Privacy Policy for Shortlist
At Shortlist, accessible from our official website, one of our main priorities is the privacy and security of our users. This Privacy Policy document outlines the types of information that is collected, processed, and recorded by Shortlist and how we use it.
1. Google API Disclosure & Limited Use
Shortlist connects to your Gmail inbox using Google API Services to automate data extraction.
Shortlist’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2. Information We Access and Why
Shortlist is a fully automated email ingestion and data entry engine. We use secure OAuth2 authentication tokens to securely connect to your designated Gmail inbox.
- Scoped Access: We only monitor specific incoming emails within labels or folders explicitly chosen by you (such as a designated recruitment or application inbox).
- Data Extraction: Our engine programmatically reads email headers, body text, and attachments (such as CVs and invoices) solely to extract structured data points (such as Name, Phone Number, Email, and Experience).
- Zero Retention Policy: Raw email body text and attachments are parsed programmatically in temporary memory (RAM). Once the parsed data is successfully delivered to your designated destination (such as your Google Sheet, database, or CRM), the raw email content is completely purged from our active data processing layer. We do not store or keep copies of your email text on our servers.
3. Strict Restrictions on Data Use
To ensure institutional trust and protect candidate and corporate privacy, Shortlist enforces the following absolute restrictions:
- No Human Reading: Shortlist is a completely automated system. No human being reads, reviews, or scans your emails.
- No Third-Party Sharing: We do not sell, rent, trade, or share any accessed email data or extracted content with third parties.
- No AI Model Training: Shortlist does not use, store, or share your email data or candidate application content to develop, improve, or train public or non-personalized Artificial Intelligence (AI) or Machine Learning (ML) models.
4. Data Security and Idempotency Ledger
While we do not store the content of your emails, our database stores a highly secure Idempotency Ledger. This ledger saves only the metadata (such as the unique Gmail_Message_ID and a status timestamp) of processed emails.
This is used strictly to ensure that our system never accidentally processes or duplicate-logs the exact same email twice. All data in transit is protected using bank-grade encryption (HTTPS/TLS).
5. User Control and Access Revocation
You maintain absolute ownership and control over your Gmail inbox at all times. You can completely revoke Shortlist's access to your Google account instantly at any moment through your official Google Security Settings panel under “Third-party apps with account access.” Revoking access immediately halts all webhooks and background processes.
6. Changes to This Privacy Policy
We may update our Privacy Policy from time to time to maintain compliance with changing platform laws. We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes.
7. Contact Us
If you have any questions or security concerns regarding this Privacy Policy or how your data is handled, please contact us at:
Email: support@shortlist.io
Company Office: Nairobi, Kenya
