Skip to content

Legal

Privacy

A screen recording with your voice on it, and the GitHub identity attached to it, is personal data. Here is exactly what we do with it and how you get it removed.

Draft pending review by Spanish counsel. The site is operated by an individual, not a company; the identifying details in [[brackets]] are filled before accounts open. Nothing here is applied retroactively, and if a term changes we say what changed and when.

01Controller

[[FULL NAME]], tax ID [[NIF]], [[ADDRESS]], acting as an individual. There is no company and no data protection officer — the controller is a person, and that person reads [email protected].

02What is running today

Right now this site is a public library of drills with no accounts and no recording. If you only read it, the only thing recorded about you is aggregate page analytics, with no cookie and no identifier.

The sections below describe accounts, arenas and recordings, which are being built. They apply from the moment you can sign in, and the date that happens is published in the journal. We would rather publish the terms before the feature than the other way round.

03What we collect

When you sign in with GitHub: your GitHub username, display name, avatar and email address. The email is stored encrypted, is never shown on the site, never exported, and never disclosed to anyone.

When you run a drill: which drill, when you started, when you pushed, the commit reference, the automated test report, and the state of the temporary repository created for you.

While you run a drill: the recording of your screen, captured in your browser and streamed to us as it happens, and the scores and reviewer notes produced from it.

What we never ask for: surname, phone number, postal address, employer, salary, or a CV.

We do not sell data, we do not build audiences from it, and nothing here is shared with recruiters or employers.

04Why, and on what legal basis

To run your account, create your arena and record your attempts — performance of a contract at your request (GDPR art. 6.1.b).

To store your recording and have a reviewer watch it and score it — your explicit consent (art. 6.1.a), asked for before the capture starts and withdrawable at any time.

To publish an excerpt of your recording, or use it in a post or a video — a second, separate consent. Withholding it does not affect your score in any way.

To keep the competition honest — checking that the tests were not edited, that the clock was respected, that one person ran one attempt — legitimate interest (art. 6.1.f), limited to your own attempt record.

Your public profile shows your GitHub handle, your tier, your delivered drills and your Index. Your handle is already public on GitHub; nothing more identifying than that is ever published without a separate consent.

05Who else sees it

Processors, each bound by a data processing agreement: Cloudflare (hosting, database, recording storage), GitHub (identity and the temporary arena repository), Resend (transactional email), and Vercel (only for drills that require a deployment).

Some of these transfer data outside the EEA under the EU Standard Contractual Clauses. The database and the recording storage are configured in the EU.

Your reviewer sees your recording. Reviewers are named on the rubric page, are bound to confidentiality, and see no more of you than the recording and the drill.

Nobody else. Your email address is never disclosed to a third party, and there is no process by which anyone can pay to reach you.

06How long we keep it

Recordings: 90 days from the day they are scored, then deleted automatically. The score survives; the raw video does not, because keeping it is risk without value.

Account, attempts and scores: until you delete the account. Deletion is immediate as far as you are concerned and final after 30 days, which is the window to change your mind.

Temporary arena repositories: destroyed 24 hours after the clock ends.

Aggregate statistics with no name attached — attempt counts, ship rates, medians: kept indefinitely, because that anonymised series is what the drill library is calibrated with. Deleting your account does not rewrite them, and there is nothing personal left in them to delete.

07Cookies

The public site sets none, which is why there is no banner to click.

Once accounts exist, signing in sets one cookie holding an opaque session identifier. It is strictly necessary to keep you signed in, it is not shared, and it is not used to track you anywhere. Signing out destroys it on the server, not just in your browser.

08Automated decisions

Whether a drill counts as delivered is automated: a test suite runs against your commit and returns a result. It is deterministic, the criteria ship inside the arena repository, and you get the full report.

Your Orchestration Index is not automated. A person watches the recording and scores it against the public rubric. A model is never the reviewer.

If you think an automated result is wrong, write to [email protected] and a person looks at it.

09Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of any consent at any time, without affecting what was lawful before.

Two of these are buttons, not emails: your account page exports everything we hold about you as JSON, and deletes the account outright. For anything else, write to [email protected] and we answer within one month.

If you think we have handled this badly, you can complain to the Agencia Española de Protección de Datos (aepd.es).

10Age

Accounts are for people aged 18 or over. If we learn an account belongs to a minor it is deleted, and the recording with it.

[email protected]