Back to Home

Privacy Policy

Last updated: 8/28/2026

Introduction

Handoff ("we", "us", "our", or "Company") operates the https://handoff.one website and related services (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.

Data Collection

We collect information you provide directly, including:

  • Account registration information (name, email, password)
  • Profile information (work authorization status, target roles, locations)
  • Job applications and related data
  • Resume documents and career memory vault entries
  • Communication preferences (WhatsApp opt-ins, notification settings)
  • When you connect your LinkedIn account, we receive your name, email address, profile picture, and LinkedIn member identifier via LinkedIn’s “Sign In with LinkedIn using OpenID Connect” product. We request only the openid, profile, and email scopes.
  • When you connect your Gmail account, we receive your email address and profile information from Google, along with read-only access to your Gmail messages via the gmail.readonly scope — and nothing else. Handoff cannot send mail as you; it holds no send or compose scope and contains no code that sends mail. We read your mailbox only as the tail of an action you took: when Handoff submits or requests something on your behalf it records what it is waiting for, and reads only within that narrow window, from that sender. If there is no such record, no read happens. We do not use your Gmail content to train AI or machine learning models.

How We Use Your Data

We use the collected data for various purposes:

  • To provide and maintain our Service
  • To process and track your job applications
  • To provide AI-powered career insights and recommendations
  • To send you notifications and updates (with your consent)
  • To analyze usage patterns and improve our Service
  • To comply with legal obligations

Third-Party Services

We integrate with third-party services including:

  • Supabase for authentication, database, and file storage services.
  • LinkedIn for optional profile sign-in via “Sign In with LinkedIn using OpenID Connect.” You can disconnect LinkedIn at any time from your settings page, and you can fully revoke our access from your LinkedIn permitted services page. Our use of information received from LinkedIn APIs adheres to the LinkedIn API Terms of Use.
  • Google & Gmail for optional email connector features. Handoff’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke Handoff’s access at any time from your Google Account permissions page.
  • Anthropic and OpenAI for AI-powered analysis of job postings and resume content. We do not send raw email bodies or LinkedIn profile data to these providers.
  • Bird (MessageBird) for the optional SMS / WhatsApp verification-code relay: if a site texts you a code during an application, we can forward the request to your phone and accept your reply. This is the only outbound messaging Handoff does, and it is off unless you turn it on.
  • Chrome Extension for enhanced job tracking features.

These services have their own privacy policies, and we encourage you to review them.

Google API Limited Use Disclosure

Handoff’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Handoff does not use Gmail data for serving advertisements, does not allow humans to read your Gmail data unless we have your explicit consent for specific messages, and does not transfer or sell Gmail data. We use Gmail data solely to power the features you explicitly enable in your settings (confirming that an application you sent was actually received, and reading a verification code a site emailed you at the moment you asked for one).

Data Security

Your data is encrypted in transit (TLS) and at rest, held in a Postgres database where row-level security scopes every row to its owner. It is not end-to-end encrypted, and we will not claim otherwise: Handoff has to be able to read your answers in order to type them into an employer’s form for you, and it holds the OAuth token for any mailbox you connect. Treat anything you store here as readable by Handoff.

One category is different by construction. Handoff cannot type a password. The browser extension has no password action in its vocabulary, any credential you enter during a sign-up is kept isolated on your own device and never synced to us, and a runtime check rejects any payload that looks like secret material before it can leave the browser. That is a property of the code, not a policy we could quietly relax.

We are not SOC 2 certified and have not undergone an independent security audit. No method of transmission over the Internet or electronic storage is completely secure.

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data (subject to legal obligations)
  • Opt-out of communication emails
  • Withdraw consent for data processing

Cookies

We use cookies and similar tracking technologies to enhance your experience. You can manage cookie preferences through your browser settings. Some cookies are essential for the Service to function properly.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Email: privacy@handoff.one