Privacy Policy — Job Application Tracker Google Sheets
Last updated: Aug 31, 2026
This extension is built and run by a single independent developer, not a company. This page explains what data it involves and how it's handled.
What we collect
- Google account identity — your email address and Google account ID, obtained via Google Sign-In, used to identify your account with the backend.
- Usage data — the number of applications logged, saved auto-fill field counts (per form-tab type), your Google Sheet's ID, your plan status (free/paid/exempt), and your on/off toggle preferences for the extension's features. Stored so free-tier limits can be enforced and your settings can sync.
- Résumé/CV file name — if you use the auto-attach CV feature, we store the file name and upload timestamp only, so the extension can show you what's on file. We do not receive or store the file's contents.
- Job application data — company, job title, location, salary, job description, and application status. This is written directly to the Google Sheet in your own Google Drive. We do not receive or store a copy of this content — only a numeric count of rows/fields.
- Email integration data (optional feature) — if you turn on the Gmail auto-status feature, it deploys a Google Apps Script project under your own Google account, which you separately grant Gmail access to via Google's own consent screen (not through this extension). Our server stores only: your Sheet ID, that script's deployment URL, a shared secret and license key used to authenticate requests from it, whether you've completed Google's consent step, and a running count of automated status updates it's made. The script reads and classifies your Gmail messages entirely inside your own Google account — message content is never sent to, or seen by, our server. Only the count above is reported back.
- Server access logs — like most web servers, ours incidentally logs the IP address of each request for basic operation and security. We do not use this for tracking or profiling.
What we don't collect
We never see your Google password. We don't collect health data, payment card numbers, personal messages, or precise location. We don't track your browsing beyond the specific job posting pages this extension is built to work with, and — as above — we never see the content of your Gmail messages or your spreadsheet rows.
How data is used
Solely to operate the extension: identifying your account, enforcing free-tier limits, and (if you opt in) enabling the email-status feature described above. Not used for advertising, profiling, or anything unrelated to these functions.
Sharing
We don't sell or share your data with third parties. Your account identity is verified directly against Google's own servers. Your job application data goes only to the Google Sheet you control, and any Gmail access happens only inside the Apps Script project running under your own Google account.
Who can see this data
Your email address, usage data, and plan status are visible to the developer via an internal admin dashboard, used only to manage plan status and troubleshoot issues. No one else has access.
Data retention and deletion
Account identity and usage data are kept for as long as you use the extension. If you disable email integration, the deployment record is removed from our server (the license key itself may be retained so that re-enabling later doesn't require a new one). Your job application data lives in your own Google Sheet and stays under your control — edit or delete it, or delete the sheet itself, independent of anything on our end. To request deletion of your account record from our server, contact us below; as a one-person project this is handled manually, on a best-effort basis, typically within a couple of weeks.
Data protection
Sensitive data — your Google account identity, OAuth tokens, and the license key/shared secret used for email integration — is protected as follows:
- Encryption in transit — all communication between the extension, our server, and Google's own servers happens over HTTPS (TLS). We never transmit these values unencrypted.
- Encryption at rest — the license key and shared secret used to authenticate your email-integration deployment are encrypted (AES-256) before being stored on our server.
- No password or Gmail content ever reaches us — you authenticate directly with Google; we never see or store your Google password. If you enable email integration, your Gmail messages are read and classified entirely inside the Apps Script project running under your own Google account — message content never reaches our server.
- Token isolation — your Google access and refresh tokens are stored only in Chrome's extension-isolated local storage on your device, and our OAuth client secret is stored only in a server-side environment variable — it is never included in the extension itself.
- Access control — account and usage data are visible only to the developer through a password-protected admin dashboard secured with a signed, time-limited session token.
- Random, scoped credentials — the license key and shared secret used to authenticate your Apps Script deployment are generated with a cryptographically secure random generator and are used only for that single purpose.
Children
This extension is not directed at children and is not knowingly used by anyone under 13.
No warranty, best-effort service
This is an independently maintained project, not a company product with an SLA. It's provided as-is; see the Terms of Service for details.
Changes
If this policy changes, the date at the top of this page will be updated.
Contact
[email protected]