dossier← Back to site

Privacy Policy

Last updated: July 20, 2026

Dossier is a job-application tracker operated by Ken Yeung (“Dossier,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect when you use our website, web application, and browser extension (together, the “Service”), how we use and share it, and the rights and choices you have. By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Information We Collect

Information you provide

  • Account information. You sign in with Google. We do not create or store a password. Through Google’s sign-in, we receive your name, email address, and profile picture as permitted by the scopes you approve.
  • Job-search records. The information you add about your applications — company, job title, job posting URL, status, application and interview dates, interview counts, and free-text notes.
  • Contacts you choose to record. If you use networking features, information you enter about people you know (such as name, role, company, and your own notes). This is optional and entered by you.
  • Support communications. Information you provide when you contact us for support or feedback.

Information collected with your permission

  • Email-to-save and forwarded rejections (optional). Every account has a private, unguessable address. When you choose to send an email to it — sharing a job posting from your phone, or forwarding a rejection message — we process that one email in memory to do one of two things: extract the company, role, and link so we can save the job, or recognize a rejection and move a job you already track to “Rejected.” We then discard the email — its subject, body, and sender are never stored. What persists is only the job record or status change you would otherwise have entered by hand. We never access your inbox or mailbox; we only ever see the specific emails you send to your address.
  • Your résumé (optional). If you turn on Resume Fit and add a résumé, we store the extracted text so we can compare it against postings you save. We never store the file you uploaded — a PDF or Word document is converted to text in memory and discarded. Your résumé is private to your account, is excluded from data exports and from any analytics, and you can delete it at any time in Settings.
  • Your background profile (optional). You can build a short summary of your background — your skills, seniority, job titles, the domains you’ve worked in, the languages in your public GitHub repositories, and the topics you write about — so our résumé feedback is grounded in your real experience. If you upload a résumé or share a link, we read it once to build your skills profile and immediately discard the file or page. We never store the document. The same is true of profile text you paste. We store only the short structured summary — the kind of thing you could have typed into a form — and you can view all of it, remove any single source, or delete the whole profile at any time in Settings.
  • GitHub (optional). If you give us your GitHub username, we read your public repositories through GitHub’s public API to work out which languages you build in and how recently you’ve published code. We do not sign you in to GitHub, do not hold a GitHub token, and cannot see anything private. Removing it deletes those fields outright.
  • We never fetch LinkedIn. Dossier does not automatically access LinkedIn profiles — not yours, not anyone else’s, and not through the browser extension. Automated access would breach LinkedIn’s terms and put your account at risk. If you want LinkedIn information in your profile, you copy and paste it yourself.

Information collected automatically

  • Essential cookies. We use cookies strictly necessary to keep you signed in and to operate the Service. We do not use advertising cookies or third-party tracking or analytics.
  • Server logs. Our hosting and infrastructure providers generate standard logs (such as IP address, timestamps, and error diagnostics) used for security, debugging, and abuse prevention. We do not log the contents of your notes, contacts, or emails.

Information we do not collect

We do not collect passwords, payment or card details, government identifiers, files or documents of any kind — a résumé you upload is converted to text and the file itself is discarded, and a page we read at your request is discarded the same way — your general browsing history, or location beyond what Google sign-in provides. We do not store LinkedIn profiles or fetch them automatically. The browser extension activates only on supported job-posting pages.

2. How We Use Your Information

  • To provide, maintain, and operate the Service and your account.
  • To power the features you use — tracking applications, apply reminders, analytics on your own data, contact surfacing, and the optional email-to-save feature (saving jobs and logging rejections you forward).
  • To generate AI-assisted insights you request (see Section 5).
  • To secure the Service, prevent abuse, debug, and enforce our terms.
  • To respond to your support requests.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use it for advertising or share it with recruiters or data brokers.

3. Legal Bases for Processing (EEA/UK Users)

Where the EU or UK General Data Protection Regulation applies, we process your information on these bases: performance of a contract (to provide the Service you request); consent (for optional features such as email-to-save, which you may withdraw at any time); legitimate interests (to secure and improve the Service, balanced against your rights); and legal obligation (to comply with applicable law).

4. How We Share Information

We do not sell or rent your personal information. We share it only with service providers who process data on our behalf, under contracts that limit them to providing their services to us:

Supabase
Database, authentication, and storage of your account and job-search records.
Vercel
Application hosting and delivery.
Google
Sign-in (OAuth) only — we receive your name, email, and profile picture. We do not request access to your Gmail or any other Google API data.
Anthropic
Processes limited text to power AI features (job-posting analysis and company-news relevance). We do not send your name, email, or account identifier with these requests, and under Anthropic’s API terms your data is not used to train its models.
Cloudflare
Routes inbound mail for the optional email-to-save feature.

We may also disclose information if required by law, to respond to valid legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will provide notice as required by law).

5. Artificial Intelligence Features

Some features use a third-party AI provider (Anthropic’s Claude API) to analyze a job posting you capture, to compare your résumé against a posting, to build your background profile from a résumé or pasted text, to pull the topics from a page you ask us to read, or to judge whether a news headline is relevant to a company you track. We send only the text needed for the task and never include your name, email, or account identifier. Under the provider’s commercial API terms, your inputs and outputs are not used to train its models. AI-generated insights are provided for convenience, may not be accurate, and should not be relied upon as professional advice.

6. Google API Services — Limited Use Disclosure

Dossier’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We use Google only to sign you in. We request just the basic profile scopes needed for authentication (your name, email address, and profile picture) and do not request access to Gmail or any other restricted Google API data — Dossier never reads your mailbox. Any information received from Google is used solely to create and secure your account, is not transferred to others except as necessary to provide the Service, is not used for advertising, and is not read by humans except with your consent, for security, or as required by law. You can revoke Dossier’s access at any time in your Google Account settings.

7. Data Retention

We keep your account information and job-search records for as long as your account is active. When you delete your account, we delete your associated data from our production systems. Backups and provider-side logs are retained for a limited period and then purged in the ordinary course (server logs are retained for approximately 30 days). We may retain limited information where required to comply with legal obligations or resolve disputes.

8. Security

We take reasonable and appropriate measures to protect your information, including encryption in transit, row-level access controls that isolate each account’s data, encryption of sensitive credentials such as authentication tokens, and restricted operational access. No admin tool reads your individual records for support; we work from scrubbed logs instead.

A straight answer about what a breach could expose. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a compromise of our database, the information most exposed would be operational fields we must keep readable to run the product — the companies you applied to, job titles, posting links, statuses, and dates. We will notify affected users and regulators of a personal-data breach as required by applicable law.

9. Your Rights and Choices

  • Access and export. You can export your data as a CSV file at any time from Settings.
  • Correction. You can edit or update your records directly in the app.
  • Deletion. You can delete your data and your account from Settings; this is irreversible.
  • Withdraw consent. You can stop using optional features at any time — for example, stop forwarding email to your save-by-email address, or rotate it from Settings so the old one no longer works.

Depending on where you live, you may have additional rights under laws such as the GDPR or the California Consumer Privacy Act (CCPA) — including the right to access, correct, delete, or port your information, and to object to or restrict certain processing. Because we do not sell personal information or use it for cross-context behavioral advertising, there is no such activity for you to opt out of. To exercise any right, contact us at info@thelettertwo.com. We will not discriminate against you for exercising your rights.

10. International Data Transfers

We and our service providers may process and store your information in the United States and other countries whose data-protection laws may differ from those in your jurisdiction. Where required, we rely on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) for such transfers.

11. Children’s Privacy

The Service is not directed to children, and we do not knowingly collect information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice as appropriate. Your continued use of the Service after an update means you accept the revised Policy.

13. Contact Us

If you have questions about this Policy or your information, contact us at info@thelettertwo.com or at 15730 116th Ave NE, 312, Bothell, WA 98011.

This Policy is governed by the laws of the state of the State of Washington, without regard to its conflict-of-laws rules.

© 2026 Dossier. All rights reserved.