Privacy Policy

Last updated: July 4, 2025

1. Introduction

Welcome to MatchStix (the "Service", "App", "we", "us", "our"). This Service is operated by Agentic Enterprises Inc d/b/a MatchStix located at 1 Broadway, Cambridge, MA 02142, United States.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application. It specifically details our practices regarding data accessed from Google APIs. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access or use the Service.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any significant changes by updating the "Last Updated" date of this Privacy Policy and, where required by applicable law or Google's policies, by notifying you directly and obtaining renewed consent. You are encouraged to periodically review this Privacy Policy to stay informed of updates. You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the changes in any revised Privacy Policy by your continued use of the Service after the date such revised Privacy Policy is posted.

MatchStix's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

2. Information We Collect

We may collect information about you in a variety of ways. The information we may collect via the App includes:

A. Personal Data

Personally identifiable information, such as your name, email address, phone number, professional information, and account credentials that you voluntarily give to us when you register with the Service or when you choose to participate in various activities related to the Service, such as creating profiles and using our communication features.

B. Google User Data

When you choose to sign in with Google or connect your Google account to our Service, we may collect and process the following Google user data, strictly in accordance with the permissions you grant through Google's authorization process:

  • Your Google account email address and basic profile information (name, profile picture) for authentication and account creation.
  • Your Google email messages (read-only): Accessed via the https://www.googleapis.com/auth/gmail.readonly scope.
  • Your ability to create, read, update, and delete drafts, and send messages and drafts from your Google account: Accessed via the https://www.googleapis.com/auth/gmail.compose scope.
  • Your Google Contacts (read-only): Accessed via the https://www.googleapis.com/auth/contacts.readonly scope.

Important: We only access Google user data that you explicitly authorize through Google's consent screen. We use this data solely for the specific purposes detailed in Section 3, "How We Use Your Information," to provide and improve our Service's core functionality, including account creation, authentication, email aggregation, the ability to send emails on your behalf, professional network identification, and sentiment analysis. We do not use Google user data for advertising, selling to data brokers, creating user profiles for external purposes, or any purposes unrelated to our Service's core functionality.

C. Usage Data

Information our servers automatically collect when you access the Service, such as your IP address, browser type, operating system, access times, the pages you have viewed directly before and after accessing the Service, and other actions taken within the application.

D. Device Data

Information about the computer or device you use to access the Service, including the device model, operating system and version, browser type, and IP address.

E. Data From Third Parties

We may receive information about you from other sources, such as public databases, social media platforms, and third-party login services like Google, LinkedIn Sign-In if you connect those services to our App.

F. Cookies and Tracking Technologies

We may use cookies, web beacons, tracking pixels, and other tracking technologies on the Service to help customize the Service and improve your experience.

3. How We Use Your Information

Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience for career management. Specifically, we may use information collected about you via the Service to:

  • Create and manage your account.
  • Provide, operate, and maintain the Service.
  • Improve, personalize, and expand the Service.
  • Process your transactions.
  • Send you technical notices, updates, security alerts, and support messages.
  • Respond to your comments, questions, and customer service requests.
  • Communicate with you about products, services, offers, promotions, and events offered by MatchStix and others.
  • Monitor and analyze trends, usage, and activities in connection with our Service.
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities and protect the rights and property of MatchStix and others.
  • Comply with legal and regulatory requirements.
  • Help you connect with potential employers, optimize your job search experience, and track your professional communications.

How We Use Google User Data

We use Google user data exclusively for providing and improving our Service's core career management functionality. Specifically, we use Google user data for the following prominent, user-facing features:

  • Authentication and Account Creation: To verify your identity and streamline the sign-up and login process using your Google account email and profile information.
  • Email Aggregation: We access your Gmail email content (read-only) to consolidate messages from different email accounts within your MatchStix career management dashboard. This provides you with a unified view of all your job-related communications, helping you track applications, interviews, and follow-ups effectively.
  • Sending Emails on Your Behalf: We enable you to create and send emails directly from your connected Gmail account through the MatchStix platform. This feature streamlines your job application outreach, follow-ups, and professional communications by allowing you to manage and send messages without leaving our Service. This functionality requires access to compose and send emails from your Gmail account.
  • Contact Pulling for Professional Networking: We access your Google Contacts (read-only) to help you identify individuals in your professional network who may be relevant to your job search. This enables features like suggesting potential referrals, identifying common connections, and streamlining outreach within your career management process.
  • Sentiment Analysis of Email Communications: We analyze the sentiment (like positive, negative, neutral) of email responses related to your job applications. This provides you with insights into communication effectiveness and helps you track the tone of your outreach efforts. This analysis is automated and performed on aggregated, anonymized data whenever possible. We will NEVER allow humans to read your individual email content for this purpose unless you provide explicit, documented consent for a specific, legitimate reason (like direct support, debugging an issue you report), which will be clearly communicated to you at that time.
  • Personalized Features and User Experience: To tailor your experience within the app based on your connected Google data, enhancing the relevance and efficiency of our career management tools.

We do not use Google user data for: advertising purposes (including retargeting, personalized, or interest-based ads), selling to third parties, creating profiles for marketing, training AI models unrelated to our Service's core functionality, or any purpose other than providing and improving our Service's explicit core functionality as described above.

4. How We Share Your Information

We may share information we have collected about you in certain situations. Your information may be disclosed as follows:

  • By Law or to Protect Rights: If we believe the release of information about you is necessary to respond to legal process like a court order or subpoena, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of MatchStix, our users, or others, we may share your information as permitted or required by any applicable law, rule, or regulation.
  • Third-Party Service Providers: We may share your information with third parties that perform services for us or on our behalf, including secure cloud hosting, database management, email delivery, customer support, and analytics. These service providers are authorized to use your personal information only as necessary to provide these services to us and are contractually obligated to protect your information in a manner consistent with this Privacy Policy and applicable data protection laws. For example, we use AWS for secure data storage and Pixel tracking for usage analytics.
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. In such cases, the acquiring entity will be bound by this Privacy Policy or a substantially similar privacy policy that provides equivalent protection for your data.
  • With Your Explicit Consent: We may disclose your personal information for any other purpose with your explicit consent.
  • Aggregated or Anonymized Data: We may share aggregated or anonymized information that does not directly identify you, for research, analysis, and product improvement purposes.

Google User Data Sharing

We do not sell, rent, or trade Google user data to third parties. We do not use or transfer Google user data to AI models for training beyond the explicitly stated functionality of sentiment analysis within our core service. We may share Google user data only in the following extremely limited circumstances, strictly for purposes directly related to providing and improving our core Service functionality:

  • With your explicit consent.
  • With service providers who assist in providing our Service, and only to the extent necessary for them to perform their services (these providers are contractually obligated to protect your data, comply with Google's API Services User Data Policy, and use it only for authorized purposes).
  • When required by law or to protect rights, property, or safety, such as responding to valid legal process.
  • In connection with a business transfer, where the acquiring entity agrees to honor this Privacy Policy and Google's API Services User Data Policy.

We do not share Google user data for advertising, marketing by third parties, creating user profiles for external purposes, or any use unrelated to our Service's core functionality.

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies (like pixels) to access or store information, improve your experience, and analyze Service usage. You can typically set your browser to remove or reject browser cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of our Service.

6. Data Security

We are committed to protecting your personal information, including Google user data. We use administrative, technical, and physical security measures to help safeguard the data we collect. Our security measures include:

  • Encryption of data both in transit using SSL/TLS and at rest (in our databases and storage systems).
  • Regular security audits, vulnerability scanning, and monitoring for unauthorized access.
  • Strict access controls and authentication requirements for employees and authorized personnel.
  • Secure development practices, including regular code reviews and penetration testing.
  • Comprehensive employee training on data protection, privacy best practices, and our internal security policies.
  • Implementation of Google's security guidelines for applications accessing sensitive user data, including specific requirements for apps handling Restricted Scope data.

While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse. Any information disclosed online is vulnerable to interception and misuse by unauthorized parties. Therefore, we cannot guarantee complete security if you provide personal information.

7. Data Retention and Deletion

We will retain your personal information, including Google user data, only for as long as is necessary for the purposes set out in this Privacy Policy to provide our Service, or as required by law. We will retain and use your information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Data Retention Periods:

  • Account information: Retained while your account is active and for a reasonable period typically up to 180 days after account closure to facilitate re-activation or for legal compliance.
  • Google user data (emails, contacts): Retained only as long as necessary to provide the specific Service features you utilize for email aggregation, sending emails, contacts for professional network identification or as required by law. Once you disconnect your Google account or delete your MatchStix account, this data will be securely deleted from our systems within 30 days.
  • Usage data: Generally retained for a shorter period, except when used to strengthen security, analyze long-term trends, or improve functionality.
  • Communication records: Retained according to legal requirements and business needs.

Data Deletion:

When the retention period expires for a given type of data, we will securely delete or destroy it. You may request deletion of your data, including all Google user data associated with your account, by contacting us using the information provided below. We will respond to deletion requests in accordance with applicable law and Google's policies within 30 days.

8. Your Privacy Rights

Depending on your location (California, Virginia, Colorado, Utah, Connecticut, or other US states with specific privacy laws, or international regions like the EEA, UK) you may have certain rights regarding your personal information. These rights may include:

  • The right to access: You have the right to request copies of your personal data we hold about you.
  • The right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • The right to erasure ("right to be forgotten"): You have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • The right to object to processing: You have the right to object to our processing of your personal data, under certain conditions.
  • The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
  • The right to opt-out: You may have the right to opt-out of certain data uses, such as marketing communications or the sale/sharing of your personal information (where applicable).

Google Data Access and Revocation

You can manage or revoke MatchStix's access to your Google data at any time directly through your Google Account security settings (at https://myaccount.google.com/permissions) or within your MatchStix account settings under Settings > Connected Accounts. Revoking access will prevent MatchStix from collecting new data from your Google account, and your existing Google data will be deleted as per our data retention policy.

To exercise these rights, please contact us using the contact information provided below. You may also be able to access and update some of your information directly through your account settings. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before processing your request.

9. Children's Privacy

Our Service is not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we become aware that we have collected personal information from a child under the relevant age without verification of parental consent, we take steps to remove that information from our servers.

10. International Data Transfers

Your information, including personal data and Google user data, will primarily be stored and processed on servers located in the United States. However, due to the global nature of the internet and certain service providers, your information may be transferred to — and maintained on — computers located outside of your state, province, or country, where the data protection laws may differ from those in your jurisdiction.

If you are located outside the United States and choose to provide information to us, please note that by using our Service, you consent to the transfer of your data, including Personal Data, to the United States and its processing there. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable law, including implementing appropriate safeguards such as standard contractual clauses or relying on adequacy decisions where applicable, for any transfers outside the US.

11. Contact Us

If you have questions or comments about this Privacy Policy or our data practices, please contact us at:

Agentic Enterprises Inc d/b/a MatchStix
1 Broadway
Cambridge, MA 02142
United States
Email: privacy@thematchstix.com