Privacy Policy — RecruiterReach
Last updated: 2026-09-24
RecruiterReach (“we”, “the extension”) is a Chrome extension that helps solo recruiters run personalized outreach from Gmail and track candidates in a pipeline backed by their own Google Sheet.
What we access
With your explicit Google OAuth consent, the extension may access:
| Access | Scope | Why |
|---|---|---|
| Send email via Gmail | gmail.send | Send outreach as yourself |
| Drive files you select or the app creates | drive.file | Read and update the Sheet you connect |
| Your Google account email | userinfo.email | Identify your mailbox in the UI |
We do not request permission to read all of Drive, or to read full Gmail bodies (gmail.readonly is not used).
Where candidate data lives
- Source of truth: your Google Sheet.
- On your browser: campaign settings, UI state, license status, and short-lived candidate rows in
chrome.storage.local. - On our servers (MVP): we do not store candidate PII or email content. This Worker hosts the Google Picker page, this policy, and a license-validation proxy. License validation transmits only a license key — never Gmail bodies or Sheet rows.
Pipeline status
You mark Replied, Bounced, or other statuses in the Gmail panel or People tab (or directly in your Sheet). We do not read Gmail threads, headers, or message bodies. Opening a sent thread only uses the thread ID saved when you sent, so the panel can highlight that person.
Licensing
If you activate a Pro license, the extension sends your license key to this Worker, which calls Lemon Squeezy’s License API. That call does not include Gmail content or candidate rows.
How we use, share, and protect Google user data
We use Google user data only to provide RecruiterReach’s features: sending outreach you compose, updating the Sheet you connect, and showing your connected mailbox. We do not use Google user data for advertising, credit, lending, data brokerage, or to train generalized AI/ML models.
We do not sell Google user data. We do not transfer or disclose Google user data to third parties except as needed to run the product: Google (Gmail and Drive/Sheets APIs you authorized) and, if you activate Pro, Lemon Squeezy (license key only — not Gmail or Sheet rows).
Security procedures are in place to protect the confidentiality of your data. We use encryption
in transit (HTTPS/TLS) for Gmail, Sheets, and this Worker. OAuth access tokens remain in Chrome’s
identity storage on your device; we do not store Google tokens on our servers. Candidate lists
and mail stay in your Google account (Sheet and Gmail), which Google encrypts at rest under your
account. A short-lived copy of candidate rows may sit in chrome.storage.local on
your computer for the popup and Gmail panel. We do not store candidate PII or Gmail bodies on
the Worker. You can disconnect, revoke RecruiterReach at
Google Account Permissions, or uninstall
to drop local tokens and cache.
What we do not do
- We do not sell or share recruiter or candidate data for advertising.
- We do not use candidate data to train AI models.
- We do not scrape LinkedIn or other sites in bulk.
- We do not read Gmail threads, headers, or message bodies.
- We do not add open/click tracking pixels to outreach emails.
Data retention
- Browser cache: until you disconnect, clear storage, or uninstall.
- Google Sheet data: retained under your Google account policies.
- License validation: processed for billing/abuse prevention; we do not keep candidate lists on the Worker.
Your choices
- Disconnect Google from the extension popup to clear the local token cache; also revoke access at Google Account Permissions.
- Uninstall the extension to remove local storage.
- Edit or delete candidate data directly in your Google Sheet.
Contact
Support: recruiterreachsupport@gmail.com
Changes
We may update this policy. The “Last updated” date at the top will change when we do. Material changes for a published product will be noted in the Chrome Web Store listing or product changelog.