JoinIntelli

Privacy policy

Last updated: August 2026

This policy describes how JoinIntelli ("JoinIntelli," "we," "us") collects, uses, and protects information when you use the JoinIntelli web app, the JoinIntelli Outlook add-in, or the JoinIntelli Gmail add-on (together, the "Service"). JoinIntelli helps recruiters track offer-acceptance risk for candidates they're actively hiring, by reading signals from email conversations they're already having.

What we collect

Account information. When you or your organization's admin creates a JoinIntelli account, we store your name, work email address, role (recruiter, HR leadership, or admin), and organization. We never collect or store a password — sign-in is always a one-time email link, never a password.

Mailbox data (only if you connect Gmail or Outlook). If you choose to connect your mailbox, we request read-only access (Gmail's gmail.readonly scope, or Outlook's Mail.Read scope) — we can never send, delete, or modify email on your behalf, on any mailbox, ever. From messages involving candidates you're tracking (or that our discovery step flags as a likely new candidate conversation), we read the subject line, sender/recipient addresses, timestamps, and a short preview snippet — not the full email body, and not attachments.

Candidate information. For each candidate you track, we store their name, email address, the role they're being hired for, an expected join date if you provide one, and a computed join-confidence score with the reasoning behind it. Candidates themselves never create a JoinIntelli account and never sign in — this data comes from you, the recruiter, and from the email signals described above.

How we use it

Message previews are sent to Anthropic's Claude API to assess sentiment, detect mentions of competing offers, and produce an updated join-confidence score — this happens per-thread, only for candidates you're actively tracking or reviewing for tracking, and only the short preview text described above is sent, never a full mailbox export. We use your email address to send transactional email only: sign-in links, team invites, and (if you've set a timezone) a daily reminder about candidates awaiting your confirmation. We do not send marketing email, and we do not sell or rent any data to third parties.

To be explicit: Google and Microsoft mailbox data is used solely to provide and improve JoinIntelli's core functionality described in this policy — candidate discovery, signal extraction, and join-confidence scoring. We do not use this data for advertising, ad targeting, or any analytics, profiling, or research unrelated to that core functionality, and we never sell or share it with data brokers or advertisers.

AI processing and Limited Use compliance

The use of information JoinIntelli receives from Google Workspace APIs (Gmail) will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The same commitment applies equally to data JoinIntelli receives from Microsoft Graph (Outlook): we do not use Google or Microsoft user data — raw, aggregated, or derived — to develop, train, or improve any generalized or foundational AI/ML model, regardless of which mailbox provider it came from.

Message previews from either provider are processed the same way, by Anthropic's Claude API (accessed directly via Anthropic's own commercial API, not through any intermediary aggregator or model hub). Under Anthropic's Commercial Terms of Service, API inputs and outputs are not used to train Anthropic's models. We do not self-host any AI model — all processing described here happens via Anthropic's hosted API.

Where it's stored, and who else sees it

Application data is stored in a Supabase-hosted Postgres database, access-controlled so a recruiter can only ever read their own candidates and an admin can only read within their own organization — this is enforced at the database layer, not just in the app's UI. All traffic between your browser, our servers, and the third-party services below is encrypted in transit (HTTPS/TLS). Mailbox refresh tokens are encrypted at rest and are never logged or exposed in plaintext. The following third-party services process data on our behalf, each only for the purpose described: Google and Microsoft (mailbox OAuth, if you connect a mailbox), Anthropic (candidate scoring and discovery), Resend (transactional email delivery), and Vercel (application hosting).

Data retention and deletion

Mailbox-derived data (message previews, sender/recipient addresses, timestamps, and extracted signals) is retained only for as long as the associated candidate is actively tracked. Mailbox refresh tokens are retained only until you disconnect your mailbox from Settings, at which point they are deleted and the corresponding access is revoked on Google's or Microsoft's side directly.

Marking a candidate "do not track" immediately and permanently deletes all Google or Microsoft user data associated with that candidate — every stored email thread reference, extracted signal, and message preview is erased outright, not soft-deleted or archived. See "Your controls" below for the full scope of what's removed.

Your controls

You can disconnect your mailbox at any time from Settings — this immediately stops any further mailbox reads and, for Gmail, revokes the granted access on Google's side directly.

Marking a candidate "do not track" permanently and immediately deletes their email address, name, role details, every stored email thread reference, every extracted signal, every quick-log note, and every score — the candidate record is anonymized and kept only as a billing reference, it is not a soft delete.

Contact

Questions about this policy or a request regarding your data can be sent through our support page.