Privacy Policy
Last updated: August 27, 2026
Scope and data controller
This policy applies to Postulate.Me, a project in a pilot stage for tracking job searches. Whoever develops and administers it is also who is responsible for handling your data.
For any question about this policy or your data, write to us through the Contact form.
Your account data
To create your account we use your Google account or a magic link to your email, through Supabase Auth. If you sign in with Google, we receive the name, email address, and profile photo that are public on that account. If you sign in by email, only your email address.
We never see or store your Google password: authentication is handled by Google, not by this server.
The data you enter
Everything you register in the application — applications (company, role, dates, status, notes), their stages (interviews, exams, trainings), the HR contact directory (name, email, company, notes), and the files you attach (resume and cover letter per application) — is stored in your account and only you can see it.
The HR contact directory includes data about people who are not Postulate.Me users. You're responsible for entering that data reasonably, in the context of your own job search, and for that use complying with whatever regulation applies to you.
Isolation between accounts
No one but you can see your data, not even with access to the application's code: isolation between accounts is guaranteed by row-level security policies in the database, not by a check on the application side.
Who your data is shared with
We don't sell your data or use it for advertising. It's shared only with the providers that make the service possible:
- Supabase: database, authentication, and storage for the files you attach.
- Vercel: hosts the web application.
- Google: if you choose to sign in with your Google account, it handles that authentication.
- Google Gemini: generates the synthetic job listings shown in the admin section. It never receives your applications, contacts, or attachments — it's only used to produce sample listings.
AI connectors
If you connect an AI client (such as Claude or ChatGPT) through our MCP server, that client can read or modify the data you explicitly authorized, within the scope — read-only, or read and write — you chose when approving the connection.
You can review and cut off any of those connections at any time from your profile.
How long we keep your data
Your data is kept while your account is active. There isn't yet a self-service option to delete the whole account: if you want us to delete your data, write to us through Contact and we'll do it manually.
Connection tokens (personal or OAuth) that you revoke are marked as revoked. Ones nobody ever authorizes, or that are never used, are purged automatically after seven days.
About email notifications
Postulate.Me doesn't actually send email notifications yet: when the system would generate a notice, it logs internally what it would have said, but doesn't dispatch it. It's a feature under development and the interface says so wherever it applies.
Your rights over your data
You can export your applications and contacts to CSV at any time from the application. To correct, update, or delete any data — including fully closing your account — write to us through Contact.
Minors
Postulate.Me isn't directed at anyone under 18 and doesn't knowingly request data from minors.
Changes to this policy
If we make a significant change to this policy, we'll note it on this same page along with the update date.
Contact
Questions about this policy or your data? Write to us through the Contact form, in this page's footer.