Privacy Policy
Last updated 2026-07-12
Lynder, a general partnership operated from California, USA ("Lynder," "we," "us," or "our")
- Effective date: 2026-07-12
- Last updated: 2026-07-12
This Privacy Policy explains what personal information Lynder collects, why we collect it, how we use, store, share, and protect it, and the rights and choices you have. It applies to the Lynder website, application, and related services (together, the "Service").
Lynder is an AI agent that helps engineers get hired at startups. It monitors public hiring signals, prepares outreach and application materials, and — with your explicit, per-message approval — sends outreach from your own connected email account. Lynder's Gmail permission is send-only: the Service cannot read, list, or search your mailbox, and your email content never reaches Lynder. Because the Service can access your resume and your profile, and can send messages you approve from your connected account, we take the handling of your information seriously.
If you have any questions, contact us at info@lynder.ai.
1. Who we are
Lynder is a general partnership operated from California, USA. The party responsible for your personal information is:
Lynder (a general partnership)
California, USA
Email: info@lynder.ai
Lynder is not a corporation; it is operated as a general partnership, and its principal place of business is California, USA.
2. Summary (the short version)
- We collect your account details, the profile and preferences you enter, your uploaded resume, and — only if you connect Gmail — your connected address and the OAuth tokens needed to send messages you approve. We also collect basic usage and device data. We never collect your email content: Lynder's Gmail permission is send-only and cannot read your mailbox.
- We use it only to run the job-search agent for you: to find opportunities, prepare drafts and application materials, and send outreach that you have personally approved, from your own connected email account.
- We never sell your personal information, and we do not use it for advertising or to train generalized AI/ML models.
- We share it only with the named service providers listed in Section 6 who help us run the Service.
- You control it. You can access, correct, export, or delete your data, disconnect any linked account at any time, and exercise the privacy rights described in Sections 9 and 11.
This summary is for convenience only; the full Policy below governs.
3. Google API Services: Limited Use disclosure
Lynder's use of information received from Google APIs, and any transfer of that information to others, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, and consistent with those requirements, Lynder will:
- Use Google user data only to provide and improve the user-facing features of the Service that are prominent in the Lynder interface (sending outreach and follow-ups that you have personally approved, from your own account);
- Not transfer or sell Google user data to third parties for advertising, marketing, or other purposes, and not use it for personalized advertising, credit, or lending decisions;
- Not use Google user data to train, develop, or improve generalized or standalone artificial-intelligence or machine-learning models;
- Not allow humans to read your Google user data unless (a) you have given affirmative consent to view specific messages, (b) it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, (c) the data has been aggregated and anonymized, or (d) it is required for internal operations and the data has been de-identified where reasonably possible.
Because Lynder's Gmail permission is send-only, the Google user data we receive is minimal by construction: the address of the account you connect and the OAuth tokens needed to send messages you approve. Lynder never receives your mailbox content, so the commitments above operate on that minimal data — there is no email content for us (or anyone) to read, transfer, or train on.
See Section 5 for the specific Gmail permissions Lynder requests and how each is used.
4. Information we collect
We collect the following categories of personal information.
4.1 Information you provide
| Data | What it is | Why we collect it |
|---|---|---|
| Account information | Your email address and, where applicable, authentication identifiers from a sign-in provider (e.g., a Google or GitHub sign-in). | To create and secure your account, sign you in, and communicate with you about the Service. |
| Profile and onboarding answers | Your name, target roles, companies you care about, seniority, location and work-authorization preferences, and similar details you enter during onboarding. | To configure the agent and match you to opportunities. |
| Resume and application materials | Any resume, work history, or supporting materials you upload or that the agent generates for you (e.g., tailored resumes and outreach drafts). | So the agent can represent your background accurately and prepare application materials. |
| Outreach content you create or approve | The recipients, subjects, and message bodies of outreach drafts, and your approval of specific messages. | To prepare drafts for your review and to send only the messages you approve. |
| Communications with us | Support requests, feedback, and other messages you send us. | To respond to you and improve the Service. |
4.2 Information from connected accounts (only if you connect them)
You are never required to connect a third-party account. If you choose to, we collect:
- OAuth access and refresh tokens issued by Google (Gmail) and/or GitHub, so the agent can act with your permission. You can revoke these at any time (see Section 8).
- Your connected Gmail address (obtained from Google's standard identity endpoint), used to label the connection in Settings and to set the From header of messages you approve. We do not collect Gmail mailbox content — Lynder's Gmail permission is send-only and cannot read your email. See Section 5.
- GitHub data, where you connect GitHub for its optional features (for example, repository or profile information exposed to our GitHub App per the permissions you grant). GitHub App permissions are governed by the GitHub App configuration you authorize.
4.3 Information we collect automatically
- Usage data — pages and features you use, actions you take (such as approving a draft), and timestamps.
- Device and log data — IP address, browser type, operating system, and similar technical information, and error/diagnostic logs.
- Cookies and similar technologies — used for authentication (keeping you signed in) and for essential Service functionality. We do not use third-party advertising cookies. Where required by law, we will present a cookie/consent choice.
4.4 Payment information
When you subscribe to a paid plan, payments are processed by Stripe. Stripe collects and processes your payment-card and billing details directly under Stripe's Privacy Policy; Lynder does not receive or store your full payment-card number. We receive limited billing metadata (such as your subscription status, plan, the last four digits of your card, and billing country) to manage your subscription.
4.5 Sensitive information
Some information you provide — such as the contents of your resume — may include sensitive personal information. (The contents of your mailbox are never among it: Lynder cannot access them — see Section 5.) We process it only to provide the Service, as described in this Policy, and we do not use it to infer characteristics for advertising or to sell it. See Section 11 for your right to limit the use of sensitive personal information under California law.
We do not intentionally collect special categories of sensitive data (such as health, religious, or political information). Please do not upload such information unless it is necessary and you consent to its processing as part of your materials.
5. How we access your Gmail (Google user data)
If — and only if — you connect your Google account, Lynder requests the following permissions (OAuth scopes). None of them can read your mailbox.
| Google OAuth scope | Google classification | What Lynder does with it |
|---|---|---|
https://www.googleapis.com/auth/gmail.send | Sensitive | Sends outreach messages that you have explicitly approved, from your own Gmail account, so that you are the sender of record. This permission cannot list, read, or search mailbox content — a restriction Google enforces, not just a promise we make. |
openid, email | Non-sensitive | Identifies the address of the account you connected (via Google's standard identity endpoint), so we can label the connection in Settings and set the From header of messages you approve. |
Important facts about Gmail access:
- We send only what you approve. Lynder never sends a message on its own. Every send is triggered by your explicit approval of that specific message. See our Terms of Service — you review and approve each message and are the sender of that message.
- We never read your inbox. Lynder requests no Gmail read permission of any kind and holds no ability to access, list, search, or read your messages or mailbox metadata. Replies to your outreach arrive in your own inbox, where only you see them; reply detection is not a feature of the Service.
- No human at Lynder can read your Gmail content, because Lynder never receives it. The only Google user data we hold is the address of the account you connected and the OAuth tokens that authorize sending. The narrow human-access circumstances described in Section 3 apply to that minimal data.
- AI drafting. When the agent prepares a draft or a follow-up, your profile, resume, and public-signal context may be processed by our AI provider (AWS Bedrock) solely to generate that user-facing output. No mailbox content is ever involved — the Service has none. Google user data processed this way is used only to power the feature, is not used to train generalized AI/ML models, and is handled consistent with the Limited Use requirements in Section 3.
- You can revoke anytime. You can disconnect Gmail inside Lynder or revoke Lynder's access at any time at Google Account permissions. See Section 8.
Before we display Google's consent screen, we present an in-app disclosure describing this access. If we ever change the way we use Google user data, we will update this Policy and re-request your consent.
6. How we use information (purposes)
We use personal information to:
- Provide the Service — create and secure your account; run the job-search agent; monitor public hiring signals; prepare outreach drafts, follow-ups, and application materials; and send outreach you have approved from your connected account.
- Personalize the agent's work to your target roles, companies, and preferences.
- Generate AI output — use AWS Bedrock to draft outreach and materials from your profile, resume, target context, and (where relevant) content of messages you drafted or approved in the Service. (Never from mailbox content — Lynder has none.)
- Process payments and manage subscriptions via Stripe.
- Communicate with you — send service, security, and account messages, and respond to support requests.
- Maintain, secure, and improve the Service — monitor performance, debug, prevent fraud and abuse, and enforce our Terms. (We do not use Google user data to train generalized models; see Section 3.)
- Comply with law and enforce our legal rights.
We do not use your personal information for third-party advertising, and we do not sell it.
7. Where the Service is available (United States only)
The Service is intended only for users located in the United States. We do not target, market to, or knowingly provide the Service to residents of the European Economic Area (EEA), the United Kingdom, or Switzerland. If you are located outside the United States, do not use the Service.
8. Data retention and deletion
We keep personal information only for as long as needed for the purposes in this Policy, then delete or anonymize it. Our criteria and typical periods:
| Data | Retention |
|---|---|
| Account, profile, and agent state | For the life of your account, and deleted within 30 days of account deletion or a verified deletion request, subject to the exceptions below. |
| Resume and generated materials | For the life of your account; deleted with your account, or sooner if you remove them. |
| Gmail/GitHub OAuth tokens | Until you disconnect the account or delete your account, at which point tokens are deleted and, where supported, revoked with the provider. |
| Gmail mailbox content | None is ever accessed or stored. Lynder's Gmail permission is send-only; the Service cannot read your mailbox, so there is no mailbox content to retain. |
| Outreach records (recipients, approval, send receipts) | Retained for the life of your account so you have a record of what you approved and sent. |
| Billing metadata | Retained as required for tax, accounting, and audit purposes (typically up to 7 years). |
| Server and security logs | Retained for 90 days. |
| Backups | Residual copies may persist in encrypted backups for up to 30 days after deletion, then are overwritten. |
How to delete your data. You can delete your account and associated data by emailing info@lynder.ai from the address on your account. On deletion we remove your profile, resume, generated materials, and stored connected-account tokens, and we disconnect linked accounts. Some information may be retained where required by law, to resolve disputes, prevent abuse, or enforce our agreements, and residual copies may persist briefly in backups as described above.
You can also disconnect Gmail or GitHub at any time without deleting your account — this stops the agent from accessing those services and removes the stored tokens.
9. Your rights and choices
Regardless of where you live, you can:
- Access and update your profile and preferences in the Service.
- Request a copy of the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and data (see Section 8).
- Disconnect any linked Gmail or GitHub account at any time.
- Withdraw consent where processing is based on consent.
To exercise any right, email info@lynder.ai from the address on your account. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
10. Users outside the United States
The Service is offered only to users located in the United States (see Section 7). We do not target, market to, or knowingly serve residents of the EEA, the United Kingdom, or Switzerland. Because we do not serve users in those regions, we do not provide GDPR-specific data-subject rights, an EU/UK representative, a Data Protection Officer, or international-transfer mechanisms such as Standard Contractual Clauses. If you are located outside the United States, please do not use the Service.
11. Your California rights (CCPA/CPRA)
This section applies to California residents under the California Consumer Privacy Act, as amended by the CPRA.
Notice at collection — categories of personal information we collect, and the sources, purposes, and disclosures:
| CCPA category | Examples we collect | Business/commercial purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Name, email, account/sign-in IDs, IP address | Provide the Service, secure accounts, communicate | Service providers in Section 6 |
| Customer records | Resume, work history, billing metadata | Run the agent; process payments | Service providers; Stripe |
| Commercial information | Subscription/plan, transaction history | Manage billing | Stripe |
| Internet/network activity | Usage, feature interactions, logs | Operate, secure, and improve the Service | Hosting/infra providers |
| Geolocation (coarse) | Approximate location from IP | Security, localization | Hosting/infra providers |
| Electronic/communications content | Outreach drafts and messages you approve in the Service (never your mailbox content — Lynder cannot read it) | Provide outreach and follow-up drafting; send only what you approve | Google (only when you approve a send), AI provider (AWS Bedrock) |
| Professional/employment information | Roles, seniority, employer history from your resume/profile | Match you to opportunities; prepare materials | Service providers; AI provider |
| Inferences | Preferences derived from your inputs to tailor the agent | Personalize the Service | Service providers; AI provider |
| Sensitive personal information | Contents of your resume | Provide the Service you requested (not used to infer characteristics) | Google (in messages you approve), AI provider |
We collect this information from you, from your connected accounts (with your permission), and automatically as you use the Service.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.
We do not use or disclose sensitive personal information for any purpose other than those permitted under the CCPA/CPRA (namely, to provide the Service you requested and related operational purposes). Because we limit our use of sensitive personal information to these permitted purposes, the "right to limit" does not require any additional action — but you may still request that we restrict it by contacting us.
Your California rights:
- Right to know / access the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties.
- Right to delete personal information we have collected, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information — not applicable, because we do not sell or share it.
- Right to limit the use of sensitive personal information — see above.
- Right to non-discrimination for exercising your rights.
To exercise these rights, email info@lynder.ai. We will verify your identity (typically by confirming control of the account email) before acting. You may use an authorized agent to submit a request on your behalf with proper authorization. We will respond within the timeframes required by the CCPA (generally 45 days, extendable once).
"Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.
12. How we share information — sub-processors
We do not sell or rent your personal information. We share it only with the service providers ("sub-processors") that help us operate the Service, each bound by contract to protect it and use it only to provide services to us:
| Provider | Role | What it may process | Reference |
|---|---|---|---|
| Google LLC | Sign-in and Gmail integration (OAuth; sending outreach you approve — send-only, no mailbox reading) | Google account identifiers; OAuth tokens; the content of messages you approve for sending | Google Privacy Policy |
| Amazon Web Services (AWS) — Bedrock | AI model hosting used to draft outreach and materials | Profile, resume, target context, and (where relevant) the text of messages you drafted or approved in the Service (never mailbox content) | AWS Privacy Notice |
| Stripe, Inc. | Payment processing and subscription billing | Payment-card and billing details (collected by Stripe directly); billing metadata | Stripe Privacy Policy |
| Supabase, Inc. | Managed PostgreSQL database (primary data store) | All stored account, profile, resume, token, and usage data | Supabase Privacy Policy |
| Vercel, Inc. | Application hosting and delivery | Requests, IP/log data, and data in transit | Vercel Privacy Policy |
| GitHub, Inc. | Optional GitHub sign-in / integration features | GitHub account and repository data you authorize | GitHub Privacy Statement |
We may also disclose information: (a) to comply with law or valid legal process; (b) to protect the rights, safety, and security of Lynder, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and any successor will be bound by this Policy or a policy at least as protective.
13. Data security
We use reasonable technical and organizational measures designed to protect personal information, including:
- Encryption in transit (TLS/HTTPS) for data moving between you, Lynder, and our providers, and encryption at rest for stored data via our managed database and hosting providers.
- Restricted access to production systems and personal data on a need-to-know basis, with authentication controls.
- Secure storage of OAuth tokens and secrets, isolated from general application data where practical.
- Logging and monitoring to detect and respond to anomalies and abuse.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and any regulators as required by applicable law.
14. Children's privacy
The Service is intended for adults and is not directed to children. You must be at least 18 years old (or the age of majority in your jurisdiction) to use Lynder — see our Terms of Service. We do not knowingly collect personal information from anyone under 16, and in no case from children under 13 in a manner requiring parental consent under the U.S. Children's Online Privacy Protection Act (COPPA). If we learn that we have collected such information, we will delete it. If you believe a child has provided us personal information, contact info@lynder.ai.
15. Third-party services and links
The Service integrates with and may link to third-party services (such as Google, GitHub, and Stripe). Your use of those services is governed by their terms and privacy policies, not this one. We are not responsible for the privacy practices of third parties. Review their policies before connecting or using them.
16. Changes to this Policy
We may update this Policy as the Service evolves or as law requires. When we make a material change, we will update the "Last updated" date above and, where appropriate, notify you (for example, by email or an in-app notice) and, where required, obtain your consent. Your continued use of the Service after an update takes effect means you accept the revised Policy.
17. Contact us
Questions, requests, or complaints about this Policy or your personal information:
Lynder (a general partnership, California, USA)
Email: info@lynder.ai
We will do our best to resolve your concern.