Go to our app
THE DETAILS THAT MATTER

Privacy Policy

What your workspace stores, when information leaves it, and the choices available to you.

Last updated

GRMD AI Solutions Private Limited, India, operates SchoolWhool and is responsible for the personal information processed through the service. This policy describes the information handled by SchoolWhool's website and personal workspace, including optional AI and Gmail features. Your workspace records are associated with your account and separated from other accounts.

1. Information you provide

SchoolWhool processes the information you choose to enter, including:

  • Account information used for sign-in through Supabase Auth.
  • Your profile, contact details, skills, employment history, and résumé text.
  • Saved jobs, application materials, approvals, form values, notes, statuses, and submission records.
  • Recruiter messages you paste or import from a connected Gmail account.

Provide only information you want processed for your job search. Employers may ask for additional information on their own forms; you decide what to provide and must review it before submission.

2. Why information is used

SchoolWhool uses this information to authenticate you, maintain your private workspace, show relevant job information, prepare materials you request, support reviewed applications, and connect recruiter updates with tracked roles. Request and error information may also be processed by the server and its infrastructure for operation and troubleshooting.

The application does not include advertising tracking or personal-data sales features.

3. Services that receive information

ServiceInformation and purpose
Supabase AuthAccount credentials, authentication requests, and session information needed to sign you in.
OpenAI, when you request AI assistanceYour profile and the selected role's title, company, and description, to generate the requested review and drafts.
Google Gmail, when connectedAuthorization and message requests needed for the manual sync described below.
Employer application systemsInformation needed to prepare supported forms, and the materials and answers you approve for submission. When you open an employer site, its own privacy practices apply.
The infrastructure running SchoolWhoolWorkspace records and requests needed to host the application and its database. Storage location and infrastructure arrangements depend on the deployment.
Google Analytics, only if you acceptPage addresses, referrer, approximate location, and device and browser information, to measure use of the public website. Not loaded if you decline, and never loaded in your personal workspace.

Public job-board discovery reads company listings. It does not send your résumé to those boards to rank results. Opening or preparing an employer form can still generate requests to that employer's systems before submission.

Payment processing

When you choose subscription checkout or billing management, Stripe receives a billing customer reference linked to your SchoolWhool account and processes the payment details you enter on its hosted pages. SchoolWhool stores the account-to-customer mapping, Stripe subscription and price identifiers, subscription status and billing period, cancellation settings, checkout retry information, and minimal webhook event receipts. It does not store your card number or banking credentials. Stripe processes payment information under its Privacy Policy.

Billing records are retained separately from your job-search workspace. Deleting workspace data does not cancel a subscription or remove records needed to manage billing and meet applicable obligations. Manage cancellation through Settings → Billing → Manage billing, or contact us for assistance. An authentication-account deletion request is separate and may require resolving an ongoing subscription and any legally required record retention.

4. Optional Gmail access

Gmail is optional. If you connect it, SchoolWhool requests the gmail.readonly scope. This permission is broader than the messages imported: the application uses job-related search terms and requests message metadata and snippets.

When you choose Sync inbox, SchoolWhool retrieves message IDs, senders, subjects, timestamps, and snippets. It does not retrieve full message bodies or attachments. Initial sync looks back 30 days and imports up to 150 messages per sync. These imported records are stored in your workspace for review and tracking.

Email classification uses application rules, not a language-model call. The Gmail sync feature does not send imported message content to the AI provider. SchoolWhool does not send messages, create email drafts, or train AI models on Gmail data.

Gmail tokens are encrypted in HttpOnly cookies. Disconnecting Gmail revokes access and clears the integration cookie; already imported messages remain in your workspace until removed. You can also revoke access through your Google account connections.

Information obtained from Google APIs is used for the recruiter-tracking features described here, subject to the Google API Services User Data Policy, including its Limited Use requirements.

5. AI processing

AI assistance sends your profile and the selected job to OpenAI when you request analysis and tailoring. Requests disable response storage through the API's store: false setting; this is not a promise of zero provider retention. The provider's applicable policies and account settings govern its processing.

Generated drafts and reviews may be saved in your SchoolWhool workspace. Your original résumé is preserved. See the AI Disclosure for limitations and review controls.

6. Cookies and local browser data

SchoolWhool uses cookies for authentication, OAuth security, and the Gmail connection. Older locally stored workspace data may be imported into your account once; the import is designed not to duplicate previously imported records. The public marketing preview holds its sample interactions only in page memory.

The public marketing pages offer optional Google Analytics 4, which counts visits and measures which pages and lessons people read. It is asked for, never assumed: on your first visit a banner asks you to accept or decline, and analytics is not loaded until you accept. Declining means no analytics cookie is set and no request is made to Google at all. Advertising storage stays switched off in both cases, and analytics is never loaded in your signed-in workspace at /app, so the roles you track, the messages you import, and the materials you prepare are never measured.

Your choice is stored in your own browser and can be changed at any time through Cookie settings in the site footer. If you accept, Google processes the resulting information under its Privacy Policy. SchoolWhool does not link analytics records to your account and does not use them for advertising.

Free course lectures use embedded YouTube players served from youtube-nocookie.com. When a published player loads or you interact with it, your browser connects to YouTube, which may process connection and playback information under Google’s Privacy Policy. SchoolWhool does not require an account for courses or store your viewing progress.

The website serves its fonts from SchoolWhool’s own origin; viewing a page does not request fonts from Google.

Disabling essential cookies may prevent sign-in or connected features from working.

7. Retention and your controls

Saved profiles, drafts, tracked roles, and imported messages remain available in your workspace until you remove them or delete workspace data. Temporary browser application sessions close after ten minutes. Job-discovery history used to identify unseen listings is periodically pruned according to the server's configured retention period.

You can edit your profile, download application materials, export the application tracker as CSV, remove tracked applications, and disconnect Gmail. Settings → Your account → Delete workspace data removes workspace records from the active database and signs you out. The Supabase authentication account remains. Copies already submitted to employers, provider records, and any infrastructure backups are not deleted by this workspace action.

8. Security and external processing

Account checks and ownership filters restrict workspace access. Gmail credentials use encrypted cookies. These controls reduce risk, but no internet service can guarantee complete security. Provider storage locations, backup retention, and international processing depend on the services configured for the deployment; this policy does not promise storage in a particular country.

9. Updates

The date above identifies this policy's latest revision. We may update it when features or data practices change. Applicable privacy rights and any legally required notices continue to apply.

10. Privacy questions and requests

Contact GRMD AI Solutions Private Limited, India, at hello@schoolwhool.com to ask about your personal information, request access or correction, request authentication-account deletion, withdraw consent, or raise a privacy concern. Your available rights depend on applicable law. We may need to verify your identity before acting on a request, and some records may need to be retained where required by law.

Workspace deletion and authentication-account deletion are separate. Use the workspace controls described above for workspace records, or email us for assistance with the authentication account and other privacy requests.