Privacy PolicyHow Kroot handles your data

Your Privacy, Security, and Control

This Privacy Policy explains what information Kroot collects, how we use it to track your job applications and power coaching, and the choices available to you. It applies to the Kroot application at krootme.com.

Information We Collect

We collect only the data needed to operate the platform, track your job applications, and connect learners with mentors:

  • Account details: Kroot accounts are created and accessed through Google or LinkedIn sign-in. We receive your email address and basic profile details from whichever provider you choose. Kroot has no separate password, so you never create one with us and we never receive or store one.
  • Profile information: During onboarding we store the details you provide to personalize matches—students share interests, school affiliations, preferred track, focus areas, and price ranges, while mentors share role details, experience level, LinkedIn URLs, focus areas, rates, and alumni schools.
  • Google user data from your connected mailbox: If you choose to connect a Gmail account, we access your Gmail messages read-only in order to detect and track your job applications. See the dedicated section below.
  • Job application records: The companies, roles, application stages, interview rounds, and action items we derive from your connected mailbox, together with any corrections you make.
  • Booking and availability data: Scheduling data includes mentor availability ranges, booked session times, time zones, contact details (email and optional phone), and any session notes you add when requesting or documenting a session.
  • Uploads: If you add a profile image, we store it in Supabase Storage under a path scoped to your account.
  • Support and diagnostics: We log limited technical metadata (such as request status and errors) to troubleshoot issues and keep the service reliable.

Google User Data

If you sign in to Kroot with Google, the Google consent screen you approve at sign-in covers both of Kroot's Google features, and the mailbox you sign in with is connected for job-application tracking from that point on. You can disconnect it at any time from your dashboard, and you can sign in with LinkedIn instead if you would rather not grant Google access at all.

What we request at sign-in. Read-only access to your Gmail messages (gmail.readonly), which powers automatic job-application tracking; access to your Google Calendar (calendar, calendar.events) and to Google Meet links we create (meetings.space.created), which is used only to put coaching sessions you book on your calendar with a Meet link attached; and your basic identity (openid, email, profile) to create your account. We never request permission to send, modify, or delete your mail.

Reconnecting a mailbox. If you disconnect and later reconnect Gmail from your dashboard, that second consent screen asks only for gmail.readonly and openid — it does not request calendar access.

What we access and store. We look through your mailbox to find messages that relate to job applications. For each message we process we keep a limited record — the sender, the subject, the date, and a hash used to avoid processing the same message twice — together with the application information we extract from those that are job-related. Message content itself is never written to our database: it is held only for as long as it takes to process the message, and is then discarded as described under Data Retention.

What we use it for. Gmail data is used solely to provide and improve the job-application tracking features you see in Kroot: identifying the companies you have applied to, recognizing changes such as screens, interviews, offers, and rejections, and surfacing upcoming interviews and follow-up actions to you. Calendar access is used solely to create the event and Google Meet link for a coaching session you book, on the calendar of the account you signed in with. We do not read your existing calendar events to build your application pipeline.

What we never do. We do not sell Google user data. We do not transfer it for advertising, credit assessment, or lending purposes. We do not use it to train generalized artificial intelligence or machine learning models. We do not allow humans to read it except in the narrow circumstances described under Human Review below.

Kroot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Automated Processing and AI

To recognize job-application activity, Kroot uses Google's Gemini models, through the Google Gemini API, to interpret the content of candidate messages. Google acts as our service provider for this purpose and processes the content only to return a result to Kroot. This content is not used to train generalized artificial intelligence or machine learning models.

This processing is automated and can be wrong. You can review, correct, or delete any application record Kroot creates from your mail.

Human Review

Messages are processed automatically and are not read by our staff in the ordinary course. Where automated processing is uncertain, or where the result would be significant for you, Kroot asks you to confirm or correct it yourself within the application.

  • Kroot personnel access message content only where you have asked us to, where it is necessary to investigate a security issue or misuse of the platform, or where we are required to by law.
  • When you confirm or correct a result, we keep a record of that decision so we can improve the accuracy of the feature for you. The content of the message is not kept for this purpose.

How We Use Information

  • Provide authentication, keep you signed in, and secure your account.
  • Detect and track your job applications, interviews, and follow-up actions from your connected mailbox.
  • Match learners and mentors based on the focus areas, experience, and pricing information supplied during onboarding.
  • Schedule, manage, and record the status of bookings, including handling approvals or declines and updating availability.
  • Display profile and session details to the counterparties involved in a booking so they can prepare for the session.
  • Improve reliability through logging and health checks that verify database, storage, and booking functions are operating correctly.
  • Produce aggregate, de-identified statistics—only if you opt in. See Your Choices and Controls.

How We Share Information

We do not sell your personal information. We share data only as needed to deliver the service:

  • With session participants: Mentors and learners can see relevant booking details (times, time zones, contact info, and notes) for sessions they are part of. Your connected mailbox and the applications derived from it are never shared with mentors or other users.
  • With our service providers: Supabase (authentication, database, and file storage), Vercel (application hosting), Google (message processing, as described above), and our payment platform. Each processes data on our behalf and for no other purpose.
  • For compliance and safety: We may access or preserve information to comply with legal obligations or investigate misuse of the platform.

Payments

Payments for coaching sessions are processed by a third-party payment platform. Kroot does not collect, receive, or store your card number or other payment credentials; those are handled by the payment platform under its own terms and privacy policy. Kroot records only whether a session has been paid.

Data Retention

  • Message content: Held only for as long as it takes to process a message, and in any case no longer than 30 days.
  • Your job-search records: The limited message details we keep, and the applications, interviews, and action items built from them, are retained while your account is active so your history stays accurate.
  • After you disconnect a mailbox: Disconnecting revokes our access and stops all further access to your mail right away. Records already in your account remain so your history is not lost, and you can remove them at any time by deleting your account or by asking us.
  • Profile, booking, and availability records: Retained for your ongoing use of the platform and to maintain accurate session histories.
  • On account deletion: Deleting your account revokes any outstanding Google authorization and removes your profile, your mailbox connection, and the job-search records derived from it.

Your Choices and Controls

  • Connect a Gmail account only if you want automatic application tracking—it is never required to use Kroot.
  • Disconnect your mailbox at any time from Kroot settings. You can also revoke Kroot's access directly from your Google Account permissions page.
  • Review and correct any application, interview, or action item Kroot creates from your mail.
  • Aggregate analytics are off by default. We produce de-identified, aggregated statistics only if you opt in, and you can withdraw that consent at any time.
  • Update your profile details at any time through the onboarding and dashboard experiences.
  • Modify availability or booking requests to control when sessions can be scheduled.
  • Request account deletion to remove your profile, your mail-derived data, and your authentication credentials from the service.

Security

We use industry-standard safeguards to protect your information, including encryption in transit and at rest, access controls that keep your records readable only by your account, and credentials that are held securely on our servers and never exposed to your browser. We also validate booking requests so your scheduling data stays consistent.

No service can be completely secure, but we work to protect your information and to limit who can access it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change to how we handle Google user data, we will notify you in the application before the change takes effect. The date below reflects the most recent revision.

Contact

If you have questions about this policy or how your information is handled, or if you would like your data deleted, please reach out through the support channels provided in your Kroot account, or contact us at trykroot@gmail.com.

Last updated: August 9, 2026

Need legal terms instead? Visit our Terms of Service.

Kroot | Personalized PM Coaching & Job Board