1. What this policy covers
This policy explains information handling in the nowEmployed website and job-search workspace, including account access, resume uploads, job matching, application drafts, tracking, and optional Gmail sending. For privacy questions or requests, contact youarenowemployed@gmail.com.
You can read the public website and use its illustrative product preview without creating an account or uploading a resume. Preview jobs, companies, and match scores are examples, not public copies of a member’s workspace.
2. Information in your workspace
- Account and profile: your name, email address, authentication information, and the contact details, location, career summary, and experience you provide. Google sign-in supplies account identity information when you choose that option.
- Resumes and career facts: uploaded PDF or DOCX files, filenames, extracted resume text, and the skills and facts you review in your profile. Text extraction takes place within the application service; uploading a resume does not itself call Gemini.
- Search and matching: your target roles and search preferences, imported job links, job matches, scores, matched requirements, saved or dismissed roles, and search-run history.
- Applications: drafts, document versions, application questions and answers, approvals, recipient details, application status, follow-up reminders, and recorded outcomes.
- Connected Gmail: your connected email address, granted permissions, encrypted authorization tokens, and sending records. Google sign-in and Gmail sending are separate connections.
- Operation and support: usage-limit records, notifications, technical request and error information, and messages you send to support. Hosting and authentication providers also process technical information needed to deliver and secure their services.
3. What matching does with your information
nowEmployed compares job information with your verified skills, target roles, and work preferences to rank opportunities. Recorded application outcomes can contribute to personal ranking adjustments once enough outcome information is available.
A match score is a recommendation for your review. It is not an employer assessment, a hiring decision, or a probability of receiving an offer. You decide which roles to pursue. Job-feed discovery and matching do not require sending your resume to Gemini.
4. Gemini and application generation
When you request AI application documents, nowEmployed sends Google’s Gemini API the resume context, verified career facts, relevant job description, and application questions needed to prepare the draft. This context can contain personal information from your resume. The response is stored in your workspace as application artifacts for your review.
Current provider setup: unpaid Gemini API. Google’s unpaid-service terms allow submitted content and generated responses to be used to improve Google products and machine-learning technology, and allow human review. Those terms instruct users not to submit sensitive, confidential, or personal information to the unpaid service. Do not use AI generation to submit such information. See Google’s Gemini API terms.
nowEmployed therefore does not promise that content submitted through AI generation is excluded from Google’s model improvement or human review. The API request asks Google not to store the interaction as a retrievable interaction; that setting does not override Google’s data-use terms.
Profile setup records an AI-processing permission. You can avoid new AI submissions by not requesting generation. There is currently no self-service switch to withdraw that recorded permission; contact support to request withdrawal. Withdrawing permission or deleting an account cannot undo processing that already occurred at an external provider.
5. Gmail, sending, and device sharing
Connecting Gmail grants permission to send email on your behalf. The integration requests identity and send permissions; it does not request permission to read your inbox. Your Gmail authorization tokens are encrypted before storage. They are used to obtain sending access and are not included in Gemini prompts.
When you approve and send an application, the selected recipient and email provider receive the message and attachments. When you use device sharing, the destination you choose receives the shared files. Those recipients and services handle their copies under their own practices; disconnecting Gmail or deleting your workspace does not recall an email or remove a recipient’s copy.
nowEmployed’s use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements. Gmail access is used for the sending feature you authorize, not inbox analysis or advertising.
You can disconnect Gmail in Settings and remove access through your Google Account connections. Disconnecting removes the usable stored connection from nowEmployed; it does not delete messages already sent.
6. Services involved in processing
- Supabase: account authentication, workspace database records, and private resume-file storage.
- Vercel: website hosting and application request processing.
- Google: optional Google sign-in, optional Gmail sending, and Gemini generation when requested, as explained above.
- Email delivery services: configured SMTP delivery or Resend processes recipient addresses and message content for product emails; authentication emails are delivered through the authentication service’s configured email provider.
- Destinations you select: employers, recruiters, application websites, or device-share applications receive the information you choose to send or share.
These services may process information outside Nigeria. We do not claim that all information stays in Nigeria or that all provider copies use a single retention period. Provider terms and international-transfer requirements remain relevant to their processing.
7. Session cookies and security
Authentication cookies maintain your signed-in session. Google’s sign-in interface, when loaded on an authentication page, can process browser and connection information under Google’s policies. Blocking necessary cookies can prevent account access.
Private workspace access is restricted to authenticated accounts, and account-owned database and storage access is controlled by authorization rules. These controls reduce unauthorized access; they are not a guarantee against every security incident. Do not upload passwords, bank credentials, identity documents, or unnecessary third-party personal information in your resume.
8. Retention, exports, and deletion
Your workspace keeps resumes, extracted text, drafts, and tracking records so you can return to them. The current product does not apply an automatic inactive-account purge.
Settings provides an account-data export. It exports structured workspace records; download any document files you want to keep separately. The resume library permits deletion of a non-default resume when another resume remains. Replace your only resume or select another default before removing it.
Removing a resume does not remove its content from documents already generated from it. For account closure, complete erasure requests, or a self-service deletion error, contact support. We do not promise immediate removal of every file, backup, security record, or provider-held copy. A deletion request needs confirmation of the records and files removed, and any applicable retention exception.
9. Your requests and choices
You can ask to access, correct, export, or erase your personal information, withdraw permission where processing relies on consent, or object to or request restriction of processing where applicable law provides those rights. The available response depends on the request and any legal exception.
Email youarenowemployed@gmail.com from your account address, describe the information or feature involved, and tell us what you want changed. We may need to verify account ownership. Do not email your password. You can also raise a concern with the Nigeria Data Protection Commission or another competent data-protection authority.
10. Changes to this notice
The date above identifies this version. Updates should reflect changes to actual features, providers, or information handling. A revised notice does not reverse previous disclosures or replace any fresh permission required for a new use of information.