Minimaly is an independently operated software service (Minimaly, we, us, or our). Minimaly is responsible for website, account, waitlist, and support data. When we handle interview or room data for an organiser, the organiser decides how that data is used, and the organiser's own privacy notice also applies. For privacy questions or requests, email privacy@minimaly.io.
1. Information we collect
We collect only information needed to operate and secure the Service:
- Information you provide: account and profile details, workspace information, support messages, and feedback.
- Interview and room data: participant names and roles, shared code, text, whiteboards, collaboration events, playback, timestamps, and limited in-browser activity signals such as focus or tab changes, paste length, an excerpt of up to 1,024 characters from text pasted from outside the room, copy-all events, and fast-typing signals. These signals provide context only, may be incomplete or inaccurate, and do not prove misconduct. We do not record audio, video, webcam feeds, biometric identifiers, or system-wide keystrokes.
- Waitlist data: full name, work email, company, role, approximate interview volume, and any optional message you submit. We also create a random request reference and delivery-status fields.
- Technical data: IP address, approximate country, browser and device information, request and security logs, session details, and anti-abuse results. For the waitlist, the raw source IP is used transiently for abuse checks and is stored only as a salted one-way hash in the waitlist database.
- Device storage: necessary cookies and local storage used to keep you signed in, remember preferences, and preserve room access or local notes.
Our service providers may process basic website usage, network, and security information to provide hosting, analytics, and protection against automated abuse. We do not use advertising cookies or cross-site behavioural advertising.
2. Google Sign-In
When you choose Continue with Google, Minimaly requests only the basic openid, email, and profile scopes. Google and our authentication provider give us an account identifier, your verified email address, your name, and your profile image or image URL, if available.
We use this information only to authenticate you, create and maintain your Minimaly account, display and update your profile, prevent abuse, and provide support. We store it with your account and disclose it only to service providers that operate authentication, hosting, and security, or when required by law.
Minimaly does not receive your Google password and does not access Gmail, Google Drive, Google Calendar, contacts, or other Google product content. We do not sell Google user data, use it for advertising, train general-purpose AI models with it, or use it to make automated hiring or eligibility decisions.
You can revoke Minimaly's access from your Google Account connections. Revocation stops future Google access but does not automatically delete information already stored in your Minimaly account. To delete that information, email privacy@minimaly.io.
Minimaly's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
3. How we use information
We use personal information to:
- authenticate users and provide accounts, rooms, collaboration, and playback;
- secure the Service, prevent spam and abuse, and diagnose errors;
- respond to support, feedback, and waitlist requests and send related service emails;
- maintain and improve the Service; and
- comply with law, enforce our Terms, and protect users and the Service.
We do not sell personal information, use interview data for advertising, or independently assess whether someone should be hired.
We use information when it is needed to provide the Service you request, keep the Service and its users secure, improve the Service responsibly, meet our legal obligations, or for a purpose you have agreed to. You may withdraw your agreement at any time without affecting earlier use of your information.
5. Retention and deletion
We keep information only as long as reasonably needed for the purposes above. Current default limits are:
- We keep Google Sign-In and other account profile data while the account is active. After a verified deletion request, we delete or de-identify it within 30 days unless limited retention is required by law or for an unresolved security issue.
- Active sign-in sessions last up to 30 days. Metadata for expired or revoked sessions may be kept for up to 90 days.
- Closed anonymous rooms and playback are kept for up to 72 hours. Closed rooms linked to an account are kept for up to 7 days under the current free plan.
- Waitlist submissions are kept for up to two years. The salted IP hash stored with a waitlist request is removed after 7 days. Security, Turnstile, email-delivery, and other provider-held logs follow the relevant account settings, provider terms, and any retention required for security or law; they are not deleted by the waitlist database's nightly sweep.
- Information stored only in your browser remains until the Service removes it or you clear the site's data.
Data may be deleted sooner when it is no longer needed, when you close an account, or for security, capacity, or legal reasons. Backups and records required by law may take longer to expire.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal information. You may also have the right to withdraw consent and not to be subject to a decision with legal or similarly significant effects based solely on automated processing. Minimaly does not make such automated decisions.
Email privacy@minimaly.io to make a request. We may need to verify your identity. We normally respond within one month. Where permitted, a complex request may take up to two additional months, and we will tell you why. Requests are normally free. Where permitted, we may charge a reasonable fee or decline repeated or abusive requests.
For data controlled by an interview organiser, the organiser is normally responsible for your request. We may forward the request or help identify the relevant room. You may also complain to the data-protection authority where you live or work.
You can clear cookies and local storage in your browser, but doing so may sign you out or remove access to an anonymous room.
7. Security and international transfers
We use reasonable technical and organisational safeguards designed to protect personal information. No online service can guarantee complete security. Keep account credentials and room links private, and report suspected vulnerabilities or compromised access to security@minimaly.io.
Our service providers may process personal information in the European Economic Area and in other countries, including the United States. Where required, we use recognised protections for information transferred between countries.
8. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal information. Users must be at least 18 to create an account or host a room. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
9. Changes and contact
We may update this Policy as the Service or law changes. We will update the date above and provide additional notice for material changes where appropriate.
Service operator: Minimaly, an independently operated software service. Privacy and data-rights contact: privacy@minimaly.io.