Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how personal data is processed when you use Frimbim, a code-review interview tool available at frimbim.com.
1. Who operates Frimbim
Frimbim is operated by:
Boris Nikolaev PR BeogradĐure Jakšića 1
11000 Belgrade (Stari Grad)
Republic of Serbia
Company registration number (MB): 67021835
Tax identification number (PIB): 113709500
Email: support@frimbim.com
We process personal data in accordance with the Serbian Law on Personal Data Protection and, where applicable, the EU General Data Protection Regulation (“GDPR”).
2. Our role
Our role depends on why personal data is processed.
When Frimbim acts as controller
We act as the data controller when we determine why and how personal data is processed. This includes processing connected with:
- account registration and authentication;
- service security and abuse prevention;
- transactional email;
- support correspondence;
- operation and maintenance of Frimbim;
- compliance with legal obligations; and
- establishment, exercise or defence of legal claims.
When Frimbim acts as processor
When an account holder, organisation or demo user uses Frimbim to prepare or conduct an interview, that person or organisation generally determines:
- which candidates and observers are invited;
- which code and prompts are shown;
- what information is collected during an interview;
- how comments, notes and findings are evaluated;
- how interview information is used in recruitment; and
- how long that information should be retained.
For this template and session data, the person or organisation conducting the interview generally acts as the controller. Frimbim processes the information on its behalf as a processor.
The person or organisation conducting the interview is responsible for:
- having an appropriate legal basis for processing participant data;
- providing candidates and other participants with any additional privacy information required by law;
- complying with applicable employment, privacy and anti-discrimination laws; and
- using interview information only for lawful and appropriate purposes.
Where required by applicable law, processing performed by Frimbim on behalf of an organisation must be covered by an appropriate data-processing agreement.
3. Personal data we process
Depending on how you use Frimbim, we may process the following categories of personal data.
Account information
When you create or use an account, we process:
- your email address;
- a cryptographically hashed version of your password, if you set one;
- an internal account identifier;
- account creation and update timestamps;
- authentication status;
- authentication tokens;
- password-reset tokens; and
- magic-link login tokens.
We do not store your password in readable form.
Password-reset and magic-link tokens are intended to be temporary and single-use.
If you sign in with Google or connect Google sign-in to your account, we additionally process, received from Google:
- a stable Google account identifier;
- the email address asserted by your Google account, and whether Google reports it as verified;
- the Google Workspace hosted-domain of the account, if any (used only to decide whether the email address can be trusted for account linking); and
- the time the Google sign-in was linked.
We store only the Google account identifier and the email address it asserted at the time of linking. We do not store Google access or refresh tokens, and we do not request or receive Google profile information, contacts or any other Google account data.
Template and session information
Information uploaded or created through an account or the interactive demo may include:
- diffs and source-code content;
- filenames, commit information and code context included in a diff;
- template names, candidate-view titles and descriptions;
- session labels, settings and expiry times;
- private interviewer notes;
- expected findings, scores and evaluations;
- comments made by candidates and interviewers;
- candidate display names stored with comments;
- participant roles;
- candidate, observer and session identifiers; and
- information about when a template, session or private link was created or used.
Diffs may contain personal or confidential information. Remove passwords, private keys, access tokens, production secrets and unnecessary personal information before importing a diff.
Candidate information
Candidates may access an interview session through a private link without creating an account.
We may process:
- the display name entered by the candidate;
- comments submitted by the candidate;
- activity within the relevant interview session;
- session-access and security information; and
- any personal information voluntarily included in submitted comments.
We do not require a candidate email address.
Observer information
Observers may access a read-only session view through a private link without creating an account. Observers do not choose a display name and cannot submit comments, notes or findings.
We may process:
- technical activity needed to provide the read-only session view; and
- session-access and security information.
Technical and application-log information
The Frimbim application records limited information about requests for operational and debugging purposes, including:
- HTTP method;
- requested path;
- response status;
- request duration; and
- a randomly generated request identifier.
Application request logs do not intentionally include:
- IP addresses;
- browser user-agent strings;
- account identifiers;
- request parameters; or
- SQL query contents.
When an application error occurs, logs may contain a technical stack trace and the corresponding request identifier. A copy of the error report is also sent to our error-monitoring service, Sentry (see section 7).
Application logs are written to local server storage and automatically rotated by file size. At most approximately 30 MB of application logs are retained at a time. Because rotation is based on size rather than age, there is no fixed retention period.
Rate-limiting information
We temporarily use IP addresses to prevent excessive requests, token guessing and abuse.
IP addresses used for rate limiting:
- are held only in server memory;
- are not written to the Frimbim database;
- are used only as rate-limit keys;
- are automatically removed after the relevant rate-limit window and cleanup cycle; and
- are removed when the application restarts.
Depending on the affected endpoint, a rate-limit entry is retained for no more than approximately 20 minutes and usually for substantially less time.
We do not use IP addresses for advertising, analytics or profiling.
Support correspondence
If you contact us, we may process:
- your email address;
- your name, if provided;
- the contents of your message;
- attachments you send; and
- related correspondence.
Do not send passwords, authentication tokens, private keys or unnecessary confidential information through support email.
4. Why we process personal data
Providing the service
We process account, authentication and service information to:
- create and maintain accounts;
- authenticate users, including through optional Google sign-in;
- provide password-reset and magic-link login functionality;
- create and operate interview sessions;
- store and display authorised content;
- manage invitations and participant access;
- provide requested functionality; and
- respond to service-related requests.
For account holders, this processing is necessary to perform our agreement with you or take steps at your request before entering into that agreement.
For interview information processed on behalf of an account holder or organisation, we process the information according to that controller’s documented instructions.
Security and abuse prevention
We process limited technical, authentication and security information to:
- protect accounts and sessions;
- enforce access restrictions;
- apply rate limits;
- prevent token guessing, spam and misuse;
- investigate suspected security incidents;
- diagnose operational failures; and
- protect Frimbim, its users and other people.
We rely on our legitimate interests in maintaining a secure and reliable service and preventing unauthorised access and abuse.
Transactional communications
We use email addresses to send essential service messages, including:
- password-reset messages;
- magic-link login messages;
- security-related notices;
- material service or legal notices; and
- responses to support requests.
This processing is necessary to provide and secure the service and manage our agreement with account holders.
We do not send marketing email without an appropriate legal basis.
Legal obligations and claims
We may process or retain limited information where necessary to:
- comply with applicable law;
- respond to lawful requests from courts or competent authorities;
- investigate unlawful activity;
- establish, exercise or defend legal claims; or
- enforce our Terms of Service.
The legal basis is compliance with a legal obligation or our legitimate interest in protecting our legal rights, as applicable.
5. Cookies and browser storage
Frimbim uses a small number of first-party cookies and browser storage. Most are strictly necessary to provide requested functionality. We also use one first-party, privacy-preserving cookie to measure aggregate site traffic, described below. We do not use third-party, advertising, or cross-site tracking cookies.
Session cookie
We use a cookie named
_frimbim_key
to maintain an authenticated session.
The cookie may contain:
- authentication and session state;
- temporary sign-in flow state (for example, Google sign-in state while a “Continue with Google” redirect is in progress);
- a cross-site request forgery protection token;
- a live-connection identifier;
- the currently selected workspace; and
- the selected locale.
The cookie is cryptographically signed to prevent tampering.
In production, it is transmitted only over secure HTTPS connections and uses the
SameSite=Lax
setting.
It is a session cookie and normally expires when the browser session ends or when the user signs out.
Remember-me cookie
If an account holder chooses to remain signed in, we use a cookie named _frimbim_web_user_remember_me.
This cookie:
- is used for authentication;
- is cryptographically signed;
-
uses the
SameSite=Laxsetting; - is transmitted securely in production; and
- expires after 14 days.
Theme preference
The selected light or dark theme is stored in the browser’s local storage under phx:theme.
This preference remains in the browser and is not used for advertising or cross-site tracking.
Candidate display name
The candidate display name is stored in the browser’s local storage for the specific candidate link. This allows the candidate view to restore the name after a refresh. The name is also sent to Frimbim when the candidate joins a session or submits a comment. The browser retains the local copy until it is cleared.
Diff and cockpit display preferences
The browser’s local storage records the selected diff layout. In the cockpit, it also records whether findings or notes appear inline. The browser retains these preferences until they are cleared. They are not used for advertising or cross-site tracking.
You can remove local-storage values through your browser settings.
Traffic-measurement cookie
We use a first-party cookie named
_frimbim_vis
to measure aggregate site traffic (for example, approximate visitor and page-view counts and
which public pages a visit reaches). It:
- contains no name, email, IP address, or other directly identifying information — only a short marker and up to a few letters recording which public pages have been viewed;
- is used only by Frimbim and is not shared with third parties;
- is not used for advertising, profiling, or cross-site tracking;
-
is set with
HttpOnlyandSameSite=Lax, and in production is transmitted only over secure HTTPS connections; - expires after approximately two years; and
- is not required to use the service — you can delete it at any time through your browser, and activity while signed in is excluded from these measurements.
No third-party tracking cookies
We do not use:
- third-party analytics cookies;
- advertising cookies;
- cross-site tracking;
- behavioural advertising; or
- third-party marketing pixels.
6. Automated decisions
Frimbim provides tools that allow people to conduct and document code-review interviews.
Frimbim does not automatically:
- score candidates;
- rank candidates;
- recommend whether a candidate should be hired;
- make hiring or employment decisions;
- create behavioural or employment profiles; or
- make decisions producing legal or similarly significant effects.
Hiring decisions and interpretations of interview content are made by the account holder or organisation conducting the interview.
7. Who receives personal data
We do not sell personal data.
We disclose personal data only where necessary to provide and secure Frimbim, follow the instructions of the organisation controlling an interview, or comply with applicable law.
Authorised session participants
Interview content may be displayed to people authorised by the account holder, including:
- interviewers;
- candidates;
- observers; and
- other authorised session participants.
The account holder is responsible for controlling invitations and deciding who may access a session.
DigitalOcean
We use DigitalOcean to host the Frimbim application and database on a Droplet located in a European Union data-centre region.
DigitalOcean may process information stored or transmitted through the server as our infrastructure provider.
Cloudflare is currently used only to provide authoritative DNS for the frimbim.com domain. Frimbim traffic is not proxied through Cloudflare.
Backblaze
We use Backblaze to store off-site backup copies of the application database in a European Union data-centre region, so that the service can be recovered if our primary infrastructure fails.
Because these are backups of the full application database, they may contain all categories of data described in this policy that are stored in the database, including account information, template and session information, candidate information, and observer-access information.
- backup copies are encrypted at rest using server-side encryption;
- the credentials held on our server can only upload backups — they cannot read existing backups back or delete them;
- backups are deleted automatically on the schedule described in section 9; and
- backups are used only for disaster recovery, not for ordinary business purposes.
Resend
We use Resend to send transactional email.
Resend may process:
- recipient email addresses;
- sender and recipient information;
- email subject and content;
- delivery status;
- bounce and complaint information; and
- technical email-delivery metadata.
We use Resend only for:
- account-confirmation email;
- password-reset email;
- magic-link login email; and
- security notices (for example, when a Google sign-in is linked to your account).
Email open tracking and link-click tracking are disabled.
Resend retains email data for approximately 30 days under its standard service settings.
We use Google services in two ways.
Support email. Email sent to support@frimbim.com is received and stored using Gmail, a service provided by Google.
Google may process:
- sender and recipient addresses;
- email content;
- attachments;
- timestamps; and
- technical email-delivery information.
Optional Google sign-in. If you choose “Continue with Google”, you authenticate directly with Google, and Google learns that you are signing in to Frimbim (including the time of the sign-in). Google acts as an independent controller of the data it processes during that authentication, under its own privacy policy. Google then provides us the account information described in section 3. Using Google sign-in is optional — email-and-password and magic-link login remain available, and a connected Google sign-in can be removed in account settings as long as another login method exists.
Sentry
We use Sentry (Functional Software, Inc.) to collect reports about application errors so that we can detect and fix failures. Error data is processed in Sentry's European Union region.
An error report may include:
- the time and type of the error and its technical stack trace;
- the HTTP method and requested path, with access tokens removed;
- the browser user-agent string;
- the request identifier;
- the deployed application version; and
- the environment name.
Error reports are configured not to include request bodies, cookies, authorisation headers, IP addresses, email addresses or interview content; Sentry's server-side data scrubbing and IP-address storage prevention are enabled as a second layer.
We use Sentry only for error monitoring — not for tracing, profiling, session replay, analytics or advertising.
Professional advisers and authorities
We may disclose limited personal data:
- to lawyers, accountants or other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations;
- where required by applicable law, court order or a valid request from a competent authority;
- where reasonably necessary to investigate fraud, abuse or a security incident; or
- as part of a merger, acquisition, restructuring or transfer of the Frimbim business, subject to applicable law and appropriate safeguards.
8. International transfers
Frimbim is established in Serbia.
The primary Frimbim server, its off-site backups and application error reports are located or processed in the European Union. Some service providers, including Resend and Google, may process information in the United States or other countries.
Information submitted by users or organisations located outside Serbia may also be transferred to and processed by Frimbim in Serbia.
Where applicable data-protection law requires safeguards for an international transfer, the relevant processing must be covered by an appropriate lawful transfer mechanism. This may include:
- an adequacy decision;
- standard contractual clauses;
- a data-processing agreement containing appropriate transfer provisions; or
- another mechanism permitted by applicable law.
EU or EEA organisations that require a data-processing agreement or international-transfer safeguards should contact support@frimbim.com before submitting candidate, employee or other controlled personal data.
9. How long we retain information
We retain personal data only for as long as necessary for the purposes described in this policy.
Interactive demo data
Anonymous demo templates and sessions expire no later than two hours after creation. The first use of a candidate link can reduce the session expiry time to 45 minutes after that use.
Expired demo records remain briefly so Frimbim can show an expiry notice. They are normally deleted from the active database within approximately six and a half hours after expiry. If you save a demo template to an account before it expires, the saved template and sessions follow the account-retention rules below.
Deleted demo records may remain in database backups until those backups expire under the schedule below. Backups are not used for ordinary business purposes.
Account, template and session data
We retain an account and its associated information while the account remains active.
When an account is deleted, Frimbim deletes from its active database the account and its associated:
- authentication information;
- templates;
- imported diffs;
- candidate sessions;
- notes and findings;
- comments;
- candidate display names stored with comments;
- invitations; and
- participant data.
Account deletion cannot be undone.
Backups
We take automated daily backups of the application database so that the service can be recovered after a failure. Backups are kept in two places and rotated automatically:
- on our server infrastructure — approximately the most recent 7 daily backups; and
- as encrypted copies stored with Backblaze (see section 7) — approximately the most recent 35 daily backups, plus one backup per month retained for approximately 13 months.
Older backups are deleted automatically.
You can request account deletion at any time by contacting support@frimbim.com from the email address associated with the account; we action verified requests within 30 days. Once your account is deleted, the associated data is removed from the active database, and it disappears from backups as they age out and are deleted — within approximately 7 days for local copies, approximately 36 days for daily off-site copies, and up to approximately 13 months for monthly off-site copies. Backups are used only for disaster recovery, not for ordinary business purposes; if we restore a backup, we re-apply account deletions actioned after that backup was taken.
Rate-limiting information
IP-address rate-limit entries are retained in server memory for no more than approximately 20 minutes and usually for less time.
Application logs
Application logs are retained according to a size-based rotation policy.
At most approximately 30 MB of application logs are retained at a time. The actual period represented by those logs depends on service activity.
Error reports
Error reports sent to Sentry (see section 7) are retained for approximately 90 days under its standard service settings.
Transactional email
Resend retains transactional email data for approximately 30 days.
Support correspondence
Support correspondence stored in Gmail is retained for up to two years after the last communication.
Account deletion does not automatically delete separate support correspondence. You may request deletion of support correspondence by emailing support@frimbim.com.
We may retain a support message for longer where reasonably necessary to address a security incident, comply with law or establish, exercise or defend a legal claim.
Legal retention
We may retain the minimum information necessary for longer where required by law or reasonably necessary to establish, exercise or defend a legal claim.
Where possible, information retained for these purposes will be restricted from ordinary use.
10. Your data-protection rights
Depending on the circumstances and applicable law, you may have the right to:
- obtain confirmation of whether we process your personal data;
- access your personal data and information about its processing;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive eligible personal data in a structured, commonly used and machine-readable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data-protection authority.
These rights are not absolute and may depend on the purpose and legal basis of the processing.
To exercise a right concerning information for which Frimbim is the controller, contact support@frimbim.com.
We may request information reasonably necessary to verify your identity and prevent unauthorised disclosure or deletion.
We will respond without undue delay and within the period required by applicable law. Serbian law generally requires a response within 30 days. Where GDPR applies, the period is generally one month.
Applicable law may permit an extension because of the complexity or number of requests. Where GDPR applies, the period may be extended by two additional months. We will notify you within the initial response period and explain the reason for the extension.
11. Requests concerning candidate and interview data
For candidate comments, interviewer notes, evaluations and other information connected with a particular interview, the account holder or organisation conducting the interview is generally the controller.
Candidates and other participants should normally direct requests concerning that information to the interviewer or organisation that invited them.
Participants may also contact support@frimbim.com.
Where Frimbim acts as processor, we will:
- identify the relevant account holder or organisation where reasonably possible;
- forward or help route the request;
- assist the controller in responding where required by applicable law; and
- avoid independently using interview information for purposes unrelated to providing or securing the service.
We may respond directly regarding information for which Frimbim is the controller, such as security or support information.
12. Security
We use reasonable technical and organisational measures intended to protect personal data, including:
- TLS encryption for information transmitted between supported browsers and Frimbim;
- cryptographic password hashing;
- signed authentication cookies;
- restricted access to production data;
- rate limiting and abuse-prevention controls;
- encrypted, integrity-verified off-site database backups uploaded with write-only credentials;
- automatic log rotation; and
- deletion of account-associated data from the active database.
No method of transmission or electronic storage is completely secure. We cannot guarantee that unauthorised access, disclosure, alteration or loss will never occur.
Account holders are responsible for:
- protecting their account credentials;
- controlling who receives private invitation links;
- removing secrets and unnecessary personal information from uploaded code;
- limiting access to authorised participants; and
- promptly notifying us of suspected unauthorised access.
13. Children
Frimbim is intended for professional and business use.
Account holders and interview participants must be at least 18 years old.
We do not knowingly collect personal data from anyone under 18.
We do not perform age-verification checks. If we learn that information belonging to a person under 18 has been submitted, we may delete it and restrict the associated session or account.
A parent, guardian or other person who believes that Frimbim contains personal data belonging to someone under 18 may contact support@frimbim.com.
14. Changes to this policy
We may update this Privacy Policy as Frimbim changes or where necessary to reflect legal, technical or operational developments.
We will update the “Last updated” date when changes are made.
Where a change materially affects how we process personal data, we will make reasonable efforts to notify affected account holders through the service or by email before the change takes effect.
15. Contact and complaints
For privacy questions or requests, contact:
Boris Nikolaev PR BeogradĐure Jakšića 1
11000 Belgrade (Stari Grad)
Republic of Serbia
Company registration number (MB): 67021835
Tax identification number (PIB): 113709500
Email: support@frimbim.com
You have the right to lodge a complaint with the Serbian Commissioner for Information of Public Importance and Personal Data Protection if you believe that your personal data has been processed contrary to applicable law.
Submitting a complaint does not prevent you from using any other administrative or judicial remedy available under applicable law.
See also our Terms of Service.