Back

Privacy

What we read, and what we never touch.

Last updated 20 August 2026

Pending Desk reads the job-application emails in your inbox so it can tell you where each application stands. That is the whole purpose, and this page describes exactly what that involves. No lawyer wrote it; it is meant to be read.

The short version

  • We ask Gmail for read-only access. We cannot send, reply to, archive or delete anything.
  • We look at emails that match job-application patterns, and we ignore the rest.
  • We store a small summary of each job email — not your mail.
  • We never sell your data, and we never use it to train anything.
  • One button deletes all of it, immediately and for good.

What we access

If you connect Gmail, we request a single Google permission: gmail.readonly. It is the narrowest scope that lets us read message metadata and content, and it grants no ability to change your mailbox. We request no other Google scope.

You can also skip Google entirely. If you upload an email export instead, the file is parsed in your own browser and only the same summary described below is ever sent to us.

What we store

For each email we identify as job-related, we keep:

  • Sender name and address, and the recipient address it arrived at
  • Subject line, date, and the Gmail message and thread identifiers
  • The company, role and application it belongs to, as we matched it
  • The stage we inferred — applied, screening, interview, offer, rejected, quiet — and the short phrase we inferred it from
  • A snippet of surrounding text, capped at roughly 500 characters, so you can see why a stage was assigned
  • Date, time and location of interviews found in calendar invites on those threads

We also store your account email address, your settings, and an encrypted Gmail refresh token so scanning can continue without asking you to sign in every time. Tokens are encrypted at rest and are never exposed to the browser.

What we never store

  • Full email bodies, and no attachments of any kind
  • Anything from emails we did not classify as job-related — those are read in memory during a scan and discarded
  • Your Google password, which we never see
  • Contacts, Drive files, or anything outside the mail we were given access to

Google API Services — limited use

Pending Desk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Gmail data is used only to provide and improve the application-tracking features you can see in the product; it is not transferred to anyone except as needed to provide those features, to comply with the law, or as part of a merger with equivalent commitments; it is never used for advertising; and no human reads it except with your explicit permission for support, for security, or where the law requires it. We do not use Gmail data to develop, improve or train generalised artificial-intelligence or machine-learning models.

Where it lives, and who else is involved

Data is stored in a Postgres database hosted by Supabase, with row-level security so one account can never read another's rows. The application runs on Vercel. Both hold data in the United States. These two companies, plus Google for the mail itself, are the only third parties that touch your data — there are no analytics vendors reading your inbox, no advertising networks, and no data brokers.

How long we keep it

Until you delete it. Deleting your account removes every row associated with it, and revokes the stored Gmail token, within 24 hours. There is also a delete-all-data button that clears your tracked applications while keeping the account open. You can independently revoke our access at any time from your Google account permissions page — do that and scanning simply stops.

Your choices

  • Export everything we hold about you as a CSV, from Account settings
  • Correct a company, role or stage we got wrong — your edit wins over ours
  • Delete individual applications, all of your data, or the whole account
  • Ask us for a copy or a deletion in writing if you would rather not use the buttons

If you are in the UK, EU or California, the rights your law gives you — access, correction, deletion, portability, objection — are the ones described above, and we will honour a request within 30 days.

Cookies

One cookie, holding your sign-in session. No advertising cookies, no third-party trackers, no cross-site profiling. Your theme and layout preferences are kept in your browser's local storage and never leave the device.

Security, honestly stated

Data is encrypted in transit and at rest, tokens get a second layer of application-level encryption, and access to the production database is limited to the one person who runs this. It is also a small beta run by an individual, not a company with a security team, so please weigh that when deciding what to connect.

Children

Pending Desk is not intended for anyone under 16, and we do not knowingly collect data from them.

Changes

If this policy changes in a way that affects what we collect or how we use it, we will email everyone with an account before the change takes effect, and the date at the top will move.

Contact

Questions, requests, or something that reads wrong — write to us at the address below.

Add the real contact address here before publishing. Google's consent screen will not save without one.