Candidate Privacy Notice
Last updated: February 3, 2026
You have been invited to take a Ducker assessment. This notice explains, in plain terms, what happens to your data while you do.
It is deliberately short. The full Privacy Policy covers everything else.
Who Is Responsible for Your Data
The employer who invited you decides why you are being assessed, what happens to your results, and how long they keep them. In data protection terms, they are the controller.
Ducker runs the assessment for them. We are the processor. We act on the employer's instructions and we do not make or influence hiring decisions.
If you want your assessment data corrected or deleted, ask the employer first. Write to privacy@ducker.ai as well and we will help them respond.
What Is Recorded
Ducker exists to show an employer how you worked, not just what you submitted. So the working session is recorded. Specifically:
- The prompts you send to the AI agent, and its responses
- Tool calls the agent makes and what they return
- Code you write yourself, and code the agent generates — and which is which
- File changes, diffs, and changes you reverted
- Commands you run in the terminal, and their output
- Tests you run and their results
- Application runs and database operations inside the workspace
- Agent suggestions you accepted or rejected
- Timestamps, time spent, token usage, agent iterations, and errors
- Your final submission and snapshots of your workspace
From this we produce a report for the employer: scores across correctness, code quality, architecture, edge cases, testing, and AI collaboration, plus a timeline of the session that the employer can replay.
The report attributes decisions. It may say that you identified a problem before the AI raised it, or that you accepted generated code without reviewing it. That attribution is the point of the product, and you should know it is being made.
What Is Not Recorded
We want to be exact about this.
- No webcam and no microphone. Ducker never asks for camera or microphone access and never records you.
- No screen recording. We see what happens inside the assessment workspace, nothing else on your screen.
- No keystroke logging outside the workspace.
- No access to your other tabs, your browsing history, your files, or your clipboard.
- No monitoring after you submit. Recording stops when the attempt ends.
Where Your Code Runs
The workspace runs inside your own browser, using WebAssembly and, for some tasks, an in-browser Linux emulator. The editor, the terminal, the test runner, and your code all execute on your own machine.
What reaches our servers is the telemetry listed above, your final submission, and workspace snapshots — not a live feed of your computer.
The Device Check Before You Start
Before the timer starts, we check that your device can actually run the workspace. That check reads:
- Your browser and operating system version
- Whether your browser supports WebAssembly, Web Workers, SharedArrayBuffer, cross-origin isolation, and OPFS
- Roughly how much memory and how many processor cores your device has, and how much browser storage is available
- A short runtime and filesystem benchmark
- Your download speed and network latency to our CDN
This is a capability check, not a fingerprint for advertising. If your device cannot run the assessment well, we would rather tell you before the clock starts than have it fail halfway through.
Your timer does not start until the workspace is ready. If our setup fails, the clock does not run.
Other Information We Hold About You
- The name and email address the employer gave us in order to invite you
- Your account details if you create one, including how you signed in
- Your IP address, approximate location from it, and standard request logs
- Any support messages you send us
AI Processing
Your prompts, your code, the task, and the session telemetry are sent to our AI providers — currently Amazon Bedrock and OpenAI — so the coding agent can respond and the reviewer can produce the report. They are listed at ducker.ai/subprocessors.
Your work is not used to train AI models. Our agreements with these providers prohibit it, and we do not do it ourselves.
Automated Decisions
Ducker produces scores and a recommendation using deterministic checks, your session telemetry, and AI-assisted review.
Ducker does not decide whether you are hired. Employers using our Platform agree not to use our output as the sole basis for a decision about you and to apply human review.
If you believe a decision about you was made by automated means alone, contact the employer. Depending on where you live, you may have the right to obtain human intervention, give your point of view, and contest the decision.
Where Your Data Is Stored, and for How Long
Assessment data is stored on Amazon Web Services in Frankfurt, Germany (the eu-central-1 region). Ducker Ltd. is based in Israel, which the European Commission has recognised as providing adequate data protection. Some of our vendors are in the United States, and we use Standard Contractual Clauses for those transfers.
We keep assessment telemetry, submissions, and snapshots for 24 months after your attempt, or until the employer deletes them — whichever is first. The employer may keep the report for as long as their account is active. Their own retention policy applies to anything they export.
Your Rights
Depending on where you live, you can ask to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, or withdraw consent.
Because the employer is the controller of your assessment data, ask them first. Email privacy@ducker.ai in parallel — we will identify what we hold, pass the request on, and help them act on it. We respond within 30 days, or sooner where the law requires.
You can also complain to a supervisory authority: your national data protection authority in the EEA, the UK Information Commissioner's Office, the Israeli Privacy Protection Authority, or the California Privacy Protection Agency.
Contact
Ducker Ltd. privacy@ducker.ai
For anything about the job itself — the role, the outcome, feedback — contact the employer who invited you. We cannot answer those questions.