PRIVACY
Privacy & Security
This Privacy Policy explains what information Vinskal collects, how it is used, who processes it, and the choices you have. Your data is yours: you can export or delete it from Account & Settings.
Summary
- We collect only the information needed to run your account and the features you use.
- We do not sell your personal information or use it for third-party advertising. AI providers receive only the information needed for the AI features you request, such as generating drafts, and our contracts with them exclude training on your inputs.
- When you approve an application, Vinskal’s own browser fills and submits it. We keep a replay of that run for 30 days so you can see exactly what was entered, and we hold, encrypted, any candidate account Vinskal created at an employer with your consent.
- Google sign-in and Gmail are separate: sign-in does not grant Gmail access. Gmail, when connected, is optional and user-triggered: Vinskal reads to detect application updates and can place a follow-up draft in your own Drafts folder, but never sends, deletes, or modifies mail.
- The browser extension sends nothing until you click. It detects job pages on your device and, on your click, opens the job’s address in Vinskal — that address is the only thing it sends.
- AI apps you connect see only the permissions you grant them, and you can disconnect them at any time.
- You can access, export, schedule deletion of, and disconnect integrations from Account & Settings.
Information we collect
We collect the following categories of information:
- Access requests — if you ask for early access on our website, the name, email, role, and note you enter, plus the network address the request came from, are emailed to the Vinskal operators so they can reply. Access requests are not stored in the application database.
- Account information — your email address, authentication credentials (passwords are stored only as salted hashes), the Terms revision you accepted and when, and, if you choose Google sign-in, basic profile identifiers from Google (such as your Google account ID and verified email).
- Early access and referrals — while Vinskal is in early access, your account carries a member number and a referral key. If your key opens someone else's account we show you the date it happened and nothing about who; if you joined through someone's key we record whose it was, and they see only that a key of theirs was used that day. Nobody else sees either.
- Career Profile data — the skills, experience, projects, education, certifications, writing samples, application answers, links, voice/style preferences, location, work-authorization details, and job preferences you choose to enter.
- Uploaded documents — resume and related files you upload, plus structured data extracted from them when you ask us to parse or tailor them.
- GitHub information (optional) — if you add a GitHub handle, we read your public repositories and profile to suggest projects and skills as evidence for your Career Profile. We do not access private repositories.
- Application data — saved jobs, generated materials (resumes, cover letters, answers), the packages you approve and their revision history, application status, submission receipts and evidence, follow-up records, and outbound email drafts you create.
- Apply-run recordings — when the Apply Agent runs an application you approved, it keeps a screencast of that run (a sequence of screenshots of the employer’s form as it was filled) together with an event log and per-step evidence frames. Because the recording shows the form, it shows your own answers as they were typed. It is visible only to you, and it is deleted after 30 days.
- Employer candidate accounts — if you consent to Vinskal creating candidate accounts at employers’ applicant tracking systems, we store, per employer, the email used, the password Vinskal generated (encrypted with a key dedicated to this purpose), the account’s status, and the password policy the employer stated. Revealing a stored password to you requires re-authentication and is audited.
- Connected AI apps — if you connect a third-party AI app, we store the app’s identity, the permissions you granted, the tokens that let it act within those permissions, and an audit trail of what it did through Vinskal.
- Mobile app and devices — if you use the Vinskal mobile app, your session is kept in the device’s secure storage, and if you enable push notifications we store the push token, the platform, and a device label so you can tell your devices apart and switch notifications off per device.
- Optional integrations — if you connect Gmail, bounded message metadata and snippets from scans you explicitly trigger (see below). Integration tokens are encrypted at rest.
- Billing information — paid plans are not currently offered. If billing is enabled in future, we would store your subscription tier, Stripe customer and subscription identifiers, and billing events; payment card numbers are handled by Stripe, never stored on our servers.
- Usage and diagnostic data — service logs, security and audit events, AI usage and spend records, weekly allowance counters, and product analytics scoped to your account (for example, usage counts and application outcomes you track).
- Shared job catalog (optional) — if you leave “contribute anonymized job metadata” enabled in your privacy settings, non-identifying facts about a posting you save (such as employer, title, and URL patterns) may be linked to the shared job catalog every user searches. Nothing about you is attached to the catalog record.
How we use your information
- To provide and operate the features you ask for.
- To find and rank postings that match the profile you build.
- To generate AI drafts (resumes, cover letters, answers, emails) that you review and approve.
- To fill and submit applications you approved, and to show you what was submitted.
- To secure your account and detect, prevent, and investigate abuse or fraud.
- To enforce early-access allowances and, if enabled in future, to process subscriptions.
- To maintain, debug, and improve the product.
- To comply with legal obligations.
We do not sell your personal information or share it for third-party advertising.
Where the GDPR applies, our legal bases are: performance of a contract (to provide the features you sign up for, including submitting applications you approve), your consent (for optional integrations such as Gmail, for candidate-account creation at employers, for AI apps you connect, for push notifications, and for shared-catalog contribution — each of which you can withdraw at any time), our legitimate interests (to secure the Service and prevent abuse), and compliance with legal obligations.
When we access your information
Vinskal does not access or view your personal information except when:
- You request support or troubleshooting that requires it,
- It is required for security or to investigate malicious activity, abuse reports, or policy violations, or
- It is required to provide the app functionality you asked for (minimized to what is necessary).
Administrators can see the operational state of apply runs (status, timing, errors, and the evidence frames of a run) to diagnose failures; they do not read your profile or documents for that purpose.
Service providers
We use trusted subprocessors to run the Service and perform functions on our behalf. Each processes data only to perform services for us under contractual confidentiality and security obligations, and we share only what is necessary for the feature you requested:
- Google (Gemini API) — AI inference to generate the drafts you request (resumes, cover letters, answers, follow-ups), to read job postings and application forms, to score matches, and to summarize company insights. Under Google's paid/API terms your inputs are not used to train their public models.
- Perplexity (Search API) — web search for company insights. Only an employer’s name and the role family being researched are sent; never your profile, documents, or identity.
- Google (OAuth & Gmail API) — Google sign-in and, only if you connect it, Gmail read plus draft-creation access for the tracking and follow-up features you trigger. Vinskal does not use its send capability.
- Resend — transactional email delivery (verification codes, password resets, security notices, and reminder digests you enable).
- Expo — delivery of push notifications to the mobile app, if you enable them. Expo receives the push token and the notification text.
- Sentry — error monitoring for the web app and API. Reports carry technical details of a failure; personal identifiers are not attached, and browser session replays sent with an error mask all text, inputs, and media.
- Fly.io and Neon — the application servers and the Postgres database that store your account data, in the United States.
- Cloudflare — serves the web app and protects the Service’s edge. No advertising or cross-site tracking.
- S3-compatible object storage — uploaded files, generated documents, and apply-run recordings and evidence.
- Shifter — a residential proxy for application runs on Vinskal's own browser, matched to the region on your profile, so the employer sees an address near you rather than a datacenter. Only the employer page traffic passes through it.
- Stripe — payment processing and subscription management, only if paid plans are enabled in future. Card details would be handled by Stripe and are not stored on our servers.
- Logo and place lookups — employer names are sent to Brandfetch and Clearbit to find company logos and domains, and locations are resolved against an offline GeoNames dataset. Neither involves any information about you.
We may update our subprocessors as the Service evolves; we keep this list current and require comparable data-protection commitments from any provider we add.
AI processing
To generate drafts, we send the relevant parts of your inputs to a third-party AI provider (currently Google's Gemini API). We rely on the provider's paid/API terms, under which your inputs are not used to train their public models, subject to each provider's applicable terms and technical controls. AI output is a draft until you review and approve it. Vinskal does not invent career facts — it may only rephrase or emphasize information you provide or approve. Questions that ask for a fact your profile does not hold are left blank for you rather than guessed.
Company insights are researched per employer, not per user: the employer’s name and the role family are sent to a web-search-enabled query (Perplexity, summarized by Gemini) together with public sponsorship figures from U.S. government filings, and the resulting summary is stored once and shown to every Vinskal user who looks at that employer. Your resume, profile, and identity are never part of that request, and nothing in an insight comes from any user’s private data.
The Apply Agent
When you approve an application package, a browser run by Vinskal opens the employer’s form, fills it with the approved content, uploads the approved files, and submits it. During a run:
- Only the fields in the approved package are filled. Social Security or tax identifiers, payment details, passwords, one-time codes, signatures, self-identification surveys, background-check authorizations, and legal declarations your profile does not hold are never filled by the agent.
- CAPTCHAs, sign-in challenges, and one-time codes are handed to you through the live view; Vinskal does not solve them and does not read them from your inbox.
- The employer’s page traffic passes through the residential proxy described above. Your Vinskal data never does.
- The run is recorded (see Apply-run recordings above) and each step keeps an evidence frame, so you can verify what was submitted. The recording and evidence are served only to your account and deleted after 30 days.
- If the employer requires a candidate account and you have consented, the agent creates it as described under Employer candidate accounts; it ticks the employer’s required terms box on your behalf and never optional opt-ins.
Gmail and integrations
Gmail access is optional and separate from Google sign-in. When connected, Vinskal uses two scopes: read-only access, for the status signals you explicitly request by triggering a scan, and draft-only access, used solely when you ask it to place a follow-up in your Drafts folder. It never sends, modifies, archives, deletes, or labels mail in Gmail — although the compose scope technically permits sending, Vinskal does not call Gmail's send methods, so a follow-up leaves your mailbox only when you press Send in Gmail yourself. It does not run background mailbox sync, and it does not automatically read employer verification or OTP codes — those stay with you. Outbound email to employers or recruiters uses Vinskal's own email provider stack only after you approve a draft and click Send (or schedule an approved draft for a time you choose). You can disconnect Gmail or other integrations at any time from Account & Settings.
Google user data and Limited Use
When you connect Gmail, Vinskal accesses your Google user data using the read-only gmail.readonly scope, and — only to create a follow-up draft you asked for — gmail.compose, which technically permits managing drafts and sending email. Vinskal uses this access only to create follow-up drafts you explicitly request, does not call Gmail's send methods, and does not use it to read your inbox or alter existing mail. Vinskal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Gmail is:
- used only to provide the application-tracking features you explicitly trigger — detecting interview, offer, rejection, and status-update signals for jobs you are tracking;
- never sold or transferred to third parties, and never used for advertising, ad targeting, or credit-scoring;
- never used to train, develop, or improve generalized or third-party AI/ML models. Gmail signal detection runs on Vinskal's own deterministic rules — Gmail message content is not sent to our AI provider;
- never read by a human, except with your explicit consent for a specific support request, where required for security or to investigate abuse, or as required by law.
Connected AI apps
You can connect a third-party AI app that supports the Model Context Protocol to your Vinskal account. When you do, Vinskal shows you exactly which permissions the app asks for (for example, reading your profile, listing jobs, editing an application package, or approving one), and you choose which to grant. The app then acts within those permissions using tokens issued to it; every action it takes is checked against your grant on each request and recorded in your account’s audit trail. Vinskal sends the app only what the tools it calls return. What the app does with that information is governed by the app’s own privacy policy, not this one. You can disconnect an app at any time from Account & Settings, which immediately invalidates its tokens.
Browser extension
The Vinskal browser extension is a job-page detector. It requests three permissions: storage (your on/off and per-site settings), activeTab, and scripting (to draw the “Open in Vinskal” control on the page you are looking at). By default it runs only on the job boards and applicant tracking systems Vinskal supports; access to any other site is optional, off by default, and granted one site at a time from the extension’s popup.
Before you click, detection reads the page on your device and sends nothing — not the address, not the title, not the page. When you click the control, the extension opens one Vinskal address carrying the job’s URL, and that is the only thing that leaves your browser. The extension holds no Vinskal login, calls no Vinskal API, does not fill forms, and does not read what you type. Its settings are stored locally in extension storage.
Sensitive fields are optional
Sensitive application fields are always optional and never required to use Vinskal. We do not fill SSN, payment details, OTP/2FA codes, or CAPTCHAs. Flagged application questions may skip AI generation and require your manual review.
Data retention
We keep your information for as long as your account is active or as needed to provide the Service. Apply-run recordings and evidence frames are deleted 30 days after the run. When you delete data or close your account, we remove it from active production systems within a reasonable period; a recording of a run may remain in storage until its own 30-day deletion. Residual copies may remain in encrypted backups for a limited time before those backups rotate out, except where we must retain certain records for legal, security, or fraud-prevention purposes. Shared job catalog records and company insights are not personal data and remain after account deletion; your private profile, applications, employer-account credentials, connected-app grants, and identifying linkage are removed.
Security
We use industry-standard safeguards — including encryption in transit, hashed passwords, access controls, encrypted storage for integration tokens and employer-account passwords (each under its own key), audited reveal of stored passwords, and per-request permission checks for connected apps — to protect your information. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to notify you of material incidents as required by law.
Your rights and choices
You can access, correct, export, and delete your information, and adjust privacy toggles (including shared job catalog contribution), employer-account consent, connected AI apps, and push notifications in the app. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA/CPRA, including the right to object to or restrict certain processing and to lodge a complaint with a supervisory authority. We will not discriminate against you for exercising these rights.
Export and deletion
You can export your data and manage account deletion from Account & Settings. Export is provided as a JSON bundle of your structured account data; original uploaded file binaries and run recordings are not included in the bundle. Deletion can be scheduled with a grace period (typically 14 days) so you can cancel before it is final, and confirming it requires a fresh code sent to your email. Deletion removes your private account data from active systems; it does not delete messages in your Gmail mailbox, and it does not close candidate accounts Vinskal created for you at employers — those remain yours to close with the employer, and the stored credentials are deleted. The account controls explain the available deletion options before you confirm.
Children's privacy
Vinskal is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
International users
Vinskal is operated from, and your information is processed in, the United States, which may be a different country from your own. Where required, we use appropriate safeguards for cross-border transfers.
Changes to this policy
We may update this policy as the product evolves. When we make material changes, we will update the date above, ask you to accept the updated Terms in the app, and, where appropriate, notify you. Continued use after changes take effect means you accept the updated policy.
Staying safe from scams
See the safety guide for how to spot fake jobs and what information you should never share early in an application. Company insights and match scores in Vinskal are advisory only and do not guarantee a posting is legitimate.
Contact us
Questions about privacy or a data request? Email [email protected] or [email protected].