JHBuddy (“JHBuddy”, “we”, “us”) operates the JHBuddy Planner web app at app.jhbuddy.com (the “Service”). JHBuddy is a trade name of a New Jersey limited liability company. This policy explains what we collect, how we use it, and the choices you have. The Service is intended for residents of the United States.
1. Information we collect
- Account. Your email address and authentication details (via Supabase Auth). If you sign in with Google, we receive your basic profile and email.
- Profile you provide. Household persona, work arrangement, commute, learning goal, target skill, and timezone.
- Activity you log. Daily time entries by category and optional energy check-ins.
- Professional Buddy data.If you use the networking feature, contacts you import (e.g. a LinkedIn connections file) and any notes or relationship details you add. This data stays in your account and is used only to compute your private networking insights. We never email, message, or otherwise contact the people in your imported list, and we do not combine one user’s contacts with another’s. You are responsible for having the right to upload the contact data you import.
- Connected accounts (optional).If you connect a Google or Microsoft account, the data described in section 3.
- Usage. Basic product events (e.g. onboarding completed, report opened) to improve the Service, and standard server logs.
2. How we use information
We use your information to provide and improve the Service: to compute your benchmarks and coaching, generate your reports, deliver email you’ve asked for, prevent fraud and abuse, comply with law, and keep the Service secure. We do notsell or “share” (as defined by the California Consumer Privacy Act) your personal information, we do not use it for third-party advertising, and we do not use your personal data to train generalized AI models. We may use aggregated or de-identified data (which cannot reasonably identify you) for analytics, benchmarks, and product improvement.
2a. Cookies and local storage
We use only the cookies and browser storage necessary to run the Service — primarily to keep you signed in (authentication session) and remember basic preferences. We do not use third-party advertising or cross-site tracking cookies. Because we do not track you across other sites, the Service does not respond differently to browser “Do Not Track” signals.
3. Google and Microsoft connected accounts
Connecting an account is optional and used to power features you turn on. You can disconnect at any time in Settings, which revokes our access going forward.
- Google Calendar (read-only). With your permission we read calendar event metadata (such as timing and attendees) to derive networking signal and time-availability insights. We do not request access to your Gmail messages.
- Microsoft (Outlook/Microsoft 365) — standard access. By default we request only metadata: message headers and timestamps (who, when), calendar event timing and attendees. At this level we cannot read the subject or body of any message. We use it to derive your private networking signal — how often you are in contact with people, who replies, and how quickly.
- Microsoft — application tracking (optional, separately enabled). If your account has application tracking switched on, we additionally request permission to read your mail and to send mail as you. This is a meaningful expansion and we describe it plainly:
- Reading. We scan recent inbound messages to find three things: job-alert emails from job boards, confirmations that an application was received, and replies within conversations for applications you sent from JHBuddy. Other messages are passed over and nothing from them is stored.
- What we keep.For a tracked reply we store an automatic classification (for example “wants to talk” or “passed this time”), a confidence score, and an excerpt of at most 200 characters. We never store full message bodies. Message content is held in memory only long enough to classify it, then discarded.
- Sending. We send only a message you have composed or reviewed in JHBuddy and explicitly pressed Send on. We never send email on your behalf automatically, and we never submit applications to job boards or employer portals on your behalf.
- Automated classification.To label an ambiguous reply we may send the message text to a third-party language-model provider (see “How we share information”). The provider processes it to return a label and does not use it to train models. Classifications are automated guesses and can be wrong.
Application tracking is off unless we have enabled it for your account. Turning it on requires you to reconnect your Microsoft account and approve the additional permissions on Microsoft’s own consent screen; you can revoke them at any time by disconnecting in Settings or from your Microsoft account security page.
Limited Use.JHBuddy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use connected-account data only to provide and improve user-facing features you have enabled, we do not transfer or sell it, we do not use it for advertising, we do not allow humans to read it except with your consent, for security, or as required by law, and we do not use it to develop, improve, or train generalized AI models.
4. How we share information
We share information only with service providers that help us run the Service:
- Supabase — database, authentication, and storage.
- Vercel — application hosting and logs.
- Resend — transactional and report emails.
- Google / Microsoft — only for the accounts you choose to connect.
- DeepInfra — automated text classification, used only if you have application tracking enabled and only for the specific messages described in section 3. Data sent for classification is not used to train models.
These providers process data on our behalf under their own security and privacy commitments. We may also disclose information if required by law or to protect the Service and its users. Job market data shown in the app is aggregate and contains no personal information.
5. Data retention
We keep your information while your account is active. Connected-account data is refreshed as needed and can be removed by disconnecting the account. When you delete your account, we delete your personal data from our systems, except where we must retain limited records to comply with legal obligations.
6. Your rights and choices
You can export your data (as JSON) and permanently delete your account and associated data at any time from Settings — these self-service tools satisfy access, portability, and deletion requests directly. You can disconnect any connected Google or Microsoft account there as well, which stops further collection from it.
US state privacy rights.Depending on your state (for example, California, Colorado, Virginia, or New Jersey), you may have the right to know, access, correct, or delete personal information, and the right not to be discriminated against for exercising those rights. We honor these rights for all users via the Settings tools above, or by email — we will verify and respond to requests within the time required by your state’s law. Because we do not sell or share personal information, no opt-out is needed.
Email choices. Report and reminder emails can be adjusted in Settings; any marketing email includes an unsubscribe link.
7. Security and breach notice
We protect data with encryption in transit, row-level security so users can only access their own rows, encrypted storage of any connected-account tokens, and least-privilege access controls. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; you use the Service with that understanding. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law.
8. Children
The Service is not directed to children under 18, and we do not knowingly collect their data.
9. Changes
We may update this policy. Material changes will be reflected by the “Last updated” date above, and where appropriate we will notify you in the app or by email.
10. Contact
Questions or requests: privacy@jhbuddy.com.