GrindLens · Legal

Privacy Policy

What GrindLens handles, which information is public, and what remains when you unlink a profile or delete an account.

Last updated

01Information we handle

  • Account information: email address, display name, account creation time, privacy preferences and linked LeetCode username. Email/password signup stores a salted password hash.
  • Sign-in information: session records, password-reset tokens and, for Google/GitHub sign-in, provider account ID, email, verification status and display name. GrindLens does not ask for your Google, GitHub or LeetCode password.
  • Practice information: public LeetCode profile and activity data retrieved for analysis; stored submission IDs, problem names/slugs, status, language and timestamps; sync metadata, manual solved-problem records, sheet check-offs and progress snapshots.
  • Billing information: Razorpay order/payment references, amount, currency, payment redemption and Pro access dates/status. The checkout receives your account name and email for prefilling; orders include an account reference and selected plan.
  • Usage information: feature events, timestamps, a browser identifier and event metadata. Metadata can include page paths, acquisition source/campaign, sheet/problem identifiers, searched LeetCode usernames and error categories. Signed-in events can be associated with your account ID.

Requests also use network information, including IP-derived identifiers for abuse limits. Contacting support shares the information you include in your email.

02How information is used

We use this information to authenticate accounts, verify email and linked profiles, retrieve and analyze LeetCode activity, save progress, enforce access permissions, process Pro access and handle account requests. Usage events help measure acquisition and feature use; request limits help prevent abuse.

Looking up a public profile sends the requested username to LeetCode. Signing in with a provider, requesting an email or opening payment checkout involves that provider as described below.

03Public profiles and your controls

GrindLens accounts default to public profile visibility. Public LeetCode profile information and derived analysis can be viewed through profile lookup. Settings lets you make your linked profile private on GrindLens and separately control the authenticity display. Private linked profiles are restricted to their owner through GrindLens’s profile lookup.

These settings do not change your LeetCode account’s visibility or remove information already held by LeetCode, search engines or other visitors. Public lookup is not an account directory: your account email, sign-in credentials and billing records are not fields in the public profile response.

04Cookies and browser storage

  • Sign-in: the session cookie lasts up to seven days. Short-lived cookies support Google/GitHub sign-in and verification of the sign-in response.
  • Usage and attribution: a random browser identifier is kept in local storage and mirrored to a 30-day cookie. A separate 30-day attribution cookie stores first-visit source, campaign, referrer and landing path. Local storage has no automatic expiry equivalent to that cookie.
  • Product preferences: local storage can hold recent profile searches, locally saved sheet progress/layout and theme preferences. Session storage supports navigation state and avoids duplicate tracking events within a tab. Loaded profile/dashboard data also uses memory caches.

You can clear browser storage or restrict cookies/scripts using browser controls. This can affect sign-in, saved local state and analytics. Signing out is not a blanket deletion of all browser storage.

05Google Analytics and usage events

GrindLens loads Google Analytics through its shared page layout and sends selected interaction events. Selected signup/sign-in events may also be sent server-side when that integration is configured. Internal usage events are stored separately in the application database.

Internal usage analytics is separate from Google Analytics and can associate the browser identifier with your signed-in account. The current app has no in-app analytics opt-out or cookie-consent preference control. Making your profile private does not disable analytics.

Google’s handling of information is described in its Privacy Policy. Google Analytics settings and retention are managed outside this application; we do not state a fixed Google retention period here.

06Service providers

  • LeetCode: supplies public profile, submission and activity information requested for analysis.
  • Google and GitHub: authenticate provider sign-in and supply the account information listed above.
  • Resend: handles password-reset email delivery, receiving the recipient email and message containing the link.
  • Razorpay: hosts payment checkout and processes payment details. GrindLens stores payment references and access records, not card numbers, CVVs or UPI credentials. See Razorpay’s Privacy Policy.
  • Application infrastructure: account and product records are stored in a PostgreSQL database accessed through the Neon client. A configured Redis service can store rate-limit counters; some temporary controls use application memory.

Provider records are governed by their own practices. This page does not promise a storage country, provider deletion deadline or backup retention period that the application cannot establish.

07Retention and account deletion

Account and practice records remain stored while your account exists; there is no general age-based deletion schedule for submissions, snapshots or internal analytics. The analytics retention period is not yet finalized. Switching or unlinking a LeetCode profile preserves stored history. Expiry of Pro access does not delete progress.

Password-reset links expire after one hour; expiry makes a link unusable and does not necessarily remove its database row immediately. Expired session/reset records do not have a general automatic purge schedule.

Settings provides account deletion while signed in. It deletes the account and associated sessions, provider links, reset tokens, submissions, sheet progress, manual solved problems, progress snapshots, subscription and payment-redemption records from the application database.

Internal analytics events remain: deletion clears their account ID, but their browser identifier, timestamps and metadata—including any recorded usernames—can remain. They are not guaranteed to become fully anonymous. Browser storage, provider records, infrastructure logs and backups are not erased by the account-deletion operation; this page does not promise a purge deadline for those records.

08Security practices

The application hashes passwords with a unique salt, uses HttpOnly session cookies with the Secure flag in production, and checks authentication and ownership on protected routes. Session and password-reset records contain authentication credentials; password hashing does not mean all stored identifiers are hashed.

Request validation, rate limits, browser security headers and payment-signature/order verification provide additional protections. These measures do not guarantee that every attack, outage or disclosure can be prevented. This policy makes no claim of a security certification or of encryption practices for infrastructure that are not established by the application code.

09Requests and questions

Use Settings to manage supported profile controls or delete your account. For questions about retained information, corrections or other privacy requests, contact grindlens.support@gmail.com. Include enough information to identify the request, but do not send passwords or sign-in links.

There is no self-service export tool or promised response deadline in the current application. This page describes the current implementation; the update date identifies the version shown here. See also the Terms of Service.

Read also: Terms of Service.