CareerCRM
Privacy Policy
Last updated: July 11, 2026
CareerCRM ("we", "us", or "our") is committed to protecting your privacy. This policy explains what personal information we collect, how we use it, and the choices you have.
Short version: We collect only what we need to run an individual job-search workspace. We never sell your data. We do not sell, rent, or provide marketing lists. You control your messages; we never send anything on your behalf without your explicit approval for each recipient and message.
1. Information we collect
Account information: When you register, we collect your name, email address, and password (hashed and salted — we never store plaintext passwords).
Resume data: If you upload a resume, we store the content to power company matching and message drafting. You can delete it at any time.
Job search activity: Companies you've saved or approved, contacts you've added or reviewed, messages you've drafted, message statuses, and follow-up schedules, all stored to power your personal job-search pipeline.
Contact and source information: CareerCRM may store limited professional contact context, source URLs, confidence signals, and verification status where those details are relevant to a company or role in your job search. Contact status may be found, inferred, unverified, or unavailable, and is shown so you can decide whether a specific contact is appropriate before any message is sent.
Location, only if you ask for it: CareerCRM never requests your location on its own. If you choose "Use my current location" on the location row in Settings, your browser asks your permission and, if you grant it, sends us your coordinates for a single lookup with our mapping provider. We use the result to work out a city-or-larger place name — never a street address — and save that name to your profile, where you can change it or undo it immediately. Your coordinates are never stored, never written to our logs, and never shared; only the place name is kept. You can decline the browser prompt, or ignore the feature entirely, and search for your city by name instead. Both are equally supported, and neither is required.
Your saved location describes where you are. It is not how CareerCRM decides where to look for roles — that comes from what you ask for in a given search, and from the locations you have told us you want to work in, which can be entirely different places. Your current location is used for your profile and to judge whether a specific role is realistically open to someone based where you are.
Usage data: Pages visited, features used, and session data (browser, device type, IP address) to help us improve the product and diagnose issues.
2. How we use your information
- To provide, maintain, and improve CareerCRM
- To match your profile with relevant companies and roles
- To support application packets with role-relevant professional context, source notes, and confidence context
- To generate individualized message drafts for your review and approval
- To send transactional emails (password resets, billing receipts, product updates)
- To detect and prevent fraud, abuse, unauthorized access, commercial prospecting misuse, or attempts to bypass job-seeker-appropriate limits
- To comply with legal obligations
We do not use your data to train AI models sold to third parties. We do not send any message on your behalf without your explicit, per-recipient and per-message approval.
We do not use CareerCRM data to build, sell, rent, license, or distribute marketing lists, sales lists, recruiting lists, lead lists, or contact databases.
3. Cookies and tracking
We use strictly necessary cookies to keep you logged in and maintain session state. We use analytics cookies (privacy-respecting, aggregated) to understand how people use the product. You can disable non-essential cookies in your browser; this will not affect core functionality.
4. Google user data
Connecting a Google account to CareerCRM is optional. The product works without it; only the features listed below depend on it. When you connect, Google asks you to approve a specific set of permissions, and we request only these:
- Send email on your behalf (
gmail.send) — to send outreach you have written or reviewed, and only after you explicitly approve that specific message to that specific recipient. This permission allows sending and nothing else. It does not allow CareerCRM to read, search, or delete anything in your mailbox. - Access files this app creates in Drive (
drive.file) — to save resumes you generate. This permission cannot reach any other file in your Drive. - Your email address and basic profile (
openid,email) — to show which Google account is connected.
What we read, and what we keep
We do not read your mailbox. CareerCRM does not request permission to read, search, or list your Gmail. We cannot see your inbox, your sent mail, your drafts, or your attachments, and we cannot tell whether anyone has replied to you. The only thing we do with Gmail is deliver a message you have approved.
What we store about outreach is what you wrote and who you chose to send it to — information you gave us, not information we took from your account.
Because no mail is read, no mail content is sent to any AI provider. Messages CareerCRM helps you draft are written from your own profile, the company, and the contact you selected.
What we never do
- We do not sell, rent, or license Google user data.
- We do not use Google user data for advertising, and we do not build advertising or marketing profiles from it.
- We do not use Google user data to train, retrain, or improve generalised or third-party AI models.
- We do not transfer Google user data to others except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit consent, where necessary for security purposes such as investigating abuse, or where required by law.
- We do not send any message on your behalf without your explicit, per-recipient and per-message approval.
Limited Use
CareerCRM's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
You can disconnect Google from CareerCRM at any time in Settings, which deletes the access and refresh tokens we hold for your account. You can also revoke our access directly from your Google Account at myaccount.google.com/permissions. Rows already imported into your Tracker remain yours and stay in your account until you delete them; disconnecting stops any further reading of your mailbox.
5. Data sharing
We share your data with a limited set of trusted vendors who help us operate the service, such as cloud hosting, payment processing, transactional email delivery, search providers, mapping and place lookup, and AI infrastructure. Each vendor is permitted to process data only as needed to provide services to CareerCRM and not for their own advertising or marketing purposes.
Our mapping provider receives only what a single place lookup requires: the text you type into the location search box, or — if you used "Detect" and granted your browser's permission — the coordinates for that one request. It receives no other profile, resume, message, or job-search data, and we send it nothing when you are not actively looking up a place.
We never sell, rent, trade, or provide your personal data or CareerCRM application packet context to third parties for advertising, marketing, sales prospecting, recruiting, staffing, or lead-generation purposes.
CareerCRM does not offer bulk contact export, CSV email-list downloads, campaign tools, sequence tools, automatic sending, or shared team prospecting workspaces.
We may disclose data if required by law, court order, or in response to a valid government request.
6. Data retention
We retain your account data as long as your account is active. If you close your account, we delete your personal data within 30 days, except where we're required to retain it for legal or regulatory reasons (e.g., billing records for up to 7 years). Where abuse is suspected, we may retain relevant records for investigation, enforcement, or legal compliance.
7. Security
We use industry-standard security measures: TLS encryption in transit, AES-256 encryption at rest, least-privilege access controls, and regular security audits. No system is perfectly secure — if you discover a vulnerability, please use the contact form and choose the security/privacy topic.
8. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (right to be forgotten)
- Port your data to another service
- Object to certain processing
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, use the contact form and choose the security/privacy topic. We'll respond within 30 days.
9. Children's privacy
CareerCRM is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected data from a child, please contact us immediately.
10. Changes to this policy
We may update this policy periodically. We'll notify you by email and post the updated policy with a revised "Last updated" date. Continued use of CareerCRM after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this policy? Use our contact form and choose the security/privacy topic, or email support@careercrm.ai.