Privacy Policy
Last updated: 2026-08-27
What we store
- Your name, email, and profile photo (from Google or email sign-in).
- An encrypted copy of your Upwork OAuth tokens (AES-256-GCM).
- Your saved searches and the parameters you configure.
- A snapshot of every job we considered for you and every proposal we drafted — kept indefinitely for audit purposes. We also record when you report a proposal as sent and, separately, when we confirm that against your Upwork account.
- Notification channel targets you add (a Telegram chat id, a Slack webhook URL, an email address, or your own webhook URL).
- Stripe customer ID and subscription status. We never see your card.
What we don't store
- Your Google or Upwork passwords.
- Payment-card details (handled entirely by Stripe).
- The contents of your private Upwork messages.
How we use your data
Strictly to operate the Service: poll Upwork's official, read-only API on your behalf, draft proposals via the Anthropic Claude API, confirm proposals you report as sent against your Upwork account, and deliver notifications to the channels you configure. Upwork's public API has no mutation for submitting a proposal, applying to a job, or spending Connects — we never submit anything on your behalf, at any point. We do not sell or share your data with third parties for advertising or analytics beyond what's required to deliver these functions.
Subprocessors
- Stripe — billing.
- Anthropic — proposal drafting (Claude API).
- Upwork — job feed, profile, and reconciling proposals you sent.
- Google — sign-in (OAuth only).
- Telegram / Slack / your email provider — only for channels you enable.
Your rights
Email rajib@inicreatechnologies.com to request data export or full account deletion. We delete account data within 30 days of a deletion request.
Security
All Upwork access and refresh tokens are encrypted at rest with application-level AES-256-GCM. The encryption key is stored separately from the database.