies
We use a few necessary cookies and browser storage entries: to keep you signed in, protect sign-in with Google or GitHub, remember your cookie choice, keep your help-assistant conversation, and let an interview recording resume after a dropped connection. Google Analytics and session replay run only if you choose "Accept analytics", and never in the signed-in product, on sign-in pages or in interview rooms. Our own visit counting uses no cookies. The full list, and how to change your choice, is in our Cookie Policy.
8. Who we share it with
We share personal data only with:
- Hiring companies, as section 5 describes.
- Our service providers, listed below, each of which receives only what it needs to provide its service to us. The same list, with any changes, is kept at Sub-processors.
- Professional advisers, and courts, regulators or law enforcement where the law requires it.
- A buyer or successor, if the business is sold or reorganised, who would be bound by this policy.
We never sell personal data.
| Provider | What for | Data it receives | Where | Transfer safeguard |
|---|---|---|---|---|
| Contabo | Hosts the application servers and the database. Always in use. | All data held by Career1. | France (EU) | Within the EU. |
| Amazon Web Services (Amazon S3) | Stores resumes, interview recordings, company logos and database backups. Always in use. | Resume files, interview video with audio, backups of the database. | EU (Stockholm, eu-north-1) | Within the EU. |
| OpenAI | Runs the voice interviewer and transcription, writes interview reports and feedback, reads resumes into profiles, powers talent search, the free tools and the help assistant. Always in use. | Live interview audio, candidate name and resume text, job details, transcripts, help-chat messages, text pasted into the free tools. | United States | EU Standard Contractual Clauses and the UK Addendum. OpenAI does not train its models on data sent through its API. |
| Resend | Sends account, sign-in and interview emails. Always in use. | Email address, name and the content of the email. | United States | EU Standard Contractual Clauses and the UK Addendum. |
| Stripe | Takes payment for company subscriptions. Only when a company subscribes to a paid plan. | Billing email and company reference. Card details go to Stripe directly and never reach Career1. | Ireland and United States | EU Standard Contractual Clauses and the UK Addendum. |
| Google sign-in, Google Calendar scheduling, Google Analytics, and the connection helper (STUN) that lets the interview's voice link reach you. Only when you sign in with Google, a company connects its calendar, you accept analytics cookies, or you join a voice interview. | Sign-in: name and email. Calendar: event details and attendee emails. Analytics: pages visited, device and approximate location. STUN: your IP address. | United States | EU–US Data Privacy Framework, EU Standard Contractual Clauses and the UK Addendum. | |
| GitHub | Optional GitHub sign-in and the public-repository summary shown on a talent profile. Only when a job seeker connects GitHub. | GitHub username, name, email and public profile and repository details. | United States | EU Standard Contractual Clauses and the UK Addendum. |
| ip-api.com | Looks up the approximate country and city of website visitors for our own visit statistics. Always in use. | IP address. | Not published by the provider | The provider states it keeps the queried address in memory for up to one minute. |
9. International transfers
Career1's servers and database are in France, and stored files and backups are in Sweden, both in the EU. Career1 itself is in the UK, which the European Commission recognises as giving adequate protection (its adequacy decision was renewed in December 2025 and runs to December 2031). OpenAI, Resend, Stripe, Google and GitHub are in the United States. For those transfers the safeguard is the European Commission's Standard Contractual Clauses, with the UK Addendum for data from the UK, and, for a provider certified under it, the EU–US Data Privacy Framework and its UK extension. The table in section 8 gives each provider's safeguard.
One provider, ip-api.com, which turns visitors' IP addresses into an approximate location, does not publish who operates it or where. It receives IP addresses only. We have no agreement with it beyond its published terms, which say it keeps each address it is asked about in memory for up to one minute.
10. How long we keep it
This is how long we keep data today. Where there is no automatic deletion yet, we say so.
| Data | How long |
|---|---|
| Accounts and profiles | While the account is open. There is no delete button yet: email us and we delete it. |
| Resumes, interview recordings, transcripts and reports | While the account or the hiring company's workspace that holds them exists, or until the candidate asks us to delete them. Files stored on Amazon S3 are removed in a separate step, by hand, because the application itself has no permission to delete stored files. |
| Session replays of our public pages | 30 days, then deleted automatically. |
| Records of visits to the website, including the IP address | No automatic deletion yet. |
| Help-assistant conversations and contact enquiries | No automatic deletion yet. Ask us and we delete them. |
| Security and audit records | Kept to protect accounts and investigate misuse. No automatic deletion yet. |
| Database backups | A full copy of the database every night, on Amazon S3. Old copies are not yet deleted on a schedule, so something removed from the live service can remain in a backup. |
11. Security
All traffic to Career1 is encrypted in transit. Passwords are stored only as Argon2 hashes, sign-in sessions are held on our server and can be revoked, each company's data is kept apart from every other company's at three separate levels in the code, and the admin area needs an approved address and a one-time code sent by email. Some protections are not in place yet, and we list them on our Security page rather than let you assume them.
12. Your rights
In the UK and the EU
You have the right to:
- access the personal data we hold about you and get a copy;
- have it corrected if it is wrong;
- have it deleted;
- restrict how we use it while a question about it is settled;
- object to a use based on legitimate interests;
- receive data you gave us in a portable, machine-readable form;
- withdraw consent at any time, for example to analytics cookies;
- not be subject to a decision based solely on automated processing that significantly affects you, and to have a person review an assessment (see section 5);
- complain to a data protection authority (see section 13).
How to use them
Email hello@career1.ai, from the address on your account if you have one, so we know the request is yours. There is no delete or download button in the product yet, so we handle every request by hand. We reply within one month, which the law lets us extend by two further months for a complex request, and we tell you if we do. There is no charge. Hiding your profile from companies needs no request: it is one switch on your dashboard and takes effect at once.
If you applied to a company's job, the company decides what happens to that application. Send the request to the company, or to us and we will pass it on and help it answer.
In the United States
If a US state privacy law gives you rights over your data, such as to know what we hold, to delete or correct it, or to opt out of its sale or use for targeted advertising, email us and we will honour them. You can ask through an authorised agent, and you will not be treated differently for asking. We do not sell personal information, and we do not share it for targeted advertising.
13. Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk), or the data protection authority where you live or work.
14. Children
Career1 is not for anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has used Career1, tell us and we will delete their data.
15. Changes to this policy
We update this policy when what we do changes, such as when we add a provider or start keeping something new, and the date at the top of the page always shows the current version. When a change materially affects how we use your data, we will also tell account holders by email or in the product, and where a change needs your consent, we will ask for it.
16. Contact
Email hello@career1.ai, or write to Answerflix Ltd, 44 Church Street, Stoke-on-Trent, ST4 1BL, United Kingdom. The help page reaches us too.