Legal
Privacy Policy
What JobHunt collects, what it does with your Google account, where it is stored, and how to get rid of all of it. Written to be checked against the software, not skimmed.
Last updated 21 August 2026
JobHunt is a free tool by ULYX. It has one job: find jobs that match you and apply for you, from your own Gmail. This policy tells you precisely what that involves. The ULYX-wide baseline is at ulyx.in/privacy; where this page is more specific, this page governs.
1. Who is responsible
ULYX is an independent, self-funded software project operated from India, and is the data controller for the processing described here. Contact admin@ulyx.in for any privacy question, data request, or complaint.
2. What we access in your Google Account
When you connect, Google shows you exactly four permissions. Here is what each is for and what we do with it:
| Scope | Why we ask | What we store |
|---|---|---|
gmail.send |
To send your applications from your own mailbox, so they arrive as genuinely from you. In auto mode this happens without a per-message prompt; review mode requires your approval each time. | Nothing from your mailbox. We keep only the message we composed and its delivery outcome. |
openid |
To identify your account across sign-ins. | Your Google account identifier (sub). |
userinfo.email |
To know which address applications will be sent from, and to contact you. | Your email address. |
userinfo.profile |
To put your name on the application rather than a blank. | Your display name. |
What gmail.send cannot do
This is the narrowest Gmail scope Google offers. It permits sending only. It gives us no ability to read, search, list, download, modify, or delete any message in your mailbox - including messages JobHunt itself sent - and no access to your contacts, drafts, labels, or attachments. We chose it precisely so that reading your mail is not a matter of our good behaviour: the permission we hold simply does not allow it.
3. What else we collect
- Your profile - the target roles, skills, seniority, regions, and sending caps you set, plus the resume details used to write applications.
- Your resume file - if you upload a PDF, we store the exact bytes so it can be attached to applications. A SHA-256 checksum is recorded at both ends so you can confirm the copy that reaches a recruiter is the file you picked. Limit 1.8 MB.
- Job postings - title, company, location, description, and the application address, as published in the feeds we pull. These are about employers, not about you, and go into a pool shared by all users so the same posting is not re-processed for everyone.
- Applications - the drafts generated for you, whether you approved or skipped them, and the send result.
- Operational counters - per-company, per-mailbox and per-day send counts that enforce the caps.
- Whether your Google account belongs to an organisation - if it does, we store the domain, so the dashboard can keep warning you that applications are going out of your employer's mail system. Read from the sign-in token Google gives us; it tells us nothing else about your employer.
If you joined the waitlist before 11 August 2026
Access used to be opened in batches, so the site offered a waitlist. It is closed. Sign-up is open to anyone, the form is gone, and no new entry can be created. We are not collecting this, and there is no mailing list to be on: no newsletter, no marketing sequence, nothing further will be sent.
If you did join, the entry we still hold is the email address you
typed, an approximate location (country, region, city and time
zone, resolved by Cloudflare from your connection - city-level at
best), a one-way salted hash of your IP address that cannot be
reversed into an address or matched against one, and browser and
referral details (user agent, language, screen size, time zone,
the page you arrived from and any utm_* tags on the
link you followed). The IP address itself was never
stored.
Email admin@ulyx.in and the entry is deleted outright. If you go on to create an account with the same address, deleting that account deletes the waitlist entry with it, automatically.
How postings are collected
Postings come from public job feeds and employer career APIs that permit automated access, fetched by our own servers on a schedule. Nothing on your machine collects them, and we do not sign in to any job site as you. Nothing about you is attached to a posting when it is stored - the pool is built impersonally and shared across all users.
Our collector identifies itself by name on every request. It does not disguise itself as a web browser, and where a site declines to serve it, that is the end of the matter rather than the start of a workaround.
If you are a recruiter, and this is about you
This section is not about our users. It is about the people our users write to, who did not sign up for anything.
When a job posting publishes an address to apply to, we store that address alongside the posting so an application can be sent to it. We take it verbatim from what the employer published, in the same breath as the invitation to apply - we do not guess addresses, we do not compose them from somebody's name, and we do not use an address that merely appears in a posting for some other reason.
Every application we help send carries a link to stop them. Following it adds your address - or your whole domain, if you prefer - to a list checked before every application is queued and again in the seconds before it is sent, for every user of the service. It takes effect immediately. We keep that entry indefinitely and deliberately: it is the record of the fact that you told us to stop, and deleting it would let the same address be written to again.
To have an address removed from a posting, corrected, or to ask what we hold about you, mail admin@ulyx.in. If you are in the EU, the UK or India you may also have rights under the GDPR or the DPDP Act, including the right to complain to your data protection authority.
If you install the JobHunt Helper browser extension
JobHunt Helper is a separate, optional Chrome extension. It is not required to use this service, and this service does not need it to work.
It sends us nothing. The extension makes no network requests of any kind: no API calls, no analytics, no error reporting, no contact with our servers or anyone else's. We cannot tell whether you have installed it, and nothing you type into it reaches us.
What you type into it - your name, email, phone, location, current employer and profile links - is stored by your own browser, on your own device, in the extension's local storage. Uninstalling the extension deletes it. Deleting your ULYX account does not, because we never had a copy to delete.
On a Greenhouse or Lever application page it reads the form in order to fill it, and it fills only fields it can stand behind. Questions about immigration status, pay, protected characteristics, background checks, health or government identifiers are deliberately left empty and shown to you with the reason. It never submits an application: you review what was filled and press the employer's own submit button yourself.
4. What we do with it
- Match postings against your profile and generate a draft application.
- Send applications through Google's Gmail API from your account - automatically if you chose auto mode, or after your approval on each one if you chose review mode. You are asked which during setup and cannot skip the question.
- Enforce the sending caps, and the list of addresses that must never be written to.
- Keep the shared posting pool free of duplicates and stale entries.
- Answer the questions you ask the Assistant, from your own data and from figures about the shared job pool.
- Show you, without naming you, to employees at companies whose openings you matched, so they can refer you — while Let employees refer me is on.
That is the complete list. We do not profile you, we do not build an advertising audience, and we do not use your data - or Google user data - to train machine-learning models.
5. Who we share it with
We do not sell, rent, or broker your data. It is disclosed only to:
- Google - to send the mail you approved, via the Gmail API, using your own credentials.
- The recipient you approved - the employer or recruiter receives the application and the resume you attached, because that is the entire point.
- Cloudflare - our infrastructure provider, which hosts the service, the database, and the key-value store as a processor acting on our instructions.
- Google Tag Manager - website analytics on ulyx.in only. It sees page views, not your mailbox, resume, or applications. See section 9.
- Resend - the mail provider we used for the waitlist confirmation and invite emails, acting as a processor on our instructions. Those emails have stopped. It handled the address given to the waitlist form and nothing else: no access to your mailbox, your resume, or any application. It was never involved in sending your applications, which go through your own Gmail.
- OpenRouter - the AI provider that reads your resume when you upload it, writes the draft of each application, and answers your questions in the Assistant. It receives the text of your resume, the job posting being applied to, and anything you type into the Assistant, as a processor acting on our instructions. It does not receive your mailbox, your Google credentials, or anything about other users. If you connect your own OpenRouter account in Settings, that traffic is billed to you and governed by your agreement with them as well as by this policy.
-
An employee at a company you matched with -
only if you have left Let employees refer me on, and
only when they commit to referring you. Until that moment they
see your skills, seniority, city and years of experience and
nothing that identifies you - no name, no
contact details, no employer, no summary. When they commit, they
receive your name, contact details and CV so they can put you
forward through their own company's referral system, and
we email you every time, naming who and for what.
Each person can do this a small number of times a day. Turn the
setting off and you are not shown to anyone.
To recruit those employees in the first place, we publish a page for each hiring company showing that real candidates match its openings. A reduced version of the same anonymous card can appear there — seniority, years, city, skills and the match score, with no headline, no identifier and no way to reach you — for at most five people against one role, and the page is blocked from search engines. It follows the same setting: turn Let employees refer me off and you are not on it either. -
Another JobHunt user building something —
only if you have left Let people build a team with me
on. Someone describes an idea and we work out which roles it
needs; if your CV shows you could fill one, you appear on their
screen as an
anonymous card — the role, your skills, seniority,
years and city, and nothing that identifies you. No
name, no contact details, no headline, no summary.
They can pay a one-off fee to reach the team. At that moment, and not before, they receive your name, contact details and CV — and you receive theirs, because this introduction goes both ways. We email you every time it happens, naming what they are building and whether they say the work is paid, equity, unpaid or exploratory. Nobody is obliged to reply to anybody.
You can be introduced this way at most once a week, however many people are looking, and each person can bring together one team a day. We keep a record of which teams hold your details and you can read it in Settings. Turn Let people build a team with me off and you stop being shown to anyone — it is a separate switch from Let employees refer me, so turning one off leaves the other alone. - Legal authorities - only where we are compelled. We will tell you unless legally barred.
We still do not sell, rent or broker your data, and nobody pays us to see you. The people who can search are verified as working at a company we hold job postings for — through their work Google account or a code sent to their work address — and each of them can only see candidates for their own company's openings.
The Assistant is a question-and-answer feature and can only read. It cannot change your settings, apply for a job, or send anything. What it may look at is your own profile, matches and application history, plus figures about the shared job pool. Where it compares you to other users it uses aggregates only - counts and medians across everyone in your experience band - and it declines to answer at all when that band is too small for an aggregate to be anonymous. It is never shown another user's profile, resume, matches, or identity.
If you connect JobHunt to your own AI app over MCP, the token you generate in Settings lets that app read the same things through the same tools. Anything it then does with them is between you and that app; revoke the token in Settings to end it.
Job postings in the shared pool are visible to other users of the service. They contain no personal data about you.
6. Where it is stored, and how it is protected
- All data lives on Cloudflare infrastructure. The primary database is hosted in Western Europe; sessions and caches sit on Cloudflare's global edge.
- All traffic is HTTPS.
- Your Google refresh token is encrypted with AES-GCM before it is written to the database, using a key held in managed secret storage separate from the data. A copy of the database alone does not yield your token.
- Short-lived access tokens are cached only for their lifetime and then discarded.
- Credentials and tokens are never written to logs.
7. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, resume | Until you delete it or close your account |
| Refresh token | Until you disconnect, revoke access at Google, or close your account |
| Sessions | Expire automatically; deleted on sign-out |
| Applications and send records | While your account is open - they are what enforce the caps and stop duplicate applications |
| Job postings (shared pool) | Pruned automatically as they go stale |
| Your notifications — what JobHunt did and what needs you | 30 days, then deleted |
| A record of which teams were given your details | Until you delete your account, or the person who brought the team together deletes theirs |
| A record of who was referred you, and by whom | While your account is open — it is how we can tell you who has your details. Deleted with your account, and deleted if the person who referred you deletes theirs |
| Assistant conversations | Until you delete the conversation, or close your account. Unlike the rest of your account they are not kept in the 30-day recovery copy below - they are destroyed immediately |
| Deleted account (recovery copy) | 30 days, then destroyed permanently |
| Addresses a recruiter asked us to stop writing to | Indefinitely. It is the record that we were told, and removing it would let the address be written to again |
| Usage counts (no identifier that reaches you) | Kept indefinitely; anonymous once your account is gone |
| Waitlist entry (list closed, none can be created) | Until you ask us to remove it, or until you delete an account created with the same address |
On account deletion we remove your personal data within 30 days. Job postings you contributed remain in the shared pool, because they are information about employers and contain nothing about you.
What "within 30 days" means in practice. When you delete your account, everything the product can reach is gone immediately: your profile, resume, matches and any queued applications are deleted, your session ends, and we tell Google to revoke our permission to send mail as you. A copy is then held in a separate store that the product cannot read, for 30 days, so that an accidental deletion can be undone if you write to admin@ulyx.in. After 30 days a scheduled job destroys that copy permanently, and at that point it cannot be recovered by us or by anyone else. Your Gmail refresh token is never part of that copy - it is destroyed at once.
What survives deletion, and why it is not about you. We keep counts of how the product was used - how many matches were scored, how many applications were approved, whether sending was ever paused. These records are stored against a random identifier that was never derived from your name, email or Google account, and deleting your account destroys the only thing that connected that identifier to you. What remains is a set of numbers attached to a random string, which is no longer information about a person. We use it to understand whether the product works, and it contains no email address, no employer you applied to, and no part of your resume.
8. Your controls
- Revoke Google access instantly, without involving us, at myaccount.google.com/permissions. Sending stops immediately.
- Remove an old waitlist entry by writing to admin@ulyx.in. The entry is deleted, not flagged. The list is closed either way.
- Delete your resume from your dashboard at any time.
- Choose review mode, where you approve or skip every single application and nothing is sent without you. You are asked to choose between this and auto mode during setup, with nothing preselected; in auto mode applications are sent within the caps without asking you first, which is what it is for. You can switch either way at any time, and your dashboard shows which mode you are in at the top of every page. If you never answered the question - you left setup part-way, or your account predates it - you are in review mode and nothing is sent without you. Accounts created before 9 August 2026 were set to auto by default and were left that way.
- Pause sending outright, at any time. Nothing already queued goes out either.
- Lower the caps below our defaults whenever you want. You cannot raise them.
- Export or delete everything - email admin@ulyx.in and we will respond within 30 days. No reason required.
Depending on where you live you may have further rights under India's Digital Personal Data Protection Act, the EU/UK GDPR, or comparable law, including the right to complain to your data protection authority.
9. Cookies and analytics
This website loads Google Tag Manager (container
GTM-NWNJB8HS), which in turn loads
Google Analytics (G-JMTLE2K44M). We
use it to measure how the site is used - which sections people
read, and how many go on to sign in. Tag Manager and the
measurement tags it loads may set cookies and send Google your IP
address, the page URL, and basic device information.
What it records is the interaction - a page view, a section read, a button pressed. It has never received an email address from this site. The waitlist form it used to measure is gone.
This applies to the ulyx.in website only. It is not present in the API, and it has no access to your mailbox, your resume, your profile, or your applications. We do not use it for advertising, we do not sell what it collects, and we run no advertising networks or ad retargeting tags.
If you would rather not be measured, any tracker blocker will stop it, and browsers' “Do Not Track” and cookie controls apply as normal. Your sign-in session cookie is separate from these analytics cookies. Typefaces on these pages load from Google Fonts, which means Google also sees the page request.
10. Children
JobHunt is not for anyone under 16, and we do not knowingly collect their data.
11. Changes
Material changes will be announced here with an updated date before they take effect. If a change would broaden what we access in your Google Account, Google will ask you to consent again - we cannot expand it silently.