Privacy Policy

Last updated: July 20, 2026. Discover how we safeguard your source code, authentication credentials, and session transcripts.

Source Code Security & Zero-Cloning Ingestion

GitGrilled operates on a strict zero-retention model for raw source code. During codebase scanning, our ingestion worker parses the file tree and fetches targeted manifests or high-value source files. These files are processed entirely in-memory and are never written to disk or cloned persistently.

Only structural briefs (analysis_brief JSON) containing high-level architectural topologies, dependency manifests, and line references are stored securely in Cloudflare D1 to provide context for your interview plans.

Data We Collect & Store

Account Info: Name, email address, and profile pictures provided via Firebase Authentication (Google / GitHub OAuth).

Encrypted Tokens: GitHub OAuth tokens are encrypted using AES-GCM prior to storage in Cloudflare D1 and are used solely to fetch repositories on your behalf with explicit consent.

History & Transcripts: Textual transcripts, AI-generated critique scorecards, category rubrics, drill results, and overall practice metrics.

Audio & Voice Streaming Policy

All live rounds use a real-time WebSocket proxy managed by Cloudflare Durable Objects connecting to Google Gemini Live API.

Raw PCM16 microphone audio streams are processed live in-flight and are never saved to disk or stored in our database. Only textual transcripts derived during the conversation are saved to your session history.

Your Controls & Instant Data Purge

You can delete any individual session from your History dashboard at any time, permanently purging its transcript, scorecards, and AI critiques from D1.

You can execute a complete data purge from your Settings page, instantly erasing your user profile, uploaded resumes, encrypted tokens, and full session history from our database.