Privacy Policy

Last updated: August 2026

Project Shield ("we", "our", or "the Service") is operated by Yumiko Morinaga. This Privacy Policy explains what information we collect, how we use it, how we protect it, and your choices regarding that information.

1. Information We Collect

When you use Project Shield, we collect: (a) job opportunity emails you forward to your personal inbox address, which are parsed to extract job details; (b) your resume text, which you provide directly; (c) your stated preferences (target rate, availability, remote work preference); and (d) account information via Supabase Authentication, including your email address and, if you choose to sign in with Google, your basic Google profile information (name, email address, profile photo). Resume text and forwarded job email content may contain sensitive personal and professional information; we treat this data with the protections described in Section 3 below.

2. Google Sign-In

Project Shield offers "Continue with Google" as an optional way to sign in, in addition to email-based login. This uses only basic, non-sensitive profile scopes (openid, email, profile) to identify you. Project Shield does not request access to your Gmail inbox, does not read or send email on your behalf, and does not request any sensitive or restricted Google API scopes.

3. Data Protection and Security

We apply the following safeguards to protect your information, including sensitive data such as your resume and forwarded job email content:

  • Encryption in transit: all traffic to and from Project Shield is encrypted using HTTPS/TLS.
  • Encryption at rest: data is stored in Supabase (PostgreSQL), which encrypts data at rest.
  • Access controls: your data is protected by row-level security policies so that only your authenticated account can access your own records. Internal access by the Service operator is limited to what is necessary for maintenance, debugging, and support.
  • AI processing:job email content you forward is sent to OpenAI solely to classify relevance, extract job details, and draft reply suggestions. This data is submitted via OpenAI's API, which by default does not use API-submitted data to train OpenAI's models.
  • No sale of data: we do not sell your personal information, and we do not use it for advertising or third-party marketing purposes.
  • Data minimization: we only collect the information described in Section 1, and only use it for the purposes described in Section 4.

4. How We Use Your Information

We use your information to: parse and score job opportunities against your preferences and resume; generate AI-drafted reply emails (which you copy and send yourself, or open pre-filled in your own email client); track your active projects and invoices; and authenticate you when you sign in.

5. Third-Party Services

We use the following third-party services to operate Project Shield: Supabase (database and authentication), OpenAI (email classification, job data extraction, and AI reply drafting), Mailgun (inbound email processing), Vercel (hosting), Stripe (payment processing for paid subscriptions), and Google (optional Sign-In only). Each of these providers processes data solely to provide their respective service to us, under their own security and privacy commitments.

6. Data Retention and Deletion

We retain your data for as long as your account is active. If you request deletion of your account and associated data, we will delete it within 30 days, except where retention is required for legal, tax, or fraud-prevention purposes. You may request deletion at any time by contacting us at the email address below.

7. Contact

Questions about this Privacy Policy can be directed to yumikoissasairahiro@gmail.com.