Your inbox access is sensitive. Here's exactly how we protect it.
Juubli only requests the https://www.googleapis.com/auth/gmail.readonly scope — the most restrictive Gmail permission available. This means Juubli cannot send, delete, or modify any email in your account, ever. We read only what is technically required to detect and organize job-application activity.
Your Google OAuth access and refresh tokens — the keys that allow Juubli to read your inbox — are encrypted at rest using AES-256-GCM before being written to our database. They are never stored as plain text.
All data transmitted between your browser, Juubli's servers, Google's APIs, and our subprocessors travels over HTTPS/TLS. We enforce TLS on every connection and do not support unencrypted channels.
Juubli runs on AWS (Amazon Web Services). Attachments and file data are stored in Amazon S3 or S3-compatible object storage. AWS maintains a broad set of compliance certifications including SOC 2, ISO 27001, and PCI DSS. Access to production infrastructure is managed through least-privilege IAM policies.
Juubli uses AI services (including OpenAI-compatible providers and Anthropic) to classify emails and parse offer letters. When Gmail message content is sent to these providers, it is transmitted over TLS and subject to data processing agreements. We do not use Gmail-derived content to train generalized AI models, and we require our AI subprocessors to uphold the same constraint.
We use Sentry for application error monitoring. Sentry may capture stack traces and request metadata to help us diagnose bugs. We configure Sentry to scrub sensitive fields and avoid sending raw Gmail message bodies to Sentry.
You can revoke Juubli's access to your Gmail account at any time through your Google Account permissions. Once revoked, Juubli immediately loses access to your inbox. To also delete stored data, email privacy@juubli.com.
If you discover a security vulnerability in Juubli, please report it responsibly to security@juubli.com. We review all reports promptly and aim to respond within 48 hours. We ask that you do not disclose vulnerabilities publicly before we have had a reasonable opportunity to address them.
For any security-related questions, contact security@juubli.com.