Privacy

Privacy & Security

This Privacy Policy explains what information Vinskal collects, how it is used, who processes it, and the choices you have. Your data is yours: you can export or delete it from Account & Settings.

Last updated: August 10, 2026

Summary

  • We collect only the information needed to run your account and the features you use.
  • We do not sell your personal information or use it for third-party advertising. AI providers receive only the information needed for AI features you request, such as generating drafts or researching company insights.
  • Google sign-in and Gmail are separate: sign-in does not grant Gmail access. Gmail, when connected, is optional and user-triggered: Vinskal reads to detect application updates and can place a follow-up draft in your own Drafts folder, but never sends, deletes, or modifies mail.
  • The browser extension captures a job only when you click it, and never submits an application without your explicit review and confirmation. On the job sites it supports, it does watch page requests for the application’s question list as the page loads — see Browser extension for exactly what that means and why.
  • You can access, export, schedule deletion of, and disconnect integrations from Account & Settings.

Information we collect

We collect the following categories of information:

  • Account information — your email address, authentication credentials (passwords are stored only as salted hashes), and, if you choose Google sign-in, basic profile identifiers from Google (such as your Google account ID and verified email).
  • Career Profile data — the skills, experience, projects, education, certifications, writing samples, application answers, links, voice/style preferences, and job preferences you choose to enter.
  • Uploaded documents — resume and related files you upload, plus structured data extracted from them when you ask us to parse or tailor them.
  • GitHub information (optional) — if you add a GitHub handle, we read your public repositories and profile to suggest projects and skills as evidence for your Career Profile. We do not access private repositories.
  • Application data — saved jobs, generated materials (resumes, cover letters, answers), application status, execution plans, submission snapshots (what you used — not employer form field values), follow-up records, and outbound email drafts you create.
  • Extension and assist data — when you use the browser extension or Application Assist, job page metadata (such as title, company, and URL), question labels/options, and session linkage — not passwords, payment details, OTP/2FA codes, or what you typed into employer forms.
  • Optional integrations — if you connect Gmail, bounded message metadata and snippets from scans you explicitly trigger (see below). Integration tokens are encrypted at rest.
  • Billing information — subscription tier, usage limits, Stripe customer and subscription identifiers, and billing events. Payment card numbers are handled by Stripe, not stored on our servers.
  • Usage and diagnostic data — service logs, security events, AI usage records, and product analytics scoped to your account (for example, usage counts and application outcomes you track).
  • Community metadata (optional) — if you leave “contribute anonymized job metadata” enabled in your privacy settings, we may link non-identifying job facts (such as employer, title, and URL patterns) to shared catalog records. Reporter identity is not shown publicly on community listings.

How we use your information

  • To provide and operate the features you ask for.
  • To generate AI drafts (resumes, cover letters, answers, emails) that you review and approve.
  • To run advisory job-trust analysis on posting text you save — not as a guarantee of legitimacy.
  • To secure your account and detect, prevent, and investigate abuse or fraud.
  • To process subscriptions and usage limits when billing is enabled.
  • To maintain, debug, and improve the product.
  • To comply with legal obligations.

We do not sell your personal information or share it for third-party advertising.

Where the GDPR applies, our legal bases are: performance of a contract (to provide the features you sign up for), your consent (for optional integrations such as Gmail and for optional community-metadata contribution, which you can withdraw at any time), our legitimate interests (to secure the Service and prevent abuse), and compliance with legal obligations.

When we access your information

Vinskal does not access or view your personal information except when:

  • You request support or troubleshooting that requires it,
  • It is required for security or to investigate malicious activity, abuse reports, or policy violations, or
  • It is required to provide the app functionality you asked for (minimized to what is necessary).

Service providers

We use trusted subprocessors to run the Service and perform functions on our behalf. Each processes data only to perform services for us under contractual confidentiality and security obligations, and we share only what is necessary for the feature you requested:

  • Google (Gemini API) — AI inference to generate the drafts you request (resumes, cover letters, answers, follow-ups) and web-grounded company insights. Under Google's paid/API terms your inputs are not used to train their public models.
  • Google (OAuth & Gmail API) — Google sign-in and, only if you connect it, Gmail read plus draft-creation access for the tracking and follow-up features you trigger. Vinskal does not use its send capability.
  • Stripe — payment processing and subscription management. Card details are handled by Stripe and are not stored on our servers.
  • Resend — transactional email delivery (verification codes, password resets, and reminder digests you enable).
  • Cloud hosting and database — infrastructure that runs the application and stores your account data and uploaded files.

We may update our subprocessors as the Service evolves; we keep this list current and require comparable data-protection commitments from any provider we add.

AI processing

To generate drafts, we send the relevant parts of your inputs to a third-party AI provider (currently Google's Gemini API). We rely on the provider's paid/API terms, under which your inputs are not used to train their public models, subject to each provider's applicable terms and technical controls. AI output is a draft until you review and approve it. Vinskal does not invent career facts — it may only rephrase or emphasize information you provide or approve.

When you request company insights, the company name and role you are researching are sent to a web-search-enabled AI query so we can summarize publicly available information (such as reviews and interview reports) about that employer. We do not send your resume or personal profile data for that feature, and the resulting summary is saved privately to your own account — it is not shared with other users.

Gmail and integrations

Gmail access is optional and separate from Google sign-in. When connected, Vinskal uses two scopes: read-only access, for the status signals you explicitly request by triggering a scan, and draft-only access, used solely when you ask it to place a follow-up in your Drafts folder. It never sends, modifies, archives, deletes, or labels mail in Gmail — although the compose scope technically permits sending, Vinskal does not call Gmail's send methods, so a follow-up leaves your mailbox only when you press Send in Gmail yourself. It does not run background mailbox sync, and it does not automatically read employer verification or OTP codes — those stay with you. Outbound email to employers or recruiters uses Vinskal's own email provider stack only after you approve a draft and click Send (or schedule an approved draft for a time you choose). You can disconnect Gmail or other integrations at any time from Account & Settings.

Google user data and Limited Use

When you connect Gmail, Vinskal accesses your Google user data using the read-only gmail.readonly scope, and — only to create a follow-up draft you asked for — gmail.compose, which technically permits managing drafts and sending email. Vinskal uses this access only to create follow-up drafts you explicitly request, does not call Gmail's send methods, and does not use it to read your inbox or alter existing mail. Vinskal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Gmail is:

  • used only to provide the application-tracking features you explicitly trigger — detecting interview, offer, rejection, and status-update signals for jobs you are tracking;
  • never sold or transferred to third parties, and never used for advertising, ad targeting, or credit-scoring;
  • never used to train, develop, or improve generalized or third-party AI/ML models. Gmail signal detection runs on Vinskal's own deterministic rules — Gmail message content is not sent to our AI provider;
  • never read by a human, except with your explicit consent for a specific support request, where required for security or to investigate abuse, or as required by law.

Browser extension

The Vinskal browser extension requests six permissions: activeTab, scripting, storage, tabs, sidePanel, and identity (used only to sign you in to Vinskal with Google). By default it can read only the applicant tracking systems Vinskal supports, plus Vinskal’s own API. Access to any other site is optional, off by default, requested one site at a time when you turn it on in the side panel, and revocable from the same place.

It captures job details only when you click to capture, fills only fields covered by an execution plan you approved in the web app, and never fills SSN, payment, password, OTP/2FA, or CAPTCHA fields. Final application submit, when supported on a site, requires an explicit preview and your confirmation — it never submits silently or in the background.

One thing that does run before you click. Application forms usually load their question list over the network as the page opens, and that request has already finished by the time you press capture. So on supported job sites the extension watches page requests from the moment the page loads, and keeps only responses that look like an application’s question list — a response has to come from an application-shaped address and contain a question-list structure before any of it is read. Anything else is ignored and never leaves your browser. This runs only on the job sites listed in the extension’s permissions, and it is deliberately switched off on HR and payroll platforms — Rippling, ADP Workforce Now, Dayforce, Cornerstone, Personio, BambooHR, SAP SuccessFactors and Oracle Cloud — where your own employment records live behind the same web address as the job board. On those sites capture works only when you click.

Screenshot-assisted field detection. When enabled, and only during a capture you initiate, Vinskal may use a single image of the visible application page when fields cannot be identified reliably from page structure alone, so an AI model can identify the form’s fields. The image is used for that analysis and is not stored on our servers or written to our logs. It is skipped automatically whenever the page already contains personal information you have typed or a file you have attached. This capability is not currently enabled.

Sensitive fields are optional

Sensitive application fields are always optional and never required to use Vinskal. We do not autofill SSN, payment details, OTP/2FA codes, or CAPTCHAs. Flagged application questions may skip AI generation and require your manual review.

Data retention

We keep your information for as long as your account is active or as needed to provide the Service. When you delete data or close your account, we remove it from active production systems within a reasonable period. Residual copies may remain in encrypted backups for a limited time before those backups rotate out, except where we must retain certain records for legal, security, or fraud-prevention purposes. Some shared community job catalog records derived from anonymized metadata may remain after account deletion; your private vault, applications, and identifying linkage are removed.

Security

We use industry-standard safeguards — including encryption in transit, hashed passwords, access controls, and encrypted storage for integration tokens — to protect your information. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you of material incidents as required by law.

Your rights and choices

You can access, correct, export, and delete your information, and adjust privacy toggles (including optional anonymized job metadata contribution) in the app. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA/CPRA, including the right to object to or restrict certain processing and to lodge a complaint with a supervisory authority. We will not discriminate against you for exercising these rights.

Export and deletion

You can export your data and manage account deletion from Account & Settings. Export is provided as a JSON bundle of your structured account data; original uploaded file binaries may not be included in the bundle. Deletion can be scheduled with a grace period (typically 14 days) so you can cancel before it is final. Deletion removes your private account data from active systems; it does not delete messages in your Gmail mailbox. See the deletion plan in the app for what is removed, preserved, or deferred.

Cookies and local storage

We keep you signed in using a token stored in your browser's local storage, and we use local storage to remember essential preferences. We do not use advertising cookies or cross-site tracking. The browser extension stores your API connection locally in extension storage and does not share it automatically with the web app session.

Children's privacy

Vinskal is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

International users

Vinskal may be operated from, and your information processed in, countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the date above and, where appropriate, notify you. Continued use after changes take effect means you accept the updated policy.

Staying safe from scams

See the safety guide for how to spot fake jobs and what information you should never share early in an application. Job-trust scores in Vinskal are advisory only and do not guarantee a posting is legitimate.

Contact us

Questions about privacy or a data request? Email [email protected] or [email protected].