Privacy Policy
Last updated: 21 July 2026This page explains what personal data Interview Radar collects, why, where it is stored, how long we keep it, and the rights you have over it. It is written to be read, not to hide things. The short version: we collect what the service needs to run, and nothing more. No advertising, no selling of data, no tracking across the web.
1. Who is responsible
The controller for the data processing described here is the operator of Interview Radar, based in Berlin, Germany. The fastest way to reach us for anything in this policy is michael.amoabeng2015@gmail.com. This policy follows the EU General Data Protection Regulation (GDPR).
2. The short summary
- We store your email address, your password (hashed, we can never read it), a random public handle, and the content you post.
- Your email address is never shown to other members. On the site you are your handle, like quiet-falcon-77.
- We use only cookies that keep you logged in. There is no advertising, no analytics profile of you, and no consent banner because there is nothing to consent away.
- You can delete your account yourself at any time. Your questions stay anonymized, your personal data goes.
- You have the full set of GDPR rights, described in section 11.
3. What data we collect
Account data. When you sign up we store your email address and your password. The password is stored only as a cryptographic hash by our authentication provider; nobody, including us, can read it. We also store the time your account was created, whether your email address is confirmed, and a randomly generated handle under which you appear on the site.
Content you post. The interview questions you post, with the company, role, level, stage, month and other tags you pick. Posted questions are linked to your account so the site can count your contributions and show your handle next to them.
Activity needed for the rules.When you press "Asked this too" on a question or report a question, we store that your account did so, once per question. This is what stops double counting and double reporting.
Payment status, later. When the paid pass launches, we will store whether your account has bought it, when it expires if ever, and a customer reference from the payment provider. Your card or bank details never reach us; they go directly to the payment provider.
Technical data. Like every website, the servers that run the site keep short lived technical logs (IP address, time, requested page) to keep the service secure and to find faults. We also apply rate limits, which briefly count requests per account or address to stop abuse.
Support mail. If you write to us, we have your email and what you wrote, and we keep the exchange as long as needed to help you and to document that we did.
4. What we deliberately do not do
- No advertising and no advertising networks on the site.
- No selling, renting or sharing of your data for anyone else's marketing.
- No third party analytics scripts following you, and no fingerprinting.
- No reading of your email address by other members, ever.
5. Cookies
The site sets only the cookies that keep you logged in (the session with our authentication provider). They are strictly necessary for the service you asked for, which is why there is no cookie banner. Log out and they are gone. There are no advertising or cross site tracking cookies.
6. Why we may process your data (legal bases)
GDPR requires a legal basis for every use of personal data. Ours are:
- Contract (Art. 6(1)(b) GDPR): running your account, confirming your email, counting your posted questions for access, showing your handle next to your posts, providing paid access once bought, and answering your support requests.
- Legitimate interests (Art. 6(1)(f) GDPR): keeping the service secure, rate limiting, preventing abuse and dishonest posting, short lived technical logs, and defending legal claims. Our interest here is running a safe, honest service; you can object as described in section 11.
- Legal obligation (Art. 6(1)(c) GDPR): once payments exist, keeping the records tax law requires.
7. Who processes data for us
We do not run physical servers in a basement; specialist providers process data on our behalf under data processing agreements:
- Supabase hosts the database and the authentication system, which means account data, content and confirmation state live there.
- The hosting platform that serves the website (for example Vercel) processes technical request data to deliver the pages.
- An email delivery provider sends the confirmation and password reset mails to your address.
- A payment provider (planned: Paddle) will handle payments as seller of record once the pass launches. They process your payment details under their own privacy policy; we only receive the confirmation and a customer reference.
These providers may process data in countries outside the EU. Where that happens, it rests on EU standard contractual clauses or an adequacy decision, the mechanisms GDPR provides for such transfers.
8. How long we keep data
- Account data: until you delete your account, or until we delete it under the Terms of Use.
- Posted questions: they stay on the site after account deletion, but anonymized: the link to your account is removed and the shown name becomes "former member". The question text itself contains no personal data if you posted within the rules.
- Confirmations and reports: deleted when your account is deleted; the public counters are corrected accordingly.
- Technical logs and rate limit counters: short lived, kept only as long as security and fault finding need them.
- Support mail: as long as needed for the request and its documentation.
- Payment records, later: as long as tax and commercial law require, which in Germany is up to ten years.
9. Deleting your account
On your account page you can delete your account yourself, immediately, without asking anyone. What happens then: your login is deleted at the authentication provider, your email address and handle are removed from our database, your reports are deleted, your "Asked this too" taps are removed from the counters, and your posted questions stay with no connection to you, shown as posted by a former member. This keeps the community collection whole while cutting every thread back to you.
10. Security
All traffic to the site is encrypted (TLS). Passwords exist only as hashes. The database is locked so that browsers have no direct read or write access at all; every access runs through the application server, which enforces the access rules. Admin abilities are limited to admin accounts. No system is perfectly secure, but the service is built so that the sensitive surface stays as small as possible.
11. Your rights
Under GDPR you can, at any time and free of charge:
- Access (Art. 15): ask what data we hold about you and get a copy.
- Rectification (Art. 16): have wrong data corrected.
- Erasure (Art. 17): have your data deleted. The account page does most of this instantly; for anything else, write to us.
- Restriction (Art. 18): have processing limited while something is disputed.
- Portability (Art. 20): receive the data you gave us in a machine readable format.
- Objection (Art. 21): object to processing based on legitimate interests; we then stop unless compelling legitimate grounds outweigh your interests.
- Complaint (Art. 77): complain to a supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information; you may also complain to the authority where you live.
To use any of these rights, write to michael.amoabeng2015@gmail.com from the address of your account, so we know it is you. If we cannot identify you, we may ask for more proof before releasing data; that protects your data from strangers.
12. Children
Interview Radar is for people in working life. You must be at least 16 to use it, and we do not knowingly collect data from anyone younger. If you believe a younger person has an account, tell us and we will delete it.
13. Changes to this policy
When the service changes (for example when payments launch), this policy will be updated before the change goes live, and the date at the top will show it. Meaningful changes are announced on the site. Older versions are available from us on request.
14. Contact
For anything about your data: michael.amoabeng2015@gmail.com, or the support page. Also see the Terms of Use.