Privacy policy
Panelio runs technical interviews inside a Zoom meeting. This page says what Panelio collects, why, for how long, who else touches it, and what you can ask for. It covers the Zoom app, the app at app.panelio.ai, and this site.
Who decides
The employer that adds Panelio to its Zoom account is the controller of its interview data, and the business under California law. Panelio is its processor and service provider, and handles that data only to run the service for that employer, under the terms and the data processing addendum. If you are a candidate, the employer that invited you decides what happens to your data, and its own privacy notice applies too.
Panelio decides for itself only about the data of this site's visitors, people who ask for a demo or write to support, and the records it keeps to run, secure and bill the service.
What Panelio collects
- From the interviewer and the rest of the hiring team. Name, email, Zoom user id and Zoom account id at sign-in, to find or create the workspace membership, and the person's role in the workspace. Their Zoom sign-in tokens, encrypted, to make, move and cancel the Zoom meetings Panelio makes for rounds, to read their Zoom contacts when they invite a colleague, and to let Panelio join a meeting on their behalf. Notes, marks, ratings, grades and decisions made during and after a round, each recorded with the person who made it. The country a sign-in comes from, read from its network address, to make a new workspace only from the United States; it is not kept.
- From the employer. The job description and the candidates' resumes the employer uploads or imports from its applicant tracking system: each resume as the file uploaded and as its text; a job description as its text, its file removed once read. Applicants' names and emails, the rounds planned and the questions approved.
- From the meeting. Audio, only while the interviewer has started the round, transcribed as it arrives; the transcript with its moments; the code timeline (every edit and test run in the editor); the whiteboard as drawn, in a system design round; prompts to the coding assistant and what it did, in an AI readiness round; who is in the meeting, by the name Zoom shows, and when they join and leave. Video is never recorded. The candidate's screen is never recorded. Nothing outside the editor and the whiteboard is read. Panelio itself is a participant named Panelio, muted with its tile dimmed until the interviewer hands it the turn; while it holds the turn, the voice of the candidate and of anyone not on the hiring team reaches the AI voice that answers them.
- From the candidate. Name and email as the employer entered them; what the candidate says and types during the round; their answer to the invitation. No account is created. A voice check runs only when the employer offers it and the candidate signs its notice, by ticking a box and choosing I agree on their screen in Zoom when a round starts: a voiceprint, a set of numbers that describes how their voice sounds, made from their own speech in the round and never a recording, used only to confirm that the same person joins every round and never to grade. Where a round asks for it and the candidate agrees, a link to a public code repository of their own and the files read from it. The country their invitation page or their screen in a round is opened from, read from the network address: kept, as the country alone, only when it is one where Panelio's AI is not offered, so that Panelio does not take the turn or offer the assistant there, and cleared after a visit from anywhere else.
- From the Zoom Marketplace. Which of Panelio's plans the employer's Zoom account holds and when it changes. No card, price or payment detail reaches Panelio.
- From someone who asks for a demo on panelio.ai. Name, work email, a company and a note if given, the half hour picked and the browser's time zone, to arrange the call and write about it. Deleted on request to support@panelio.ai.
- From someone who writes to support. The message and the address it came from, to answer it.
- From every visitor. Our hosts keep request logs (the network address, the browser, the page asked for and the time) for a short period, to run the service and keep it safe.
- Never. Webcam recording, gaze tracking, emotion or stress inference, device agents, keystroke logging outside the editor, protected attributes in any prompt or rubric.
The Zoom data Panelio uses
Panelio reaches Zoom data only through the permissions the person adding it grants, and only for the features below.
| Zoom data | Why Panelio uses it | What is kept |
|---|---|---|
| Your Zoom profile: user id, name, email, account id | To sign you in and find your workspace | On your membership while the workspace keeps you; erased when you remove the app |
| Your Zoom sign-in tokens | To do the things below on your behalf | Encrypted; given back to Zoom and deleted when you remove the app |
| Meetings Panelio makes, moves or cancels | To give each round its own Zoom meeting, and move or cancel it when you ask | The meeting's ID and link on the round |
| Your Zoom contacts | To find a colleague you invite to look at a role's candidates | Read when the address book opens; only the person you invite is kept |
| In the meeting: its ID, your role in it, who is in it | To run the round in the right meeting, know the candidate, and hold a debrief only among the team | On the round's record |
| The meeting's audio and Zoom's transcript, through Realtime Media Streams | The transcript of the round, the voice check with consent, and Panelio's voice when it holds the turn | The transcript, for the retention period; never the audio |
| A token for one meeting, and its passcode | To let Panelio join that meeting on behalf of the interviewer in it | Nothing; neither is stored |
| Your Marketplace plan | To put the account on the plan it bought | The plan's name and ids, and each change without any amount; the Zoom user id of whoever bought it or changed it is erased when they remove the app |
Panelio uses Zoom data only to provide these features to the employer that added it. It does not sell Zoom data, use it for advertising, or use it, or let anyone use it, to train or improve an artificial intelligence or machine learning model, Panelio's or anyone else's. OpenAI, which runs Panelio's models on Panelio's own account, does not train its models on it. Zoom shows everyone in the meeting when an app is reaching its content, and Panelio's own participant is in the participant list by name.
Why
To run the round, to build the evidence pack the employer's people confirm, to let a person make the decision on the record, to send the mail the employer's people ask Panelio to send (invitations, notes to the team and, after a decision, a note to the candidate), to keep the service working and safe, and to bill the employer through the Zoom Marketplace. Interview data is never used to train models.
AI, and automated decisions
Panelio does not make hiring decisions. The model shortlists resumes against the job description with the evidence beside each name, suggests follow-up questions to the interviewer, grades against the employer's answer key and anchors after the round, and drafts notes; it never advances, declines or scores a candidate on its own. Every decision is recorded by a named person; the grades a model suggests quote the transcript or the code they come from, and a grade the record cannot ground is left blank for the interviewer. A candidate can ask to talk to a human at any point of an AI-led screen and nobody asks why. Where the law requires a notice of an automated employment decision tool or a bias audit, the employer carries it; Panelio puts its notice in every invitation it sends, and the audit export gives the employer every decision with its actor, its reason and its rubric version.
The voice check
The voice check confirms that the same person joins every round of a candidate's interviews for a role. An employer may turn it off, and it never runs in a demo workspace.
- Notice and consent first. When the interviewer starts a round, the candidate sees the notice in full on their own screen in Zoom: what a voiceprint is, what it is for, who has it and how long it is kept. They agree only by ticking the box and choosing I agree; I don't agree sits beside it with the same weight, and saying no counts against nothing. Nothing is captured before they agree. The record of their answer (the name they signed under, the notice's version and a hash of its exact words, the round and the time) holds no biometric data.
- What is made. About thirty seconds of the candidate's own speech become a voiceprint inside Panelio's seat in the meeting, and the audio is dropped as soon as it is made. The voiceprint from their first round is kept, encrypted with the employer's workspace key; later rounds make one, compare it and discard it. The interviewer sees only whether the voices match, never the voiceprint.
- Who has it. The employer, and Panelio as its service provider. A voiceprint is never sold, leased, traded or shared, never used to profit, and never used for another purpose, role or employer.
- Retention schedule and destruction. A voiceprint is deleted when the employer records its hiring decision for the role, and never later than one year after the candidate's last round of that role, whichever comes first. Taking back the agreement deletes it at once; a daily job deletes any whose time has passed, and any left when a candidate's record is erased. Deleted means gone from the database; the database provider's backups expire on their own schedule.
- If something goes wrong. If a security incident may have reached voiceprints, Panelio tells the employer within 72 hours of confirming it, and helps it tell the people affected as the law requires.
This schedule is Panelio's public written policy for biometric information, as the Illinois Biometric Information Privacy Act asks of whoever holds it. It also meets Texas's rule to destroy biometric identifiers within a year after their purpose ends, Washington's rules on notice, consent and keeping them no longer than necessary, and Colorado's 24-month limit after the last interaction: the voiceprint goes at the decision, and never more than a year after the last round.
How long
Audio is transcribed and not kept as audio. A candidate's record (the transcript, the code timeline, the whiteboard, the evidence pack, and the resume as its file and its text) is kept for 90 days after the employer's decision on the candidate by default, then erased; the employer sets the period, from 30 days to one year. What stays for the employer's audit is each decision as it was recorded (who, what, when and why), the shortlist's order and the dates of the rounds, with the candidate as a number. When the employer deletes a role for good, its candidates' resumes go with it, and each of its candidates is kept only as a number, with no name or email. A public pack link expires at the decision plus the retention period at the latest. A voiceprint is deleted when the employer records its hiring decision for the role, and never later than one year after the candidate's last round of that role, whichever comes first; the record of the candidate's answer to the voice check stays as the record of consent, with the name they signed under, after the rest of their record is erased or their role is deleted. The link to a candidate's own code and the files read from it are deleted at the decision. Erasure of a candidate's data within 30 days of the employer's request. A demo workspace's synthetic candidates are labelled as generated and never mix with an employer's data.
A member's account stays while the workspace keeps them. Removing Panelio from Zoom erases the person at once, in every workspace: their name, their email and their Zoom login (the sign-in tokens, which Panelio also tells Zoom to revoke, and the Zoom user and account ids) are deleted, and the notes, ratings and decisions they recorded stay as the employer's hiring record under "A former member". A whole workspace is deleted 7 days after one of its admins asks for it in Settings, Data, with its files, voiceprints and key, unless an admin cancels before then. The count of interview rounds and resumes a workspace used stays with its Zoom account when the workspace is deleted, by month under the account's id and nothing else, since the plan is the account's. To hold the mail limits, Panelio keeps a count of each day's mail per workspace and per invited address, each address only as a one-way hash, never the address itself. Plan changes are kept, without any amount, as the account's billing record, and without the Zoom user id of anyone who has removed the app. A demo request is kept until it is deleted on request.
Who else touches it
Subprocessors: Vercel, Supabase, OpenAI, Resend, Vultr. Changes are emailed to workspace admins 30 days ahead.
| Subprocessor | What it does | Region | When |
|---|---|---|---|
| Vercel | hosts the app and the API, and Panelio's seat in each live meeting | United States and EU edge | always |
| Supabase | the database, stored resume files and realtime channels | United States (Ohio) | always |
| OpenAI | the model behind grading, the coach, the AI interviewer and the agent, on Panelio's account; no training on the data | United States | always |
| Resend | transactional email: invitations, the candidate's note, reviewer nudges | United States | when a workspace sends email |
| Vultr | the execution box that runs the candidate's code, in a container with no network; nothing is kept there after a run | United States (New Jersey) | when a round runs code |
Zoom runs the meeting, the sign-in and the Marketplace under the employer's own agreement with Zoom; what Zoom does with meeting data is in Zoom's own privacy statement. An applicant tracking system the employer connects is the employer's own account under its own agreement with that vendor. A public code repository a candidate gives is read from GitHub. Panelio sells personal information to no one.
Where
Panelio is offered to employers in the United States. The database and the stored files live in the United States (Ohio), and every subprocessor processes the data in the United States; requests may pass through the hosting network's nearest edge. The app runs on Vercel. Model calls go to OpenAI on Panelio's account. An employer brings no model keys.
Security
TLS on every connection; each workspace's sensitive records encrypted with a key of its own; access by role inside a workspace and to the workspace's own data only. If a security incident reaches an employer's data, Panelio tells the workspace's admins within 72 hours of confirming it, with what was reached and what was done. The security page has the detail.
Cookies
The app at app.panelio.ai sets only the cookies it needs to sign you in, all of them secure and out of reach of the page's scripts:
| Cookie | What it does | How long |
|---|---|---|
| pn_session | Keeps you signed in, signed so it cannot be forged | 7 days, or until you sign out |
| pn_oauth | Ties Zoom's sign-in back to the browser that started it | 10 minutes, during sign-in |
| pn_join | Holds a sign-in, encrypted, while you choose whether to join a workspace you were invited to | 30 minutes |
The app also remembers in the browser how wide you like the meeting panel and which invitations you set aside for now. This site sets no cookies. Neither runs analytics, advertising or tracking of any kind. Both load the Manrope font from Google Fonts, which receives the browser's network address to serve it. Zoom's own sign-in page sets Zoom's cookies under Zoom's terms.
Your rights
Candidates, and anyone else whose data an employer put into Panelio. Ask the employer: it can give you a copy of your interview data, correct it or erase it, and tell you how its decision was made. Panelio erases a candidate's data within 30 days of the employer's request and helps the employer answer. A request that reaches Panelio about an employer's hiring is passed to that employer, and you are told it was.
Members of a workspace. Ask your workspace admin to change or remove your membership. Removing Panelio from Zoom erases your name, your email and your Zoom login at once, in every workspace you are in, and Panelio tells Zoom to revoke its access; what you recorded stays on the employer's hiring record under "A former member".
Everyone, for the data Panelio decides about. You may ask to know what Panelio holds about you, to have a copy, to correct it or to delete it, by writing to support@panelio.ai yourself or through someone you authorize. Panelio may ask you to confirm it is you before it answers, and answers within 45 days. Nobody is treated differently for asking.
Sale and sharing. Panelio does not sell personal information and does not share it for advertising across sites, and has not in the past twelve months, so there is nothing to opt out of. The voiceprint, the one piece of sensitive personal information Panelio handles, is used only for the purpose its notice states.
California applicants
This is the notice at collection for what Panelio processes for an employer when you apply in California. The employer gives its own notice too, and your requests go to it.
| Category | What, for what | How long |
|---|---|---|
| Identifiers | Name and email, to invite you and keep your rounds together | The employer's period after its decision, 30 days to one year |
| Professional or employment information, education | Your resume and the job you applied for, to shortlist and to ask about your experience | The same |
| Audio and electronic information | The meeting's audio, heard to make the transcript and never kept; the transcript, your code and the whiteboard, as the record of the round | The same; the audio not at all |
| Assessments | Grades against the role's rubric, each quoting the record, confirmed or changed by a person | The same; each decision stays for the employer's audit |
| Biometric information, sensitive | A voiceprint, only with your written consent, to confirm the same person joins every round | Until the hiring decision, one year after your last round at most |
None of it is sold or shared for advertising.
Children
Panelio is for employers and their hiring teams and is not meant for children. Employers must not use it to interview anyone under 16, and Panelio does not knowingly collect the data of anyone under 16; if it learns it has, it deletes it.
Changes
This page changes when the product does, and the date at the top moves. A change that matters is emailed to workspace admins 30 days before it takes effect.
Contact
support@panelio.ai. Bose Ventures LLC, 2150 N First St, Suite 400-2010, San Jose, CA 95131.