Where each kind of data goes
RolePilot is a job-application service. One account is one candidate, and their data lives in that account's own workspace on the operator's host, plus the Google services the candidate controls.
Draft: needs legal review. This page states what the product does with data so a reviewer can assess it. It makes no legal claims and is not a warranty or a compliance certification.
What the service holds
- Identity: name, email, phone, city, country, date of birth, LinkedIn and GitHub links.
- Career: current and past employers, role titles, degree and institution, year, tenure, stack.
- Money: current gross salary, target floor, asking range.
- Authorization: work-permit status and expiry, sponsorship requirement, languages.
- Accounts: the Google refresh token (encrypted at rest), an alert chat id, a licence key.
Google data the service requests, and why
Sign-in asks for three read scopes and nothing more:
| Scope | What it is used for |
|---|---|
gmail.readonly | Reading your own mailbox to find employer replies, interview invitations, and verification codes for applications you have started. |
calendar | Placing a confirmed interview on your own calendar. |
spreadsheets | Writing your application tracker to a Google Sheet in your own Drive. |
gmail.send is requested separately, per account, and only if you turn on the option that has the service send an application from your own mailbox. It is off by default and is never requested at sign-in.
Google API Services User Data Policy and Limited Use
RolePilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In substance:
- Google user data is used only to provide and improve the features described on this page.
- It is not sold, and not used for advertising, creditworthiness, or lending decisions.
- It is not used to train or improve generalised artificial-intelligence or machine-learning models.
- It is not transferred to third parties except as needed to run the service, to comply with law, or with your consent.
- No human reads your mail. Automated processing does. A human reads it only with your consent for support, for security or abuse investigation, to comply with law, or where the data is aggregated and anonymised.
Where each kind goes
| Data | Processor | Why |
|---|---|---|
| Your candidate details (name, contact, employers, salary, permit, stack) | the model provider | rendered into the screening and tailoring prompt for each run |
| Your mailbox | Google (Gmail API, read-only) | replies and interview invitations are detected |
| Your tracker | Google (Google Sheets) | the tracker is the Sheet in your own Drive |
| Interview times | Google (Google Calendar) | a confirmed interview is booked on your calendar |
| Alerts | the alert channel you configure | interview and offer notifications, outbound only |
| Billing | Stripe | subscription billing; the card is stored by Stripe, never by RolePilot |
Storage and retention
- Your data lives in your account's workspace on the operator's host, plus the Sheet, Calendar and mailbox in your own Google account.
- There is no third-party analytics, no advertising tracker and no web beacon on this site.
- The Google refresh token is encrypted at rest; the key is a restricted file or an environment variable, never this site.
- Data is kept while your account is open so the service can keep working.
Revoking access and deleting your data
- Revoke RolePilot's Google access at any time from your Google Account, at myaccount.google.com/permissions. The service can then no longer read your mail or calendar.
- Download your data or delete your account from the Account screen inside the app. Deleting removes your workspace and generated documents permanently.
- Your Google Sheet, Calendar and mailbox are in your own account and are yours to delete separately.
Contact
Questions about this page or your data: vishalsehgal414@gmail.com.