JPJobPortal
PrivacyTerms

Plain-language policy

Privacy, without the fog.

JobPortal is a private, single-user job-search tool. This policy explains exactly what it reads, what it keeps, and what stays out of reach.

Effective and last updated: August 23, 2026

On this pageOverviewGoogle dataHow data is usedStorage & retentionSharingYour choicesContact

1. Overview

JobPortal helps one authorized user discover, organize, and evaluate job opportunities. It combines approved public job-board data with job-alert messages the user deliberately routes to a dedicated Gmail label. The public website you are reading uses no account system, advertising cookies, or analytics.

2. Google user data

JobPortal requests the Gmail API's read-only scope, gmail.readonly. Google's permission can technically allow messages and settings to be viewed. JobPortal applies a narrower application-level boundary:

  • It resolves only the exact Gmail label JobPortal/Alerts.
  • It queries only that label using fixed LinkedIn and Handshake sender and subject rules.
  • It rechecks label membership and provider eligibility before processing a message.
  • It cannot send, modify, label, archive, or delete email.

The OAuth flow may also receive the Google account address so JobPortal can show which account is connected.

3. How data is used

Eligible alert messages are parsed to extract job-listing information such as employer, role title, location, listing URL, and posting details. Raw message bodies are processed transiently and are not retained as raw bodies or written to application logs.

JobPortal stores extracted listing data and limited operational metadata—including Gmail message or thread identifiers, a content hash, processing status, and timestamps—to prevent duplicates, retry failures, and explain where a listing came from.

Email content is not currently sent to a large language model. A bounded LLM fallback is disabled by default. If that practice changes, this policy will be updated before the feature is enabled.

4. Storage, security, and retention

Extracted job and operational records are stored in the private JobPortal database. OAuth client configuration and the refresh token are stored separately in a dedicated Azure Key Vault. The local OAuth client file remains in an ignored secrets directory and is not committed to source control.

Records are retained until the user deletes them or decommissions the environment. Deleted cloud secrets or records may remain briefly in encrypted backups or provider recovery systems according to those providers' retention controls.

5. Sharing and sale

JobPortal does not sell Google user data, use it for advertising, or share it with data brokers. Data is processed only by the infrastructure providers required to operate the private service, currently Google's Gmail API and the user's private Microsoft Azure resources.

JobPortal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Your choices and controls

  • Remove a message from JobPortal/Alerts to keep it outside future discovery runs.
  • Use JobPortal's Disconnect action to delete the active refresh-token secret and disable email sources.
  • Revoke JobPortal from your Google Account's third-party access settings to end Google authorization.
  • Delete stored job records or decommission the private environment to remove retained application data.

7. Contact

Questions about this policy or a deletion request can be sent to privacy@jobportalonline.tech.

JPJobPortal

Built for a thoughtful, human-led job search.

HomeTermsContact