[EFFECTIVE DATE: TBD — set to publish date] · Draft — reviewed by counsel before public launch.
Reqon ("we", "us") is a job-search CRM operated by its founder. Our contact email is privacy@reqon.app.
Account & contact data. When you join the waitlist or create an account we collect your email address, and optionally your name and job title. We use this to send you an invite, notify you of product updates, and identify your account. Legal basis: performance of a contract / legitimate interest in communicating with beta users.
Job-search data you enter. Roles you track, notes, résumé/profile content, interview stages, and salary/location preferences. This data lives in your account on our servers and is used solely to power the product for you. We never read, sell, or share this data with third parties except as described under "Processors" below.
AI feature inputs. When you use an AI feature (draft, score, guide, map fields), the relevant text — job description, résumé excerpt, your notes — is sent to OpenAI to generate the response. AI features are always user-initiated and never run automatically on your data. See "Processors."
Usage & diagnostic logs. Basic server logs (timestamp, route, status code, errors). We do not run third-party analytics or ad pixels. Logs are retained for up to 30 days then rotated.
Billing. If you subscribe to a paid plan, Stripe collects and stores your payment details. We never see your full card number. We receive a Stripe customer ID, subscription status, and the last-four of your card for display only.
We do not collect precise location, device identifiers, advertising IDs, contacts/call logs, health data, financial accounts, or browsing history. We do not sell data to data brokers or use it for cross-context behavioral advertising.
| Processor | What they handle | Retention |
|---|---|---|
| Railway | Hosting / servers / persistent disk where your data is stored | Stored while your account exists |
| Cloudflare | CDN / edge network in front of the hosting above — sees request metadata in transit, does not store account data | Standard CDN log retention per Cloudflare policy |
| Supabase | PostgreSQL database hosting — write-through mirror of your job-search data and the shared job/company catalog | Stored while your account exists; deleted within 30 days of account deletion |
| OpenAI | AI features (draft, score, guide) — receives only the text you provide for that request | Up to 30 days per OpenAI policy; zero-data-retention API tier available on request |
| Brevo (Sendinblue) | Transactional email (invites, confirmations, password reset) | Email log per Brevo policy |
| Stripe | Payment processing for paid plans | Per Stripe data-retention policy |
| Gmail / Google | Gmail IMAP access — only when you enable the Gmail integration; Reqon reads your inbox to detect job-application responses. Message contents are processed in memory and are not stored on our servers; only the resulting status update is saved to your board. | Not stored; read-only, processed transiently |
All processors are contractually bound to process data only on our behalf and in accordance with their privacy programs.
Gmail (Google). If you connect your Gmail account, Reqon reads your email messages via the Gmail IMAP protocol to ingest recruiter responses and leads into your pipeline. Google is the source and data controller of your Gmail data; Reqon reads it only to populate your job-search pipeline at your direction. This access is user-initiated, requires explicit authorization, and can be revoked at any time from your Google Account settings or from Reqon's Settings. Google's privacy policy applies to data held in your Gmail account: policies.google.com/privacy.
We do not sell your personal data. We share it only: (a) with the processors above as necessary to run the service; (b) if required by law or a valid legal process; (c) in connection with a merger or acquisition, with equivalent privacy protections applied.
You may at any time: access your data (Settings → export or email us); correct inaccurate data; delete your account and all associated data (in-app "Delete account" or email us); withdraw consent for marketing emails (unsubscribe link in every email). If you are in the EEA, UK, or California you have additional rights under GDPR/UK GDPR/CCPA — contact us at privacy@reqon.app to exercise them. We will respond within 30 days.
Your data is kept while your account is active. When you delete your account, your data is wiped from our servers within 30 days (backups within 90 days). Basic billing records required for tax/audit purposes may be retained longer per legal obligation.
Passwords are hashed (scrypt). API tokens are HMAC-signed and stored hashed. All traffic is served over HTTPS. Persistent data is stored on Railway's encrypted disk. We follow security best practices but no system is perfectly secure; if you discover a vulnerability, please email security@reqon.app.
We will notify beta users by email before any material changes take effect. The current version is always at reqon.app/privacy (or cloud.reqon.app/privacy).