1. Scope and who is responsible
Authenti8 provides consent-based integrity verification for live interviews. This policy applies when you visit Authenti8, create or use a recruiter account, connect an organization's calendar, join a protected interview as a candidate, install or use an Authenti8 browser extension, or use the Authenti8 device agent.
Authenti8 is responsible for information used to operate and secure the service. A recruiting organization may separately control interview scheduling information and decide which authorized team members can view an interview's live status and report. You may also contact that organization about its hiring records and decisions.
2. Information we handle
Account, organization, and commercial information
- Name, work email address, organization name and domain, role, account status, and authentication or session records.
- Contact details and company information submitted through our forms, together with the source page, referral information, campaign parameters when available, and privacy request details submitted through the privacy request form.
- Subscription, credit, invoice, and transaction identifiers. Payment providers process payment-card details; Authenti8 does not receive complete card numbers.
Interview and calendar information
- Calendar and event identifiers, event title, scheduled time, Google Meet link or meeting code, organizer details, and participant names or email addresses needed to identify an eligible interview.
- Candidate name and email address, verification-link status, consent choice and time, consent version, IP address and browser user-agent recorded with the consent decision, and setup or dispute communications.
- Interview status, monitoring start and end times, service health, evidence coverage, integrity events, supported-product findings, reports, and related audit records.
Device and integrity information
- Random device or browser-profile identifiers, device public key, operating-system and agent versions, extension version, rule-set version, event times, sequence data, and connection or sensor health.
- Limited application identity and activity indicators required to evaluate supported interview-assistance software, such as application name and version, publisher or signature information, executable digest, process state, limited window-state indicators, and audio-endpoint state.
- For supported browser extensions, the matched extension identifier, version, enabled state, and installation type. Authenti8 does not transmit the candidate's complete Chrome extension inventory.
Website and service operations
We may process IP or hashed IP information, browser and device type, timestamps, requested pages, authentication events, diagnostic logs, and security events. We use necessary cookies or similar storage to keep users signed in, maintain security, and remember service state.
3. Chrome extension disclosures
Authenti8 Candidate Verify
Candidate Verify periodically compares the Chrome environment on the device with Authenti8's signed list of supported products and keeps only matched-product state. It does not send the complete extension inventory. It passes matched-product details, browser-profile and connection health, and whether the Google Meet tab is visible and focused to the Authenti8 device agent, which keeps a bounded encrypted queue on the device. Authenti8's servers receive this limited integrity evidence only during an authorized interview monitoring window after the candidate has consented. Candidate Verify stores a random browser-profile identifier, the last active-profile confirmation, matched-product state, and a verified signed rule set locally in Chrome.
Authenti8 Recruiter
The Recruiter extension reads the Google Meet code from the current Meet URL so it can request the corresponding protected-interview status. It displays the candidate name, consent and monitoring status, coverage, findings, and integrity timeline received from Authenti8 to an authorized recruiter. It stores a short-lived access token, approved API location, panel position, minimized state, and acknowledged event sequence locally in Chrome.
Permissions
The extensions request only the Chrome permissions needed to perform these functions. Candidate Verify uses extension-management access to compare installed extensions with the signed supported-product list, native messaging to communicate with the Authenti8 device agent, storage for the limited local state described above, alarms for periodic health checks, and host access limited to Google Meet and Authenti8. The Recruiter extension uses storage, alarms, and host access limited to Google Meet and Authenti8 to authenticate, retrieve, and display the protected interview timeline.
Chrome Web Store Limited Use
Authenti8's use and transfer of information received from Google APIs and Chrome extension permissions complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this information only to provide and improve the user-facing interview-integrity features described in this policy, maintain security, prevent abuse, and comply with law. We do not sell this information, use it for advertising, use it to determine creditworthiness or for lending, or allow people to read it except when required to provide or secure the service, comply with law, or with the user's affirmative agreement.
4. How we use information
We use information to:
- create and secure accounts, authenticate authorized users, and administer customer organizations;
- identify eligible interviews and provide candidate invitations, disclosure, consent, device enrollment, and monitoring controls;
- provide live integrity status and evidence-backed reports to authorized recruiters;
- verify service health, troubleshoot failures, maintain auditability, detect fraud or abuse, and protect users and the service;
- process subscriptions and transactions, answer requests, and send operational or requested product communications;
- comply with legal obligations and enforce our agreements; and
- analyze aggregated or de-identified service performance where the information no longer identifies an individual.
Depending on the context and applicable law, we rely on consent, performance of a contract, compliance with legal obligations, and legitimate interests such as securing and operating the service. Before consent, Candidate Verify may perform the local readiness comparisons and pass limited matched-product state to the device agent as described in Section 3. Authenti8's servers receive interview-integrity evidence, and authorized interview monitoring begins, only after the candidate explicitly consents and only within the authorized interview window. Declining consent is recorded as a declined or unverified outcome, not as a cheating finding.
5. How we share information
We may disclose information to:
- the recruiting organization: authorized members may receive the candidate's consent and setup status, live integrity timeline, findings, coverage, and report for its interview;
- service providers: vendors supporting cloud hosting, database and security operations, email delivery, payment processing, and customer support, acting under contractual restrictions appropriate to their role;
- connected services: Google services when an authorized customer connects Google Calendar or uses Google Meet, subject to the customer's settings and Google's terms;
- legal and safety recipients: courts, regulators, law enforcement, or other parties when disclosure is reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish or defend legal claims; and
- transaction participants: advisers and a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality measures.
We do not sell or rent personal information. We do not share extension-derived user data with data brokers, advertising networks, or unrelated third parties.
6. Retention and deletion
Authenti8 keeps personal information only for as long as necessary for the purposes in this policy, customer instructions, security, dispute handling, and legal obligations. By default, detailed interview evidence is scheduled for deletion 30 days after the interview ends. Reports and identifying interview data are scheduled for deletion or de-identification after 90 days. Customer organizations may configure shorter or longer periods within Authenti8's permitted settings.
Deletion may be delayed while a candidate dispute, legal hold, security investigation, or legal requirement applies. Audit, billing, account, and transaction records may be retained for the period required for security, accounting, tax, contractual, or legal purposes. Completed privacy requests are scheduled for deletion after 365 days unless a legal obligation requires longer retention. Calendar information is retained while needed to provide the connected service and is removed or disconnected according to account and customer controls.
Local extension data remains in the Chrome profile until it is replaced, acknowledged and cleared by the extension, removed through Chrome controls, or the extension is uninstalled. The companion device agent may keep a bounded encrypted queue of limited browser integrity evidence until it is transmitted and acknowledged during an authorized session, replaced by newer records under the queue limit, or the agent's local data is removed. Access tokens expire or are revoked. Backup copies may persist for a limited period before secure deletion.
7. Your choices and privacy rights
- Candidates may accept or decline monitoring before collection begins and may stop monitoring during the authorized interview window.
- Recruiters can disconnect connected services and manage account or organization access through available settings.
- Chrome users can review permissions, clear extension storage, disable an extension, or uninstall it through Chrome.
- You may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where applicable. Applicable law may provide only some of these rights, and we may need to verify your identity before acting.
- A candidate may also contact the recruiting organization regarding its copy of hiring records or its decisions.
We do not make hiring decisions. Authenti8 provides integrity evidence and service-health context for review by the recruiting organization.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, scoped credentials, signed software and rule packages, audit records, and retention controls. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
9. International data transfers
Authenti8 and its service providers may process information in countries other than the country where it was collected. Where required, we use contractual or other recognized safeguards for international transfers and apply the protections described in this policy.
10. Children
Authenti8 is a business service and is not directed to children under 16. We do not knowingly collect personal information from children under 16 through the service. If you believe a child has provided information to us, contact us so we can review and delete it as appropriate.
11. Changes to this policy
We may update this policy as the service, extensions, or legal requirements change. We will post the revised policy here, update the date above, and provide additional notice when required by law or when a change materially affects how we handle information.
12. Contact us
Use this form for privacy questions or requests. Include enough information for us to identify the relevant account, organization, or interview without sending passwords, complete payment-card numbers, or other unnecessary sensitive information. Candidates may also contact the recruiting organization that arranged their interview.