Privacy Policy
Last updated: this is a beta — expect this to be revised as the product matures.
What we collect
- Account identity. When you sign in with GitHub or Google, we receive your username or profile name, display name, and email address (if the provider shares it), via Supabase Auth.
- IP addresses — hashed, never stored raw. Every ad-serving and dwell-confirmation request is fingerprinted using a salted, one-way hash of your IP address, used only to detect fraud (e.g. many accounts run from one machine). We cannot reverse this hash back to your IP, and we never store the raw address.
- Ad interaction data. Which ads were shown, on which surface (sidebar/status bar/explorer), how long they were visible, whether you clicked, and the coding-activity trigger that caused the ad to refresh (e.g. a build finishing). This is tied to your account to calculate earnings and detect abuse.
- Tech stack tags — optional. If "share tech stack" is enabled in the extension settings (on by default), we detect coarse language/framework tags from manifest files (e.g. "typescript", "react") to show more relevant ads. We never collect file contents, file paths, or source code.
How we use it
- To authenticate you and operate your dashboard and balance.
- To select relevant ads and calculate verified-impression earnings.
- To detect and prevent fraudulent activity (see our Terms).
- To report aggregate, non-identifying performance stats to advertisers (impression counts, click-through rate, surface/country breakdowns). We never share your identity, username, or individual activity with advertisers.
Website analytics
On this website (not the extension) we use Vercel Analytics and Google Analytics to understand aggregate traffic — page views, referrers, rough geographic region, and device type. Google Analytics sets cookies and may process this data on Google's servers, including outside your country. We use it only for site-usage statistics, never to identify you individually or to profile your coding activity. You can opt out by blocking it with any standard tracker-blocking browser extension or Google's official opt-out add-on.
Infrastructure
Data is stored with Supabase (database) and served via Vercel (hosting). Analytics are processed by Vercel and Google (see above). Supabase and Vercel act only as infrastructure processors — neither uses your data for their own purposes; Google Analytics data is subject to Google's own policies.
Retention & your rights
We retain account and activity data for as long as your account is active. To request access to or deletion of your data, contact us at the address below — this is currently a manual process while the product is in beta.
Children
This service is not directed at, and should not be used by, anyone under 16.
Changes
We may update this policy as the product evolves during and after beta. Material changes will be reflected on this page.
Contact
Questions or requests: malay@virdl.com