Skip to main content
Greenlit

Privacy policy

Last updated: August 5, 2026

Overview

Greenlit (aigreenlit.com) helps you search for jobs, score fit against your profile, prepare application materials, and fill forms in your browser. By default you review and submit every application yourself. Pro Auto-submit Beta only submits Greenhouse jobs after you select them and confirm a batch.

This policy explains what we collect, how we use it, and your choices. Questions: [email protected].

What we collect

  • Account — email, optional display name, and authentication data via our auth provider (Supabase).
  • Profile & documents — apply profiles (target roles, skills, preferences), resume and cover letter files you upload, and text we extract to help you apply.
  • Job search & applications — searches, match scores, application pipeline status, and events (including extension fill telemetry for reliability).
  • Usage & quotas — logs that enforce free-tier limits (searches, AI generations, ATS checks, Auto-submit).
  • Gmail (Pro, optional) — if you connect Gmail, we store an encrypted OAuth refresh token and use read-only Gmail API access. We may read message metadata (headers such as subject, from, and date), snippets, and — only when needed to match a reply to an application or to surface a Greenhouse security/verification code — limited message body content. We do not send, modify, label, or delete email in your account. You can disconnect anytime on Profile.
  • Feedback — messages and optional screenshots you submit.
  • Visit & device signals — an anonymous visitor cookie (`gl_visitor`) on public pages for unique-visit analytics; when you use the signed-in app we may record approximate location from edge headers (city/region/country) and IP for abuse prevention and product analytics. We do not sell this data.
  • Payments — billing is handled by RevenueCat and Stripe. We receive entitlement/plan status and billing events; card numbers are processed by Stripe, not stored on Greenlit servers.

How we use data

We use your data to:

  • Score jobs and show explainable match breakdowns
  • Generate or improve resume-grounded cover letters and profile fields — we do not fabricate experience
  • Fill application forms in your browser (or Auto-submit only after you confirm)
  • Sync recruiter replies when Gmail is connected — match messages to your applications, update pipeline status, show replies on Today / Applications, and compute interview-rate analytics for your account
  • Process subscriptions and enforce quotas
  • Improve reliability, security, and the product

Data protection

We protect account and Google user data with technical and organizational measures appropriate to the sensitivity of the data:

  • In transit — HTTPS/TLS for traffic between your browser, our servers, and Google APIs.
  • At rest — Gmail OAuth refresh tokens are encrypted (AES-256-GCM) before storage. Application and email match records are stored in our Postgres database hosted by Supabase.
  • Access controls — Gmail tokens and synced message data are accessible only through authenticated server routes for your signed-in account. We do not expose Google tokens to the browser client.
  • Least privilege — we request only the Gmail read-only OAuth scope needed for reply matching; we do not request send, modify, or delete permissions.
  • Infrastructure — application hosting on Vercel; auth, database, and file storage on Supabase — each under their security controls and our configuration.

AI processing

We use OpenAI (API) to score jobs and generate text from content you already provided (resume, profile, and job description). Prompts for those features are sent to OpenAI for that purpose only.

Gmail / Google Workspace user data is never sent to OpenAI or any other third-party AI/ML service. Recruiter-reply classification and matching run as rule-based logic on our servers using the Gmail data we read for your account. We do not use Google user data to train, improve, or fine-tune foundational or generalized AI/ML models.

Google Workspace APIs & Limited Use

When you connect Gmail, we access Google user data solely to provide and improve the user-facing reply-tracking features described above. We do not sell Google user data, use it for advertising or lending, or transfer it to data brokers.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Browser extension

The Greenlit Autofill extension runs on aigreenlit.com and supported job application pages. It receives fill instructions from your signed-in session and fills forms locally in your tab. Default fill pauses for your review before submit. Auto-submit Beta clicks Submit only for jobs you selected and confirmed. The extension does not browse unrelated sites.

Sharing & service providers

We share data with providers who help us operate Greenlit, including: Supabase (auth, database, file storage), Vercel (hosting), OpenAI (AI for resume/job/profile text only — not Gmail data), RevenueCat and Stripe (subscriptions), and Google (Gmail OAuth when you connect). We do not sell your personal data.

When you apply to a job, the information you submit goes to the employer (or their ATS) through their site — under their policies, not ours.

Cookies & similar tech

We use an essential session cookie for authentication and an anonymous visitor cookie on public marketing pages for aggregate visit counts. Preference settings (such as theme) may be stored in local storage on your device. We do not use third-party advertising cookies.

Retention & deletion

We retain account data while your account is active and for a reasonable period afterward for backups, legal, and security needs. Matched Gmail message records (subject, from, snippet, classification) are kept with your applications until you delete the related data or your account. You may request access or deletion by emailing [email protected]. Disconnecting Gmail removes our stored refresh token for that connection and stops further inbox sync.

Your choices & rights

Depending on where you live (including California and the EEA/UK), you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing. We do not sell personal information as that term is commonly defined under CCPA. To exercise rights, contact [email protected].

Children

Greenlit is for adults seeking employment. We do not knowingly collect personal information from children under 16. If you believe a child provided data, contact us and we will delete it.

International transfers

We and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.

Changes

We may update this policy. The “Last updated” date will change when we do. Material changes may also be noted in the product changelog on About.

Contact

About & changelog · Privacy · Terms · Home

Privacy Policy — Greenlit