Privacy Policy

Last updated: March 14, 2026

1. Introduction

Talentflow ("we," "our," or "us") operates a B2B developer marketplace that connects companies with pre-vetted software engineers through AI-powered code assessments. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, password, and role (candidate, company, or admin).
  • Profile information: skills, experience level, resume, availability status, timezone, and work arrangement preferences.
  • Company information: company name, website, description, and job listings including salary ranges, tech stack, and benefits.
  • Code submissions: GitHub repository URLs and source code submitted as part of technical assessments.

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, session duration, and interaction patterns.
  • Device information: browser type, operating system, IP address, and device identifiers.
  • Cookies: session cookies for authentication (JWT tokens) and preferences.

2.3 Information from Third Parties

  • GitHub: public repository data, file contents, and repository metadata accessed via the GitHub API for assessment purposes.

3. How We Use Your Information

  • Provide, operate, and maintain the marketplace platform.
  • Process and evaluate code submissions using AI-powered review (Anthropic Claude API).
  • Generate structured scoring across 8 assessment categories for talent pool placement.
  • Match candidates with companies based on skills, scores, and availability.
  • Facilitate communication between hiring companies and candidates.
  • Send account-related notifications (submission status, review results, interview invitations).
  • Improve our AI evaluation models and platform features.
  • Ensure platform security and prevent fraudulent activity.

4. AI-Powered Code Review

Your code submissions are processed by the Anthropic Claude AI model to generate objective technical evaluations. Code is analyzed across eight dimensions: Code Quality, Architecture, Type Safety, Error Handling, Testing, Git Practices, Documentation, and Best Practices. Each category receives a score from 1 to 5.

Code submitted for review is sent to Anthropic's API for processing. We do not use your code to train AI models. Review results are stored on our platform and visible to you and to companies who access the talent pool.

5. How We Share Your Information

  • With companies: when you are in the talent pool, hiring companies can view your profile, skills, assessment scores, and review summaries.
  • Service providers: we use third-party services including Supabase (database hosting), Anthropic (AI code review), and GitHub (repository access) to operate the platform.
  • Legal requirements: we may disclose information if required by law, regulation, or legal process.

We do not sell your personal information to third parties.

6. Data Security

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), JWT-based authentication with secure session management, hashed passwords, and access controls based on user roles (admin, candidate, client). While no system is 100% secure, we take reasonable steps to protect your data.

7. Data Retention

We retain your account data and assessment results for as long as your account is active. Code submissions and AI review results are retained to maintain your talent pool profile. You may request deletion of your account and associated data at any time by contacting us.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal data.
  • Object to or restrict certain processing activities.
  • Request portability of your data in a machine-readable format.
  • Withdraw consent where processing is based on consent.

9. Cookies and Tracking

We use essential cookies for authentication and session management. These are necessary for the platform to function and cannot be disabled. We do not use third-party advertising or tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@codeks.hr.