legal / privacy

Privacy Policy

Effective date: August 10, 2026

01Overview

US Staffing Agent (“we”, “us”, “our”) provides a recruiting operating system for US staffing firms. This policy covers the marketing site at usstaffingagent.com, the application at app.usstaffingagent.com, our browser extension, and the APIs behind them (together, the “Service”).

It explains what we collect, why, how it is protected, and how to delete it — with a dedicated section on data we access from Google and Microsoft accounts your team connects. In short: your data is used to run the recruiting features you and your organization ask for, and for nothing else. We do not sell personal information and we do not use it for advertising.

02Information We Collect

  • Account data. Name, work email address, role, and organization for each user your company invites, plus authentication records (hashed passwords, session and sign-in logs).
  • Demo requests. If you submit the “Book a Live Demo” form on our marketing site: your name, work email, and company.
  • Consultant and candidate data. Profiles your organization creates or uploads to run placements: resumes, skills, work history, work-authorization status, contact details, and — only where your organization enters it for placement paperwork — government identifiers, which are encrypted at rest and never shown in list views.
  • Mailbox data. Email data from Google and/or Microsoft accounts a user explicitly connects, described in sections 03 and 04.
  • Job and vendor data. Job requirements collected from job boards via our browser extension (section 07) and from vendor emails in connected mailboxes, plus vendor contact information derived from them.
  • Usage and log data. Application activity and security logs, including IP addresses used for rate limiting and abuse prevention.
  • Cookies. We use session cookies strictly for authentication. We do not use advertising or cross-site tracking cookies.

03Google User Data (Gmail)

A recruiter or consultant may connect a Gmail / Google Workspace mailbox to the Service through Google’s OAuth consent flow. We request the minimum scopes the features need:

  • gmail.readonly — to display the connected mailbox inside the app, detect replies and interview requests to applications we sent, and identify job requirement emails from vendors so they can be turned into structured requirements and submissions.
  • gmail.send — to send job applications and related outreach that a recruiter composes or approves, from the connected user’s own address.

We never ask for broader mailbox control (no delete, no settings, no contacts scopes). OAuth access and refresh tokens are stored encrypted (AES-256-GCM) and are never exposed in the interface or API responses.

google api limited use disclosure

US Staffing Agent’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In line with Limited Use, for all Google user data we commit to:

  • using it only to provide and improve the user-facing features described above — inbox display, reply tracking, requirement extraction, and sending approved applications;
  • never selling it, never using it for advertising, and never using it to determine creditworthiness or for lending;
  • never transferring it to third parties except the subprocessors needed to operate those same features (section 08), with your consent, for security or abuse investigation, to comply with applicable law, or as part of a merger or acquisition that keeps these commitments;
  • no human access — our staff do not read Google user data unless you or your organization ask us to for support, it is necessary for security purposes, it is required by law, or the data has been aggregated and anonymized for internal operations;
  • never using it to develop, improve, or train generalized AI or machine learning models (see section 06).

You can disconnect a mailbox in the app at any time, which deletes its stored tokens, or revoke our access from your Google Account permissions page.

04Microsoft 365 User Data (Outlook)

Users may alternatively connect a Microsoft 365 / Outlook mailbox via Microsoft’s consent flow (our Microsoft application registration is publisher-verified). We request Mail.ReadWrite and Mail.Send through the Microsoft Graph API, and use them for the same features described in section 03: showing the connected inbox, tracking replies, extracting vendor requirements, keeping read/folder state in sync, and sending recruiter-approved applications. All commitments in this policy — encryption of tokens, no advertising use, no selling, no training of generalized AI models, deletion on disconnect — apply equally to Microsoft user data. You can revoke access anytime from your Microsoft account’s app permissions or through your Microsoft 365 administrator.

05How We Use Information

  • Operate the Service: matching consultants to requirements, preparing and sending submissions, tracking replies and interviews, dashboards and analytics for your organization.
  • Authenticate users and secure the Service, including rate limiting, audit logs, and abuse prevention.
  • Respond to demo requests and support inquiries.
  • Meet legal, tax, and compliance obligations that apply to staffing workflows.

We do not use your data for advertising, and we do not sell or rent personal information to anyone.

06AI Processing Disclosure

Some features use large language models to do their job — for example classifying whether an email is a job requirement, extracting structured fields (role, rate, location, skills) from a vendor email, or drafting an application for recruiter review.

  • Content is sent to an AI provider only for real-time processing of that specific feature, and only the minimum content needed.
  • Your data — including anything derived from Gmail or Microsoft 365 — is never used to train our own or any third party’s generalized AI models. We use these providers under API terms and settings that prohibit training on submitted content.
  • Depending on your organization’s configuration, AI processing is performed by Google (Gemini API), OpenAI, or model providers routed through OpenRouter (section 08).
  • AI output is always attached to a user-facing feature — nothing is profiled or scored in the background for unrelated purposes.

07Browser Extension

The US Staffing Agent Companion extension collects job postings from job-board and applicant-tracking pages a signed-in recruiter visits (for example LinkedIn, Dice, Indeed, Monster) and sends them to your organization’s workspace so they can be matched against your bench. It does not read email and does not collect your general browsing history: page content is collected only from job postings, and it is transmitted only to our Service.

08Sharing & Subprocessors

We share data only with the infrastructure and processing providers required to run the Service, under agreements that limit their use of it to providing the service to us:

  • DigitalOcean — cloud hosting and storage (United States).
  • Google (Gemini API), OpenAI, OpenRouter — real-time AI processing as described in section 06, configured to prohibit training on your content.
  • Google (Gmail API) and Microsoft (Graph API) — to read and send mail for mailboxes your users connect.
  • IPinfo — IP-address geolocation and company lookup, used for example to identify the company behind an email open in tracking views. Only the IP address is shared; never email content or profile data.

Beyond that, we disclose data only with your direction or consent, to comply with a valid legal request, to protect the Service against fraud or abuse, or as part of a merger or acquisition bound by this policy. We do not sell personal information and do not share it for cross-context behavioral advertising.

09Data Security

  • All traffic to the Service is encrypted in transit with TLS.
  • OAuth tokens, mailbox credentials, and government identifiers are encrypted at rest with AES-256-GCM; other data lives in access-controlled databases.
  • Every organization’s data is isolated with deny-by-default scoping enforced at the application and database layers, so one customer’s data is never visible to another.
  • Role-based access inside your organization limits what each user can see; sensitive fields (like government identifiers) are excluded from list views and admin tooling by design.
  • Backups and production systems are access-restricted to authorized personnel.

10Data Retention & Deletion

  • We keep data for as long as your organization’s account is active, subject to retention windows your organization configures for email-derived data.
  • Disconnecting a mailbox immediately deletes its stored OAuth tokens and stops all further access; your organization can also choose to purge the mailbox data already synced.
  • Account deletion. On a verified request from your organization, we delete associated personal data from active systems within 30 days; encrypted backups age out on a rolling schedule after that.
  • You can request deletion of your personal data at any time at hello@usstaffingagent.com.

11Your Rights & Controls

  • Access, correct, export, or delete your personal data — through your organization’s administrator or by contacting us directly.
  • Revoke Google access at myaccount.google.com/permissions and Microsoft access from your Microsoft account’s app permissions — in both cases our stored tokens stop working immediately. Data already synced before revocation remains subject to the deletion rights in section 10.
  • Depending on where you live (for example California or the EU/UK), you may have additional statutory rights; we honor verified requests under those laws.

12Children

The Service is built for staffing businesses and is not directed to anyone under 18. We do not knowingly collect data from children.

13International Users

The Service is operated from the United States and data is stored on US infrastructure. If you use the Service from elsewhere, you consent to processing in the United States.

14Changes to This Policy

If we make material changes, we will update the effective date above and notify account administrators before the changes take effect. Prior versions are available on request.

15Contact

Questions, privacy requests, or complaints: hello@usstaffingagent.com. We respond within one business day.