HeardBack

Privacy Policy

Effective July 23, 2026Version history

Contact: pxumstudios@gmail.com

Jump to a section

HeardBack ("the app", "we") is a job-application tracker that watches your connected Gmail inbox(es) so you know the moment a company responds to an application. This policy explains what we access, what we store, and what we never do. It is written to be actually readable.

The short version

We read your email (with your explicit permission) for exactly one purpose: detecting responses to your job applications. We can never send, delete, or modify your email. We store as little as possible, encrypted. We don't sell anything to anyone. You can disconnect us at any time and everything we hold about you can be deleted.

What we access and why

Your Google identity: name, email address, and profile picture, used to create your account and show you who is signed in.

Your Gmail messages, read-only: granted via Google's gmail.readonly permission, which you grant explicitly on Google's consent screen. This permission cannot send, delete, archive, or modify mail. We check for new messages periodically and evaluate whether each one relates to a job application you are tracking.

Information you enter: the job applications you log, including company names, role titles, dates, portal links, and reminder preferences.

How email is processed

New messages pass through a three-stage filter. Most are dismissed by simple, automated matching (sender domain and keywords) and are never stored or sent anywhere. Only messages that appear job-related proceed to AI-assisted classification.

AI classification and data minimization: for the small number of messages that reach the AI step, we send only the sender address, the subject line, and a truncated snippet of the message body, roughly the first 500 characters. We never send full message bodies or attachments. This goes to whichever of our AI providers handles the request, together with the list of jobs you track, to determine which application the email concerns. We currently use three AI providers, and their data-use terms differ. We deliberately minimize what is sent to all three for this reason.

  • Google (Gemini API) and Groq: we use paid-tier billing with both. Neither uses submitted content to train or improve their models, and both retain it only briefly for abuse and reliability monitoring.
  • DeepSeek: content sent to DeepSeek is processed and stored in China, and under DeepSeek's default terms may be used to train or improve their models. We have requested an opt-out from DeepSeek and are waiting on their confirmation; we will update this policy once we hear back.

What we store

  • Your account details (Google identity) and connected inbox addresses
  • OAuth tokens that let us check your mail, encrypted at rest (AES-256-GCM); a database breach alone cannot expose usable tokens
  • For job-related emails only: sender, subject, a short snippet, and the classification result, so your dashboard can show you what happened
  • Your logged jobs, reminders, and notification subscriptions
  • For each device you turn notifications on from: its browser, operating system, and model name, so the Devices list can tell your phone from your laptop. You can rename or remove any device there.

We do not store full email bodies, attachments, or any content from emails judged not job-related. Emails dismissed by the filter leave no record at all.

Google API Services: Limited Use disclosure

HeardBack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: Google user data is used only to provide the app's user-facing features, is never sold, is never used for advertising, and is never transferred except as necessary to provide those features (e.g., the minimized AI classification described above), for security, or to comply with law. Human access to this data is prohibited except with your explicit consent, for security purposes, to comply with law, or in aggregated/anonymized form for internal operations.

Third parties we rely on

  • Google: sign-in, Gmail API, and AI classification (Gemini)
  • Groq: AI classification
  • DeepSeek: AI classification
  • Neon: database hosting, where your encrypted data lives
  • Vercel: application hosting
  • Browser push services (operated by Google, Apple, Mozilla, etc.): deliver notifications to your devices. They carry the notification text, not your inbox

We do not sell or share your data with anyone else. There is no advertising and no analytics resale.

Cookies and local storage

The only cookie HeardBack sets is your sign-in session, created when you sign in with Google. It keeps you logged in as you move between pages and is removed when you sign out.

We also keep a few small preferences in your browser's local storage: whether you've switched to dark mode, and whether you've dismissed a notification or install prompt. These stay on your device and are never sent to us.

We don't run analytics, advertising, or any third-party tracker. Nothing here follows you across other sites or builds a profile of you.

Under EU law, cookies that are strictly necessary to provide a service you asked for, like staying signed in, don't require consent. That covers everything described above. If we ever add something that isn't strictly necessary, like analytics, we'll ask first.

Your controls

  • Revoke access instantly at myaccount.google.com/permissions. This is your kill switch: HeardBack loses the ability to read anything from the moment you revoke
  • Disconnect individual inboxes from within the app
  • Delete your accountfrom within the app. Your Gmail access is revoked and you are signed out immediately. Your account then enters a 14-day grace period: sign back in during that window and you can restore it with one click. If you don't, everything (your jobs, email records, reminders, tokens, and subscriptions) is permanently erased from our database at the end of the 14 days
  • Turn off notifications per device at any time

Data retention

We keep your data while your account is active. Requesting deletion starts a 14-day grace period during which your data is kept, untouched, so the request can be reversed; your Gmail access is revoked the moment you request it, regardless of the grace period. Once the 14 days pass, your account and everything tied to it are permanently deleted, not just marked as removed. Disconnecting a single inbox deletes its stored tokens right away, without affecting the rest of your account.

Our database host, Neon, keeps its own short-term backups for disaster recovery. Those backups age out on Neon's own schedule, separate from and outside our control, so a backup may briefly retain deleted data after our own purge completes.

Children

HeardBack is not directed at children under 16 and we do not knowingly collect their data.

Reporting security issues

If you believe you've found a security vulnerability in HeardBack, please email pxumstudios@gmail.com privately with the details rather than disclosing it publicly. We take reports seriously and will respond promptly.

Changes

If this policy changes materially, we will show you a notice in the app before the changes take effect.

Also see the Terms of Service.

Version history

  • Version 2 · Effective July 23, 2026Current
  • Version 1 · Effective July 10, 2026View