Privacy

Last updated: 29 August 2026

caiscore.com runs the CAI Score API. This page explains what we collect when you use the website or the API, why we collect it, and what you can do about it.

Australian privacy law currently exempts businesses under a $3 million annual turnover, and caiscore.com is below that threshold. We follow the Australian Privacy Principles anyway, as a voluntary commitment. Where this page describes a right, we will honour it whether or not the law obliges us to.

What we collect

Usage analytics. Every page on this site loads Cloudflare Web Analytics. It records page views, referrers, and coarse performance and location data. It sets no cookies and writes nothing to your browser's storage. We use it to see which pages are read and which are ignored — nothing on this site is personalised to you, and nothing is sold or shared with advertisers.

Request logs. Calls to the API are logged server-side by Cloudflare. Those logs include the calling IP address, the path, the response status, and the time. They are retained for Cloudflare's short default retention window for Workers Logs and then discarded automatically. We use them to debug failures and to identify abuse.

API keys. When a key is created we store a one-way hash of it, the tier it belongs to, the time it was created, and the origins it may be called from. We do not store the key itself, and we cannot recover it or show it to you again. Each key belongs to the account that created it.

Your account. Creating a key requires signing in with a Google account. From that sign-in we store your email address and the account identifier Google issues for you, and nothing else — no name, no profile picture, no contact list. We use them to tell one account from another, to show you which account you are signed in as, and to link your keys to you so you can list and revoke them.

Assessment answers. Scoring is stateless. When you send five behavioural answers and a role roster to the API, we score them and return the result; the answers are not written to any store. Where you use a feature that saves your assessments — stored history, or the in-product analytics view that lets you chart and drill into past results — those answers and their results are retained against your key so that we can show them back to you. Using the scoring endpoint on its own stores nothing.

How we collect and hold it

We collect analytics through a script that runs in your browser, your account details from Google when you choose to sign in, and everything else through the API request itself. There is no third-party tag manager, no advertising pixel, and no data broker in the path.

Everything is held on Cloudflare's infrastructure. Keys are held as hashes, so a breach of our storage does not disclose a working credential. We do not run our own servers or databases.

This site writes three things to your browser's local storage: your light/dark theme choice, which language tab you last used in the quickstart, and — while a sign-in is in flight — a flag that sends you back to the keys page afterwards. None of the three is sent to us, and all three are yours to clear at any time.

Signing in sets one cookie, on the API's own domain, that identifies your session so the keys page can act as you. It is strictly necessary for signing in, it carries no advertising or tracking identifier, and signing out clears it. There is no other cookie on this site, and so no cookie banner.

Why we collect it

We do not use any of it for advertising, profiling, or scoring individuals, and we do not sell or rent it.

Automated decisions

The API produces its output automatically. It takes five behavioural answers and a roster of roles or an industry, derives three parameters from them, and returns a score, a zone, and rule-based suggestions. No person reviews a result before you receive it.

caiscore.com does not make decisions about anyone. We do not assess individuals, rank employees, or advise anyone on hiring or termination. A score describes a way of working, not a person's worth or competence.

If you use the API in your own organisation, a score, zone, or suggestion must not be the sole basis for a decision about a person's employment, engagement, or pay. Those decisions are yours, they need human judgement and context the API does not have, and you are responsible for them.

Access and correction

Write to [email protected] and we will tell you what we hold and correct anything that is wrong.

Write from the address you signed in with and we can find your account and its keys. One honest limit: request logs are keyed to IP addresses and expire on their own schedule, so for those we can usually only confirm what is collected rather than retrieve your specific rows.

Complaints

If you think we have mishandled your information, write to [email protected]. We will acknowledge your complaint and respond with what we found and what we intend to do about it.

If our response does not resolve it, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au. You do not need our permission to do that, and you can go to them directly if you would rather not come to us first.

Data held overseas

Our infrastructure provider is Cloudflare, Inc., based in the United States, and it operates a global network. Analytics data, request logs, account and key records, and any saved assessments are held and processed by Cloudflare, and are likely to be accessible from the United States and from other countries where Cloudflare operates data centres.

We remain accountable for how that information is handled. There are no other overseas recipients — no analytics vendor, no advertising network, and no subprocessor beyond Cloudflare.

Data breaches

If information we hold is exposed in a way likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, and we will say plainly what happened and what to do about it.

Changes to this page

If what we collect changes, this page changes with it and the date at the top moves. The version published here is the current one.

Questions: [email protected]