Privacy Policy
Last updated: June 2, 2026
1. Who we are
ReferSetu (refersetu.com) is an anonymous employee-referral platform built and operated by Akshay Sharma, an individual developer based in Bengaluru, India. References to "we," "us," or "our" mean ReferSetu.
2. What we collect
When you sign up and use ReferSetu, we collect:
- Account info from your OAuth provider (Google or LinkedIn): email, name, profile picture.
- Profile info you provide: claimed employer, LinkedIn URL (for verification), display mode preference.
- Content you post: referral posts, screenshots, comments, likes, requests, messages.
- Files you upload: resumes (PDF/DOC), original post screenshots — stored on Google Cloud Storage.
- Usage data: which posts you interact with, request status, notification reads.
3. How we use it
- To run the platform — show your posts, route requests to the right referrer, notify you of replies.
- To verify your employer match against your LinkedIn profile (manual admin review).
- To detect abuse — banned-user content hiding, spam reports.
- To improve the product based on aggregate usage patterns.
We do not sell your data. We do not show ads. We do not share data with marketers.
4. Who can see what
- If you post anonymously, your real name is never shown to other users — only your anonymous handle (e.g. Wild_Buddy_231).
- If you choose "public" display mode, your real name and photo appear on posts.
- Your resume and LinkedIn URL on a referral request are visible only to the specific referrer you sent it to.
- Admins can see all account info (email, real name) to handle verification and abuse reports.
5. Third parties we use
- Clerk — authentication (handles your password / OAuth tokens).
- Neon — Postgres database (your profile and content).
- Vercel — hosting (web requests and edge logs).
- Google Cloud Storage — file storage (resumes, screenshots).
- Google Gemini — AI extraction of jobs from screenshots you upload.
- Cloudflare — DNS and email forwarding.
Each has its own privacy policy and security practices.
6. Your rights
You can:
- Access your data — visible at /profile.
- Change your display mode anytime.
- Delete your account by emailing gwlakshay@gmail.com — we'll remove your posts, comments, requests, and account within 7 days.
- Request a copy of your data — email the same address.
7. Security
All connections use HTTPS. Resumes and screenshots are stored privately on Google Cloud Storage and accessed via short-lived signed URLs only by the intended recipient. We do not store passwords directly — authentication is delegated to Clerk and OAuth providers.
8. Cookies
We use cookies for authentication (set by Clerk), theme preference, and product analytics (see section 9). We do not use advertising cookies or sell your data to advertisers.
9. Analytics & session recording
We use PostHog (hosted in the European Union) to understand how people use ReferSetu — which pages are visited, what is clicked, and general navigation patterns. This includes session recordings that capture on-screen behaviour.
All text inputs and content are masked in these recordings.We do not capture what you type or upload — including resumes, chat messages, referral notes, questions, or LinkedIn URLs. Recordings show layout, clicks, and navigation only.
For logged-in users, analytics events are associated with your account to help us improve the product and detect misuse or abuse. This data is processed within the European Union and is never sold or used for advertising.
10. Changes to this policy
We'll update this page if anything material changes and notify users via in-app notification.
10. Contact
Questions about this policy or your data? Email gwlakshay@gmail.com.