Privacy
Last updated: 26 August 2026
caiscore.com runs the CAI Score API. This page explains what we collect when you use the website or the API, why we collect it, and what you can do about it.
Australian privacy law currently exempts businesses under a $3 million annual turnover, and caiscore.com is below that threshold. We follow the Australian Privacy Principles anyway, as a voluntary commitment. Where this page describes a right, we will honour it whether or not the law obliges us to.
What we collect
Usage analytics. Every page on this site loads Cloudflare Web Analytics. It records page views, referrers, and coarse performance and location data. It sets no cookies and writes nothing to your browser's storage. We use it to see which pages are read and which are ignored — nothing on this site is personalised to you, and nothing is sold or shared with advertisers.
Request logs. Calls to the API are logged server-side by Cloudflare. Those logs include the calling IP address, the path, the response status, and the time. They are retained for Cloudflare's short default retention window for Workers Logs and then discarded automatically. We use them to debug failures and to identify abuse.
API keys. When a key is issued we store a one-way hash of it, the tier it belongs to, and the time it was created. We do not store the key itself, and we cannot recover it or show it to you again. Getting a key requires no name, no email address, and no password. A key is not an account and is not linked to your identity.
The bot challenge. The key page runs a Cloudflare Turnstile challenge to distinguish people from scripts. Cloudflare processes that challenge on its own terms and may set its own storage in your browser to do so. We receive only the result — pass or fail.
Assessment answers. Scoring is stateless. When you send five behavioural answers and a role roster to the API, we score them and return the result; the answers are not written to any store. Where you use a feature that saves your assessments — stored history, or the in-product analytics view that lets you chart and drill into past results — those answers and their results are retained against your key so that we can show them back to you. Using the scoring endpoint on its own stores nothing.
How we collect and hold it
We collect analytics through a script that runs in your browser, and everything else through the API request itself. There is no third-party tag manager, no advertising pixel, and no data broker in the path.
Everything is held on Cloudflare's infrastructure. Keys are held as hashes, so a breach of our storage does not disclose a working credential. We do not run our own servers or databases.
This site writes two things to your browser, both of them preferences: your light/dark theme choice, and which language tab you last used in the quickstart. Both are stored locally so the page comes back the way you left it. Neither is sent to us, and there is no cookie banner, because there are no cookies to consent to.
Why we collect it
- Analytics — to understand which parts of the site are useful.
- Request logs — to debug failures, enforce rate limits, and stop abuse.
- Key records — to authenticate calls, apply the right rate limit, and revoke a key that breaches the terms.
- Saved assessments, where you use that feature — to show you your own history and let you analyse it.
We do not use any of it for advertising, profiling, or scoring individuals, and we do not sell or rent it.
Automated decisions
The API produces its output automatically. It takes five behavioural answers and a roster of roles or an industry, derives three parameters from them, and returns a score, a zone, and rule-based suggestions. No person reviews a result before you receive it.
caiscore.com does not make decisions about anyone. We do not assess individuals, rank employees, or advise anyone on hiring or termination. A score describes a way of working, not a person's worth or competence.
If you use the API in your own organisation, a score, zone, or suggestion must not be the sole basis for a decision about a person's employment, engagement, or pay. Those decisions are yours, they need human judgement and context the API does not have, and you are responsible for them.
Access and correction
Write to privacy@caiscore.com and we will tell you what we hold and correct anything that is wrong.
Two honest limits. A key is anonymous by design, so to reach anything held against it you will need to quote the key — we have no other way to connect it to you. And request logs are keyed to IP addresses and expire on their own schedule, so for those we can usually only confirm what is collected rather than retrieve your specific rows.
Complaints
If you think we have mishandled your information, write to privacy@caiscore.com. We will acknowledge your complaint and respond with what we found and what we intend to do about it.
If our response does not resolve it, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au. You do not need our permission to do that, and you can go to them directly if you would rather not come to us first.
Data held overseas
Our infrastructure provider is Cloudflare, Inc., based in the United States, and it operates a global network. Analytics data, request logs, key records, and any saved assessments are held and processed by Cloudflare, and are likely to be accessible from the United States and from other countries where Cloudflare operates data centres.
We remain accountable for how that information is handled. There are no other overseas recipients — no analytics vendor, no advertising network, and no subprocessor beyond Cloudflare.
Data breaches
If information we hold is exposed in a way likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, and we will say plainly what happened and what to do about it.
Changes to this page
If what we collect changes, this page changes with it and the date at the top moves. The version published here is the current one.
Questions: privacy@caiscore.com