What changed on 8 October 2026
- Sign-in: there is no password. You sign in with Google or a one-time code, and the lines that described a stored password and resetting it are gone.
- Added Resend (email) and Firecrawl (reading web pages) to the service providers.
- Added a section on applying to employers: AI screening interviews, VERA, an employer reading the links you gave, SCOUT, and your record if your employer uses insiderOne People.
- VERA: the list names only the sources VERA reads today.
Updated 3 October 2026: this policy now correctly names Aurist Private Limited, of North Lakhimpur, Assam, India, as the data controller for every user.
1. Who we are
Aurist Private Limited ("we", "us", "our") is the data controller for every user, wherever they are. It is a company incorporated in India with its registered office in North Lakhimpur, Assam, India, and it owns and operates the insiderOne Career OS platform available at www.insiderone.in and related mobile applications. insiderOne SI and insiderOne Career OS are brands of Aurist Private Limited.
The company is founded and led by Bishnu Dev Changkakoti, Founder and Chief Executive Officer.
General enquiries, and privacy or data protection enquiries including requests to exercise your rights: contactus@insiderone.in
2. What data we collect
We collect information you provide directly and information generated through your use of CareerOS:
- Account data: name, email address, profile photo, date of registration. You sign in with Google or with a one-time code we email you; there is no password.
- Career profile data: your career aspirations, skills, work experience, education, projects, and self-descriptions you enter into the platform.
- Assessment data: responses to career assessments, IOPC scoring inputs, interview simulation transcripts, and SI-generated insights about your career profile.
- Usage data: pages visited, features used, session duration, device type, browser, IP address, and referring URL.
- Communications: messages you send to our support team or feedback you submit.
We do not collect payment card information directly. Any payments are processed by third-party providers subject to their own privacy policies.
3. How we use your data
We use your data to:
- Provide and personalise the CareerOS platform, including ZENOR-Æ SI recommendations.
- Generate your Career DNA, iOPC score, Career Blueprint, and Career Identity card.
- Match you with relevant job opportunities, internships, and learning resources.
- Improve our SI and platform features using aggregated and de-identified data.
- Send transactional emails (sign-in codes, account verification, important platform updates).
- Send product and feature updates if you have opted in.
- Comply with our legal obligations under the Information Technology Act 2000, IT (Amendment) Act 2008, and applicable data protection laws.
4. SI processing and your career data
Super Intelligence (SI) is insiderOne's name for the automated features in the product. They run on third-party AI models, currently Google's Gemini. In practice, CareerOS uses large language models (LLMs), currently Google's Gemini models, to generate career insights, simulate interviews, and produce recommendations. When you interact with ZENOR-Æ or trigger SI features:
- Relevant portions of your career profile are sent to the AI model to generate personalised responses.
- We do not use your personal career data to train third-party AI models unless you explicitly consent.
- SI-generated content is not a substitute for professional career advice.
- You can delete your profile data at any time, which removes it from future SI processing.
SCOUT and VERA: where employers' agents find and check people
Employers on insiderOne can use SCOUT, an AI sourcing agent, to find people for a role, and VERA, an AI evidence agent, to check what an application says. A person at the employer makes every decision. These are the places they read:
Where SCOUT looks for people
- insiderOne members and your past applicants: Skills verified by evidence; people who applied to you before. SCOUT may email someone it finds here, with a way to stop it.
- GitHub: Public code by language and topic. Never emailed from GitHub data. SCOUT never writes to someone found here; the company decides whether to.
- GitLab: Owners of public projects on a topic. SCOUT never writes to someone found here; the company decides whether to.
- Stack Overflow: Top answerers on a tag, with their stated location. SCOUT never writes to someone found here; the company decides whether to.
- Hugging Face: Authors of public models and spaces on a topic. SCOUT never writes to someone found here; the company decides whether to.
- DEV Community: People writing about the skill, with their own links. SCOUT never writes to someone found here; the company decides whether to.
- OpenAlex (research): Authors of cited work on the topic, by country. Profile link only. Nobody found here is contacted.
- ORCID (research): Researchers by keyword and country. Profile link only. Nobody found here is contacted.
- Product Hunt: Makers of launched products on a topic. SCOUT never writes to someone found here; the company decides whether to.
- Bluesky: People whose own profile says what they do and where. Open to anyone, for any kind of work. SCOUT never writes to someone found here; the company decides whether to.
- Hacker News, people asking to be hired: The monthly "who wants to be hired" thread, where people post what they do and want work. SCOUT never writes to someone found here; the company decides whether to.
- Open web: Portfolios, personal sites and speaker pages. LinkedIn is never searched. SCOUT never writes to someone found here; the company decides whether to.
- People Data Labs (licensed): A licensed people index, searched by skill, title and location. Costs per match. SCOUT may email someone it finds here, with a way to stop it.
Some of these, including the licensed people index, are searched only while insiderOne has an account or key with them switched on. Each person SCOUT finds is shown to the employer with the source they came from. SCOUT emails people from the licensed index only in the United States.
What VERA reads, only when you agree or the employer orders a check
- The insiderOne record: skills proved on insiderOne, the screening, the panel, the dated work history.
- Current-employer code: that they work where they say they work now, when the address is at a domain known for that employer.
- References at work addresses: past jobs, titles and dates, from someone at a domain known for that company who isn't the candidate.
- EPFO passbook, read once: what the candidate's own passbook lists, employers and months, shown as their upload and never as proof.
No paid verification provider, such as a background-check company, is connected today. If one is, it will be named here and in the list of service providers before VERA reads from it.
An EPFO passbook you upload is read on our behalf by Google's Gemini model, on Google's servers outside India, for the employer names and months on it. We don't keep the file.
When you apply to an employer, or work for one
Employers use insiderOne for Employers to hire and to run their teams. When you apply to one, it controls your application and we process it on its behalf, under the employer site's privacy notice. What employers see shows what reaches them. Depending on the role:
- Screening interview. The employer may invite you to a timed interview run by an AI interviewer. Spoken answers are turned into text, and an AI model marks each answer against the role's requirements. The employer sees the questions, your answers and the marks, but no audio. On a New York City role without a current bias audit, the employer sees no mark. You can ask for more time, another format or a person instead before you start, and contest a mark on your report.
- VERA. An AI evidence agent compares your application with what has been confirmed, may ask you for evidence, and gives the employer a summary with no score. You can answer a flagged question before the employer reads it, withdraw what you added, and no background check runs without your yes.
- Your links. Someone at the employer can ask what the links in your application show. Your GitHub is read through its public API and other pages through Firecrawl, and an AI model lists what they show for and against the role's requirements. It gives no score.
- SCOUT. An employer's sourcing agent may have found you in the sources listed above. Its first email says where your details came from, with a link to see what is held and delete it, and one click stops all employer cold outreach to you on insiderOne.
A person at the employer makes every hiring decision; nothing here turns you down on its own. See who answers for our SI for each system and how to contest it.
If your employer uses insiderOne People. Your employer keeps your employee record and controls it. In your employer's employee portal you can see your record and give the pay details your employer asks for: in India your PAN, bank account and IFSC, and UAN; in the UAE your IBAN, bank routing code and labour-card personal number. Attendance records check-in and check-out times only. Questions about your record go to your employer; if you write to us, we pass them on.
5. Data sharing
We do not sell your personal data. We share data only in these circumstances:
- Service providers: Supabase (database and authentication), Cloudflare (hosting and CDN), Google (Gemini AI models), Resend (sending email), Firecrawl (reading web pages: links and documents you give as proof, and the links in an application when an employer asks what they show), where configured OpenRouter (an alternative route to AI models) and AssemblyAI (speech-to-text), and analytics tools. Each is bound by a data processing agreement.
- Employers you apply to: your application and what the section above describes. Private sections of your profile stay private.
- Public Career Identity: if you share your Career ID or public profile link, the data displayed on that page is publicly accessible to anyone with the link.
- Legal requirements: if required by Indian law, court order, or government authority.
- Business transfers: in the event of a merger or acquisition, with appropriate notice to you.
6. Data retention
We retain your account data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g. fraud prevention).
Forms and bug reports. When you fill in a form on insiderOne (for example to become a Founding Tester, book a college session or report a bug), we store only the answers the form asks for, the time you gave consent, the page that brought you to us, and a one-way hash of your IP address used to stop spam (the address itself is not stored). Uploaded files are kept privately and seen only by our team. We use these answers to review your request and reply to you, and keep them for up to 24 months or until you ask us to delete them, whichever is sooner. To have a submission deleted, email contactus@insiderone.in.
7. Your rights
You have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: update or correct inaccurate data (most data can be updated directly in your profile settings).
- Deletion: request deletion of your account and personal data.
- Portability: request your career data in a machine-readable format.
- Opt-out: unsubscribe from marketing emails at any time via the link in any email or by contacting us.
To exercise any right, email contactus@insiderone.in. We will respond within 30 days.
8. Cookies
We use essential cookies for authentication and session management, and optional analytics cookies to understand how people use CareerOS. See our Cookie Policy for full details.
9. Security
We implement industry-standard security measures including TLS encryption in transit, sign-in without passwords (Google or a one-time code), row-level security on our database, and regular security reviews. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Children's privacy
CareerOS is intended for users aged 16 and above. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us immediately at contactus@insiderone.in.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the platform. Continued use of CareerOS after changes take effect constitutes acceptance.
12. Grievance Officer
Under the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, complaints about the platform, its content or how your data is handled can be sent to our Grievance Officer:
Bishnu Dev Changkakoti, Founder and Chief Executive Officer
Email: contactus@insiderone.in (please put "Grievance" in the subject)
We acknowledge a complaint within 24 hours and resolve it within 15 days of receiving it. Tell us who you are, what the complaint is about, and where on the platform it happened, so we can act on it.
13. Contact
Aurist Private Limited
North Lakhimpur, Assam, India
General, privacy and data rights: contactus@insiderone.in