Privacy policy

Last updated 4 October 2026

Mirror builds interview problems from a hiring team's codebase. This page explains what we keep and what we don't.

Your code

  • We only read GitHub repositories. We never write to a repo or run its code.
  • We keep a cached copy of the repository on our server so later runs on it are faster.
  • We don't store your source files in our database. We keep a structural outline (how services, files and functions fit together) and an abstract description of the architecture.
  • Before any problem is written, names of services, tables, routes and hosts are replaced with generic ones. Every problem is then scanned for your identifiers, and any match is blocked.
  • What candidates see is the anonymized problems. Your code, rubrics and solutions stay with your team.

AI processing

We use an AI service to turn an outline of your code's structure into an abstract description of your system. That description is then anonymized, and problems are written only from the anonymized version. The AI service also grades candidates' answers.

Accounts

  • We store your name, your email and whether you're on a hiring team or a candidate.
  • Passwords are never stored. We keep only a salted one-way hash (scrypt), so no one, including us, can read your password.
  • With Google sign-in, Google confirms your email. We never see your Google password.
  • Signing in sets one cookie holding a random token. We store only a hash of it. We use no ad or tracking cookies.

Candidates

When you take a screen, we store your answers and their grades. The hiring team that sent you the screen can see them. You never see the company's code.

Deleting your data

Email [email protected] to delete your account, your answers or the data for a repository.

Changes

When this policy changes, we update the date at the top of this page.