Privacy & security
Confidentiality is a design constraint, not an afterthought.
This page states our privacy and security principles plainly. Where a specific operational detail, such as a hosting region or named certification, has not been finalized or independently verified, we say so rather than imply something we cannot substantiate.
Our principles
What governs how your data is handled
Assessment confidentiality
Your responses are used to score and generate your own profile. They are never published or sold and are not used to build a public profile about you.
Token security
Every assessment token is tied to one participant and one attempt. It is validated on the server, carries no scores or personal data in the URL, and is permanently locked when the attempt is finalized, whether through completion or automatic submission.
Personal-data handling
We collect the information needed to deliver the assessment and profile. Identifiable service records are kept separate from an optional pseudonymised research copy, which excludes names, contact details, payment information, public profile URLs, and raw token secrets.
Profile access
Your profile is generated for you. In an organizational context, participant-safe content and organization-only content are distinguished, and organizational access is disclosed through the relevant campaign and consent flow.
Organization permissions
Organizations access results only through campaign and access permissions configured for their specific purpose in Phoenix Human Intelligence, not through broad, unscoped access to every participant’s full response data.
Assessment and scoring versioning
Every profile identifies the assessment and scoring versions from which it was generated, so the rules that produced a result remain traceable.
Retake and attempt history
A finalized attempt is not edited. A retake creates a new, independent attempt; earlier attempts remain preserved and each profile identifies the attempt it reflects.
AI boundaries
External artificial intelligence service providers may generate narrative explanations only after deterministic scoring. AI does not calculate, alter, or override scores and does not make employment or other consequential decisions.
No question-bank exposure
Assessment questions, scoring formulas, forced-choice keys, cognitive answer keys, and validity thresholds are not published or exposed to participants because doing so would undermine the instrument.
An honest note on scope
We do not publish security certifications, penetration-test results, specific encryption implementations, or hosting-region commitments unless they have genuinely been established. Claiming otherwise would be a false technical assurance. As verified details are finalized, this page will be updated precisely.
Questions about privacy
