Privacy policy
Your profile, links, photos, swipes and saved roles stay on your device unless you choose to send something: an application to a company, an entry on your college's page, a role you post, a message to us, or your progress if you sign in to keep it on other devices. An account is optional. internd sets no cookies and loads no third-party ad scripts. Our servers see the requests your device makes, and we add up a few anonymous counts per day.
What stays on your device
When you set up your profile and swipe, the app saves this in your browser:
- Your name, school, graduation year, interests and pay floor.
- Where you are based and how far you would go.
- Links you add, such as LinkedIn, GitHub or a portfolio.
- Up to six photos of your work with captions, and an optional profile photo.
- Your swipes, saved roles, streak and XP.
- Your light or dark theme and your language.
Unless you sign in, we do not receive any of this. Photos are re-encoded in your browser before they are saved, which removes the location data inside them. Clearing the site data for internd in your browser, or using the reset button under You, erases it from that device. Without an account it lives only on this device and does not follow you to another phone or browser.
What our servers receive
- Ordinary requests. When you open a page or the app, our host receives your IP address, browser type, the page you asked for and the time. Every website works this way, and the host keeps these in its logs.
- City search. When you search for your city, the text you type is sent to us to look up cities with that name. If you tap use my location, your coordinates are sent once to find the nearest city. We do not store either.
- Internships near me. That page estimates your area from your connection, using location headers from our host. We use it to choose a page and do not store it.
- Cards. When you make a HERE WE GO card, the name, company, role and season you type go into the image link so we can draw the picture. The link carries what you typed, so it appears in server logs and in the browser history of anyone who opens it. Leave out anything you would not post publicly.
- Anonymous counts. We add one to a daily total when someone swipes, taps Apply, shares a role or downloads a card. No name, device id or IP address is attached to a count. We skip the count if your browser sends Do Not Track or Global Privacy Control.
If you sign in
Signing in is optional. It keeps your progress on every device you use. You can sign in with a link we email you or with Google.
- Your email. We use it to send the sign-in link, then keep only a scrambled version of it, made with a secret key, so the same address always reaches the same account and we cannot read the address back. The link itself stops working after 30 minutes or one use, and our record of it is deleted within a day.
- Google. If you choose Google, Google tells us your Google account number and your email address. We keep the account number and the scrambled version of the email. We ask Google for nothing else, and no Google code runs on our pages.
- Your progress. Everything listed under "What stays on your device", plus the real roles you saved and your "did they reply?" answers, is copied to our database so another device can load it. Your theme, notification settings and sponsor card counts stay on each device.
- Your photos. Up to seven photos (six work photos and a profile photo) are stored in private storage that only your signed-in devices can read. We strip location and other hidden data from each photo again before we store it. A photo you delete in the app is deleted from storage on the next sync.
- Staying signed in. Your device keeps a random sign-in code in its own storage, not in a cookie, and we keep only a scrambled version of it. Signing out deletes that code.
How long we keep it. A session you have not used for 180 days is deleted. An account, with its synced progress and photos, is deleted two years after you last used it. You can delete your account any time in the You tab: that deletes the account, its sessions, its synced progress and its photos at once. The copy on your device stays until you reset the app.
"Did they reply?" answers
A week after you save a real role, the app asks whether the company replied. If you answer, we store the role, the company, its country and fields, and your answer, linked to your account so each person answers once per role. We only ever show answers as totals: a company's reply rate appears once 10 or more people have answered about it in the last year, and the Ghost Index shows totals by country and field. If you delete your account, your answers stay in those totals with no link to you. Answers are deleted two years after they were given. "I didn't apply" stays on your device.
What you choose to send us
Nothing here happens unless you do it. Each item says what we keep, who sees it and when it goes.
- Applying with your profile. On a role that a company posted straight to internd, you can send your name, email, school, class year, up to five profile links and a note. The company sees them at once, and we store them so it can read and reply. We email the company that you applied (your name and school only) and we email you its reply. We delete an application 180 days after it was sent. The company then holds your details under its own privacy policy, so send only what you are happy for it to have.
- Your college's page. If you add where you landed, we show your entry (the short name you chose, company, role, season, class year and college) on that college's public page until you delete it. Deleting takes one click from the link in your confirmation email. We use your college email once, to send you the link. We keep only a scrambled version of it, made with a secret key, so we can stop duplicates and cannot read the address back. A link that is never used is deleted after 24 hours.
- Naming someone at the company. When you add where you landed, you can name a person there who can confirm it. We email them once with a link, keep their address only until they use it or it expires after 14 days, and show only the domain of their email (for example "confirmed by someone at acme.com"), never the address.
- Posting a role. If you post for a company, we keep your company name, website, work email and the role text. The role text is public. Your email is not: we use it to send your confirmation and manage links and to tell you when someone applies. A role that is no longer live, with its contact address and applicants, is deleted about a year after it was posted.
- Notifications. If you turn them on, your browser gives us a push address run by its own push service (Google, Apple, Mozilla or Microsoft) and we store it with the applications you want replies for (as scrambled tokens) and, only for the daily alert, the city you are based in. We send through your browser's push service, which sees the notification. Turning notifications off, or resetting the app, deletes the address. Addresses the browser has dropped, or that have not been used for 180 days, are deleted.
- Reporting a role. We keep your report and a scrambled version of your connection address, so one person counts once. The address itself is not stored.
- Advertising enquiries. We keep what you type in the form for up to a year.
What we do not do
- Accounts are optional. Without one, nothing about you is stored on our servers apart from what you choose to send.
- Sponsor cards in the app are ours. They are labelled, load nothing from other companies and set no cookies. We count how many people saw, skipped and tapped each one, with no name, device id or IP address attached.
- We use no tracking cookies. internd sets no cookies at all.
- We do not sell your data.
Where the roles come from
Most roles come from job boards that companies publish for anyone to read. They describe jobs, not applicants. When you tap Apply on one of those, you leave internd for the company's own site, and that company's privacy policy covers what you send there. Other roles are posted straight to internd by the company, after it confirmed an email address on its own domain. Applying to those works as described above.
Who handles data for us
- Vercel hosts the site and receives the request data described above.
- Supabase hosts our database and photo storage: job listings, daily counts, accounts and synced progress if you sign in, and the things you choose to send us, as described above.
- Google, only if you choose to sign in with Google, confirms who you are and tells us your Google account number and email address.
- Resend sends our emails (confirmation links, applicant alerts and company replies). It sees the address and the message.
- Google and Bing are told when a job page is added or removed. We send page addresses only, with no visitor data.
- GeoNames supplies the city data. It ships with the site, and nothing is sent to GeoNames when you use internd.
Our providers may process data outside your country, including in the United States.
Your rights
Wherever you live, you can ask what we hold about you, ask us to correct or delete it, and object to how we use it. In the EU and UK the GDPR gives you these rights, and India's Digital Personal Data Protection Act gives you similar ones. Most of your data is on your device, where you can see and erase it yourself. For anything on our side, such as a request about server logs, write to us. You can also complain to your local data protection authority.
Age
internd is only for people 18 and over. Companies message students directly here, so the app asks your age when you set it up and when you sign in, and stays closed on a device where someone says they are under 18. We do not knowingly collect data from anyone under 18. If you believe someone under 18 is using internd, write to us and we will delete what we hold.
Changes
When this policy changes in a way that matters, we update the date at the top and say so on the site.
Contact
Email hi@internd.app with any question about this page.