Legal
Privacy Policy
Thozhil helps you find jobs, tailors your resume to each one, finds the right person to write to, and drafts the email. You review everything and press send.
This policy explains exactly what we store, why we store it, who else sees it, and how to get rid of it. It describes what the product actually does — not what it might do one day.
01Who we are
Thozhil is operated from India. For any question about this policy, or to exercise any of the rights below, write to adhityaganesh49@gmail.com. We answer within 7 working days.
02What we collect, and why
2.1 Account
| Data | Why |
|---|---|
| Email address | Identifies your account; the address we reply to |
| Name | Signs the emails Thozhil drafts for you |
| Password (hashed) | Only if you register with email/password rather than Google |
If you sign in with Google, we receive your email address, name and profile picture from your Google profile. We do not receive your Google password.
2.2 Your resume
The file you upload, plus the structured text we extract from it: work history, education, skills, certifications, and the contact details printed on it (email, phone, LinkedIn, location).
We need this to score jobs against your background, to tailor the resume to each posting, and to attach it to the application email.
2.3 What you tell the intake conversation
Your target roles, cities, salary expectation, years of experience, industry or domain preference, and how much time you can spend per day. This is a short conversation, not a form, so we store the conversation and the preferences derived from it.
2.4 Your activity in the product
Which jobs you skipped, applied to, or tracked; the stage of each application; the emails drafted and sent through Thozhil; and which people were found at each company.
2.5 Replies to your outreach
See section 4. This is the most sensitive thing we hold and it has the narrowest rules.
2.6 Technical data
Standard server logs (IP address, browser type, timestamps) kept for security and debugging. We do not use advertising cookies, we do not track you across other websites, and we have no third-party analytics or advertising SDKs in the product.
03How we use your Google account
If you connect Google, Thozhil requests exactly two permissions, and uses each only for the feature it names.
| Scope | What it lets us do | What we use it for |
|---|---|---|
gmail.send | Send email as you | Sending one application email that you have read and explicitly clicked Send on |
drive.file | Create and open files this app created | Saving the tailored resume we generated into your Drive |
What we deliberately did not ask for:
- We do not request
gmail.readonly. We cannot read your mailbox. We cannot see any message that was not sent in reply to an email you chose to send through Thozhil. - We do not request
gmail.compose. drive.fileis per-file by design: it gives access only to files Thozhil itself created. It cannot see, list or open anything else in your Drive.
Thozhil never sends email on its own. Every message — including follow-ups — is prepared as a draft and waits for you. Mail leaves your account only when you click Send.
You can revoke this access at any time at myaccount.google.com/permissions. Thozhil keeps working; the features that send mail or save to Drive stop until you reconnect.
Limited Use disclosure
Thozhil's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not:
- use Google user data to develop, improve or train generalised AI or machine-learning models;
- sell Google user data;
- transfer Google user data for advertising, credit assessment or lending purposes;
- allow humans to read Google user data, except (a) with your explicit consent for a support request you raised, (b) where necessary for security purposes such as investigating abuse, or (c) where required by law.
04How we see replies without reading your mailbox
Because Thozhil has no permission to read your inbox, every email it sends carries two Reply-To addresses: your own, and a signed address on our domain.
When someone replies, their mail client sends the reply to both. You get it in your inbox exactly as normal, and we receive a copy. That copy is what lets us move your tracker to "Interview" and stop sending you follow-up reminders.
Three rules govern that copy:
- We only ever receive replies to emails you chose to send. We are never copied on anything else in your mailbox.
- Automated replies are never stored. If our classifier decides a reply is an out-of-office or a no-reply bounce, we keep the verdict and discard the text.
- Human replies are truncated to 4,000 characters and deleted after 90 days, automatically.
The reply address is cryptographically signed. A forged one is rejected, which is what stops a stranger moving your tracker.
05Who else processes your data
These providers process data strictly to deliver features you asked for. We do not sell your data and we do not share it for advertising.
| Provider | What it receives | Purpose |
|---|---|---|
| Supabase | All account data, your resume file, your activity | Database, authentication and file storage |
| Google (Gemini) | Your resume text and the job description | Fit scores, tailored resumes, draft emails, reply classification |
| Groq | Same as above, when selected as the alternative model provider | Same as above |
| Hunter.io | A company name or website domain | Finding business contact details at the company you are applying to. Your personal data is never sent. |
| Apify | A public job-listing URL | Collecting public job listings |
| Tavily | A company-related search query | Public web search when a company site names nobody |
| Resend | Your email address | Sending account emails such as sign-up confirmation |
| Railway | Traffic to the application | Hosting |
| logo.dev | A company's website domain | Displaying company logos |
Job listings are collected from LinkedIn, Naukri and Wellfound public pages. No user data is sent to those sites — we read public postings, we do not act as you on them.
Google Gemini content submitted through the paid API is not used to train Google's models.
06How long we keep things
| Data | Retention |
|---|---|
| Reply message content | Deleted automatically after 90 days |
| Automated reply content | Never stored |
| Your account, resume, preferences, tracker | Kept while your account is open |
| Company research | Cached for 14 days, then refreshed |
| Contact lookups | Cached for 30 days |
| Server logs | Up to 90 days |
07Your rights
You can:
- Access — request a copy of everything we hold about you.
- Correct — fix anything wrong. Re-uploading your resume replaces the parsed copy.
- Delete — request deletion of your account. This removes your profile, resumes, tailored documents, preferences, tracker, contacts, drafts and stored replies.
- Withdraw consent — disconnect Google at any time, at the link in section 3.
- Object or restrict — ask us to stop a specific kind of processing.
Write to adhityaganesh49@gmail.com. We complete deletion requests within 30 days.
If you are in India, these rights sit alongside the Digital Personal Data Protection Act, 2023. If you are in the EEA or UK, our legal basis is performance of a contract (running the service you signed up for) and consent (connecting your Google account, which you may withdraw).
08Security
- Data is encrypted in transit (HTTPS/TLS) and at rest by our database provider.
- Google refresh tokens are held server-side and never exposed to the browser.
- Database access is restricted per user, so one account cannot read another's data.
- The inbound reply endpoint authenticates by cryptographic signature, not a shared secret.
No system is perfect. If you find a security problem, please write to adhityaganesh49@gmail.com before disclosing it publicly, and we will work with you.
09Children
Thozhil is for people looking for work and is not directed at anyone under 18. We do not knowingly collect data from children.
10Changes
If this policy changes materially we will update the date at the top and notify you in the product before the change takes effect. Continuing to use Thozhil after that means you accept the current version.