Cover your App

Privacy Policy

Effective · Office for Visual Affairs, LLC

The short version: we store the job-search data you put on your board, identified by your Google account, and use it only to run the Service for you. We do not sell it, do not show ads, and do not use it to train AI. Gmail access and AI letter drafting are optional, read-only or under your own key, and you can switch them off. You can ask us to export or delete everything at any time. The details follow.

1. Who we are

Cover your App (the “Service”) is operated by Office for Visual Affairs, LLC, 19 Morris Ave, Brooklyn, New York 11205, USA. We are the controller of the personal data described in this policy. Questions and requests go to frontdesk@officeforvisualaffairs.com. This policy covers the web application at https://cover-your-app.vercel.app, its API and the Cover your App browser extension.

2. What we collect

Account data from Google. When you sign in with Google we receive your name, email address, profile picture and a Google account identifier. We request only the basic sign-in scopes (openid, email, profile). We never see your Google password.

What you put on your board. Job listings you add (the URL and the text we fetch from it, or text you paste), the company and role, your application status and its history, notes, star and intro flags, how you applied, people you know at the company and their LinkedIn links, companies whose careers pages you follow and the postings we find there, your board’s column names, and cover letters you write, paste or generate.

Extension tokens. If you create an access token for the browser extension, we store a one-way hash of it, its label, and when it was last used. The token itself is shown to you once and not kept.

Usage and technical data. Our hosting provider records standard server logs (IP address, request path, user agent, timestamps) for security and debugging. We use Vercel Web Analytics, which counts page views and visits using a hashed, non-persistent identifier and does not set tracking cookies. We do not use advertising trackers.

Cookies. A session cookie keeps you signed in. It is strictly necessary for the Service to work and holds no tracking information.

The optional features below collect additional data only if you turn them on.

3. Gmail connection (optional)

If you connect Gmail, you grant the Service the gmail.readonly scope. We use it for one purpose: to find replies from employers about applications on your board and show them on the matching job card. Specifically:

  • We run targeted searches of your mailbox for messages from the employer domains, applicant-tracking systems, senders and keywords tied to jobs on your board. We do not read or index your whole mailbox.
  • For each message that matches a job we store the message and thread identifiers, sender, subject, date, a short snippet, and the reason it matched. We do not store full message bodies or attachments.
  • We store the OAuth refresh token Google issues, encrypted at rest, so syncing can run on a schedule. The connection is read-only; the Service cannot send, modify or delete mail.
  • No person at Office for Visual Affairs reads your Gmail data, except with your explicit permission to investigate a problem you report, or as required by law.

Limited Use disclosure. Cover your App’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not use it to train AI or machine-learning models, and do not transfer it to third parties except as needed to provide the feature you enabled, with your consent, for security, or to comply with law.

You can disconnect Gmail at any time from Settings, or by removing the Service’s access at myaccount.google.com/permissions. Disconnecting deletes the stored token; stored matches stay on your board until you delete them or your account.

4. AI letter generation (optional)

If you enable cover-letter generation, you provide your own API key for the AI provider (currently Anthropic). We store the key encrypted (AES-256-GCM) and use it only to make requests on your behalf. To generate a draft we send the provider the job listing, the profile and résumé material you have added, your existing letters as style reference, and your instructions. The provider processes this under its own terms and privacy policy and under your account with it; we do not control the provider’s retention. You can remove your key and your profile material at any time in Settings.

We never use your data to train models, and we do not send any of it to an AI provider unless you have turned this feature on.

5. Profile and résumé uploads (optional)

You may upload a résumé, past cover letters and similar documents to help with letter generation. Files are stored in a private file store and the extracted text in our database, associated only with your account. They are used solely to build your profile and generate your letters, and are deleted when you remove them or delete your account.

6. How we use your data

We use the data above to:

  • provide the Service: show your board, fetch listings, keep you signed in;
  • run the optional features you enable, exactly as described above;
  • keep the Service secure, prevent abuse and debug problems;
  • understand aggregate usage (page views, feature adoption) so we can improve the Service;
  • contact you about your account, material changes to this policy or the Terms, or problems affecting your data;
  • comply with law.

We do not sell your personal data, and we do not share it for advertising. We do not make automated decisions with legal or similarly significant effects about you.

For visitors covered by the GDPR or UK GDPR, our legal bases are: performance of our contract with you (providing the Service), your consent (the optional Gmail and AI features, which you can withdraw at any time), our legitimate interests (security, aggregate analytics, improving the Service) and legal obligation.

7. Who we share it with

We share personal data only with the service providers that run the Service on our behalf, each bound by its own data-protection terms:

  • Vercel (USA): hosting, serverless compute, file storage for uploads and employer icons, and Web Analytics.
  • Neon (USA): the Postgres database that stores your account and board.
  • Google: sign-in, and Gmail if you connect it.
  • Anthropic: AI letter generation, only if you enable it and only with your own key.

Employer icons are shared. When you add a company, we fetch its favicon and cache it by domain. That cache is shared by every user who tracks the same employer; it contains only the public icon and the domain, never who tracks it.

We may also disclose data if required by law or legal process, to protect the rights, safety or property of our users or the public, or as part of a merger, acquisition or sale of the Service (in which case we will notify you). We do not share your data with employers, job boards or recruiters.

8. How long we keep it

Your account and board data are kept for as long as your account exists. When you delete your account, everything tied to it is deleted from our database and file store within 30 days; copies in encrypted backups expire within a further 30 days.

Server logs are retained by our hosting provider for a limited period (currently up to 30 days) and analytics data is kept only in aggregate. Gmail tokens are deleted the moment you disconnect. Sessions expire automatically; access tokens last until you revoke them.

9. Security

All traffic to the Service is encrypted in transit (HTTPS). Data is encrypted at rest by our database and storage providers, and secrets such as OAuth tokens and API keys are additionally encrypted at the application level. Every record in our database is scoped to the account that owns it; the Service is built so that one user’s data can never be returned to another. Access tokens are stored only as hashes. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay and as required by law.

10. Your rights and choices

You can view and edit almost everything we hold about you directly in the Service. In addition, wherever you live, you can ask us to:

  • access the personal data we hold about you, or receive a copy in a portable format;
  • correct anything that is inaccurate;
  • delete your account and all associated data;
  • restrict or object to certain processing, or withdraw consent for the optional features (which you can also do yourself by disconnecting them in Settings).

To exercise any of these, email frontdesk@officeforvisualaffairs.com from the address on your account. We will confirm your identity, and respond within 30 days. Deletion is permanent and cannot be undone. We will not discriminate against you for exercising your rights.

California residents. The CCPA/CPRA gives you the rights above, plus the right to know the categories of personal information we collect (identifiers, account and content data, internet activity, and, if you enable them, communications and professional information), the purposes (listed under “How we use your data”), and the categories of third parties (our service providers, listed above). We do not sell or share personal information as those terms are defined in the CPRA, and we do not use sensitive personal information to infer characteristics about you. You may designate an authorised agent to make a request for you.

EEA, UK and Swiss residents. You also have the right to lodge a complaint with your local supervisory authority. Because we are based in the United States, your data is transferred there; we rely on Standard Contractual Clauses and equivalent safeguards with our providers, and your data is protected as described in this policy wherever it is processed.

11. Children

The Service is for adults looking for work and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

12. The browser extension

The Cover your App extension adds the listing in your current tab to your board. It reads the page you are on only when you click the extension button or its keyboard shortcut, and sends that page’s URL and text to your own Cover your App instance. It stores your endpoint and access token locally in your browser and sends nothing anywhere else. It has no analytics of its own.

13. Changes to this policy

We may update this policy as the Service changes. We will change the effective date above and, for material changes, notify you in the app or by email before they take effect. The current version is always at https://cover-your-app.vercel.app/privacy.

14. Contact

Office for Visual Affairs, LLC
19 Morris Ave, Brooklyn, New York 11205, USA
frontdesk@officeforvisualaffairs.com
See also our Terms of Service.