CALIBER APP

Privacy Policy

Last updated: August 16, 2026

Caliber App ("we", "us", or "our") operates the Caliber mobile application and web portal (the "Service"). This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

1. Information We Collect

Account Information: When your organisation administrator registers you as a user, we store your name, phone number, and assigned role (instructor or supervisor). This information is provided by your organisation, not collected directly from you.

Government Identification Number: Where an organisation requires it, an administrator may record a national identification number for the users they manage. This is entered only in the web portal, never in the mobile app. It is encrypted before storage, displayed in masked form by default, and every time it is revealed the access is recorded in an audit log.

Authentication Data: We use phone number verification (SMS one-time code) to authenticate users on the mobile app, and Google Sign-In for web portal access. Firebase Authentication manages these credentials securely, and our SMS provider receives your phone number in order to deliver the verification message.

Evaluation Data: The app collects data about the candidates being evaluated, entered by authorised instructors during evaluation events. This includes candidate identifying details such as a candidate number and, where the organisation records them, a first and last name, together with task results, scores, rankings, free-text instructor comments, and personal interview write-ups. This data is collected on behalf of, and under the instructions of, your organisation.

Voice Input and Transcription: With your permission, the mobile app can use your device's microphone so that instructor comments and personal interviews can be dictated instead of typed. Speech is converted to text using the speech recognition service built into your device's operating system (Apple on iOS, Google on Android), which may process the audio on the device or on that provider's servers under their own privacy policy. We do not store the audio recording, and the audio is never transmitted to or retained on our servers โ€” only the resulting text, which you can review and edit before saving, is stored as evaluation data.

AI-Assisted Interview Summaries: If an instructor chooses to summarise an interview, the interview text is sent to Google's Vertex AI (Gemini) service, operating within our own Google Cloud project, which returns a suggested summary. This happens only when the instructor explicitly requests a summary. Under the Vertex AI terms, this content is not used to train Google's models.

Device and Usage Data: We collect basic analytics and crash reports to improve app stability and performance. This may include device type, operating system version, app version, app usage patterns, crash diagnostics, and app-generated identifiers such as an app instance identifier. It does not include your name, phone number, or identification number: values sent to these services are automatically screened to redact identifiers of that kind.

2. How We Use Your Information

We do not use your personal information for advertising, we do not track you across other companies' apps or websites, and we do not sell your personal information.

3. Data Storage and Security

Your data is stored using Google Firebase services (Firestore, Firebase Storage, Firebase Authentication), hosted on Google Cloud infrastructure. Evaluation data is isolated per organisation, so each organisation can only access its own data.

Database backups are encrypted using AES-256-GCM encryption before being uploaded to Firebase Storage. Encryption keys are derived from a PIN combined with event metadata using PBKDF2 key derivation (100,000 iterations).

The mobile app stores evaluation data locally on your device using an encrypted local database for offline operation.

Government identification numbers are encrypted at rest using Google Cloud Key Management Service, are never returned in plain form to ordinary listings, and can be revealed only by authorised administrators of the same organisation. Each reveal is written to an audit log.

4. Data Sharing

We do not sell, trade, or rent your personal information. We share it only with the parties listed below, and only to the extent needed to operate the Service on your organisation's behalf:

We do not share your personal information with data brokers or advertising networks.

5. Data Retention

We retain your data for as long as your organisation maintains an active account with us. When an organisation's account is deactivated, associated user data and evaluation records are retained for a reasonable period before deletion, unless a longer retention period is required by law.

Your organisation's administrators can also permanently delete the scoring data of a finished event at any time, from within the web portal. On the mobile device, evaluation data for an event is sealed once the event ends and is then automatically removed from the device after a short grace period.

6. Your Rights

You have the right to:

To exercise these rights, contact your organisation administrator or reach out to us directly.

For evaluation data about candidates, your organisation determines what is collected and why, and we process that data on its behalf. Requests concerning candidate records should therefore be directed to the organisation that ran the evaluation; we will assist that organisation in responding.

7. Mobile App Permissions

The mobile app requests the following device permissions. Each is optional, is requested only at the moment the related feature is first used, and can be withdrawn at any time in your device settings โ€” the rest of the app continues to work without it.

The app does not request access to your location, contacts, photos, or calendar.

8. Children's Privacy

The Service is not intended for use by individuals under the age of 18, and app accounts are issued only to adult staff of a registered organisation. We do not knowingly collect personal information directly from children. Where an organisation evaluates candidates who are minors, that organisation is the controller of the candidate data it records and is responsible for the legal basis and consents for doing so.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at:

privacy@caliberapp.io