Privacy
Effective September 18, 2026
Privacy policy
Assess Aptitude · Coco Design
This policy describes what this site collects, why, and how it is protected. It applies to candidates taking the assessment, to employer accounts that issue access codes, and to anyone who contacts us through this website.
Who we are
This assessment service is operated by Coco Design. You can reach us through our contact form.
Each employer decides who to test, what to ask of their applicants, and how long to keep the results. For candidate data, the employer that issued the access code is responsible for those decisions; we hold and process that data on the employer's behalf so their assessment can run and be scored.
Information we collect
Candidate assessment data
When a candidate starts the assessment with a valid access code, we collect:
- Candidate name and email address
- The access code used to start the assessment, and the role it was issued for
- The selected answer for each question, and whether it was correct
- The final score
- Session timing: when the test started, its time limit, and when it was submitted
- The attestation: the candidate's signed confirmation and its timestamp
- Whether the candidate met the employer-set passing score and was offered part two
- Test integrity signals recorded during the attempt — described in its own section below
Part two (behavioral) assessment data
Candidates who continue to part two provide:
- The "most like me" and "least like me" selection for each of the 28 word groups
- The four resulting work-style scores (Dominance, Influence, Steadiness, Conscientiousness) and the derived primary and supporting style
- When the questionnaire was submitted
Employer / administrator accounts
Employers and administrators create an account using an email address, or by signing in with Google (in which case we receive basic profile information from Google, such as name and email). Company name and administrator role assignments are stored to control access. We also store the company's account status, its plan and trial dates, and the plan it asked for at sign-up.
Local browser storage
While a test is in progress, answers are held in your browser's local storage so they survive a page refresh. Part two selections are also held in local storage while that questionnaire is in progress. This data stays on your device and is cleared when the assessment is submitted or the session ends. Signing in as an employer also stores a session token in your browser so you stay signed in.
Test integrity monitoring
The assessment is a timed test taken without assistance, so each attempt is monitored for signs of unauthorized help. Candidates are told this before they begin, on the attestation screen and in the header shown throughout the test. For each attempt we record:
- How long each question was on screen
- How many times an answer was changed
- How many times the test window lost focus, and for how long in total
- Attempts to paste text into the test
These signals are used only to judge whether an attempt was taken under test conditions. They are shown to the employer that issued the access code, who may flag an attempt for review or ask the candidate to retest with a new code. We do not record your screen, camera, microphone, keystrokes, or anything you do outside this website, and we do not use these signals for any purpose other than test integrity.
Hiring positions and invitations
An employer can create a role and invite a named candidate to it. To do that the employer supplies the candidate's name and email address, and we generate a single-use access code and an invitation link that fills the code in for the candidate. The completed result is linked to the role the candidate was invited for, so the employer can compare applicants for the same position. An employer can revoke an invitation before it is used.
Demo and contact requests
If you ask for a demo or contact us through this website, we store the name, company, email address, and any phone number or message you provide. We use it only to respond to your inquiry and to track whether it has been handled. We do not sell it or use it for unrelated marketing.
How we use it
Candidate data is used solely to administer and score the assessment, to check test integrity, and to share the result with the employer that issued the access code. Behavioral responses are used to build the candidate's work-style profile, which is shared with that employer; the candidate sees a brief summary only. Employer and administrator accounts are used only to manage roles, access codes, and candidate results.
Sharing
A candidate's attempt — their answers, score, work-style profile, and integrity signals — is shared only with the employer that issued their access code. Employers cannot see one another's candidates.
We do not sell candidate data and do not share it with third parties for marketing.
Service operator access
As the operator we run the service console that creates and manages employer accounts. That console shows counts and totals only — for example how many companies are active and how many assessments have been taken. It does not show candidate names, email addresses, answers, scorecards, work-style profiles, or integrity reports.
Retention & deletion
Candidate data is kept until the company that issued the access code deletes it. That company can permanently remove a candidate's session, answers and results from its own dashboard, and can remove an invitation that has not yet been used. We hold candidate data on that company's behalf and act on its instruction, so a request to delete candidate data has to go to the company that tested you — we cannot delete it ourselves. Employer and administrator accounts are retained while the user has access and can be removed on request. Demo and contact requests are kept until the inquiry is handled, and are removed on request. Email delivery records are kept for a short period for troubleshooting only.
Security
Candidate answers, scores, and integrity records are protected by server-side access controls, and the question bank and correct answers are never sent to a candidate's browser. Access to candidate results is restricted to the signed-in administrators of the employer that issued the access code.
Authentication
Sign-in offers email/password and Google sign-in. Email/password sign-up includes an email-confirmation step before access. This site does not store passwords directly; authentication is handled by the platform auth provider, and Google sign-in is completed through Google.
Emails we send
We send email from our own sending address at notify.assessaptitude.app. Candidates receive their invitation with the access code and link, and nothing else. Employers and administrators receive account emails — sign-in confirmation, invitations, password resets, a welcome message, and notice when their account is approved. Anyone who submits the demo or contact form receives a confirmation, and a copy of the inquiry is sent to our own support address.
We keep a delivery record for these messages (recipient address, subject, and whether delivery succeeded) so we can tell whether an email arrived. We do not use these addresses for marketing lists.
Plans, trials, and usage counts
When a company signs up it may tell us which plan it is interested in. We store the company's plan, the plan it asked for, when its free trial started and ends, and a count of how many assessments it has used in the current month. These are used only to run the account and to arrange billing; billing is arranged directly with us and no card details are collected or stored by this site.
Hosting and processing
The service runs on managed hosting, database, authentication, and email-delivery infrastructure provided by our technology suppliers, who process this data on our instructions and only to keep the service running. Google receives sign-in information only when an employer chooses to sign in with Google.
Children
This assessment is intended for job applicants. It is not designed for, and should not be given to, anyone under 16 years of age.
Your rights
Candidates should ask the employer that issued their access code for access to, correction of, or deletion of their assessment data. That employer decides how long results are kept and is the only party who can delete them; we cannot delete candidate data on request. If you are unsure who to ask, write to us through our contact form and we will point you to the right employer. Employers and administrators may contact us directly to access or remove their account.
Changes to this policy
If this policy changes, the updated version is posted on this page with a new effective date at the top. Material changes affecting employer accounts will also be notified by email.
Contact
Coco Design — send us a message