Privacy Policy
Last updated: July 29, 2026
JobSmoker is operated by Robert Gadala-Maria, 1861 NW 22nd St #1054, Miami, FL 33142, United States. This policy describes what we collect, how we use it, who can see it, and what your choices are. We wrote it to match how the product actually works.
What we collect
Information you give us directly: your email address; your full name; your job preferences, including target role, salary expectations, location, remote preference, industries, and dealbreakers; and the resume you upload.
Information from your Google account, if you connect one: we access and store information derived from your Gmail mailbox. For each message we store the sender name and address, recipient and Cc addresses, subject line, Google’s preview snippet, date received, Gmail message, thread, and label identifiers, message-threading headers, and attachment file names, types, and sizes. We do not store email bodies or attachments. JobSmoker no longer reads any Google spreadsheet or Google Drive file. Before that access was retired, 3,802 application rows were imported from a job-tracking spreadsheet. Those historical application records remain in the account under the retention terms below.
Information our systems create: classifications of your emails, reasoning behind those classifications, and job details extracted from emails and public job-posting pages.
Payment: payment happens on Stripe’s hosted checkout page. We never see or store your credit card details.
Your Google account access
When you sign in with Google, we request Google permissions in a single consent screen and store the access credentials Google issues, including a refresh credential, so the service can keep your job pipeline up to date while you are not using it.
- OpenID (`openid`): to sign you in with Google.
- Account email (`userinfo.email`): to identify your Google account and match it to your JobSmoker access.
- Account profile (`userinfo.profile`): to receive your basic Google profile information.
- Gmail (`gmail.readonly`): to request read-only access to view your mail and track job-application status. We do not send, modify, or delete your mail.
Signing out of JobSmoker does not disconnect your Google account. It ends your session everywhere — signing out on one device also signs you out on any other device where you are signed in — but we retain the stored Google credentials so the service can continue tracking your applications.
You can revoke JobSmoker’s Google access at any time in Google Account settings. Revoking stops new reading but does not delete information already stored.
Automated processing (AI)
We use Google’s Gemini AI service to understand job-search email. Our classifier sends Gemini the sender, subject, and up to the first 4,000 characters of message text to classify the message and extract related company, role, and job identifiers. A second step sends the sender, subject, and up to the first 1,500 characters of message text to decide whether a message needs action. We may also send text from a public job-posting page to extract job details.
The text sent to Gemini is not redacted or anonymized. We store Gemini’s result, not the message text. We use Google’s paid tier, whose terms state that submitted content is not used to train or improve Google’s models and is processed under Google’s Data Processing Addendum. Google may retain prompts for a limited period for abuse and safety monitoring under those terms.
Human access to your information
People who work for JobSmoker can see your data. A human assistant is part of the service.
- Assistants assigned to your account can see your job pipeline and, for messages flagged for action, the sender, subject, and date.
- Covered email content: Allow assistants assigned to your account to open readable text and links in account-verification and application-completion emails. These messages can include security codes or content unrelated to your job search. Support administrators may also do this while signed in as a member for support; those sessions are logged. Every authorized opening is recorded before retrieval. You can turn access off at any time in Settings. The content available through this feature is readable inline text and extracted links; attachments and raw HTML are excluded. Messages are selected by keyword rules and automated classification.
- You can allow, decline, or later withdraw this access in your account settings. A current grant for the current notice is required before each later retrieval attempt. Withdrawing blocks later authorizations but cannot retract an attempt that was already authorized.
- Before content retrieval, we write an access record for each authorized retrieval attempt. New records identify the account, message, time, requesting member, and any support administrator acting through that member. Because the record is written before token resolution and Gmail retrieval, it does not prove that content was retrieved or read.
- Support administrators can sign in as a member for up to one hour to provide support. Those sessions are logged separately, and administrators can also see customer records created at signup, including the resume.
Assistants do not sign in to Google as themselves. Mailbox access uses your stored credential, is limited to your workspace, and excludes attachments.
Who we share information with
We share information with the providers that run JobSmoker:
- Google: account sign-in, Gmail, and Gemini services described above.
- Supabase: database and file storage hosted in the United States.
- Vercel: hosting; operational server logs can include an account email and message identifiers.
- Resend: email delivery; signup notifications containing your name, email, target role, and location are sent to our team addresses.
- Stripe: hosted payment processing; card data does not touch our systems.
When applications are submitted on your behalf, your resume and profile information go to those employers. We do not sell or rent your information, and we do not use it for advertising.
Storage and security
Your data is stored in Supabase in the United States. Access is enforced by our application, and sign-in uses signed, HttpOnly session cookies. Resume files are stored in Supabase storage and served through short-lived signed links.
Retention and deletion
- We retain your data until you ask us to delete it; it does not expire today.
- The 3,802 historical application records imported from a spreadsheet follow that same retention rule; retiring spreadsheet access did not delete them.
- Removing a job from a board hides it but does not delete it, and new email may continue to match against it.
- Signing out does not end our access to your mailbox.
- Revoking Google access stops new reading but does not delete stored information.
- Security and access logs are kept for their audit purpose and are not deleted on request.
- To request deletion or a copy of your data, email hello@jobsmoker.com. Our team handles these requests manually and confirms when deletion is complete.
Cookies
We set exactly two cookies: jobsmoker_session, which keeps you signed in for 30 days and contains your email address and name in signed form, and oauth_state, which protects the Google sign-in handshake for 10 minutes. We use no analytics, advertising, or session-replay technology; set no third-party cookies; load no third-party scripts; and use no browser storage. Our fonts are self-hosted, so viewing our pages sends no font request to Google.
Google API Limited Use
JobSmoker’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only for the user-facing features described here, transfer it only to processors needed for those features, do not use it for advertising, and never sell it. Human access through the product occurs only under the recorded choice described above, when needed for security, or to comply with law.
Children
JobSmoker is not directed to anyone under 18, and we do not knowingly collect information from minors.
Changes to this policy
When we make material changes, we will update the date at the top and, for significant changes, notify you by email.
Contact
Questions about this policy can be sent to hello@jobsmoker.com. Postal contact: Robert Gadala-Maria, 1861 NW 22nd St #1054, Miami, FL 33142, United States.