Privacy
Policy.
Last updated: March 11, 2026
At Skillity®, privacy isn’t a checkbox, it’s a promise. We’re building a smarter, fairer interview practice platform where users stay in control and data is handled with the respect it deserves. This page explains how we treat your personal information and what rights you have — in plain English.
1. Who We Are
Skillity® is a trading name of Skillity Ltd (a Begility Ltd company), registered in England and Wales (Company No. 16402919).
Registered office:
20 Wenlock Road
London
England N1 7GU
We operate in full compliance with the UK GDPR, the EU GDPR, and other applicable privacy laws. Depending on your relationship with us, Skillity acts in two distinct capacities:
- As a Data Controller: When you interact with us directly – such as creating a personal account, purchasing a subscription for individual practice, or using a website – Skillity is the data controller responsible for your personal information.
- As a Data Processor: When you use our platform through an enterprise or institution, Skillity acts as a data processor. In these cases, the enterprise or institution is the data controller, and we process your data according to their specific instructions.
2. Privacy by design
Here’s what we stand for:
- Normalized & Hashed: Before storage, email addresses are "normalized" (e.g., removing dots or aliases in Gmail) and then immediately converted into a cryptographic hash. We never store your plain-text email after account deletion for fraud monitoring purposes.
- Cooling-Off Period: To keep our free offers fair, we implement a 6-month "cooling-off" period. If you delete your account, you cannot re-register with the same email (or a variation of it) for 6 months.
- No public profiles: Your activity on Skillity® is never publicly visible. We do not index your profile or practice sessions on search engines.
- Pseudonymous by default: Every practice session is linked to a unique Interview ID rather than your name or email in our primary processing database. This keeps your data secure while allowing our AI to generate your report.
- Video Retention: To protect your privacy, interview recordings are automatically deleted from our servers 14 days after upload, unless you choose to delete them sooner.
- Feedback, SWA Records, and Test Results: Deleted or fully anonymised after 18 months (or sooner, if you request deletion or withdraw consent).
- Self-Serve Deletion: You have total control. You can delete interview data or your entire account data directly through your dashboard settings.
Your privacy is our baseline. Whether you are practicing independently or through an institution, your recordings and feedback remain private to you. You decide if and when to share your results with a mentor or recruiter; until then, you remain invisible.
3. What Data We Collect
We only collect the information required to deliver your personalized interview feedback and maintain a secure practice environment:
- Hashed Identifiers: We store SHA-256 HMAC hashes of your normalized email, domain, and device characteristics (fingerprinting).
- Technical Signals: We monitor IP addresses and browser types to detect suspicious patterns and rate-limit rapid account creation.
- Practice Sessions: Audio and video recordings of your interviews, alongside the text transcripts generated for our AI analysis.
- SWA FitModel® Inputs: Your verbal and non-verbal responses to targeted Skill, Will, and Attitude prompts, used to evaluate your performance baseline.
- Analytical Feedback: The AI-generated scores, tailored summaries, and industry benchmarking data produced from your practice sessions.
- Account Credentials: Your basic contact info (name/email) for individual accounts, or institutional identifiers if you are accessing Skillity via a university or employer.
- Usage & Technical Data: Essential technical details like your IP address, browser type, and session timestamps to ensure platform security and stability.
- Diversity and Equality Monitoring (Optional): We may ask for information regarding your race, gender, and disability status. This “Special Category Data” is used strictly to monitor for and remove bias within our AI models to ensure fair, equitable outcomes for all users. Diversity data is aggregated and pseudonymized. It is never attached to your personal profile, never used in feedback reports, and is never visible to employers or institutions. Participation is entirely voluntary and does not affect the practice experience.
- Payments & Billing: Payments for subscriptions and credits are processed securely by Stripe. We do not store your full credit card information. If you request account erasure, we will cancel your active subscription and unlink your payment profile, retaining only the minimum billing records required by tax law. We deliberately do not collect: date of birth, nationality, postal address, CVs, or social profiles. No stalking, no irrelevant details.
A note on AI Processing: Our system analyzes performance patterns to generate your SWA scores. We do not use your recordings to create, store, or track biometric templates for the purpose of uniquely identifying you.
4. Why We Collect It
We process your information to provide high-quality interview coaching and to ensure our platform remains fair for every user. Specifically, we use your data to:
- Fraud & Abuse Prevention: We use aggregated signals and hashed data to detect users creating multiple accounts to bypass credit limits.
- Domain Reputation: We score and may block email domains associated with disposable or temporary "burner" email services.
- Generate Feedback: Deliver actionable AI analysis and scoring across Skill, Will, and Attitude (SWA FitModel®).
- Improve User Experience: Help replicate a realistic one-way interview experience.
- Track Performance: Allow you to monitor your progress over time and compare results against industry-specific benchmarks.
- Support Institutions: Enable partner universities and organizations to provide structured interview development and support to their members.
- Ensure Fairness: Use optional diversity data to monitor our AI models for algorithmic bias. We process this data only with your explicit consent to ensure equitable outcomes for all users.
- Improve Skillity®: Refine the accuracy, transparency, and technical performance of our platform using aggregated and pseudonymized data.
- Industry Benchmarking: We use your pseudonymized and aggregated performance scores to calculate broader industry averages. This allows us to provide you and other users with accurate “percentile” feedback, showing where your scores rank compared to the market.
We never sell your data. We do not allow third-party tracking or advertising. Aggregated, pseudonymized data may be used to improve our platform based on legitimate interest, but is never used to identify you.
Automated AI Analysis
During practice sessions, we record audio and video to generate transcripts and to simulate a realistic interview experience. Our automated AI models evaluate these transcripts based on our SWA FitModel® and industry success benchmarks to produce your personalized feedback.
- Consent: We rely on your explicit consent for this processing, which is requested before you begin any recording.
- Human Review: You have the right to withdraw consent at any time and may request a human review of your AI-generated results if you believe they are inaccurate. We have completed a Data Protection Impact Assessment (DPIA) for our automated AI interview analysis and a Legitimate Interests Assessment (LIA) for our security and fraud-prevention measures. Summaries of these assessments—detailing our risk mitigations such as pseudonymisation, limited retention, access controls, and human review availability—can be found in our Assessments section below, or provided in full upon request.
5. Who Has Access
We maintain strict boundaries to ensure your practice remains private. Access is limited to the following:
- Institutions & Organizations: If your account is provided by a university, school, or employer, they act as the Data Controller and may have access to your results and usage data according to their internal policies.
- Skillity Team: Authorized members of our team have access to pseudonymized performance data (such as SWA scores) strictly for the purpose of Industry Benchmarking, bias monitoring, and refining our AI models.
- Service Providers: We share your data only with strictly vetted third-party service providers necessary to operate the Platform. These include Google Cloud (GCS) for secure data storage, Stripe for payment processing, OpenAI (Whisper) for transcription, Anthropic (Bedrock) and other trusted LLM vendors for text analysis, and Microsoft Graph for email communications. All sub-processors operate under strict Data Processing Agreements (DPAs) or Standard Contractual Clauses (SCCs) to ensure your data is protected to GDPR standards.
- Law Enforcement or Regulatory Authorities: where required by law.
No Data Brokers: We never sell your personal information to data brokers, advertisers, or unapproved “partners”.
International Transfers: If your personal data is transferred outside the UK or European Economic Area (EEA), we implement approved safeguards to ensure it remains protected at a standard equivalent to the UK and EU GDPR. This includes using Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or the UK Addendum where appropriate.
6. Your Rights
You are in control of your personal data. Under the UK GDPR and EU GDPR, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct or update any inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request the deletion of your account and all associated personal data.
- Right to Restriction: Request that we temporarily "pause" the processing of your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format to move it to another service.
- Right to Object: Object to our processing of your data based on our "legitimate interests".
- Rights related to Automated Decision-Making: For your AI-generated feedback, you have the right to request human intervention, express your point of view, and contest the results if you believe they are inaccurate.
- Right to Withdraw Consent: Where we rely on your consent (such as for recordings or diversity data), you can withdraw it at any time.
To act on any of these, email us at contact@skillity.ai. We will respond to all legitimate data subject access and deletion requests within the legal maximum of one month, although we typically aim to process them within two weeks.
7. DATA SECURITY
We are committed to keeping your data safe
- ENCRYPTION IN TRANSIT (TLS) AND ENCRYPTION AT REST.
- STRICT ROLE-BASED ACCESS CONTROLS.
- HOSTING IN SECURE, GDPR-COMPLIANT CLOUD ENVIRONMENTS.
- REGULAR AUDITS AND MONITORING.
8. Cookies & Tracking
No cross-site trackers. No analytics. No advertising pixels. Just the basics to make Skillity® work securely for you.
- Strictly necessary session cookies (to keep you securely signed in).
- Local preference cookies (to display the correct currency for your region).
9. Retention
- Hashed Fraud Prevention Data: 6 months after account deletion.
- Technical Fraud Logs: Deleted after 6 months
- Interview videos: 14 days (or sooner, if you choose to delete).
- Interview transcripts: Deleted in line with the interview record retention period.
- Test results: 18 months (or sooner, if you choose to delete).
- Diversity and equality data (if provided): 18 months (or sooner, if you choose to delete).
- Account data: Until you delete your profile or until required for legal reasons.
10. Changes to This Policy
We may update this Privacy Policy if our practices change. When we do, we’ll update the “Last updated” date and notify you clearly in your dashboard.
11. Final Word
At Skillity®, privacy isn’t a product. It’s the foundation of how we operate. We’re building a future of hiring that’s fair, secure, and fully in your hands.
Questions?
Email us at contact@skillity.ai
If you have a complex privacy concern or wish to contact our Data Protection Officer directly, you may do so at alec.veit@begility.com.
If you are not satisfied with our response or believe we are not processing your data in accordance with the law, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO) (www.ico.org.uk).
Regulatory Assessments (DPIA & LIA)
Data Protection Impact Assessment (DPIA) Summary
Process: Automated AI analysis of audio/video mock interview responses.
Justification: To provide immediate, scalable, and objective coaching feedback to candidates practicing for interviews and focusing on self-improvement.
Safeguards: Processing relies on explicit user consent. Users can withdraw consent at any time, which automatically nullifies transcripts and deletes source media. We utilize vetted sub-processors under strict Data Processing Agreements (DPAs), including Google Cloud (GCS) for hosting/storage, Stripe for payments, OpenAI (Whisper) for transcription, Anthropic (Bedrock) and our LLM providers for text analysis. We do not use special category diversity data to train our AI models, and this AI is not used to make automated hiring decisions.
Legitimate Interests Assessment (LIA) Summary
Purpose: Fraud prevention, preventing account cycling/abuse, and ensuring platform security.
Necessity: Strictly necessary to protect the integrity of the platform and prevent automated bot abuse.
Balancing & Safeguards: We concluded that our legitimate interest in securing the platform does not override user privacy rights because:
- Signals are immediately pseudonymised on our servers using HMAC/SHA-256 hashing.
- We do not store plaintext identifiers.
- Highly invasive fingerprinting methods (like Canvas hashing) are disabled by default and are strictly opt-in.
- Data is automatically purged in accordance with our retention schedules.