Privacy policy
Last updated: 5 October 2026
Who is responsible
Majken is run by Amöba AB, org.nr 556853-4910, Folkskolegatan 5, 117 35 Stockholm, Sweden. Contact: hello@majken.ai.
Our role depends on the data.
- Employer accounts, the challenge, the GitHub report tool and our website: Amöba AB is the controller.
- Code review tests sent by an employer: the employer is the controller for its candidates' data and Amöba AB is the processor. The employer decides to test a candidate and what to do with the result. We handle the data on the employer's instructions to run and grade the test.
- Candidates with questions about a test they were sent should contact the employer first. You can also write to us at hello@majken.ai, and we will pass the request on or act on the employer's behalf.
What we store
Employers and other account holders:
- Email, name, password hash (if you set a password) and, for GitHub login, your GitHub id, username and avatar. We use the access token GitHub gives us at login once and do not store it.
- Purchase and subscription records: credits, plan, status and Stripe customer and subscription ids. We never see or store card numbers. Stripe handles them.
- Tests you send: the candidate's name and email, your name, your optional note, the test link, status and dates, and the result.
- Your own report history and disputes you raise about a grading.
Candidates who take an employer's test:
- The name and email the employer entered, to send the invitation.
- Your review: comments with file and line, the summary, your approve or request changes verdict, which AI tools you say you used, the time you spent and when you confirmed you would do the review yourself.
- The result: which planted problems you caught, a score band, notes written by the grader and a plain-English report for the employer. The employer may also see a note when your review is very similar to another candidate's review of the same test or to a plain AI review.
People who take the public challenge (no account):
- Your review and result, without your name. The result gets a public share id.
- A hashed form of your IP address, used only to limit how many challenges one connection can start per hour. We cannot read the IP address back from it.
- Your email, only if you tick the box asking us to email your breakdown. We send that one email and nothing else.
Everyone who visits the site: see the cookies section. We also keep the emails you send to hello@majken.ai, and a list of addresses that must not get marketing email.
Why we use it and on what basis
- Run an employer's test, grade it and give the employer the report: contract with the employer, and the employer's own legal basis for testing candidates, which is usually legitimate interest. Candidates are told what happens before they start.
- Run the public challenge and send the breakdown you asked for: our legitimate interest in offering the challenge, and your consent for the email. You can withdraw consent at any time.
- Accounts, payments and support: contract, and legal obligation for accounting records.
- GitHub login and, where enabled, connecting GitHub as a candidate: contract for login, consent for connecting private repositories.
- Security, abuse prevention and the rate limits: legitimate interest.
- Our own page view and funnel statistics: legitimate interest in knowing which pages work.
- Google Analytics: legitimate interest in traffic statistics.
- Welcome and tip emails to account holders who have not bought anything, and emails to companies about Majken: legitimate interest. Every such email has an unsubscribe link, and we keep the address on a suppression list so it is not emailed again.
No automated decisions about people
An AI grader grades each review against a fixed list of problems planted in the code, and compares it with other reviews of the same test. The grade and report are an aid for the employer. A person at the employer makes any hiring decision. We make no decision with legal or similarly significant effect on anyone. If an employer disagrees with a grading, it can send a dispute and a person at Majken reviews it.
How long we keep it
- Code review test data (the invitation, the candidate's name and email, the review, the result and disputes): deleted 180 days after grading. Tests that were never graded are deleted 180 days after they were submitted or expired. The same applies to the challenge, including a stored email address and the hashed IP address.
- A candidate can ask us to delete everything tied to their email address sooner. Write to hello@majken.ai.
- Accounts, purchase records and report history: while the account exists. We delete an account on request, except records we must keep for accounting.
- Event log (page views and funnel events): we have no automatic deletion yet. We delete the events linked to your account or cookie id on request.
- Login sessions: up to 30 days. Password reset links work for one hour.
- Public GitHub reports and the code excerpts they show: cached and deleted after 30 days.
- Mail to hello@majken.ai and the suppression list: kept until you ask us to delete them, except that we keep an address on the suppression list as long as needed to honour an unsubscribe.
Who receives data
We use these service providers as processors. We do not sell personal data.
- OpenAI: grades reviews and writes the plain-English report. It receives the task spec, the code, your comments, summary and verdict. It does not receive the candidate's name or email. OpenAI states that it does not use API data for training and may retain it for up to 30 days for abuse monitoring. For the GitHub report tool it receives public code excerpts, and private code only if a candidate chose the full review level.
- Resend: sends our emails and receives mail sent to hello@majken.ai. It handles recipient addresses and message content.
- Stripe: takes payments and runs subscriptions. It receives your email and payment details.
- GitHub: public profile data for the GitHub report tool, and login. GitHub is also where repositories are read if a candidate connects them.
- Google: Google Analytics, described below.
- Our hosting: a server we rent, which holds the database.
- The employer that sent you a test receives your review and result. Nobody else sees them, and we do not publish them. The public challenge result page shows the score, the planted problems and whether you caught each one. It shows no name, email or comments, and anyone with the link can open it.
OpenAI, Stripe, Resend, Google and GitHub are US companies. When data is sent to them, the transfer relies on the safeguards GDPR requires, such as the EU Commission's standard contractual clauses or the EU-US Data Privacy Framework, depending on the provider. Contact us for details.
Cookies and usage data
We run our own first-party event log on our server and also load Google Analytics.
dv_aid: a random identifier for our own statistics. It lasts one year, is HTTP-only and SameSite=Lax, and holds no personal information.- Session cookie: keeps you logged in. It is set when you log in or sign up and lasts up to 30 days.
- Google Analytics: loads on our public pages, never on test links, reset links or unsubscribe links, and sets cookies (
_gaand similar) for aggregate traffic statistics. Google receives your IP address and browser data when the script loads. We do not currently ask for consent before it loads. You can block it with your browser or an extension. - We log page views (path, the referring site's domain and campaign tags when present), report requests, signups, checkout starts, purchases and test events, linked to the identifier and, when you are logged in, to your account. We do not store IP addresses in these events and we skip known bots.
- The page path is logged as it appears in the address bar. For links with a token in them, such as a test link, the token is part of the path.
You can delete the cookies in your browser at any time. To have events linked to your account deleted, contact us at hello@majken.ai.
Candidates who connect GitHub
This optional feature may be switched off. When it is on, candidates can sign in with GitHub to get a verified report. We process this on the basis of your consent, which you can withdraw at any time. You choose one of three levels before anything is read.
- Signing in gives us your GitHub user id, username, name, avatar and email, used to create or link your Majken account. For this connect flow we do not keep the sign-in token.
- Verified owner (the default): sign-in only. No private repository is read. Your report is built from your public GitHub data.
- Private activity, no code: you install the read-only Majken GitHub App on repositories you select. We read only metadata: commits you authored (dates and counts), pull requests, reviews and language statistics. No file contents are fetched and nothing from private repositories is sent to OpenAI.
- Full review: the same, plus up to 4 private files you tick after seeing the list. Only those files are read, and their contents are sent to OpenAI's API for the review.
- The app has read-only access to the repositories you select. We create a one-hour access token when an analysis runs and do not store it. You can revoke access at any time in your GitHub settings.
- We never store code from private repositories. Excerpts are removed before your report is saved. We keep counts, scores, review notes, file paths and repository names. Employers never see private code.
- Share links show the report without private code, and without private repository names unless you turn them on. Links expire after 90 days and you can revoke them. We count how often a link is opened.
- Delete everything from your dashboard to remove your report, share links and installation record. Uninstall the app on GitHub to end our access. Your account can be deleted on request.
- If an employer asked you for a report, we store their request with your name and email and send you one email about it.
Your rights
You can ask us for access to your data, correction, deletion, restriction, a copy you can move, and object to processing based on legitimate interest. You can withdraw consent at any time. Write to hello@majken.ai. For test data held for an employer, we may direct the request to the employer.
You can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the supervisory authority in your own country.
Contact
For privacy questions, write to hello@majken.ai or to Amöba AB, Folkskolegatan 5, 117 35 Stockholm, Sweden.