Privacy Policy
Last updated: August 26, 2026
Jobinno is an autonomous job application agent for CS interns and new grads, operated by Pranav Lende and reachable at hello@jobinno.app. This policy describes what data Jobinno collects, how it is used, who it is shared with, and the choices you have about it.
What Jobinno collects
Account and profile data. When you sign up, Jobinno stores your email address, an authentication record managed by Supabase Auth, and the intake answers you provide (such as your name, phone number, work authorization status, target role, and similar fields you enter into the intake form).
Resume file. If you upload a resume, the file is stored in a private Supabase storage bucket and the parsed text is stored in the database so the agent can read it while filling application forms.
Application activity. Every application the agent submits on your behalf is logged: the role, the company, the board, a timestamp, and the outcome. This is what shows up in your dashboard.
Billing data. If you buy a paid plan, Stripe handles the payment. Jobinno stores only your Stripe customer identifier and the plan you are on. Card numbers and payment credentials never touch Jobinno's servers.
Product analytics. PostHog collects event data about how you use the dashboard so we can see which parts of the product work and which do not. Analytics are not tied to your resume content or to any Gmail data.
Gmail data
Jobinno requests read only access to your Gmail through the Google OAuth scope named gmail.readonly. Granting this scope is optional. If you choose not to connect Gmail, every other part of Jobinno still works.
Why the scope is requested
Some job boards require you to create an account on their site before you can apply, and creating that account means receiving a security code by email and typing it back into the board. Once the automated account creation feature is turned on for your account, Jobinno will read only the specific verification code messages needed to complete those signups on your behalf. Today, before that feature is enabled, connecting Gmail stores the refresh token but the app does not open any messages. The stored token exists so that when the feature ships you do not need to grant consent again.
What Jobinno reads and does not read
When the feature is enabled, the app fetches only messages that match a verification pattern (a security code, a confirm your email link, or similar) from a small allowlist of known job board sender domains. Jobinno does not read personal correspondence, marketing mail, drafts, contacts, calendar invites, attachments, or any other Gmail data. It does not search your inbox for job related content, resumes, offers, or salary information.
The scope named gmail.readonly grants more access than the app uses; the code is written to restrict itself to the messages described above. You can review or revoke Jobinno's access to your Gmail at any time at https://myaccount.google.com/permissions.
How the token is stored
The Gmail OAuth refresh token is encrypted at rest with an application key held outside the database, and written to a column on your profile that has no user side read grant. Only the code paths that call the Gmail API on your behalf can decrypt it.
Limited Use
Jobinno's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Jobinno does not use Gmail data for advertising.
- Jobinno does not sell Gmail data.
- Jobinno does not transfer Gmail data to third parties, except as needed to provide or improve the specific feature that reads verification code messages, to comply with applicable law, or as part of a merger, acquisition, or asset sale in which the acquiring party honors this policy.
- Jobinno does not use Gmail data to develop, improve, or train generalized artificial intelligence or machine learning models.
- Human beings do not read your Gmail messages except when you explicitly ask for support that requires it, when required by law, or to investigate suspected abuse or a security incident.
How Jobinno uses your data
The intake answers and resume are read by the automation agent while it fills application forms, and by the language model that decides how to answer a specific question on a specific form. Every free text answer the agent submits is grounded in what you told the intake. The model is not permitted to invent facts about you. If your intake data does not support an honest answer, the run stops and asks you rather than filling the gap.
Application activity is used to build the dashboard and to enforce the applications cap on your plan.
Billing data is used only to run billing.
Who Jobinno shares data with
Jobinno relies on a small set of infrastructure providers to run the product. Each provider processes only the data needed to deliver its part of the service:
- Supabase hosts the database, authentication, and the private resume storage bucket.
- Vercel hosts the web application.
- Inngest runs the background pipeline that queues and executes applications.
- Browserbase runs the remote browser sessions the agent drives.
- Anthropic and Google provide the language models the agent calls while deciding how to answer form questions.
- Stripe runs billing for paid plans.
- PostHog runs product analytics.
Jobinno does not sell your data. Jobinno does not share Gmail data with any third party for that third party's own purposes.
Data on job boards you apply to
The whole point of the product is that Jobinno submits your application to job boards you name. Once a form is submitted, the board holds that copy of your data under its own privacy policy, and Jobinno cannot delete it on your behalf.
Demographic data
Race, gender, veteran status, and disability status are always answered as decline to self identify on every form Jobinno fills. Those fields are never stored by Jobinno, never inferred from any other data, and never transmitted anywhere by us.
Retention and deletion
Account and profile data, resume files, and application activity are retained while your account is active. Application activity is retained after cancellation for as long as it is needed to answer billing questions and to comply with tax and accounting obligations, then deleted.
To disconnect Jobinno from your Gmail account, revoke access at https://myaccount.google.com/permissions. You can also request that the stored refresh token be removed from Jobinno by writing to hello@jobinno.app; it will be deleted within thirty days of the request.
To delete your Jobinno account and all associated data, write to hello@jobinno.app. Account data, resume files, intake answers, and application logs will be deleted within thirty days of the request, except where a longer retention period is required by law.
Security
Data is transmitted over TLS. The database uses row level security so that one user's data is not visible to another. Gmail refresh tokens are encrypted at rest. Application keys and secrets are held in the deployment environment and never checked into source control.
Children
Jobinno is not directed at anyone under the age of sixteen and does not knowingly collect their data. If you believe a minor has created an account, write to hello@jobinno.app and we will remove it.
Changes to this policy
If this policy changes in a way that meaningfully affects what Jobinno does with your data, the change will be posted here and a notice will be sent to the email address on your account.
Contact
Questions about this policy, or requests to delete your data, go to hello@jobinno.app.