Skip to content

Monitoring and data collection

SkillFoundry evaluates how candidates work as well as what they produce. That requires collecting activity data during assessments. This page explains — precisely — what is collected, what is never collected, how it's used, and how candidates can see it for themselves.

For Legal and Security

This page is the candidate-facing description. For the legal-bases, works-council, and DPIA analysis, see the behavioral monitoring privacy model; for retention/erasure, audit logging, bias audits, and the DPA, see Trust and compliance.

The principles

  1. Activity, not content. During a session we record behavioral interaction events that describe activity in the workspace, not the text you type.
  2. No keystroke logging. Ever. We record that the code changed, not the keys you pressed.
  3. No clipboard contents. We may record that a paste happened, never the pasted text.
  4. Scoped to the assessment. In the VS Code extension, only activity inside the assessment workspace folder is observed; files outside it are ignored (symlink tricks included).
  5. Sanitized. Before upload, events are scrubbed: email addresses, tokens, IP addresses, and home-directory paths are redacted.
  6. Transparent. Candidates can view the complete event stream during the session — the same data reviewers' scores are built from.

What is collected during an assessment

Category What it covers Content captured?
Session lifecycle When the assessment starts and is submitted; task and time limits No
File and editing activity Which files in the assessment workspace are opened and changed, and how much Paths only, never file text
Testing and tooling Test runs and their results; in VS Code, sanitized terminal, git and debugger activity Metadata only; commands and commit messages sanitized
Focus and timing Whether the workspace is active, and time spent in the session No
Paste activity That a paste happened and its size Pasted text is never sent
AI assistant use Use of the built-in AI assistant; in VS Code, whether third-party AI assistants are installed Never third-party prompts or completions
Documentation and search Which task documents are opened; search activity in the workspace Limited

What's captured at specific moments (with content)

Some things necessarily include content — collected once, at defined moments, and disclosed here:

  • Your submitted code. In the browser workspace, your file changes are saved to your attempt as you work. In the VS Code extension, your code leaves your machine exactly once: as a git diff when you click Submit.
  • AI chat messages. Conversations with the AI Customer/TPM personas are sent in full — they're conversations with the platform, and their quality is part of communication scoring.
  • Submission integrity metadata. In the browser workspace, when AI-usage detection is active, the submission includes summary activity statistics and periodic snapshots of the evolving code so reviewers can verify how the work progressed.
  • Comments and notes you write on tasks and submissions.

What is never collected

  • Keystrokes (no keylogging of any kind)
  • Clipboard contents
  • Screen recordings, webcam, or microphone — SkillFoundry does not do audiovisual proctoring
  • Files outside the assessment workspace (VS Code)
  • AI assistant prompt or completion text
  • Anything at all before you activate/start the assessment — in the VS Code extension, collection begins only when you run Start Timer, and stops at submission

How the data is used

  1. Behavioral assessment. Session activity is analysed to describe job-relevant working behaviors, such as how you approached the problem and tested your work. The results contribute to the report reviewers see.
  2. Integrity review. Where a task disallows AI assistance, unusual activity can flag the submission for human review — flags never auto-reject anyone.
  3. Candidate feedback. Where enabled by the organization, candidates see their own behavioral report: overall score, per-skill breakdowns, strengths, and improvement recommendations.
  4. Evidence-based assessment (rolling out to pilot customers). A newer assessment model describes how you investigated, used AI and verified your work, and reviewers can check each result against the evidence behind it. Missing evidence is never counted against you, and using AI is not penalized in itself. Correctness is graded on the code you actually submitted, in a trusted environment. Where it is the primary result, you see descriptive, plain-language feedback.

Critical negative findings — most notably secrets (credentials/API keys) committed in code — surface as red flags in the reviewer's report and heavily impact scoring. Don't paste real credentials into assessment code, ever.

Transparency tools for candidates

  • Browser workspace: the IDE-mode setup page discloses telemetry before you opt in; the AI policy banner in the editor shows integrity rules in force.
  • VS Code extension: the Assessment Panel's Behavioral Data tab shows a live view of collected events (refreshed every 2 seconds), and the command SkillFoundry: View Collected Events (Transparency) shows the complete event summary. What you see there is what the platform has.

Reliability and buffering

Telemetry is sent in batches and buffered locally when offline — a dropped connection doesn't lose your session or create gaps that count against you. Events sync automatically when connectivity returns.

Behavioral evidence: retention, deletion and research use

These apply to the behavioral evidence used by evidence-based assessment (behavioral interaction events such as workspace activity, test runs and use of the AI assistant; never keystroke content) and to its protected artifacts (code changes, test reports and AI assistant transcripts, which have secrets redacted and can only be opened by authorized reviewers, with access logged).

  • Retention. By default, behavioral evidence is kept for 24 months after the most recent evidence for the attempt, and protected artifacts for 12 months. Organizations can configure evidence retention between 90 days and 36 months, and artifact retention between 30 days and 24 months (never longer than evidence).
  • Deletion. When you ask us to delete your data, for example by deleting your account, your behavioral assessment evidence and artifacts are deleted from our live systems within 48 hours, unless a legal hold applies. Other account data is deleted or anonymized in line with our retention policy.
  • Backups. Backups are generally kept for up to 90 days and roll off on their normal schedule. Data in backups is not restored into live systems except for disaster recovery; if a backup is restored, pending deletions are applied again before the restored systems are used.
  • Research use is opt-in. The behavior record of your practice attempts is used to check and tune our analysis only if you explicitly agree. The choice is off by default, separate from the terms, limited to people 18 or older, and can be withdrawn in Settings → Security & Privacy. Research copies are pseudonymized (your name, email, code and AI transcripts are removed), are kept for up to 36 months (deleted within 48 hours if you withdraw), are never used to score you and are never shown to employers. Organization assessments are used for calibration only where the organization has agreed to it by contract.

Data handling

  • Behavioral events are stored associated with your candidate ID, task ID, and session/attempt ID, and are used for the purposes above.
  • Organization admins can export their organization's data; for deletion or access requests, contact your organization's admin (for org-run assessments) or SkillFoundry support (for self-serve accounts). See Data retention and erasure and Candidate rights and appeals.
  • Score reports may include auto-generated narrative summaries; where AI-assisted report generation is enabled, summaries of the results (not your raw code) are processed for narrative text.

Questions candidates ask most

Can my employer see everything I typed? No. Reviewers see your final submitted code (diff), your chat messages with the AI personas, aggregate behavioral results, and — if integrity detection was active — summary activity statistics with periodic code snapshots. They do not see keystrokes or a replay of your typing.

I copy-pasted from the official docs — will I be flagged? Pasting is part of normal work and is not flagged on its own. A flag only triggers human review, and if AI is allowed on your task, pasting doesn't generate integrity flags at all.

Does it watch me outside the assessment? No. Collection starts when the assessment starts, ends at submission, and (in VS Code) is confined to the assessment workspace folder.

Is my camera or screen recorded? No. SkillFoundry does not use webcam, microphone, or screen recording.