Juubli is a job application tracker. If you choose to connect Gmail, Juubli requests the read-only Gmail scope https://www.googleapis.com/auth/gmail.readonly so it can scan inbox messages for job-application activity, organize related emails into a dashboard, and surface updates such as interviews, offers, and rejections. Juubli cannot send, delete, or modify email in your Gmail account.
Gmail access & permissions
When you connect Gmail, Juubli uses Gmail API access to process inbox messages. Specifically:
We request the exact Gmail scope https://www.googleapis.com/auth/gmail.readonly.
We read message headers, sender and recipient fields, thread IDs, snippets, message bodies, and attachments as needed to determine whether a message relates to a job application and to organize the related timeline.
Because Juubli must inspect message content before classifying it, Juubli may process messages that are ultimately determined not to be job-related. We do not intentionally use non-job-related content beyond what is technically necessary to classify and filter messages.
Disconnecting an inbox in Juubli stops future scans inside the app. Revoking Juubli in your Google Account permissions prevents future Gmail access until you reconnect.
Your Google OAuth tokens are encrypted at rest using AES-256-GCM, are never stored in plain text, and are transmitted over HTTPS/TLS.
Information we collect
When you use Juubli, we collect:
Your Google account profile data, such as name, email address, and avatar, for authentication and account management.
Encrypted OAuth access and refresh tokens needed to maintain your connected account.
Gmail-derived data, including message headers, sender and recipient fields, snippets, body previews, full message bodies, classification results, job-application status data, and related timeline metadata.
Attachment records where applicable, including filenames, MIME types, storage URLs, extracted attachment data, and parsed offer-letter details for supported documents.
Operational records such as scan logs, classification logs, model metadata, and diagnostic information used to operate, secure, and debug the service.
Product analytics such as pages visited, feature usage, Gmail connection state, and high-level counts through PostHog. We do not send raw Gmail message bodies to PostHog.
How we use your data
To scan inbox content and identify job-application activity using AI.
To group related messages into application timelines and display your dashboard, statuses, reminders, and analytics.
To process relevant attachments, including parsing offer-letter documents when applicable.
To send optional product notifications related to your account and job tracking activity.
To monitor performance, investigate errors, prevent abuse, and improve Juubli's reliability and accuracy.
What we do NOT do
We cannot send, delete, or modify email in your Gmail account.
We do not intentionally use non-job-related content beyond what is technically necessary to classify and filter messages.
We do not sell your data or use Gmail-derived data for advertising.
We do not store your Google password. Authentication is handled through Google OAuth 2.0.
We do not use Gmail-derived content to train generalized AI or machine learning models.
Data storage and security
Juubli stores Gmail-derived data server-side on infrastructure hosted on AWS, including message records and related application data.
Relevant attachments are stored in Amazon S3 or S3-compatible object storage.
OAuth tokens are encrypted at rest with AES-256-GCM.
Connections between your browser, Juubli, Google, and subprocessors use HTTPS/TLS encryption in transit.
Access to production systems is restricted to authorized personnel on a need-to-know basis.
Juubli personnel do not routinely review Gmail content. Human access is limited to support, security, fraud or abuse prevention, incident response, or legal compliance, and only when needed to provide or secure the service.
Third-party services
Juubli uses third-party services to operate. See our full Subprocessors list for details. Key services include:
Google OAuth & Gmail API — for authentication and read-only Gmail access.
AWS / Amazon S3 — for hosting and attachment storage.
OpenAI-compatible AI providers — for email classification and timeline analysis.
Anthropic — for parsing offer-letter attachments and extracting structured offer details.
Sentry — for error monitoring and operational diagnostics.
PostHog — for product analytics and derived usage signals.
Google reCAPTCHA — for bot protection.
Google API Services User Data Policy
Juubli's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Juubli does not use Gmail-derived data for advertising and does not use it to develop, improve, or train generalized AI or machine learning models. We only transfer Gmail-derived data to third parties when necessary to provide, secure, or support the features described in this policy, or when required by law.
Data retention and deletion
Disconnecting an inbox in Juubli stops future scans for that inbox, but does not by itself delete previously stored Juubli records.