NexPath - Career Assessment & Guidance Platform

What the AI sees, and what it does not

Exactly which participant data reaches the AI provider, what is removed first, and what is stored afterwards — for when a parent or a data protection officer asks.

3 min read · Checked against the product on 2026-08-13

You will be asked this by a parent, a head teacher, or a data protection officer. This article is written so you can answer precisely rather than reassuringly.

The scoring is not AI

A participant's assessment is scored by a deterministic, rule-based engine. The numbers that produce their profile and their occupation matches are arithmetic, not a model. The same answers always produce the same profile.

AI is used for two things only: putting already-computed results into readable language, and powering the counselor assistant. The AI never performs or alters scoring, so no participant's results depend on a model's output.

What is removed before anything is sent

Before a request leaves NexPath, direct identifiers are stripped:

  • first name and last name
  • username
  • email address — including the part before the @, because [email protected] gives away a name even with the domain removed

This applies to everything in the request, including free text you or the participant typed. When the answer comes back, the real name is restored on our side, so what you read on screen is normal.

What is sent

So the provider receives a profile with no name attached to it:

  • the participant's assessment results, including their scores
  • their age, and gender where recorded
  • education level and field of study, where recorded
  • occupations under discussion and their reactions to them
  • the conversation itself

Age is sent deliberately, and it is worth understanding why: advice for a 14-year-old and advice for a 45-year-old are not interchangeable, and the value of getting that right is judged to outweigh the risk of an age travelling with no identifier attached to it.

What is never sent

  • Names, usernames and email addresses (see above)
  • Your private notes — the AI has no access to them at all
  • Any other organisation's data

Where it goes

Requests are handled by a third-party AI provider under contract as a sub-processor. The current provider and the routing are listed in the Trust Center, which is the authoritative place — a help article would go stale.

Participant data is not used to train AI models. That is true of NexPath — we do no training, no fine-tuning, and build no model from participant data — and the provider account is configured so that data sent to it is not used for training either.

What is stored, and for how long

Conversations with NexPilot are stored so the assistant can pick up where you left off, and so there is a record of what was said.

Anything stored about a participant, including AI conversations, is included when you export their data, and is deleted when you erase them. See Deleting and exporting data.

What it costs

NexPilot conversations draw on your organisation's AI balance. See NexPilot.

← All help articles