> ## Documentation Index
> Fetch the complete documentation index at: https://docs.exterview.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy & Residency

> Privacy posture and data residency in Exterview, including regional hosting, retention windows, deletion workflows, and candidate consent handling.

## Purpose

How Exterview handles personal data across the evaluation lifecycle, with consent, minimization, and your control over where data lives and how long it stays.

## Privacy principles

<CardGroup cols={2}>
  <Card title="Consent" icon="handshake">
    Candidates are informed, and consent is captured where required.
  </Card>

  <Card title="Data minimization" icon="filter">
    Only what's needed for the evaluation is collected and processed.
  </Card>

  <Card title="Retention" icon="calendar-days">
    Data isn't kept indefinitely. We're working out clear retention rules for
    every type of data.
  </Card>

  <Card title="Deletion" icon="trash-can">
    Deletion requests are honored. We're finishing a fully centralized process for
    handling them.
  </Card>

  <Card title="Residency" icon="globe">
    Regional hosting options support data-residency requirements.
  </Card>

  <Card title="Purpose limitation" icon="bullseye">
    Data is used for evaluation, not sold, and not pooled into a shared model.
  </Card>
</CardGroup>

<Info>
  Residency regions are set in your configuration. Retention windows are not yet
  configurable — see below. Exterview aligns its handling with applicable
  data-protection regimes; see [Compliance FAQs](/trust/compliance-faqs).
</Info>

## Models and sub-processors

Exterview's agents and Smaya run on a mix of frontier and open-source models, and specific platform capabilities are delivered through third-party sub-processors. Both lists have dedicated pages, kept current and dated: see [Models We Use](/trust/models) and [Sub-processors](/trust/sub-processors). Your candidate and configuration data is never sold or used to train shared or third-party models.

## FAQs

<AccordionGroup>
  <Accordion title="Do you sell or share candidate data?">
    No. Data is used to run your evaluations and is never sold or pooled into a shared model.
  </Accordion>

  <Accordion title="How long is data kept?">
    It isn't kept indefinitely, but a configurable retention period isn't
    available yet. We're working out clear retention rules for every type of data;
    ask your Customer Success contact about interim handling until that work is
    complete.
  </Accordion>

  <Accordion title="Can a candidate's data be deleted?">
    Yes, deletion requests are honored, in line with applicable law. We're
    finishing a fully centralized process for handling these requests consistently
    across all data types.
  </Accordion>

  <Accordion title="Where is our data stored?">
    In the region you select during setup, to support residency requirements.
  </Accordion>
</AccordionGroup>

## Related

<CardGroup cols={2}>
  <Card title="Security" icon="lock" href="/trust/security">
    How access, encryption, and isolation are enforced.
  </Card>

  <Card title="Responsible AI" icon="user-check" href="/trust/responsible-ai">
    How candidate data is scored, and never used for biometrics.
  </Card>
</CardGroup>
