Legal

Privacy Policy

This policy describes how JobMailer collects, uses, and protects your information — including the Google and Gmail data you choose to connect — and the choices you have over it.

Last updated: June 9, 2026

Summary of our commitments

  • We access your Gmail data only with your explicit consent.
  • We never sell your data or share it for advertising.
  • Recruiter emails are sent only after you initiate the action — never automatically.
  • You can revoke Google access or delete your data at any time.

01Introduction

This Privacy Policy explains how JobMailer (“JobMailer,” “we,” “us,” or “our”) collects, uses, stores, and protects your information when you use our web application and related services (the “Service”). JobMailer is a productivity tool that helps job seekers manage job-related email by identifying opportunities in their inbox, removing duplicate job alerts, categorizing roles, and sending application emails to recruiters when the user chooses to do so.

We have designed JobMailer around a simple principle: your mailbox belongs to you. We access your Google and Gmail data only with your explicit consent, use it solely to provide the features you request, and never sell it or use it for advertising. By creating an account or using the Service, you agree to the practices described in this Privacy Policy.

02Information We Collect

We collect only the information needed to operate the Service:

Account information

  • Google profile basics — your email address (via the userinfo.email scope) and your Google Account identifier, used to create and authenticate your JobMailer account.

Gmail data

  • Message content and metadata accessed through the gmail.readonly scope — such as sender, subject, date, and body — which we process to detect job opportunities, de-duplicate job alerts, and categorize roles.
  • Emails you send through the gmail.send scope — the recruiter recipient, subject, and body of application emails that you compose and explicitly choose to send.

Usage and technical data

  • Limited operational data such as log timestamps, error reports, and basic device or browser information, used to keep the Service secure and reliable. We do not use this data to build advertising profiles.

We do not intentionally collect special categories of personal data, and we ask that you do not store such information in JobMailer.

03Google OAuth Permissions & Gmail Data Access

JobMailer uses Google OAuth 2.0 for authentication and authorization. When you connect your account, Google presents a consent screen that lists exactly which permissions JobMailer requests. The Service accesses your Gmail data only after you grant that consent, and you can review or withdraw it at any time (see Your Rights & Choices).

We request the following OAuth scopes:

OAuth ScopeWhat it allowsWhy we request it
userinfo.emailReading the email address associated with your Google Account.To create and identify your JobMailer account and to know which mailbox you have connected.
gmail.readonlyRead-only access to your Gmail messages and metadata.To scan incoming mail, identify job opportunities, remove duplicate job alerts, and categorize roles in your dashboard. We never modify or delete your messages.
gmail.sendSending email on your behalf through your Gmail account.To deliver job-application emails to recruiters that you compose and explicitly choose to send. We never send mail automatically.

We request the minimum scopes necessary to deliver JobMailer’s features. We do not request access to attachments, contacts, or other Google services beyond what is listed above.

04How We Use Your Information

We use the information we collect strictly to provide and improve the Service:

  • To authenticate you and maintain your account.
  • To scan your inbox and identify job opportunities and recruiter outreach.
  • To detect and remove duplicate job alerts so your dashboard stays clean.
  • To categorize and organize opportunities for display in your dashboard.
  • To send job-application emails to recruiters only when you initiate the action.
  • To maintain the security, integrity, and reliability of the Service.
  • To respond to your support requests and communicate important Service notices.

We do not use your Gmail content to train generalized artificial intelligence or machine-learning models, and we do not use it for advertising or marketing.

05Limited Use & Google API Services Policy Compliance

JobMailer’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Gmail APIs is handled as follows:

  • We use Gmail data only to provide and improve user-facing features that are visible within JobMailer (opportunity detection, de-duplication, categorization, dashboard display, and user-initiated email sending).
  • We do not transfer or sell Gmail data to third parties for serving advertisements, market research, or any unrelated purpose.
  • We do not allow humans to read your Gmail data unless (a) you have given explicit consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data is aggregated and anonymized for internal operations.
  • We do not use Gmail data to develop, improve, or train generalized AI or ML models.

06Email Sending Functionality

JobMailer can send job-application emails to recruiters from your Gmail account using the gmail.send scope. This feature is entirely user-initiated:

  • Emails are sent only after you review the content and explicitly choose to send it through an action in the app.
  • JobMailer never sends emails automatically, on a schedule, or in bulk without your direct, per-action initiation.
  • Sent emails appear in your own Gmail “Sent” folder, exactly as if you had sent them yourself, giving you a complete record.

07Data Sharing & Third-Party Services

We do not sell your personal data, and we do not share it for advertising. We share data only with the infrastructure providers needed to run JobMailer, each acting as a service provider under appropriate data-protection terms:

  • Google LLC — provides OAuth authentication and the Gmail API. Your use of Google services is also governed by the Google Privacy Policy.
  • Vercel Inc. — hosts the JobMailer frontend application.
  • Railway — hosts the JobMailer backend (Node.js + Express) application.
  • MongoDB — stores account records and processed job data in our database.

We may also disclose information if required to do so by law, to enforce our Terms of Service, or to protect the rights, safety, and security of our users and the Service.

08Data Retention

We retain your information only for as long as necessary to provide the Service and for legitimate operational or legal purposes:

  • Account data is retained while your account is active.
  • Processed Gmail data (such as categorized opportunities) is retained to power your dashboard and is removed when no longer needed or when you delete it.
  • When you revoke Google access or delete your account, we stop accessing your Gmail and delete the associated Gmail-derived data from our active systems within 30 days, except where retention is required by law. Routine backups are purged on a rolling cycle.

09Data Security

We apply industry-standard safeguards to protect your information, including:

  • Encryption of data in transit using TLS/HTTPS.
  • Encryption of OAuth tokens and sensitive data at rest.
  • Access controls that limit data access to authorized systems and personnel.
  • Secure handling of OAuth tokens, which are never exposed to client-side code.
  • Ongoing monitoring, logging, and regular review of our security practices.

No method of transmission or storage is completely secure. While we work hard to protect your data, we cannot guarantee absolute security, and you use the Service at your own risk.

10Your Rights & Choices

You remain in control of your data at all times. You can:

  • Revoke Google access at any time from your Google Account’s Security & Permissions page or from within JobMailer. Revoking access immediately stops further Gmail access.
  • Access and review the data JobMailer holds about you.
  • Delete your account and request deletion of your associated data.
  • Correct or update your account information.
  • Object to or restrict certain processing, where applicable law (such as the GDPR or CCPA) provides those rights.

To exercise any of these rights, contact us at ar878822@gmail.com. We will respond within a reasonable timeframe and in accordance with applicable law.

11Children's Privacy

JobMailer is intended for users who are at least 16 years old and of legal working age in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can remove it.

12International Data Transfers

JobMailer relies on cloud infrastructure (Google, Vercel, Railway, and MongoDB) that may process and store data in countries other than your own. Where data is transferred across borders, we rely on appropriate safeguards and the providers’ own data-protection commitments to ensure your information remains protected consistent with this Privacy Policy.

13Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Service or in legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the app or by email. Your continued use of JobMailer after changes take effect constitutes acceptance of the revised policy.

14Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Questions about this document? Email us at ar878822@gmail.com.