§privacy
Your search is not the product.
nexste exists to help you run a job hunt cleanly. It does not exist to mine your inbox, train models on your resume, or sell your job-search anxiety to a data broker.
Last updated · August 14, 2026
What we collect
The minimum needed to run the product: an account (email, hashed password, handle), the workspace records you create (jobs, briefs, resumes, notes), provider configuration you connect (OAuth refresh tokens, encrypted at rest), and billing state if you upgrade.
The Chrome extension stores local connection state and preferences. After you connect your account, it may send lightweight role metadata (such as URL, title, company, and source labels) to check whether a job is already in your workspace. Full job-posting content is sent only when you choose to import or rank that role, or when you turn on auto-import for known job pages.
On Gmail, the extension can show pending recruiter and application replies already linked to your nexste jobs. It uses only the visible account, thread, and composer state needed to open the matching reply, prevent account mistakes, and avoid silently overwriting text. If navigation is required, a short-lived, account-, thread-, and pending-response-bound handoff may be kept in Chrome session storage; it expires and is removed after use. The generated reply is not persisted in extension storage, and the extension does not scan or persist unrelated Gmail message bodies.
Why we collect it
So your search persists between sessions and devices. So your inbox can be matched to roles. So your resume variants can be tied to the jobs they were tailored for. So model providers can parse, rank, classify, and draft the product output you ask nexste to create, including a recruiter reply you request. Nothing else.
Connected email and calendar access
When you connect Gmail or Outlook, nexste requests read-only API access to message metadata and bodies. It scans bounded time windows to detect application and recruiter threads and link them to roles. Selected thread content can be sent to our model providers so nexste can classify job-search messages, match them to jobs, and generate a reply when you request one.
The Chrome extension can insert a generated reply into the matching Gmail composer only after you choose the pending item and explicitly request insertion. This is a local browser action, not a Gmail API write: nexste does not request Gmail compose, modify, or send scopes. Gmail may autosave the inserted composer text as a draft. nexste never clicks Send, sends mail, deletes, archives, or labels a message; you review the account, recipients, and text, and you decide whether to send it. Inbox content is never used for advertising, resale, credit decisions, or general model training.
When you connect Google Calendar or Outlook Calendar, nexste requests read-only access to calendar and event details so interviews, recruiter meetings, and prep reminders can appear in your workspace. We never create, edit, cancel, or respond to calendar events on your behalf.
What we share
Nothing with advertisers. Nothing with data brokers. We use Stripe for payments, infrastructure providers for hosting/storage/database work, email and anti-abuse providers for support and account operations, and model providers for parsing, ranking, tailoring, inbox classification, and replies you request. Those providers process data only to operate nexste and not for general model training.
Limited Use
nexste's handling of user data adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. nexste's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. nexste's use and transfer of information received from Google Workspace APIs also adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
Your rights
You can request an export, request account deletion, or disconnect providers from your settings page. Deletion is real — requests may be held briefly for account-safety and recovery windows, and we don't keep shadow analytics copies after deletion is completed.
Contact
Privacy questions, data requests, or concerns: write to our contact form with the subject Privacy or email [email protected]. We'll get back inside two business days.