Privacy Policy
How ClvrJob handles your information when you connect a mailbox — what we read, what we never do with it, who can access it, how long we keep it, and the rights you have.
Effective [date]
1. Who we are and what this covers
This policy explains how Joshua Penland, a [State] [entity type] with its registered office at [address] (“we”, “us”), handles information when you use ClvrJob (the “Service”). It covers our website, our application, and — most importantly — the email mailbox you choose to connect.
It does not cover what your own customers do with their email, or what your email provider does under its own terms.
2. The short version
- We read the mailbox you connect, in order to turn messages into jobs and draft replies. That is the whole purpose of the product.
- We never use your email content to train any AI model, ours or anyone else’s.
- No employee reads your email in the ordinary course. Access happens only when you ask us to help, or during a specific incident, and it is logged.
- We do not sell or share your information, and we do not advertise.
- You can disconnect the mailbox at any time from your email provider, without asking us. Your data is deleted on the schedule in section 9.
3. What information we handle
Account information. Name, business name, work email, phone, role, and authentication credentials, which are stored only as a salted hash.
Mailbox content. Message headers, bodies, and attachments in the connected mailbox, together with the folder and label structure needed to locate them.
Derived data. Information the Service extracts or generates from mailbox content — job records, customer records, extracted specifications, quotes, summaries, drafted replies, and any search indexes or embeddings built to support them.
Usage data. Log records of actions taken in the application, device and browser information, and IP address.
Payment data. Handled entirely by Stripe. We receive the last four digits, card brand, and expiry, and never receive or store the full card number.
4. Mailbox access and the permissions we request
We connect to your mailbox through your provider’s OAuth authorization, never by asking for your email password, an app password, or IMAP credentials. We request the narrowest permissions the Service can function with:
| Provider | Permission | Why |
|---|---|---|
| gmail.readonly | Read message threads and attachments to build job records | |
| gmail.compose | Place drafted replies in your Drafts folder | |
| Microsoft 365 | Mail.Read (delegated) | Read message threads and attachments in the connected mailbox |
| Microsoft 365 | Mail.ReadWrite (delegated) | Create drafts in the connected mailbox |
We disclose one thing plainly that we are not required to: the gmail.compose scope technically permits sending as well as drafting. Our software does not send without approval, and our Terms make that a contractual commitment rather than a matter of trust — but we would rather you knew what the permission itself allows.
We do not request the https://mail.google.com/ full-access scope, and we cannot permanently delete your mail. We do not request Drive, Contacts, Calendar, or any file-storage permission. Our Microsoft permissions are delegated to the single mailbox you connect; we do not request application-level permissions, which would grant access to every mailbox in your tenant.
You may revoke our access at any time from your Google Account security settings or your Microsoft 365 administration console. Revocation is immediate and does not require you to contact us.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We are assessed annually under the App Defense Alliance CASA framework; our current Letter of Assessment is available on request.
5. How we use information, and the limits on that use
We use mailbox content and derived data solely to: identify and group messages belonging to the same job; extract the details of that job; attach the relevant files to it; draft replies for your review; produce your own reports and briefings; and provide support when you ask for it.
We use account, usage and payment data to operate the Service, bill you, secure the platform, and communicate with you about the Service. We use aggregate operational metrics — counts, timings, error rates — to run and improve the platform. Those metrics contain no message content and are not derived from the substance of your mail.
We do not use your information for advertising, and we do not perform any automated decision-making with legal or similarly significant effects.
6. AI processing and model training
The Service uses large language models to read messages and draft replies. In connection with that:
- We do not use Customer Data to train, fine-tune, or otherwise develop any machine learning model, whether ours or a third party’s.
- We do not permit our model providers to use Customer Data for training. Content sent to [model provider] is processed under zero-retention terms and is not retained by that provider after the response is returned.
- We do not create anonymized, de-identified, or aggregated datasets from message content for product development, research, benchmarking, or any other purpose.
- The Service adapts to your writing style by referring to your own past approved replies at the time a draft is generated. This is retrieval from your own account data, not model training, and it never draws on another customer’s data.
7. Human access to your data
No member of our staff accesses mailbox content or derived data in the ordinary course of business. Access occurs only:
- when you ask us to investigate something and grant access for that purpose;
- when necessary to investigate a specific fault or security incident affecting your account; or
- where we are legally compelled, in which case we will notify you unless prohibited by law.
Access is limited to named roles, requires documented approval by [role], is time-limited, and is logged. We will provide the access log for your account on request.
8. Who else processes your data
We use the following categories of subprocessor: cloud hosting and database, AI model processing, error monitoring, transactional email, and payment processing. Our current list, naming each provider, its function and its processing region, is published at [subprocessor list url].
We will give at least 30 days’ notice before engaging a new subprocessor that processes mailbox content. If you reasonably object, you may terminate your subscription without penalty and receive a pro-rata refund of prepaid fees.
9. How long we keep things, and how deletion works
| Data | Retained | Then |
|---|---|---|
| Mailbox content and attachments | While the mailbox is connected | Deleted from production within 30 days of disconnection or termination |
| Derived data (jobs, extracts, summaries, drafts, indexes, embeddings) | While your account is active | Deleted from production within 30 days of termination |
| Encrypted backups | 90 days, rolling | Deleted data ages out within 90 days of production deletion |
| Account and billing records | As required by tax and accounting law | Deleted at the end of the statutory period |
| Security and access logs | 12 months | Deleted |
You may request deletion at any time from within the application or by writing to us, and we will confirm completion in writing.
10. Security
Customer Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Internal access requires multi-factor authentication and follows least privilege; production access is logged and reviewed [frequency]. Each customer’s data is logically isolated and access is enforced server-side on every request. We commission an independent penetration test annually and remediate findings on a documented schedule.
If we confirm a breach affecting your data, we will notify you without undue delay and no later than 72 hours after confirmation, describing what happened, what data was involved, and what we are doing about it.
11. Where your data is stored
Customer Data is stored in [region], and AI processing is performed in [region]. Where data is transferred outside [region], we rely on Standard Contractual Clauses or another lawful transfer mechanism, and we will identify it on request.
12. Our role, and the agreements we sign
For personal data contained in your mailbox, you are the controller and we are the processor, acting on your documented instructions. We do not determine the purposes of processing that data and we assert no independent right to use it. Our Data Processing Addendum, incorporating Standard Contractual Clauses, is available at [DPA url] and forms part of your agreement on execution. We will assist you in responding to data-subject requests.
Where a connected mailbox may contain protected health information, we will execute a Business Associate Agreement under HIPAA before the mailbox is connected.
13. We do not sell or share your information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding twelve months. We disclose personal information only to the subprocessors described in section 8, and where legally compelled.
14. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, correction of it, deletion of it, a portable copy of it, and information about disclosures. Contact [privacy email]. We will respond within 30 days and will not discriminate against you for exercising these rights. Where you are acting for your own customers, we will assist you in meeting their requests.
15. If our business changes hands
If we are acquired or merge, we will give you notice before Customer Data is transferred, and the acquirer will be bound by this policy or one no less protective. If we discontinue the Service, we will give at least 60 days’ notice and maintain export access throughout that period before deleting Customer Data.
16. Changes to this policy, and how to reach us
We will give at least 30 days’ notice by email before any material change takes effect, and will keep prior versions available at [prior-versions url]. Questions, requests, and complaints: [privacy email], or [postal address]. Our data protection contact is [name or role].
Version [n].