Privacy policy
Effective date August 6, 2026/Last updated August 12, 2026
Blotter is still in development and is not yet connected to anyone’s Google account. Two things are already true today, and section 3 sets them out in full: if you give us your email address, we store it, and we record how this site is used. Nothing reads your Gmail, Calendar or Sheets, because that connection does not exist yet.
The rest of this policy describes how your information will be handled once the product launches. Details will change as it is built: service providers, storage locations and specific practices may all be revised, and this page will be updated when they are.
01Who this policy is from
This policy explains how Blotter handles information when you connect your Google account and use Blotter to maintain your recruiting tracker.
Blotter is referred to here as “Blotter”, “we” and “us”. You can reach us at blotterib@gmail.com.
02What this policy covers
It covers the Blotter product and this website. It does not cover Google, your email provider, or any other service you connect to or reach through a link, each of which has its own policy.
03What happens today
Blotter is still being built. The connection to Gmail, Calendar and Google Sheets described in the rest of this policy is not active, and nothing has access to your Google account.
Three things do happen now.
If you give us your email address at the end of the sign-up flow, we store it, together with what you told us about what you are recruiting for and your recruiting window, which link you arrived through, and how far through the flow you went. It is stored in our database, run by Supabase in the United States.
We record how this site is used through PostHog, in the United States: pages viewed, which steps of the sign-up flow were reached, your device and browser type, approximate location derived from your IP address, and where you arrived from. Your email address is never attached to this usage data.
If you send us a message using the contact form, we store the message, the address you gave us to reply to, your name if you chose to give one, and which page you were on when you wrote. It is stored in the same database, run by Supabase in the United States, and it is used to answer you and for nothing else.
No payment has been taken from anyone and no card details are collected anywhere on this site.
If you would like the email address you gave us deleted, write to blotterib@gmail.com and we will remove it.
04Information we collect
We collect three kinds of information.
Account information you give us directly: the email address you sign up with, and the information needed to maintain your account and subscription.
Google account information you authorise us to access: Gmail, Google Calendar and Google Sheets, limited to what sections 4 and 5 describe.
Usage information generated when you use the product, such as device and browser type, approximate location derived from an IP address, and the pages and features you use. Blotter uses PostHog for product analytics. Your email address is never sent to analytics.
05What we access in your Google account
The permissions Blotter requests, and the limits on each, are the following.
Gmail
Blotter can:
- Check sender and timing information across incoming mail.
- Read message content only when the sender matches a contact stored in the tracker.
Blotter cannot:
- Send emails.
- Edit emails.
- Process the content of unmatched messages.
Google Calendar
Blotter can:
- Read calendar events to identify scheduled or completed recruiting conversations associated with tracked contacts.
Blotter cannot:
- Create events.
- Edit events.
- Cancel events.
- Respond to events.
Google Sheets
Blotter can:
- Create and maintain the standardized Blotter recruiting view inside the user’s Google Sheets workflow.
Blotter cannot:
- Access unrelated Drive files.
- Modify unrelated files.
- Promise to preserve every arbitrary custom tracker layout exactly.
These are the authorisation scopes Blotter requests, and the wording Google shows for each on its consent screen.
- Gmail
gmail.readonly
Google shows: “View your email messages and settings.” - Google Calendar
calendar.events.readonly
Google shows: “View events on all your calendars.” - Google Sheets
drive.file
Google shows: “See, edit, create, and delete only the specific Google Drive files you use with this app.”
The Gmail scope is the reason Google’s consent screen sounds broader than what Blotter does. Google does not offer a Gmail permission limited to the contacts in your tracker, so the narrower boundary is enforced in Blotter’s own processing, as section 5 describes. The Sheets permission is limited to files you choose or that Blotter creates, which is why Blotter cannot reach the rest of your Drive.
06How Blotter decides what to read
Every message goes through the same check before any of its content is processed.
Blotter checks the sender. Blotter compares the sender’s email address with the contacts stored in your tracker.
Unmatched messages stop there. If the sender is not in your tracker, the message body is never routed into Blotter’s content-processing system.
Matched recruiting messages are processed. If the sender matches, Blotter reads the message to identify the recruiting facts needed to maintain status, timing, and next actions.
Blotter keeps facts, not full messages. Blotter stores the structured recruiting information it needs and does not retain full email bodies.
Why Google’s permission may sound broader. Google may describe the Gmail permission broadly because it does not offer a permission limited only to contacts in your recruiting tracker. Blotter enforces the narrower boundary in its processing system: unmatched messages are never routed for content analysis.
07How we use the information
We use it to operate Blotter: to identify recruiting activity involving the contacts in your tracker, to maintain the status, timing, scheduled calls and next actions in your Google Sheet, to run your account and subscription, to provide support, and to keep the service working and secure.
We do not use your Google account data to build advertising profiles, and we do not sell personal data.
Blotter’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
08What we keep
Blotter keeps only the structured recruiting facts needed to maintain your tracker—for example, sender, interaction time, reply state, scheduled-call information, and next-action status.
Full email bodies are processed only for matched recruiting messages and are not retained.
Calendar events are used to identify recruiting calls and coffee chats associated with tracked contacts. Blotter does not write to your calendar.
We keep this information for as long as your account exists, because it is what keeps your tracker current. We do not keep it afterwards. When you delete your Blotter account, the recruiting information associated with it is deleted.
09What we do not do
- Blotter does not send emails
- Blotter does not write to your calendar
- Blotter does not access Google Contacts
- Blotter does not access unrelated Google Drive files
- Blotter does not sell your data
- Blotter does not store full email bodies
- Blotter does not process the content of unmatched personal email
- You can disconnect your accounts at any time
- Deleting your account permanently deletes your Blotter data
10Google connection provider
Blotter connects to Google through an established connection provider whose Google application has passed Google’s CASA security assessment. The provider and its exact role will be disclosed in the privacy policy and connection flow.
That provider facilitates the connection between Blotter and Google. Blotter’s own processing rules determine which messages are analyzed and what information is retained.
We also rely on a small number of service providers to run Blotter: Supabase for hosting and database storage, PostHog for product analytics, and Stripe for payments. Stripe handles card details directly; Blotter never receives or stores them. Where each provider processes data is set out in section 12.
We do not sell your data. We may disclose information if we are legally required to, or to protect the rights and safety of users and the public.
11Your choices
You can disconnect your Google accounts at any time. When you delete your Blotter account, the connection is revoked and your Blotter data is permanently deleted.
You can also revoke Blotter’s access directly from your Google account security settings at any time, independently of Blotter.
You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it, and we will. Depending on where you live you may also have rights under local privacy law to object to or restrict some processing; contact us and we will honour them.
12Keeping information safe
We use technical and organisational measures intended to protect the information we hold, and we rely on established providers that maintain their own security programmes. No service can promise perfect security.
Blotter itself holds no security certification or third-party audit. The work that most needs one is not done by us: the connection to your Google account is handled by a specialist provider whose entire business is building and securing these integrations, whose Google application has passed Google’s CASA security assessment, and who is verified by Google for the permissions Blotter requests. The services that store and process information on our behalf maintain their own security programmes and independent assessments.
13Where information is processed
Your information is stored and processed in the United States. Blotter does not operate outside the United States, and we do not transfer your information elsewhere.
14Age
Blotter is built for university students and graduates recruiting for finance roles. You must be 18 or older to hold a Blotter account, and we do not knowingly collect information from anyone under 18.
15Changes to this policy
Blotter is still being built, so this policy will change as it is: providers, storage locations and specific practices may all be revised. We will update this page when they are, and the date at the top will always show when the current version took effect. If a change materially affects how we handle your information, we will tell account holders by email before it takes effect.
16Contact
Questions about this policy or your data can be sent to blotterib@gmail.com.
17Common questions
Why does Google ask for broad Gmail access?
Google does not offer a Gmail permission limited only to the contacts in your tracker. Blotter applies that narrower boundary in its own processing system. Unmatched messages are never routed for content analysis.
Does Blotter read personal emails?
No. Blotter checks sender information to find messages from contacts stored in your tracker. If the sender does not match, the message body is not processed.
Does Blotter store my emails?
Blotter does not retain full email bodies. It stores only the structured recruiting facts needed to maintain your tracker.
Can Blotter send emails or change my calendar?
No. Blotter does not request email-send permission and does not write to your calendar.
Does Blotter sell my data?
No. Blotter does not sell personal data.
What happens when I delete my account?
Your Google connections are revoked and the data associated with your Blotter account is permanently deleted.
Does a third party process my data?
Blotter uses a third-party provider to connect with Google. The provider and its exact role will be disclosed in the privacy policy and connection flow.