Privacy Policy
Last updated: August 28, 2026
The Shortlist (“we”, “us”, “our”) operates https://theshortlistapp.work, a job-application tracker. This policy explains how we collect, use, store, and delete information — including data obtained from Google APIs when you connect Gmail.
Information we collect
- Account data: name, email address, and profile information from Google Sign-In (openid, email, profile scopes).
- Application data you enter: companies, roles, statuses, notes, résumé files, and cover letters you upload or generate.
- Gmail data (optional): if you connect Gmail, we access your mailbox using the
gmail.readonlyscope to find job-related messages and update application status. We do not send, modify, or delete email for regular users. - Technical data: session cookies, CSRF tokens, and standard server logs (IP address, request time) for security and reliability.
How we use Google user data
When you authorize Gmail access, we use that data only to:
- Read email metadata and content needed to detect job-application events (confirmations, interviews, rejections).
- Match messages to applications on your dashboard and suggest status updates.
- Display matched messages in your Inbox review screen.
We do not use Google user data for advertising, sell it to third parties, or allow humans to read your mail except when necessary to provide support you request or to comply with law.
Google API Services User Data Policy
The Shortlist’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In summary:
- We only use Gmail data to provide user-facing features you request (job tracking and inbox sync).
- We do not transfer Gmail data to third parties except as needed to operate the service (hosting provider), comply with law, or with your consent.
- We do not use Gmail data for serving ads.
- We do not allow humans to read Gmail data unless you ask for support, the data is aggregated and anonymized, or it is required for security or legal compliance.
Admin send scope (optional)
Designated administrator accounts may separately authorize gmail.send so the service can send
invite and digest emails from that admin’s address. Regular users are not asked for send permission.
How we store and protect data
- Application data and account preferences are stored in an encrypted database on our hosting provider (Railway).
- Gmail refresh tokens are encrypted at rest using a server-side key (
TRACKER_TOKEN_KEY). Tokens are never exposed to the browser. - Per-user résumé and kit files are stored in isolated directories on the server volume.
- Access to production systems is limited to the service operator.
Data retention and deletion
- Account and application data are kept while your account is active.
- Disconnect Gmail: Settings → Disconnect Gmail revokes the token with Google and deletes the stored refresh token.
- Delete account: contact us to request deletion of your account and associated data.
- Cached email message records used for inbox review can be removed when you disconnect Gmail or delete your account.
Third-party services
- Google: Sign-In and Gmail API (subject to Google’s Privacy Policy).
- Railway: application hosting and persistent storage.
- LLM provider (optional): if configured, job descriptions may be sent to an AI API for scoring and résumé tailoring. Your Gmail content is not sent to the LLM.
Your choices
- You may use the app without connecting Gmail (manual status updates).
- You may revoke Gmail access at any time in Google Account settings or in-app Settings.
- You may request a copy or deletion of your data by contacting us.
Children
The Shortlist is not directed at children under 13. We do not knowingly collect data from children.
Changes
We may update this policy. The “Last updated” date will change when we do. Continued use after changes constitutes acceptance.
Contact
Questions or data requests: andrew.lancashire@gmail.com