Privacy Policy
Last updated: September 30, 2026 • Effective immediately
Vina adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements. Our use and transfer of information received from Google APIs to any other app will adhere to these requirements.
1. Information We Collect
We collect only the minimum necessary information required to operate our correspondence service:
- Account Credentials: Your email address and hashed password when creating a Supabase Auth account.
- Résumé & Profile Details: Your uploaded PDF résumé, background skills summary, and sign-off preferences stored in your private account.
- Google OAuth Tokens: When you connect your Gmail account, we receive an OAuth 2.0 authorization code exchanged for access and refresh tokens, alongside your verified Gmail address.
- Correspondence Log: The recipient’s email address, company name, extracted role title, and final sent subject/body for your personal records to prevent duplicate outreach.
2. How We Use Google User Data
When you authenticate with Google, Vina requests the following permissions:
Vina asks for permission to send messages on your behalf and to find your own sent messages so follow-ups land in the same conversation. It never reads your incoming mail.
- We never read, inspect, or store incoming mail from your inbox.
- We never access your address book, contact lists, or personal calendar.
- We never send automated bulk blasts or messages that you have not explicitly approved.
- We never sell, lease, or monetize your personal information or Google account data.
- Your Google data is never used to train artificial intelligence (AI) models.
3. Security & Token Encryption
Security and data privacy are foundational to our architecture:
- Encrypted at Rest: All Google OAuth refresh tokens are encrypted at rest using industry-standard AES-256-GCM encryption with unique initialization vectors and authentication tags. Plaintext credentials are never written to disk or logged.
- Isolated Storage: Your uploaded résumé PDF files are stored in private, user-isolated Supabase Storage buckets secured by Row Level Security (RLS). They are never publicly accessible.
- Encrypted in Transit: All data transferred between your browser, our servers, Supabase, AI providers, and Google APIs is encrypted using modern TLS (HTTPS).
4. Artificial Intelligence & LLM Data Protection
Vina uses advanced language models provided by enterprise partners (Groq Inc. and Google Cloud Vertex AI) to synthesize job descriptions and draft personalized application letters.
- Zero Model Training: Under our enterprise API terms with Groq and Google, your inputs (job descriptions, résumés, profile summaries) and generated letters are never used to train, retrain, or improve public AI models.
- Ephemeral Processing: Prompts sent to AI endpoints are processed ephemerally in memory to generate your draft and are not retained by AI vendors beyond immediate completion.
5. Cookies & Local Storage
We do not use tracking cookies or third-party advertising trackers. We utilize only essential browser storage technologies:
- Essential Authentication Cookies: Cryptographically signed HTTP-only cookies provided by Supabase to maintain your secure session.
- Local Storage (Draft Auto-Recovery): Temporary client-side caching in your browser so you do not lose in-progress job description drafts if your tab is refreshed. This data remains on your local device.
6. Third-Party Sub-Processors
We engage only trusted infrastructure and compliance vendors:
- Google Cloud Platform: Gmail API delivery and Google OAuth authentication.
- Supabase Inc.: Encrypted PostgreSQL database, authentication, and file storage.
- Dodo Payments Inc.: Merchant of Record for global checkout, recurring subscriptions, tax compliance, Apple Pay, and UPI processing. (We never handle or store raw credit card numbers).
- Groq Inc. & Google Cloud: AI letter generation and job description analysis (stateless API, zero model training).
- Vercel Inc.: Application edge hosting, serverless functions, and SSL delivery.
7. Regional Privacy Rights (GDPR, CCPA/CPRA & India DPDP)
Depending on your location, you may have specific statutory rights regarding your personal information:
- Right to Access & Portability: You may request an export of all your correspondence history, résumé files, and profile details.
- Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and all associated data at any time.
- Right to Disconnect: You can revoke Gmail OAuth permissions at any time from your Settings page or Google Security Settings, immediately purging stored tokens.
- No Sale of Personal Data: We do not sell, rent, or trade user data to data brokers or third parties.
8. Contact & Data Protection Inquiries
For any questions, requests for data export, or deletion inquiries regarding this Privacy Policy, please reach out to:
Privacy & Data Protection
Email: karangholap154@gmail.com
Response time: Typically within 24 to 48 hours.
© 2026 Vina (meetvina.app). All rights reserved.