Privacy Policy

Last updated: 20 September 2026

This policy explains what Intervues Mentors collects, who it is shared with, how long it is kept, and what control you have. It names the third parties involved rather than describing them vaguely.

Who is responsible

Intervues is operated by an independent developer based in India. For data protection purposes we are the controller for the account data described below.

You can reach us at admin@intervues.club for any question, request, or complaint about your data.

What we collect

Account data. Your GitHub username, display name, email address, avatar URL, and the GitHub access token we hold so we can act on your behalf. Tokens are stored encrypted.

Repository data. For repositories you connect: the repository name, visibility, default branch, capability settings, branch and commit metadata, pull request titles, descriptions, changed files and the code diffs themselves, plus review comments and check results.

Project data. Projects you create, tasks and acceptance criteria, board state, join requests, team membership, and status reports.

Usage and diagnostics. Error reports, request identifiers, and step-level records of background jobs, used to debug failures. These can include a route path, an error message, and a stack trace.

Analytics and session recording — only if you consent. Microsoft Clarity records how you interact with pages, which can include mouse movement, clicks, scrolling and page content. Google Analytics and Cloudflare Web Analytics record aggregate usage. None of these load until you accept them in the cookie banner, and you can change your mind at any time.

Your code is sent to Google

We want this to be impossible to miss, because it is the least obvious thing we do.

When a pull request is opened on a connected repository, we send the changed files — the actual source code diff — to Google's Gemini API so it can generate a review against the task's acceptance criteria. We do the same when generating a project task plan from a repository, when producing contribution guidance, when producing a project status report, and when preparing a task study brief (which sends the task text and the assignee's recorded skill names).

This applies to private repositories as well as public ones. If you connect a private repository, its code leaves our systems for Google's.

Google processes this content under its own API terms. We do not use your code to train our models, and we do not authorise it to be used to train anyone else's.

If that is not acceptable for a given repository, do not connect it. There is currently no way to use the project features while opting out of automated review.

Who else receives data

GitHub — we read repository, pull request and user data through the GitHub API and our GitHub App, and we write check runs, reviews and comments back to your repository.

Supabase — our database and authentication provider, where account, project, and repository data is stored.

Vercel — our hosting provider, which processes request data in the ordinary course of serving the site, and provides cookieless aggregate analytics.

Google — Gemini for the automated features described above, and Google Analytics if you have consented.

Microsoft — Clarity session recording, if you have consented.

Cloudflare — privacy-focused aggregate web analytics, if you have consented.

We do not sell your data. We do not share it with advertisers or data brokers.

Why we process it

To operate the service you asked for: authenticating you, connecting repositories, generating plans and reviews, and tracking project progress. Our basis is performance of our agreement with you.

To keep the service working and secure: diagnosing errors, preventing abuse, and enforcing usage limits. Our basis is our legitimate interest in a service that functions.

To understand usage through analytics and session recording. Our basis is your consent, which you give in the cookie banner and can withdraw at any time.

To comply with law where we are required to.

How long we keep it

Account and project data: while your account is open. If you delete your account, we delete your personal data within 30 days, except anything we must keep for legal or accounting reasons.

GitHub access tokens: until you disconnect GitHub or delete your account. Short-lived installation tokens are purged automatically once expired.

Webhook delivery records: 30 days.

Background step and diagnostic records: 14 days.

Error reports: retained until resolved and then periodically cleared.

Analytics and session recordings are retained by Microsoft, Google and Cloudflare under their own schedules, which we do not control.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data, and to receive a copy in a portable form. If you are in the EU or UK you have these rights under the GDPR; if you are in India, under the Digital Personal Data Protection Act, 2023.

To exercise any of them, write to admin@intervues.club. We will respond within 30 days. You will not be charged, and we will not degrade your access for asking.

You can withdraw analytics consent at any time from the cookie banner without affecting anything you did before.

If you think we have handled your data badly, you may complain to your local data protection authority. We would rather you told us first so we can fix it.

International transfers

We are based in India and our providers operate globally, so your data will be processed outside your country, including in the United States and the European Union.

Where required, we rely on the transfer mechanisms our providers make available, such as standard contractual clauses.

Security

We use encryption in transit, encrypted storage for access tokens, row-level access controls in our database, and least-privilege access internally.

No system is perfectly secure. If a breach affects your personal data and poses a real risk to you, we will tell you and the relevant authority as required by law.

Children

The service is not intended for anyone under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

Changes

We may update this policy as the product changes. Material changes will be posted here with a revised date.

Contact

Questions, requests, or deletion: admin@intervues.club