Privacy, in plain words.
Massif AI Inc · last updated July 2026
Your profile exists for one reason: to apply for jobs on your behalf. Everything below follows from that.
What we collect
- The profile you give us — your resume, work history, the roles and countries you want, and your salary floor.
- A record of what the product did for you — every application sent, where it went, and when.
- Basic account and usage information needed to run the service.
What we use it for
- Finding and ranking jobs against your profile, tailoring applications, and submitting them within the rules you set.
- Checking visa-relevant facts (for example, whether an employer sponsors and whether a salary clears a threshold) before anything is sent.
- Showing you the log of everything sent on your behalf.
What we never do
- We never sell your data.
- We never use your data to train models for third parties.
- We never share your profile with an employer before you say so.
- There is no public profile — nobody can browse you, and applications go only to the specific jobs that match the rules you approved.
Visa cases
When a visa case begins, the documents you provide for it are shared only with the licensed partner handling your case, for the purpose of that case. Massif itself never gives immigration advice and never practices law.
This website
The site you are reading serves everything — pages, fonts, images, video — from its own origin. Visiting it sends no request to Google Fonts or any other third-party font or tracking service.
Connected mailboxes (Google and Microsoft)
An employer can connect their own Gmail or Microsoft 365 mailbox so that messages Massif helps them write go out from their own address and replies land with them. When you connect a mailbox we ask only for permission to send email on your behalf and to see the address of the account you connected. We do not ask for, and cannot read, your inbox, your contacts or your calendar.
What we store is the address and an encrypted authorization token that lets us send from that mailbox. We use it for exactly one purpose: sending messages you compose or approve inside Massif, from your own address. We never use it to read mail, never share it, and never use the data to train models or for advertising. Every send is logged so you can see what went out and when.
You can disconnect at any time from Workspace → Integrations in the product, or by revoking Massif's access at myaccount.google.com/permissions (Google) or account.live.com/consent/Manage (Microsoft). Disconnecting deletes the stored token immediately.
Massif's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI, and your mailbox. Massif's assistant (which helps draft job posts and messages) runs on Anthropic's Claude models through their commercial API, which does not train on customer data. No data from a connected Google or Microsoft mailbox is ever sent to these models or to any other AI/ML service: the connection is send-only, so there is no inbox content to read, and the address and authorization token we store are never used as model input. No Google user data — raw, aggregated or derived — is used to create, train or improve any machine-learning or artificial-intelligence model, whether ours or a third party’s. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
How we protect your data
- Encryption in transit. Every connection to Massif — the website, the app, and every API call — is encrypted with TLS (HTTPS). We make no plain-text connections.
- Encryption at rest. Our databases and backups live on encrypted infrastructure, and the mailbox authorization tokens described above are additionally stored encrypted at the application layer.
- Access control. Access to production systems is restricted to the founders, protected by key-based authentication. Inside the product, every workspace is isolated: role-based permissions govern who on a team can see or change what, and sensitive actions are written to an append-only audit log.
- Data minimisation. We request the narrowest permissions that make a feature work — the mailbox connection above, for example, can send but can never read — and we do not collect data we do not use.
- Retention and deletion. Data is kept only while your account needs it. Disconnecting an integration deletes its token immediately; deleting your account removes your data from the service, as described under Deletion below.
- Incident response. If we ever discover a breach affecting your data, we will notify affected users promptly by email with what happened and what we are doing about it, and notify authorities where the law requires.
- Sensitive data. Identity-verification documents are handled by our licensed verification providers over encrypted connections and are not stored on Massif's own servers; immigration-case documents are shared only with the licensed partner handling the case.
Deletion
Ask for deletion and it is deleted. Email us and we will remove your profile and its data from the service.
Contact
Questions about your data: email the founder. You will get a reply within a day.
This page is a plain-language draft and is under legal review. It states our actual practices; a fuller formal policy will replace it before public launch.
