← CodeMatch

Privacy Policy

Last updated: August 10, 2026

CodeMatch helps students run peer mock coding interviews. This policy explains what we collect, how we use it, and your choices. It covers both the CodeMatch website (codematch.live) and the CodeMatch Chrome extension.

1. Information we collect

  • Account information — if you sign in with Google, we receive your name, email address, and profile picture. If you sign up with email, we store your email address.
  • LeetCode data (optional) — if you link a LeetCode username, we store your public LeetCode statistics (problems solved, contest rating, topic breakdown).
  • Profile & preferences — the topics, strengths and weaknesses, experience level, preferred difficulty, and weekly availability you set.
  • Session data — the coding problems assigned, your session notes, ratings, and match history.
  • Audio & transcripts — when the optional AI co-interviewer is enabled for a session and you start it, the extension records your microphone during that session and generates a text transcript.
  • Authentication tokens — to keep you signed in, we store session tokens in your browser and, for the extension, in local extension storage.

2. How we use your information

We use your information to match you with a compatible practice partner; to create a Google Calendar event and Google Meet link for your session and email you both; to power in-session tools (the problem, timer, notes, live AI co-interviewer/coach, and your post-session AI feedback report); and to operate, secure, and improve the service. We do not use your data for advertising, and we do not sell it.

3. Google user data and Limited Use

Signing in with Google is optional. If you do, we request your basic profile (name and email) to create your account, and access to Google Calendar (calendar.events) solely to create, update, and cancel the calendar event and Meet link for your matched sessions. We do not read your other calendar events. We do not use Google Workspace data, including Google Calendar data, to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.

CodeMatch's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke CodeMatch's access at any time from your Google Account settings.

4. Audio and AI processing

When AI assist is enabled for a session, your microphone audio is captured in short segments and sent to Google (Gemini API) to produce a transcript. The transcript is used to give the interviewer live suggested questions, give you live coaching, and generate your written feedback report after the session. Audio and transcripts are tied to your session and are never sold or used for advertising. Sessions without AI assist do not record audio.

5. Service providers (sub-processors)

We share data with these providers only to operate the service; they process it on our behalf and may not use it for their own purposes:

  • Supabase — database, authentication, and hosting.
  • Google (Gemini API) — speech-to-text transcription and AI feedback/assistance.
  • Google Calendar / Google Meet — session scheduling and video calls.
  • Resend — sending match-notification and support emails.

6. The Chrome extension

The CodeMatch extension runs as a side panel during a Google Meet call. It stores your CodeMatch session token in local extension storage to authenticate to our API, reads the Meet room code to attach the panel to your call, records your microphone (only when AI assist is on and you have started it), and saves your in-progress notes locally. It does not track your browsing or access pages unrelated to Google Meet and CodeMatch.

7. How we protect your data

We apply the following safeguards to your data, including sensitive data such as your Google Calendar event details and any session audio and transcripts:

  • Encryption in transit. All traffic between your browser or the extension and our servers, and between our servers and our providers, is encrypted using HTTPS/TLS.
  • Encryption at rest. Your data is stored in a managed PostgreSQL database (Supabase) that encrypts data at rest.
  • Access controls. Access requires authentication, and at the database level PostgreSQL Row-Level Security restricts every record so it is readable and writable only by you — and, for shared session data, the partner you were matched with. Authentication and session tokens can be revoked at any time.
  • Least privilege. We request the minimum Google scopes we need (see section 3) and use the Calendar scope only to manage the events for your own matched sessions.
  • Abuse protection. Sensitive and costly endpoints (email, AI transcription) are rate-limited to prevent misuse.
  • Limited internal access. Only authorized personnel can access production systems, and only as needed to operate and support the service.

No method of transmission or electronic storage is completely secure, but we work to protect your information and to improve our safeguards over time. If we become aware of a breach affecting your data, we will notify affected users as required by applicable law.

8. Data storage, retention, and deletion

Data is stored in Supabase (PostgreSQL). We retain your data while your account is active. You can request access, correction, export, or deletion of your data at any time by emailing support@codematch.live, and we will delete your account data.

9. Cookies

We use essential session cookies to keep you signed in. We do not use third-party advertising cookies.

10. Your rights

You may access, correct, export, or delete your personal data, and revoke Google access, at any time (see sections 3 and 8).

11. Contact

Questions or requests? Email us at support@codematch.live.