Road to J (“Road to J”, “we”, “us”) is a web app at roadtoj-dev.vercel.app that helps job seekers find the right people at companies they want to work for, research them, and send them personalised emails from their own Gmail account — and then handle replies, book meetings and prepare for interviews.
This policy explains what information we collect, how we use it, who we share it with, how long we keep it and the choices you have. It applies to everyone who uses Road to J and to the people our users contact. It is written to meet the Australian Privacy Act 1988 (the Australian Privacy Principles), the EU and UK GDPR where they apply, and the Google API Services User Data Policy.
1. Information we collect
Information you give us
- Account details: your name, email address and password (stored only as a secure hash), or your Google account if you sign in with Google.
- Profile and CV: CV text you upload or paste, your skills, experience, education, links (such as LinkedIn or a portfolio), the roles, companies and locations you are targeting, your time zone and your writing preferences.
- Content you create: email drafts and edits, notes, campaign settings, interview preparation, and personal pages you choose to publish.
- Files you import: for example a LinkedIn data export you upload to find people you already know.
- Messages to us: anything you send to support or feedback.
Information from Google, when you connect your Google account
You choose whether to connect Google, and you see Google’s consent screen before anything is shared. See section 3 for exactly what each permission is used for.
Information about the people you contact (third parties)
Name, job title, company, work email address and public professional information (such as public posts, talks and company pages). It comes from you, your LinkedIn export, your Google contacts, or data providers such as Apollo and Hunter. Every record notes where and when it came from.
Information collected automatically
- Activity in the app: actions such as creating a campaign or approving a draft, so we can show your progress and keep the service working.
- Technical data: IP address, browser type, device type and error reports, used for security and to fix problems.
- Cookies: only the cookies needed to keep you signed in and remember your settings (such as light or dark theme). We don’t use advertising or cross-site tracking cookies, and we don’t put tracking pixels in the emails we send for you.
Payment information
Payments are handled by Stripe. We receive only your plan and payment status. We never see or store your card number.
2. How we use information
- To create and run your account and provide the features you use.
- To find relevant people at your target companies, research their public professional background, and draft personalised emails for you to review.
- To send the emails you approve from your Gmail account, notice when someone replies or an email bounces, and help you answer and book meetings.
- To prepare you for interviews with the people and companies you’re talking to.
- To keep the service safe: sending limits, abuse and spam prevention, fraud prevention and fixing errors.
- To process payments and send service messages such as renewal reminders.
- To comply with the law and respond to lawful requests.
Legal bases (GDPR): performing our contract with you; your consent (for example connecting Google or importing contacts, which you can withdraw at any time); our legitimate interests in running a safe service and in contacting professionals about genuine job opportunities on your behalf; and legal obligations.
We do not sell personal information, we do not use it for advertising, and we do not share it with data brokers.
3. Google user data
Road to J’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access and why
- Basic profile (openid, email, profile): your name, email address and profile picture, to create your account and sign you in.
- Send email on your behalf (gmail.send): to send the outreach emails, follow-ups and replies that you approve, from your own Gmail address so replies come straight back to you. We only send emails you have approved, or first emails within the autopilot limits you turn on yourself.
- Read your email (gmail.readonly): only to (a) read the replies in email threads that Road to J sent for you, so we can show them in your inbox, sort them (for example interested, not now, not interested) and draft a response for you to review; (b) detect bounce notifications for emails we sent, so we stop emailing addresses that don’t work; and (c) check the date you last emailed a specific person, to tell you how strong your connection is. We don’t read, store or analyse other emails in your mailbox.
- Contacts and other contacts (contacts.readonly, contacts.other.readonly): names, email addresses, companies and job titles of people you already know, to find warm introductions to the companies you are targeting. We ask for your consent on a separate screen before importing contacts.
- Calendar free/busy (calendar.freebusy): to see when you are free (not event details) so we can suggest meeting times when someone agrees to talk.
- Calendar events (calendar.events): to create the meeting you choose to book, with a Google Meet link, and to show upcoming interviews in your preparation view.
How we protect and limit Google data
- We use Google data only to provide and improve the user-facing features described above. We don’t use it for any other purpose.
- We don’t sell Google data, use it for advertising (including retargeting or personalised ads), or use it to determine credit-worthiness or for lending.
- We don’t use Google data to develop, improve or train generalised AI or machine-learning models.
- To write drafts and sort replies, the text of a relevant reply or contact is sent to our AI provider (Anthropic) only to produce that result for you. Under our agreement with Anthropic it is not used to train their models.
- Humans don’t read your Google data, except with your explicit permission (for example when you ask for support), when needed for security or abuse investigation, or when the law requires it.
- Google access tokens are stored only on our servers, in a database encrypted at rest, and are never exposed in your browser.
- You can disconnect Google at any time in Settings, or at myaccount.google.com/permissions. When you disconnect or delete your account we delete your Google tokens and the Google data we stored.
4. Who we share information with
We share information only with service providers that process it on our behalf, under contracts that require them to protect it and use it only to provide their service to us:
- Anthropic — AI drafting, reply sorting and interview preparation.
- Google — Gmail, Calendar, Contacts and Google sign-in, as you connect them.
- Apollo and Hunter — finding and verifying work email addresses.
- Tavily and Exa — searching the public web for professional information.
- Voyage AI — turning text into embeddings to match people and roles.
- Stripe — payments.
- Sentry — error reports, with personal data removed.
- Vercel and Heroku — hosting and databases.
We may also disclose information if the law requires it, to protect the rights and safety of our users or others, or as part of a merger or sale of the business (in which case this policy continues to apply). Some providers are in the United States; we rely on their contractual safeguards for overseas transfers (APP 8, GDPR Art. 46).
5. How long we keep information
- Your account data is kept while your account is open.
- When you delete your account, your data — including Google data and tokens — is deleted within 30 days, except limited records we must keep by law (such as billing records).
- People imported but never contacted are deleted automatically after 12 months.
- Personal pages you publish can expire and can be turned off at any time.
- Addresses that opted out or bounced are kept on a do-not-contact list so they are never emailed again.
6. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access is limited to the account owner, and to a small number of administrators for abuse review and support. No system is perfectly secure, but we work to protect your information and will notify you and the regulator of an eligible data breach as the law requires.
7. Your rights and choices
- Access and export: download everything we hold about you (JSON or CSV) from Settings → Your data.
- Delete: delete your account and all its data from Settings → Your data.
- Correct: edit your profile anytime, or ask us to fix anything else.
- Withdraw consent: disconnect Google or remove imported contacts at any time.
- Object or restrict: ask us to stop or limit certain processing.
If someone you contacted asks us, we tell them where their details came from and remove them. Every outreach email includes an opt-out line. If you’re unhappy with how we handled a request, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or your local data protection authority.
8. Children
Road to J is not intended for anyone under 16, and we don’t knowingly collect their information.
9. Changes to this policy
If we change this policy in a way that matters, we’ll tell you in the app or by email before the change takes effect, and update the date above.
10. Contact us
Questions or requests: email privacy@roadtoj.com. We respond within 30 days.