Back to home

Privacy Policy

Last updated:

GrillRound ("GrillRound", "we", "us") provides an AI-assisted interview preparation platform. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

This policy is written to be accurate about what the product actually does rather than generically broad. If you find anything here that does not match your experience of the service, please tell us at privacy@grillround.com.

1. Who we are and who this applies to

GrillRound is the data fiduciary (under the Digital Personal Data Protection Act, 2023) and data controller (under the GDPR, where it applies) for the personal data described in this policy. The service is operated from India and is aimed primarily at software engineers preparing for technical interviews.

This policy applies to the GrillRound website at grillround.com, the authenticated application, and the remote MCP server that lets you access your own data from a compatible AI assistant. It does not apply to third-party services you choose to connect, which are governed by their own policies.

2. Information you give us

Most of what we hold is information you enter deliberately in order to get a personalised preparation plan. You control how much of it you provide; some features will not work well without it.

  • Account details — your name and email address, and an authentication identifier from Google or GitHub if you sign in that way.
  • Professional profile — your current role, current company, years of experience, technology stack, target track (for example backend or data engineering), target seniority, and optionally your LeetCode username.
  • Compensation information — your current annual compensation and your target compensation. We use these only to calibrate the intensity of your preparation plan. You may leave the target blank, and a current figure of zero is accepted.
  • Resume content — the text of your resume, whether you paste it or supply a PDF. A PDF is processed on your own device: the file itself is not uploaded to us and we do not store it. We receive and store only the extracted text.
  • Goals — your target companies, the kinds of company you are aiming at, and your intended preparation timeline.
  • Interview content you supply — job descriptions you paste, upload, or fetch by URL, and company and job-title details for a mock interview.
  • Interview patterns you contribute — recollections of questions asked at a company, which you may optionally submit. Please read the sharing section below before submitting these, as they are handled differently from your other data.
  • Notes and logged experiences — personal revision notes and records of real interviews you choose to log.
  • Support correspondence — anything you send us by email.

3. Information generated by your use of the service

Using the product creates records that are stored against your account so that your progress persists between sessions.

  • Your generated preparation roadmap, including weekly plans, tasks, and completion state.
  • Mock interview sessions, including the full conversation transcript, the question plan, scores, model answers, and written feedback. Transcripts are stored so you can review a past session; they are not used to train any model.
  • Practice session results, scores, and identified weak areas.
  • LeetCode statistics retrieved using the public username you provide.
  • Job listings matched to your profile, and whether you saved or dismissed each one.
  • AI usage records — for each AI call made on your behalf, the provider, model, token counts, and cost. This exists so you can see how much of your plan allowance a session used, and so that we can measure and control our own AI costs.

4. Information collected automatically

  • Standard server and request data, including IP address and browser user-agent. We use these to keep the service secure and to investigate abuse, and they are recorded in our security log.
  • Aggregate product analytics — page views and route performance. Our analytics provider is cookieless and does not build cross-site profiles or track you across other websites.
  • Error and performance diagnostics, collected by a third-party monitoring service when something goes wrong. These may include the page address, browser details, and your account identifier, so that we can reproduce and fix the fault.

5. How AI features are powered

AI features run on an API key that GrillRound holds with its AI provider. You do not supply a key, we do not ask you for one, and we no longer store one for you.

GrillRound previously ran on a bring-your-own-key model, in which each user supplied an encrypted key for Google, Anthropic, or OpenAI. That model has been withdrawn. Any key you saved under it has been deleted from our database.

Because the calls are made on our account rather than yours, we meter what each account uses. Your plan sets an allowance, and you can see what you have used in your settings. That metering is described in the AI usage records above.

6. How we use your information

  • To create and maintain your account and authenticate you.
  • To generate and update your personalised roadmap, mock interviews, feedback, and job matches.
  • To display your history, progress, and usage so the service is useful over time.
  • To send service and lifecycle emails (see the communications section below).
  • To operate, secure, debug, and improve the service, including rate limiting and abuse prevention.
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell your personal data. We do not use your content to train machine learning models. We do not serve third-party advertising.

7. Our legal basis for processing

Where the DPDP Act applies, we process your personal data on the basis of the consent you give when you create an account and provide each category of information, and for the legitimate uses that Act permits, such as security and legal compliance. You may withdraw consent at any time, as described in the rights section below; withdrawing it may make parts of the service unusable.

Where the GDPR applies, we rely on performance of a contract with you for the core service, your consent for optional items such as non-essential email, our legitimate interests in securing and improving the service, and legal obligation where relevant.

8. Community-contributed interview patterns

This section describes the one place where something you submit may be shown to other users. Please read it before contributing interview patterns.

When you optionally submit a recollection of questions asked at a company, we review it for plausibility. Submissions that pass may be combined with submissions from other users into a shared profile for that company and role, which is used to make mock interviews more realistic for anyone preparing for it.

What may be shared with other users is limited to anonymised, AI-paraphrased summaries of question themes and aggregate counts. Your name, email, account identifier, resume, compensation, and any other profile data are never attached to a shared profile and are never shown to another user. We do not publish verbatim submission text.

This is entirely optional. If you never submit an interview pattern, nothing you provide is ever shared with another user. If you have submitted one and want it withdrawn, email privacy@grillround.com and we will remove it and re-derive the affected shared profile.

9. Who we share data with

We do not sell, rent, or trade your personal data. We do use a small number of infrastructure and service providers who process data on our behalf under their own terms and security commitments.

  • Cloud infrastructure providers, for hosting the application, running our database and authentication, executing background jobs, and caching. These hold the account and application data described above.
  • A monitoring provider, for error and performance diagnostics.
  • An email delivery provider, for the emails described below. This receives your name and email address only.
  • Our AI provider, currently Anthropic, which processes the content of your AI requests as described immediately below.
  • Google or GitHub, if you choose to sign in with one of them, which receive only what is needed to authenticate you.

Our AI provider is a special case worth being explicit about. When you use an AI feature, the relevant content — which may include your resume text, a job description, and your interview answers — is sent to that provider under our commercial account. It is processed to return the response and is not used to train their models. Because the account is ours rather than yours, you cannot choose the provider or opt out of the transmission and still use an AI feature; if that matters to you, the non-AI parts of the product — your roadmap, notes, history and job matches — work without it. We will name the current provider and link its policy on request.

We may also disclose data where we are legally required to, or where it is necessary to investigate suspected abuse or protect the rights and safety of our users. If GrillRound is ever involved in a merger, acquisition, or sale of assets, your data may transfer to the acquirer, and we will notify you before it becomes subject to a materially different policy.

10. Cookies and local storage

We use only the cookies needed to run the service. We do not use advertising or cross-site tracking cookies, and our analytics provider is cookieless.

  • Essential cookies that keep you signed in and protect your session. Without these you cannot use an account.
  • Storage on your own device, used to preserve drafts of an in-progress mock interview or note so that reloading the page does not lose your work, and to remember preferences such as your chosen interview voice. This stays on your device and is not transmitted to us.

11. Voice features

Mock interviews can be conducted by voice. GrillRound does not receive, process, or store any audio at all — only the resulting text becomes part of your session transcript.

One thing you should know, because it is not obvious: speech recognition is performed by your web browser, and some browsers do this in the cloud rather than on your device. Google Chrome, for example, sends captured audio to Google for transcription. That happens between you and your browser vendor under their privacy policy, not ours, and we never see it. If you would rather no audio left your device at all, use the typed input mode, which is available throughout.

12. Emails we send

We send a small number of email types, and only these.

  • Account and security email, such as sign-in links and verification codes. These are required to operate an account and cannot be turned off while it is active.
  • A one-time welcome email.
  • A limited number of setup reminders, sent only while your setup remains incomplete.
  • A weekly progress digest, once you have completed onboarding.

Every non-transactional email carries a one-click unsubscribe link that works without signing in. You can also change your preference in settings. Opting out stops all non-transactional email; we do not run separate marketing lists and we do not share your address with any advertiser.

13. Administrative access to your account

We would rather you knew this than discovered it. A small number of authorised staff can view your account in read-only mode, in order to investigate a problem you have reported or suspected abuse of the service.

The access is strictly read-only: nothing in your account can be altered through it. It is time-limited, individually authenticated, and every use is recorded in an audit log that we review. We do not use it routinely, and never for marketing or analytics.

14. Data retention

  • Account and application data is retained for as long as your account exists, because its purpose is to give you a preparation history that persists.
  • If you do not sign in for three consecutive years we will treat the purpose as served: we will email the address on your account and, unless you sign in or ask us to keep the account, erase your personal data.
  • AI usage records are retained for as long as your account exists, because they are what your plan allowance is measured against.
  • Error diagnostics are retained by our monitoring provider on its standard retention schedule, typically ninety days.
  • Audit and security logs are retained for up to twenty-four months so we can investigate abuse.
  • Anonymised, aggregated interview patterns contributed to a shared company profile may be retained after your account is deleted, because they no longer identify you. You can ask us to remove your specific contributions before deletion.

15. Your rights and how to exercise them

Under the DPDP Act you have the right to access a summary of the personal data we process about you, to have inaccurate data corrected or completed, to have your data erased, to nominate another person to exercise these rights if you die or become incapacitated, and to a grievance redressal process. Where the GDPR applies you additionally have rights to restrict or object to processing and to data portability.

You can update most of your profile, goals, and resume yourself in settings at any time.

To request a copy of your data, or deletion of your account and all its data, email our support team at support@grillround.com — or privacy@grillround.com if you prefer — from the email address associated with your account. We will acknowledge within seven days and complete the request within thirty days. We will tell you if anything must be retained for a legal reason and why. Deletion is permanent and cannot be reversed.

Deletion is handled by our team on request rather than by a button in settings. This is deliberate: erasure is permanent, so we confirm the request genuinely came from the account holder before acting on it.

16. Security

We take the security of this data seriously, particularly because it includes resumes and compensation figures.

  • All traffic is served over HTTPS, with strict transport security and a content security policy.
  • Every database table enforces row-level security, so one account cannot read another account data.
  • Our own AI provider credential is held as a server-side secret, is never sent to the browser, and is never logged or included in an error report.
  • Administrative access is separately authenticated, tightly scoped, rate limited, and fully audit logged.
  • Requests are rate limited to limit abuse and credential-stuffing.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a personal data breach we will notify each affected user and the Data Protection Board of India without delay, and provide the Board with the detailed report the DPDP framework requires within seventy-two hours. If you believe you have found a vulnerability, please report it to security@grillround.com rather than disclosing it publicly, and we will not pursue action against good-faith security research.

17. Where your data is processed

Our providers operate globally, and your data may be processed on servers outside India, including in the United States and the European Union. Under section 16 of the DPDP Act, transfer outside India is permitted except to territories that the Central Government restricts by notification; we will comply with any such notification. Where the GDPR applies, transfers outside the European Economic Area rely on standard contractual clauses or an equivalent safeguard offered by the provider concerned.

Every provider we use processes personal data only on our instructions and under a written contract. We remain responsible to you for how they handle your data. We will name any of them on request — write to privacy@grillround.com.

18. Children

GrillRound is a professional tool for people preparing for software engineering roles. It is not directed to children, we do not market it to children, and we do not knowingly collect the personal data of anyone who is a child under the law that applies to them.

We do not carry out behavioural tracking, behavioural monitoring, or targeted advertising, for any user. We do not operate a parental-consent mechanism, so if we learn that a child has created an account we will erase their personal data. If you believe a child has provided us data, contact privacy@grillround.com and we will act promptly.

19. Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we use or share your personal data, we will notify you by email or with a prominent notice in the application before it takes effect, and where the law requires it we will ask for your consent again.

20. Contact and grievance redressal

This policy doubles as the notice required under section 5 of the DPDP Act. On request we will provide it in English or any language listed in the Eighth Schedule to the Constitution of India. Where a registered Consent Manager is available to you, you may also give, manage, review, or withdraw your consent through it.

For any privacy question, request, or complaint, contact our Grievance Officer at privacy@grillround.com. We will acknowledge within seven days and respond substantively within thirty days, and in any event within the period the DPDP framework prescribes.

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India, or with your local supervisory authority if you are in the European Economic Area or the United Kingdom.

For general support that is not privacy-related, email support@grillround.com.