Your information
Privacy policy
A clear account of what the Drive connection reads, where imported information goes, and how to remove it.
Last updated
1. Who operates Career Hub
Career Hub is a personal document workspace operated by Eliran for his own use. It organizes career-related documents and information extracted from them. There is no public registration.
Contact: eliran.tur2@gmail.com.
The Drive connection is not yet enabled. This policy describes the implemented workflow that runs only after personal authorization and activation.
2. What Google access means
The connection uses Google OAuth, through rclone, to obtain read-only access. It requests this scope:
https://www.googleapis.com/auth/drive.readonly
This scope can view and download files accessible to the connected Google account, beyond the selected folder. The importer is configured to read a chosen folder and its subfolders. That folder setting is an application-level limit; it does not make the OAuth token folder-scoped.
The current adapter uses this permission to discover and download existing files in the configured folder. It does not request Drive write access or change originals. Shortcuts and Google-native documents are skipped.
Google handles authorization. Career Hub does not collect the Google account password. When enabled, the integration uses OAuth access and refresh tokens stored in the deployment’s protected credential system; refreshed access credentials are also held temporarily by the import worker.
3. Information accessed and retained
- Source information: the configured folder reference, file identifiers, names and paths, sizes, and available content checksums. Listing can include metadata for files that are later skipped.
- Imported content: supported original files, extracted text, OCR results, and structured information derived from those documents. Content may include personal information contained in the files the owner chooses.
- Workspace history: source versions, import status and errors, timestamps, drafts, corrections, approvals, and audit history. Import records can contain file paths and references.
- Access information: OAuth credentials for the connection and application session records needed for private access.
4. How the information is used
Information is used to import and organize documents, identify repeated or changed content, extract details, display originals and drafts, and preserve review history. Imports are requested manually through “Pull now”; the current worker does not schedule periodic imports. Extraction does not approve a record.
Text extraction and OCR run inside the personal application deployment. The current integration does not transmit Drive files or extracted information to external AI services, and does not use this information to train AI models.
Google user data is not sold, used for advertising, or provided to data brokers. It is not used to assess creditworthiness or make lending decisions.
5. Storage, access, and service providers
Imported files and records are stored in the owner’s personal Linode Kubernetes Engine (LKE) deployment, using persistent file storage and PostgreSQL. The application is protected by private Tailscale network access, application authentication, and HTTPS. Google credentials are managed separately from the public information website.
Google provides the source files and authorization service. Linode provides the application and storage infrastructure, including backup storage. Tailscale provides private network access. The owner can read and review his imported documents in the application. There is no public document access.
Information is processed by infrastructure providers as needed to operate these features. This is not a promise of absolute security or of zero provider access. Any additional disclosure would be limited to an authorized purpose consistent with the Limited Use requirements, such as a necessary security investigation or a legal obligation.
6. Retention, disconnection, and deletion
Imported originals, derived records, source versions, and review history are retained until manually removed by the owner. There is no automatic retention deadline or self-service “delete all” feature. A file disappearing from Drive may be marked missing; its imported copy and history remain.
You can revoke the connection in Google Account’s third-party connections settings. The operator can also disable importing and remove the stored OAuth credentials. Revoking access stops future authorized access but does not delete information already imported.
For a deletion request, contact eliran.tur2@gmail.com. Deletion requires manual review and removal of the relevant stored files, derived information, and records. Requests relating to someone else’s data require confirmation of authority. Do not email passwords, tokens, or sensitive documents.
Backup and recovery copies may retain information after removal from the active workspace. They are managed separately and must also be considered for manual deletion; there is no fixed automatic backup-deletion period or instant-erasure guarantee. Disconnecting the integration does not delete its backups.
7. Google API Limited Use
Career Hub’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. This applies to imported information and information derived from it.
Use is limited to the personal document features described here. Any transfer or human access beyond the owner’s use must meet those requirements. This statement is a data-use commitment, not a claim of Google verification, certification, or endorsement.
8. This information website and contact email
These static pages are hosted by Cloudflare Pages. They contain no forms, scripts, analytics tags, advertising, or application cookies. They do not connect to Google Drive or receive imported documents.
Cloudflare processes ordinary web-request information, such as IP addresses, requested URLs, and browser details, to deliver and protect the site. Infrastructure request processing is separate from application analytics; this site does not enable Cloudflare Web Analytics. The private application separately uses a session cookie for login.
If you choose to email the contact address, your address and message are processed by the operator’s email provider to handle your inquiry. Contact messages are retained or removed manually.
9. Changes to this policy
The date on this page will be updated when these practices change. Before Google user data is used in a new way or for a new purpose, the policy and relevant application disclosures must be updated and any required consent obtained.