HeardBack

You're viewing an archived version of the Privacy Policy, effective July 10, 2026. See the current version.

Privacy Policy

Version 1 · Effective July 10, 2026

HeardBack ("the app", "we") is a job-application tracker that watches your connected Gmail inbox(es) so you know the moment a company responds to an application. This policy explains what we access, what we store, and what we never do. It is written to be actually readable.

The short version

We read your email (with your explicit permission) for exactly one purpose: detecting responses to your job applications. We can never send, delete, or modify your email. We store as little as possible, encrypted. We don't sell anything to anyone. You can disconnect us at any time and everything we hold about you can be deleted.

What we access and why

Your Google identity: name, email address, and profile picture, used to create your account and show you who is signed in.

Your Gmail messages, read-only: granted via Google's gmail.readonly permission, which you grant explicitly on Google's consent screen. This permission cannot send, delete, archive, or modify mail. We check for new messages periodically and evaluate whether each one relates to a job application you are tracking.

Information you enter: the job applications you log, including company names, role titles, dates, portal links, and reminder preferences.

How email is processed

New messages pass through a three-stage filter. Most are dismissed by simple, automated matching (sender domain and keywords) and are never stored or sent anywhere. Only messages that appear job-related proceed to AI-assisted classification.

AI classification and data minimization: for the small number of messages that reach the AI step, we send only the sender address, the subject line, and a truncated snippet of the message body, roughly the first 500 characters. We never send full message bodies or attachments. This goes to whichever of our AI providers handles the request, together with the list of jobs you track, to determine which application the email concerns. We currently use three AI providers, DeepSeek, Google (Gemini API), and Groq, routing classification requests to whichever is available. Under the terms of the API tiers we use, a provider may use submitted content to improve its services, including human review of de-identified data. We deliberately minimize what is sent for this reason. [VERIFY EACH PROVIDER'S CURRENT DATA-USE TERMS BEFORE LAUNCH, INCLUDING DEEPSEEK'S DATA RESIDENCY/RETENTION POLICY, AND UPDATE OR REMOVE THIS BRACKETED NOTE ACCORDINGLY: Our AI provider(s) do not use submitted content for training or product improvement.]

What we store

  • Your account details (Google identity) and connected inbox addresses
  • OAuth tokens that let us check your mail, encrypted at rest (AES-256-GCM); a database breach alone cannot expose usable tokens
  • For job-related emails only: sender, subject, a short snippet, and the classification result, so your dashboard can show you what happened
  • Your logged jobs, reminders, and notification subscriptions

We do not store full email bodies, attachments, or any content from emails judged not job-related. Emails dismissed by the filter leave no record at all.

Google API Services: Limited Use disclosure

HeardBack's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: Google user data is used only to provide the app's user-facing features, is never sold, is never used for advertising, and is never transferred except as necessary to provide those features (e.g., the minimized AI classification described above), for security, or to comply with law. Human access to this data is prohibited except with your explicit consent, for security purposes, to comply with law, or in aggregated/anonymized form for internal operations.

Third parties we rely on

  • Google: sign-in, Gmail API, and AI classification (Gemini)
  • Groq: AI classification
  • DeepSeek: AI classification
  • Neon: database hosting, where your encrypted data lives
  • Vercel: application hosting
  • Browser push services (operated by Google, Apple, Mozilla, etc.): deliver notifications to your devices. They carry the notification text, not your inbox

We do not sell or share your data with anyone else. There is no advertising and no analytics resale.

Your controls

  • Revoke access instantly at myaccount.google.com/permissions. This is your kill switch: HeardBack loses the ability to read anything from the moment you revoke
  • Disconnect individual inboxes from within the app
  • Delete your account from within the app. This deletes your jobs, email records, reminders, tokens, and subscriptions from our database
  • Turn off notifications per device at any time

Data retention

We keep your data while your account is active. Deleting your account deletes your data. Disconnecting an inbox deletes its stored tokens.

Children

HeardBack is not directed at children under 16 and we do not knowingly collect their data.

Reporting security issues

If you believe you've found a security vulnerability in HeardBack, please email pxumstudios@gmail.com privately with the details rather than disclosing it publicly. We take reports seriously and will respond promptly.

Changes

If this policy changes materially, we will show you a notice in the app before the changes take effect.