Your data powers your job hunt — not our ad network
🔒 Delete your account anytime from Settings — data removed immediately.
📧 We do not request Google Gmail API / read-your-email access.
1. About ManifestJob Portals
ManifestJob operates two distinct user-facing portals with different data access needs:
⚡ Apply Portal
apply.manifestjob.com
- Google SSO (email + profile)
- CV tailoring & job matching
- LinkedIn automation
- No Gmail access
🎯 Concierge Portal
concierge.manifestjob.com
- All Apply features
- Top 100 Companies / external portal apply
- Priority automation
- No Gmail API access
Progressive Permission Model: Sign-in uses Google email + profile only.
Portal applies (Amazon, Workday, etc.) may use a Gmail sign-in inside our secure apply browser — the same pattern as LinkedIn Connect.
ManifestJob does not request Google “read your email” / gmail.readonly API access for any plan.
2. Data We Collect
2.1 Google Account Data
| Google OAuth Scope | Purpose | Portal |
openid |
Keep you signed in to ManifestJob |
Both |
userinfo.email |
Identify your ManifestJob account |
Both |
userinfo.profile |
Display your name in the dashboard |
Both |
ManifestJob does not request gmail.readonly or any other Gmail API scope.
Company-portal applies that need email verification use a secure browser session where you sign into Gmail (session cookies only — not Google API mail reading).
2.2 User-Provided Data
- CV content — resume text uploaded or pasted by you
- Job preferences — target roles, locations, salary expectations
- Job portal credentials — encrypted using AES-256, never stored as plaintext
- Answer book — application Q&A answers you provide (notice period, CTC, etc.)
- LinkedIn session data — browser storage state for LinkedIn automation; stored encrypted in AWS S3
2.3 Automatically Collected Data
- Application tracking records (which jobs you applied to, outcomes, timestamps)
- Automation run logs (step names, errors, HITL events) — retained for 90 days
- Payment metadata (plan, amount, Razorpay payment/order ID — no card data)
- Basic usage metrics (feature credit consumption per billing cycle)
3. How We Use Your Data
- Authenticate you and maintain your session
- Tailor your CV to specific job descriptions using AI
- Match and score job listings against your profile
- Submit job applications on your behalf via browser automation
- Send transactional emails (application success, HITL alerts, billing confirmations)
- Process payments and manage your subscription plan
ManifestJob DOES NOT use your data for: targeted advertising, selling to data brokers, determining credit-worthiness, interest-based advertising, or training AI models on your personal information.
4. Gmail — What We Do and Don’t Do
ManifestJob does not request Google Gmail API access (including gmail.readonly) for any user plan.
4.1 Secure apply browser (company portals only)
Some employer portals (e.g. Amazon, Workday) email OTPs or verification links.
When needed, you can sign into your Gmail inside ManifestJob’s secure apply browser —
the same pattern as LinkedIn Connect. We keep a browser session so portal applies can continue; we do not obtain Google “read your email” permission.
4.2 What we never do
- We do NOT request Gmail API scopes from Google
- We do NOT sync or scan your inbox via OAuth for status tracking
- We do NOT send emails from your Gmail account via API
- We do NOT sell or share your mailbox contents
4.3 Disconnecting
You can disconnect LinkedIn and clear apply-browser sessions from your dashboard anytime. LinkedIn Easy Apply does not require Gmail.
Google API Limited Use: ManifestJob’s use of Google Sign-In (email + profile) adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. We do not use Gmail API data because we do not request Gmail API access.
5. Data Storage & Security
- Infrastructure: AWS (us-east-1) — DynamoDB (user records), S3 (CV files, LinkedIn sessions), Secrets Manager (API keys)
- Encryption in transit: TLS 1.2+ on all connections
- Encryption at rest: DynamoDB and S3 server-side encryption (AES-256)
- Credential vault: Portal passwords encrypted with Fernet symmetric encryption before storage. Only decrypted in-memory during automation
- OAuth tokens: Stored encrypted in DynamoDB. Access tokens are short-lived and refreshed automatically
- Access controls: Strict AWS IAM roles. Admin dashboard requires separate credentials. No user data is exposed in application logs
6. Data Sharing
- AWS: Cloud infrastructure provider. Data never leaves AWS us-east-1 region
- OpenAI / LLM providers: Your CV content is sent to OpenAI APIs for tailoring. OpenAI's data processing agreement applies. We do not send your name, email, or contact details to OpenAI
- Razorpay: Payment processing only. We share your email for payment receipts. Card data is handled entirely by Razorpay
- Amazon SES: Email delivery for transactional notifications
We do not sell, rent, or trade your personal data to any third party.
7. Data Retention & Deletion
- Active accounts: Data retained for the duration of your account
- Deleted accounts: Personal data (profile, CV, applications, tokens) is deleted immediately when you use Settings → Delete account. Payment records are anonymized and retained for 7 years per Indian financial record-keeping requirements.
- Automation logs: Retained for 90 days, then automatically purged
- Payment records: Retained for 7 years per Indian financial record-keeping requirements
Delete your account anytime from Settings & Plans → Delete account, or email [email protected] with subject line "Data Deletion Request".
8. Your Rights
- Access: Request a copy of your data via email
- Correction: Update your profile and CV through the dashboard
- Deletion: Delete your account from Settings, or request deletion by email
- Portability: Request your application history and CV data in JSON format
- Revoke Google access: via Google Account Permissions
9. Cookies & Sessions
ManifestJob uses session cookies to maintain your login state. We do not use advertising cookies, third-party tracking pixels, or analytics cookies. Session data is stored server-side in encrypted form and expires after 24 hours of inactivity.
10. Changes to This Policy
We will notify you of material changes via email or in-app banner at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
11. Contact
For privacy questions or data requests:
- Email: [email protected] or [email protected]
- Subject line: "ManifestJob Privacy Request"
- Business: VARTANA (OPC) PRIVATE LIMITED (CIN: U62090KA2026OPC216160 | GSTIN: 29AALCV9050H1ZS)
- Address: 2B202, Suncity Gloria, Sarjapura Road, Carmelaram, Bangalore South, Bangalore, Karnataka, India, 560035