Privacy Policy
Privacy Policy for ApplyInbox Effective date: March 9, 2026
ApplyInbox is a service operated by Rosyvid Oy, Finland ("Rosyvid", "ApplyInbox", "we", "us", "our").
ApplyInbox helps users track job application and recruiter email conversations. To provide that service, ApplyInbox connects to a user's Gmail account with the user's consent, analyzes email threads to detect recruitment-related communication, and presents relevant information to the user.
ApplyInbox is built to use as little access and storage as reasonably possible while still providing the core product value.
1. Who we are
Data controller: Rosyvid Oy, Finland. Contact: privacy@applyinbox.com
Under EU data protection law, the company deciding why and how personal data is processed is the data controller.
2. What ApplyInbox does
ApplyInbox connects to a user's Gmail account and requests read-only access. The service cannot send, modify, delete, or otherwise alter emails in the user's Gmail account.
ApplyInbox analyzes email threads in stages:
- Some thread metadata is processed in memory to detect likely recruitment-related emails
- Non-recruitment emails are dismissed and are not stored in the product database
- When a thread is classified as recruitment-related with high confidence, ApplyInbox stores thread metadata (subject, sender, dates) and extracted application details (company name, role, stage). Email body content is used for classification but is not stored in the database
To classify emails, ApplyInbox may send thread metadata and, in some cases, email content to Google Gemini, a large language model service provided by Google. This processing is used solely for recruitment detection and metadata extraction required to operate the service. Google processes this data according to its applicable data processing terms and privacy commitments. ApplyInbox does not permit this data to be used for training AI models.
3. What personal data we collect
Depending on how you use the service, we may collect and process:
Account and profile data
- name
- email address
- authentication identifiers
- account settings, such as timezone
Gmail connection data
- Google account email address
- access tokens needed to maintain the Gmail connection
Email data processed through the service
- thread metadata such as subject, sender, recipients, labels, dates, and message counts
- job-application-related details extracted from email analysis, such as company name, role title, recruiter contact, stage, action needed, and dates
- email body content is processed for classification but is not stored
Product usage and operational data
- log data
- sync status and error information
- billing and subscription status
- customer support communications
Payment data
Payments are handled by Stripe, which acts as an independent payment processor. We do not store full payment card numbers on our own servers. Stripe processes payment data according to its own privacy policy and terms.
4. How we use your data
We use personal data to:
- provide and operate ApplyInbox
- connect to your Gmail account and sync relevant email data
- detect recruitment-related email threads
- create and maintain your application dashboard
- identify likely actions needed, such as replying to a recruiter
- send service emails, including transactional and reminder emails
- manage subscriptions, trials, and billing
- secure the service, prevent abuse, and troubleshoot issues
- comply with legal obligations
We do not sell personal data to advertisers.
5. Gmail data and Google API use
ApplyInbox uses Google APIs to access Gmail data only with your consent.
ApplyInbox requests the gmail.readonly scope for the limited purpose of providing the job application tracking service. In practice, that means reading email threads to identify and organize recruitment-related conversations. ApplyInbox does not request permission to send, modify, or delete emails.
ApplyInbox does not use Gmail data to serve ads.
ApplyInbox does not sell Gmail data.
ApplyInbox does not allow humans to read your Gmail content except:
- when necessary for customer support that you request or authorize
- when required for security, legal compliance, or to protect the service and its users
ApplyInbox only processes Gmail data as necessary to provide its core functionality and does not use Gmail data for advertising, profiling unrelated to the service, or AI model training.
ApplyInbox's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Legal basis for processing
If you are in the EEA, UK, or Switzerland, we generally rely on these legal bases:
- Contract: processing needed to provide ApplyInbox to you
- Consent: connecting your Gmail account
- Legitimate interests: maintaining security, improving reliability, and preventing abuse
- Legal obligation: where we must comply with law
7. What we store and what we do not store
ApplyInbox is designed to reduce unnecessary retention.
- Non-recruitment emails are filtered out and not stored in the product database.
- Recruitment-related threads are stored with metadata only (subject, sender, dates). Email body content is processed in memory for classification but is never stored in the database.
- Access tokens are stored encrypted at rest.
ApplyInbox processes email content to classify threads, but only stores metadata and extracted application details, not the email content itself.
8. Third-party services and processors
ApplyInbox uses third-party service providers to operate the service, including:
- Google Cloud for hosting and infrastructure (EU region: europe-west1)
- Google Gmail API for Gmail access
- Google Gemini for email classification and metadata extraction
- Resend for transactional emails
- Stripe for billing and payments
These providers may process personal data on our behalf as processors or independent controllers, depending on the service and context.
9. International transfers
Our primary infrastructure is hosted in the EU (Google Cloud europe-west1). Some of our service providers may process data outside the EEA. When personal data is transferred outside the EEA, we use appropriate safeguards, such as standard contractual clauses and other lawful transfer mechanisms required by applicable law.
10. Data retention
We keep personal data only as long as reasonably necessary for the purposes described in this policy.
- Account data: while your account is active, plus up to 30 days afterward for legal and accounting purposes
- Email data: while your account is active, deleted when you delete your account
- Dismissed thread records: retained while the associated email account is connected, to avoid re-processing
- Billing and transaction records: as required by Finnish accounting law (typically 6 years)
- Logs and operational records: up to 90 days
Account deletion
When you delete your account, we immediately revoke your Google OAuth access token and permanently delete all personal data, including stored email content, application data, and Gmail connection data. Billing records required by law may be retained in anonymized form.
11. Security
We use reasonable technical and organizational measures to protect personal data, including access controls, encryption of sensitive credentials, and infrastructure security practices. No system can be guaranteed perfectly secure, but protecting user data is a core requirement of the service.
12. Your rights
Depending on applicable law, you may have the right to:
- access the personal data we hold about you
- request correction of inaccurate data
- request deletion of your data
- request restriction of processing
- object to certain processing
- request data portability
You can delete your account and associated data directly through the service. For other requests, contact us at privacy@applyinbox.com.
If you believe your rights have not been respected, you may lodge a complaint with a supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).
13. Cookies and similar technologies
ApplyInbox uses minimal technical cookies required for authentication, session management, and service operation. We do not use third-party advertising trackers.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and take reasonable steps to notify users when appropriate.
15. Contact
Rosyvid Oy Retkeilijänkatu 6 B 41, 00980 Helsinki, Finland privacy@applyinbox.com