Privacy Policy

Last updated: July 19, 2026

1. Overview

CareerVine ("we", "our", or "us") is a personal networking CRM that helps you manage professional relationships, track meetings, and stay on top of follow-ups. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. It covers both the CareerVine web app and the CareerVine Chrome extension.

2. Data We Collect

Account Information

Your name, email address, and password (stored securely via Supabase Auth) when you create an account, plus an optional phone number and an optional school. The school is used only to tailor which contacts we suggest and how intro emails are worded, and you can change or clear it at any time in Settings. You can also sign in to the Chrome extension with the same credentials.

Contact Data

Names, email addresses, phone numbers, job titles, companies, schools, locations, and notes that you manually enter or import via the Chrome extension.

Meeting & Interaction Logs

Meeting notes, transcripts, dates, and interaction history that you record within the app.

Google Account Data (optional)

If you connect your Google account, CareerVine requests only the permissions it needs: your basic account email address (to identify the account you connected), permission to send email on your behalf, and access to read your calendar and create or update events. We use these to send the emails you compose, schedule, or automate from your Gmail address, and to display and sync your calendar; calendar events are cached in your CareerVine account to enable filtering and syncing features. We also store your Gmail address (and, where available, its send-as aliases) so messages are sent from the right identity. The standard connection does not include permission to read your Gmail inbox. If your account has been granted optional inbox access, we store only metadata and a short preview of messages we read (sender, subject, date, and a snippet), never the full body. Inbox access also lets us read the delivery failure notices your mail provider sends back when a message cannot be delivered, so we can tell which address failed. From those notices we store only the fact that a given contact address bounced and when, never the notice itself. We also store your preferences for which CareerVine notification emails you want to receive, and which items you have removed from your CareerVine history so they stop counting toward your suggestions and stats; removing an item does not touch the original in Gmail or Google Calendar. Emails you write and send through CareerVine are handled separately, as described next. Section 6 describes exactly with whom this Google data is and is not shared.

Emails You Send Through CareerVine

When you send, schedule, or draft an email through CareerVine, or when it sends an automated follow-up you set up, we store the full content of that message (its subject and body), its recipients, and its send status in your account. We keep this so you can re-read exactly what you sent, review and edit your scheduled messages and drafts, and manage your follow-up sequences without re-fetching from Gmail. These messages are stored as part of your account data and are deleted when you delete your account.

LinkedIn Data (via Chrome Extension)

The CareerVine Chrome extension works on LinkedIn profile pages and handles profile data in two ways:

Duplicate check (automatic while you are signed in): when you view a LinkedIn profile, the extension sends that profile's URL (not the page content) to our servers to check whether the person is already one of your contacts, so it can show you an "already in CareerVine" indicator. Only the profile's URL is sent for this check.

Profile import (when you choose to import): when you start an import, the extension reads the publicly visible text of the profile as it appears in your browser (the person's name, headline, location, current and past roles and companies, their "About" summary, and education), along with the profile's URL and profile photo, and sends it to our servers, where it is parsed by AI (OpenAI) into structured contact fields for you to review and edit before saving. This full read happens only when you start an import, or, if you turn on the optional auto-analyze setting, when you open a profile page.

In both cases the extension only accesses the LinkedIn profile you are viewing. It does not read your LinkedIn messages, connections, or feed, does not access your LinkedIn account or credentials, and does not use LinkedIn's private APIs.

Contact Enrichment & Prospect Discovery (LinkedIn)

Separately from the Chrome extension, CareerVine collects publicly available LinkedIn profile information on our servers through a third-party data provider (Apify) to keep your contacts current and help you grow your network:

Enriching your contacts: when you save or refresh a contact, we look up their public LinkedIn profile to fill in details like their current role, company, location, and education.

Finding an email address: when a contact you save has no email address on file, we may run a paid lookup that attempts to find and verify a likely professional email address for them.

Suggesting new people: for discovery features, we collect publicly available profile information (such as name, headline, location, current role, and photo) for people who are not yet your contacts, for example recent hires in relevant roles at companies you follow, and store it as suggestions in your account. When you dismiss a suggestion or add it as a contact, we clear the stored profile details for that suggestion and keep only a minimal record so it does not resurface. Suggestions you never act on are removed automatically once they stop appearing in our searches. The curated contact lists you can subscribe to are built from the same kind of publicly available professional information, which can include professional email addresses.

This collection uses only publicly available profile information, runs under per-account spending limits, and is used only to power the CareerVine features described in this policy. We do not sell it or use it for advertising.

File Attachments

Files you upload and attach to contacts or meetings are stored in a private, user-scoped storage bucket. Only you can access your files.

Usage Analytics

We use product analytics (via PostHog) to understand how CareerVine is used so we can improve it. On the web app this includes usage events (for example, signing up, connecting Gmail or Calendar, importing a contact, or sending an email), page views, and interaction events, along with session recordings in which all text you type is masked and sensitive fields are redacted, so your email contents and contact details are not captured in recordings. The Chrome extension sends only a small set of usage events (that it was installed, that you signed in, and that you imported a profile); it does not record your session or capture the content of pages you visit. Analytics are linked to your account when you are signed in, or to an anonymous identifier before then. We do not sell this data or use it for advertising.

3. How We Use Your Data

  • To provide and operate the CareerVine service
  • To display and sync your Google Calendar and your CareerVine email history within the app
  • To send emails from your Gmail address on your behalf when you compose, schedule, or set up automated follow-ups in CareerVine
  • To parse LinkedIn profiles using AI when you use the Chrome extension
  • To enrich your contacts with public profile details and suggest new people to add, using publicly available LinkedIn data collected through Apify
  • To generate AI-written emails, parse transcripts, and power follow-up suggestions using OpenAI
  • If you provide your own OpenAI API key, to route your AI requests through your OpenAI account instead of ours
  • To transcribe audio/video recordings you upload using Deepgram (or, if you provide your own Deepgram API key, through your Deepgram account instead of ours)
  • To send you follow-up reminder emails if you configure them
  • To read delivery failure notices in your mailbox so we can flag an address that has stopped accepting mail, cancel anything still queued to it, and email you about it. Each of these emails can be turned off individually in your settings or through the unsubscribe link in the email itself
  • To measure product usage with privacy-respecting analytics so we can improve CareerVine
  • We do not sell your data to third parties
  • We do not use your data for advertising

4. Third-Party Services

Supabase

We use Supabase for database storage and authentication. Your data is stored on Supabase-managed servers. See Supabase's Privacy Policy.

Google APIs

When you connect your Google account, we use Gmail and Google Calendar APIs. CareerVine's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

OpenAI (optional BYO key)

By default, AI features (email drafting, transcript parsing, follow-up suggestions, LinkedIn profile parsing) are processed using CareerVine's shared OpenAI API key. If you add your own OpenAI API key in Settings → AI, your key is encrypted before storage and used server-side only for your requests. We never return it to your browser. You may optionally enable OpenAI's data-sharing program on your own account for free daily tokens; if you do, prompts sent through your key (which can include contact names and conversation content) may be used by OpenAI per their policies. See OpenAI's Privacy Policy.

Deepgram (optional BYO key)

When you upload an audio or video recording of a meeting, the audio is sent to Deepgram to produce a transcript. By default this uses CareerVine's shared Deepgram API key. If you add your own Deepgram API key in Settings → AI, your key is encrypted before storage and used server-side only for your requests. We never return it to your browser, and transcription runs on your Deepgram account instead. See Deepgram's Privacy Policy.

Apify (LinkedIn data)

We use Apify, a third-party web data platform, to collect publicly available LinkedIn profile information for contact enrichment, email-address lookup, and prospect discovery (see Section 2). See Apify's Privacy Policy.

PostHog

We use PostHog for product analytics and, on the web app, session replay (with all inputs masked). Usage data is processed on PostHog's infrastructure. See PostHog's Privacy Policy.

Cloudflare R2

Contact photos are stored on Cloudflare R2 and served through Cloudflare's content delivery network. These photos are removed when you replace them, delete the contact, or delete your account, and a daily cleanup removes any copies that are no longer referenced. See Cloudflare's Privacy Policy.

5. Google API Limited Use Disclosure

CareerVine's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google data to provide and improve the features visible to you within CareerVine.

6. How We Share Google User Data

This section describes with whom we share, transfer, or disclose Google user data, meaning the information we receive from Google APIs when you connect your Google account: your Gmail messages and their metadata, your Google Calendar events, your Gmail address and send-as aliases, and your Google OAuth tokens. We do not sell Google user data, and we do not share it with advertisers or data brokers. We share it only in the following limited circumstances:

Service providers that process it on our behalf

We share Google user data with Supabase, which hosts our database and stores your synced Gmail data, calendar events, and encrypted Google OAuth tokens, and with Vercel, which hosts our application servers and processes this data in transit when we call Google APIs on your behalf. Both act as data processors for CareerVine, use the data solely to operate the service, and are bound by their own privacy and security commitments.

At your direction

When you send an email through CareerVine, the message is delivered to the recipients you choose through Gmail. If you connect a third-party AI assistant to CareerVine through our MCP integration, that assistant and its provider can access the email subjects, previews, sender and recipient addresses, and calendar events you ask it to work with. This applies only to assistants you explicitly connect and authorize through CareerVine's sign-in and consent screen.

Legal reasons

We may disclose data if we believe in good faith that doing so is required by law, regulation, legal process, or an enforceable governmental request.

Business transfers

If CareerVine is involved in a merger, acquisition, or sale of assets, we will notify you and obtain your explicit consent before your Google user data is transferred as part of that transaction or becomes subject to a different privacy policy.

Human access

No person at CareerVine reads your Gmail data or calendar events except with your explicit permission (for example, if you ask us to look at a specific issue while helping you with support), when necessary for security purposes such as investigating abuse, to comply with applicable law, or as part of aggregated and anonymized internal operations.

No one else receives your Google user data. In particular, we do not send your Gmail message content or calendar events to OpenAI or any other AI provider, they are not included in the analytics data we send to PostHog, and they are never used for advertising or model training.

7. Data Storage, Security & Retention

All data is stored with row-level security policies so that only your account can access your data. We use HTTPS for all data transmission. Google OAuth tokens are encrypted before storage and used only to make API calls on your behalf.

We retain your data for as long as your account is active. If you disconnect Gmail without deleting your account, we revoke our access token with Google and delete the Gmail message history stored for your account at that time; if you disconnect Google Calendar, we delete your cached calendar events. When you delete your account, we remove your data, including your contacts, sent and scheduled messages, and uploaded files, from our database and file storage, along with any contact photos we host on our content delivery network (Cloudflare R2, see Section 4). We also periodically remove scraped profile data we no longer need, such as suggestions you have dismissed or added and prospects removed from curated lists. Some data is stored on our third-party providers' systems (see Section 4) and is removed according to their retention practices.

8. Your Rights

  • You can delete your account and all associated data at any time by contacting us
  • You can disconnect Google at any time from your account settings, which revokes our access to your Gmail and Calendar and deletes the synced email messages and cached calendar events we hold (see Section 7)
  • You can uninstall the Chrome extension at any time from your browser, which stops all collection by the extension and clears the data it stored locally
  • You can request an export of your data, or ask us to stop using your data for product analytics, by contacting us

9. Chrome Extension

The CareerVine Chrome extension's in-page component runs only on LinkedIn (linkedin.com). To do its job it communicates in the background with CareerVine's servers, with Supabase (to sign you in), and with PostHog (to record the usage events described in Section 2). It requests only the browser permissions it needs: storage (to keep you signed in and cache your recent work) and access to LinkedIn pages (to detect profiles and import them).

Stored locally in your browser: your CareerVine sign-in session (so you stay logged in), a short-lived cache of profiles you recently viewed (about two hours, so revisiting loads instantly), and your list of recent imports. Sent to our servers: the URL of a LinkedIn profile you view (for the duplicate check described in Section 2), the profile text you choose to import, and the small set of usage events described under "Usage Analytics".

The extension does not read your browsing history and does not access your LinkedIn account, credentials, private messages, connections, or feed. While you are signed in, when you view a LinkedIn profile it sends that profile's URL to our servers to check whether the person is already one of your contacts. It reads the full content of a profile only when you start an import, or when you enable the optional auto-analyze setting. It does not collect data from any site other than the LinkedIn profile you are viewing.

Limited Use. CareerVine's collection and use of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this data only to provide the profile-import feature you request. We do not sell it, use it for advertising, or use it for any purpose unrelated to the features described in this policy.

10. Changes to This Policy

We may update this policy from time to time. We will post the updated policy on this page with a new "Last updated" date, and continued use of CareerVine after changes constitutes acceptance of the updated policy. There is one exception: if a change means we would use your Google user data in a way this policy does not already describe, we will notify you and ask for your consent before applying that new practice to your data.

11. Contact

If you have any questions about this Privacy Policy, please contact us at dawson@careervine.app.