Privacy policy

Last updated: August 23, 2026

Overview

Refine is a company tracking and job search tool. Your search is personal, and we treat your data that way. This policy explains what we collect, why, and what we do with it. The short version: we collect what's needed to run the product, we don't sell your data, and we don't share your activity with employers.

Information we collect

Account information

When you create an account, we collect your name and email address. If you sign in with Google or LinkedIn, we receive your name, email, and profile photo from those services. We don't receive your passwords from third-party sign-in providers.

Job search data

Everything you add to Refine: job applications, interview notes, offer details, company tracking preferences, and other content you create within the product. This data is private to your account, but it can be processed by the service providers described below and accessed by an AI assistant or other client when you explicitly authorize that client.

Company tracking

When you add a company to Refine, we monitor that company's public careers page for new openings. We store the company name, careers page URL, your filters, and the openings we detect. This data comes from public careers pages, not from your employer or any private source.

Connected Gmail and Google Calendar

If you connect a Google account, Refine receives the Google account email address, the permissions you granted, encrypted OAuth access and refresh tokens, and data needed for the features you enable. Depending on your grants, this can include Gmail message metadata and bodies, conversation threads, mailbox state, Calendar events, and calendars created for Refine.

We use Gmail data to identify job-search conversations, extract application, interview, offer, and recruiter details, show relevant threads, mark acted-on mail as read, process unsubscribe requests, and send replies you approve. We use Calendar data to recognize interview events and synchronize interviews with a Refine-created calendar. Refine does not scan attachments.

For automated classification, Google Gemini receives the sender, subject, short preview, and unsubscribe status. When a message is identified as job-search related, Gemini may also receive relevant message text so Refine can extract structured details. We do not use Google Workspace data to train generalized AI or machine-learning models.

Authorized assistants and API clients

When you authorize an MCP or API client, that client can read or change Refine data allowed by the scopes you approve. A client with inbox access may receive relevant email content, and a client with write access may update your board or send an approved reply. You can revoke OAuth access or personal access tokens from Refine.

Usage data

We collect product usage events to understand which features are used, page views, client type, tool outcomes, and general interaction patterns. We use a Refine account or pseudonymous installation identifier to connect events from the same user or installation. We do not send email subjects, message bodies, access tokens, or job notes to PostHog.

Technical data

We collect standard technical information: IP address, browser type, device type, and error logs. This helps us keep the service running and debug issues. Error monitoring is handled by Sentry, and performance monitoring by New Relic.

How we use your information

  • Provide the service: store and display your job applications, interviews, offers, and tracked companies
  • Send notifications: alert you when companies you track post new openings that match your interests
  • Process connected services: identify job-search email, extract relevant details, synchronize interview events, and carry out mailbox actions you request
  • Support authorized clients: let assistants and API clients perform the scoped Refine actions you approve
  • Improve the product: understand usage patterns and diagnose where workflows fail
  • Maintain security: detect abuse, prevent fraud, and keep the service secure
  • Communicate with you: send essential product updates and respond to support requests

What we will never do

  • Sell your personal data to third parties
  • Share your job search activity with current or prospective employers
  • Use your data to serve advertisements
  • Share individual user data with other Refine users
  • Send you marketing emails without your consent

Data storage and security

Your data is stored on servers in the United States. We use encryption in transit (TLS/HTTPS) for all connections. Our database is hosted on PlanetScale with encryption at rest. Application servers run on Fly.io with isolated containers. Cloudflare provides DDoS protection and CDN caching for static assets.

We follow security best practices: HMAC-signed internal API communication, Content Security Policy headers, rate limiting, and input validation. Access to production systems is restricted to authorized personnel.

Google OAuth access and refresh tokens are encrypted at the application layer. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

Third-party services

We use the following services to operate Refine:

Service Purpose Data shared
PlanetScaleDatabaseAll application data (encrypted)
Fly.ioApplication hostingRequest logs
CloudflareCDN and securityIP addresses, request metadata
UpstashBackground job queueJob metadata only
SentryError monitoringError details, stack traces
New RelicPerformance monitoringRequest timing, route performance
PostHogProduct analyticsAccount or installation identifier, account metadata, feature and tool usage
Google Workspace APIsConnected Gmail and Calendar featuresOAuth grants and the Gmail or Calendar data requested by the feature
Google Gemini APIClassify job-search email and extract structured detailsSender, subject, preview, unsubscribe status, and relevant message text
PostmarkTransactional emailRecipient address and message content for Refine account email
Google / LinkedInAccount sign-inName, email, profile photo, and provider account identifier received from the provider

Cookies

We use essential cookies to keep you signed in and maintain your session. We use PostHog for product analytics as described above. We do not use advertising cookies or cross-site advertising trackers.

Data retention

We keep your data for as long as your account is active. Guest accounts without sign-up may have their data cleared after 30 days of inactivity. Disconnecting a Google account revokes Refine's grant and stops future access. When you delete your Refine account, we delete associated personal data within 30 days. Aggregated statistics that no longer identify you may be retained.

Google API Limited Use

Refine's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your rights

You have the right to:

  • Access: request a copy of all data we hold about you
  • Correct: update or fix any inaccurate information
  • Delete: request deletion of your account and all associated data
  • Export: receive your data in a portable format
  • Restrict: ask us to limit how we process your data

To exercise any of these rights, email [email protected] or reach out through our contact page.

Children's privacy

Refine is not intended for users under 16 years of age. We do not knowingly collect information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Changes to this policy

We may update this privacy policy from time to time. If we make significant changes, we'll notify you through the app or by email. The "last updated" date at the top of this page indicates when the policy was last revised.

Contact

For privacy questions or requests, email [email protected] or visit our contact page.