Who we are
Tsunami is a job-application service that applies to jobs on behalf of its clients across job boards such as LinkedIn, Indeed, ZipRecruiter, and Dice. A client signs up, tells us the roles they want, and authorizes us to submit applications for them. This policy explains what data we handle to provide that service and how we protect it. You can reach us at hello@gotsunami.us.
Information we collect
- Profile and application data you provide so we can apply on your behalf: name, contact details, resume, work history, and your answers to common application questions.
- Job-board account access you grant us so we can sign in and submit applications for you, including session cookies for the boards you connect.
- Limited, read-only Gmail access when you choose to connect your Google account, used only as described in the next section.
- Operational records of the applications we submit for you, so you can see what was sent and where.
How we use Google user data (Gmail)
If you connect your Google account, Tsunami requests the gmail.readonly scope for a single, narrow purpose: to read the one-time sign-in verification codes that job boards email you when we log in to apply on your behalf. Many boards send a numeric code to your inbox as a second factor; without the ability to read that code, the automated sign-in cannot complete.
What we do with this access:
- We search your inbox only for recent messages from the specific job-board senders (for example, messages from linkedin.com or indeed.com) at the moment a sign-in is in progress, and we extract the verification code from that message.
- We do not read, index, store, or analyze the rest of your mailbox. We do not retain message contents after extracting a code. We use the code once to complete the sign-in and discard it.
- We do not use Gmail data for advertising, profiling, training machine-learning or AI models, or any purpose other than retrieving these sign-in codes.
- We do not sell Google user data and we do not transfer it to third parties except as needed to operate the sign-in (for example, our cloud-browser provider that performs the login), or where required by law.
Tsunami’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we store and protect data
- Credentials and access tokens are encrypted at rest. Access is limited to the systems that perform sign-ins and submit applications.
- Gmail access tokens are used to fetch a verification code and are not used to browse or back up your mail.
- We retain your profile and application records for as long as your account is active, and delete them on request.
Your choices
- You can disconnect your Google account at any time from your Tsunami portal, which revokes our access. You can also revoke access directly from your Google account permissions.
- You can request a copy or deletion of your data by emailing hello@gotsunami.us.
Changes to this policy
We may update this policy as the service evolves. We will revise the date at the top when we do, and material changes will be communicated to active clients.