Trust & Safety

Security

Your inbox access is sensitive. Here's exactly how we protect it.

← Back to home

Gmail access scope

Juubli only requests the https://www.googleapis.com/auth/gmail.readonly scope — the most restrictive Gmail permission available. This means Juubli cannot send, delete, or modify any email in your account, ever. We read only what is technically required to detect and organize job-application activity.

Encryption at rest

Your Google OAuth access and refresh tokens — the keys that allow Juubli to read your inbox — are encrypted at rest using AES-256-GCM before being written to our database. They are never stored as plain text.

Encryption in transit

All data transmitted between your browser, Juubli's servers, Google's APIs, and our subprocessors travels over HTTPS/TLS. We enforce TLS on every connection and do not support unencrypted channels.

Infrastructure

Juubli runs on AWS (Amazon Web Services). Attachments and file data are stored in Amazon S3 or S3-compatible object storage. AWS maintains a broad set of compliance certifications including SOC 2, ISO 27001, and PCI DSS. Access to production infrastructure is managed through least-privilege IAM policies.

Access controls

Third-party AI processing

Juubli uses AI services (including OpenAI-compatible providers and Anthropic) to classify emails and parse offer letters. When Gmail message content is sent to these providers, it is transmitted over TLS and subject to data processing agreements. We do not use Gmail-derived content to train generalized AI models, and we require our AI subprocessors to uphold the same constraint.

Error monitoring

We use Sentry for application error monitoring. Sentry may capture stack traces and request metadata to help us diagnose bugs. We configure Sentry to scrub sensitive fields and avoid sending raw Gmail message bodies to Sentry.

Revoking access

You can revoke Juubli's access to your Gmail account at any time through your Google Account permissions. Once revoked, Juubli immediately loses access to your inbox. To also delete stored data, email privacy@juubli.com.

Vulnerability disclosure

If you discover a security vulnerability in Juubli, please report it responsibly to security@juubli.com. We review all reports promptly and aim to respond within 48 hours. We ask that you do not disclose vulnerabilities publicly before we have had a reasonable opportunity to address them.

Questions

For any security-related questions, contact security@juubli.com.