Privacy policy
What we hold about you, what happens to the answers you write, and who gets to see the result. In plain language.
Effective July 27, 2026
Your written answers are read by an AI
Bvisionry is an assessment instrument, not a brochure. When you take an assessment, the text you write is sent to an external AI provider, which produces your scores and a written narrative about you. That score and that narrative are shown to the administrator of the program that invited you. Everything below is the detail.
Reading this site vs. using the platform
You can read every page of this public website without an account. These marketing pages set no advertising cookies, run no third-party analytics or tracking pixels, and do not build a profile of you.
Taking an assessment is different. For that you either sign in to an account your program created for you, or open a one-time link we shared with you. Everything from here down describes that side of the product.
What we hold about you
Your account: your name, email address, the organisation and program you belong to, your role, the invitation that created the account, and a hashed password — or no password at all, if your organisation signs in through its own identity provider.
Your assessment: every answer you give, stored as you wrote it. That includes the free text, the ratings, and the general-information section at the start (first name, last name, gender, and whatever else your program's version of that section asks). While you are still answering, a draft copy also sits in your own browser's storage so closing the tab does not cost you your work.
Your results: a score for each pillar, an overall score, a maturity band, strengths, development areas, a written narrative, and the timestamps for when you started, submitted, and were evaluated.
Your other written work: the assessment is not the only place you write. Workshop answers and exercise sheets are stored the same way — as you wrote them — along with any review comments on them. Who can read those is different from who can read your assessment answers, and the next section says so.
Your answers go to a third-party AI provider
This is the most important paragraph on this page. When your assessment is evaluated, your written answers are sent word for word — together with the question that prompted each one — to an external large-language-model provider. We currently use OpenRouter or Anthropic. Which one, and which model, is a configuration choice we make; it is not something you set.
Your first name, last name and gender are sent with them as context, so the narrative can address you by name. That is why the result reads as though it is talking to you.
We keep a log of those AI calls, including the text that was sent, so we can diagnose a bad evaluation. Those log entries are deleted after 90 days by default, and an evaluation result is cached for 30 days so an identical re-run does not pay for a second call.
We do not train any model on your answers. What an AI provider does with data sent to its API is governed by that provider's own terms, not by this policy.
The AI-use check
Separately from scoring, we can run a second AI pass over your free-text answers that estimates how likely they were written by an AI. It returns a score from 0 to 100, a band from likely human to likely AI, and notes citing specific answers. One result is stored per submission, and it is replaced each time it is re-run.
It is a heuristic signal for a human to weigh, never proof. Only Bvisionry's own platform administrators can see it or run it — your program administrator can do neither.
Who can see what
You see your own results in full.
The administrator of the program that invited you sees your name and email address, the general-information answers you gave at the start, whether you have started and finished, your scores, the AI-written narrative, and your strengths and development areas.
There is exactly one thing they cannot read: the verbatim text of your assessment answers. That one is refused at the API, not merely hidden in the interface. Treat it as the exception rather than the rule, because it does not extend to anything else you write.
Your workshop answers and your exercise sheets are readable by your program administrator, in full, as you wrote them. They can open any single member's workshop answers from the completion log, and they can export every member's workshop answers as one file. That bulk file has names masked, but masking is a control on what leaves the building, not anonymity — the same administrator sees your name attached to your work everywhere else in their console.
A coach your program assigns to you reads the exercise sheets you submit — the contents of the cells, not merely the fact that you submitted — together with your name and email, and comments on them. That review loop is the point of the coach console. A coach sees nothing at all about founders outside the ones assigned to them. Beyond that they see your pillar scores, maturity labels and program progress, but not your assessment narrative and not your assessment answers.
Bvisionry's own platform administrators can see all of the above plus your verbatim assessment answers, the AI-call log, and the AI-use result. That access exists for support and for checking evaluation quality.
Where a report is exported with names hidden, your name is also scrubbed out of the narrative text itself — blanking a name column would not be enough, because the narrative says your name out loud.
We keep results you replaced
If your program administrator asks you to redo part of an assessment, the pillar scores and the overall narrative you had before are copied into a versioned history record before the new ones overwrite them.
Those snapshots are kept. A result you replaced is archived, not erased.
Third parties
We do not sell, rent or trade your personal information, and we do not hand it to advertisers or data brokers.
We do pass it to the suppliers that make the product work: the AI provider described above; the email service that delivers your invitation, password resets and notifications; and the hosting, database and file-storage providers our servers run on. Each processes it in order to deliver that service.
Beyond those, we disclose information only where the law requires it.
Cookies, drafts, and error reports
Signing in sets two first-party cookies that carry your session. They are httpOnly, so page scripts cannot read them, and they exist only to keep you signed in. There are no advertising or tracking cookies, and no third-party analytics.
Your in-progress assessment answers are also kept in your browser's local storage until they are saved to the server.
When something breaks in your browser, the error message, the stack trace and the page path are sent to our own servers so we can fix it. They go nowhere else.
How long we keep things
Your account and your assessment records last as long as your organisation's account with us, unless you delete them yourself or your administrator removes you.
The defaults our servers ship with: AI-call logs 90 days, cached evaluation results 30 days, browser error reports 90 days, and an unfinished anonymous-link session 14 days.
Superseded score and narrative snapshots are kept, as described above.
Your rights
If you have an account, you can act on your own data without asking anyone. Your profile page has a Download my data button that returns everything we hold about you as a single file, and a Delete my account button that erases your account and your personal data.
A few records outlive the account rather than disappearing with it: reviews you wrote and certificates you earned stay in place but stop being linked to you, and the security log keeps a dated note that the account was deleted. That is what lets an employer still verify a certificate you shared, and lets us show we honoured your request.
Two accounts cannot delete themselves from that button: a platform super admin, and the last remaining admin of an organisation. Deleting either would strand a whole organisation, so the platform refuses and names the one step that unblocks it.
Separately, your program administrator can remove you from their organisation. By default that anonymises your account in place and leaves your submissions attached to the anonymous record, so the program's aggregate numbers stay intact; they can also delete it outright.
For anything else — a correction, or data tied to an email address rather than to an account — email us and we will take care of it.
Children's privacy
Bvisionry is built for founders, programs, and institutions. Our services are not directed at children, and we do not knowingly collect information from anyone under 16.
Changes to this policy
This page describes how the platform behaves today. When that behaviour changes, we will update this page and revise the effective date above.
If you think a sentence here does not match what the product actually does, tell us. That is a defect, and we would rather hear it from you than not.
Questions?
If you have a question about this policy, want a correction, or think something here does not match what the product does, email hello@bvisionry.com.