Legal
Privacy Policy
Last updated: July 15, 2026
PandaSends (“PandaSends,” “we,” “us,” or “our”) helps high school students discover research mentors and prepare thoughtful, personalized outreach emails. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using PandaSends, you agree to the practices described here.
1. Information we collect
We collect only what is needed to run the service:
- Account information from Google Sign-In: your name, email address, and basic profile information.
- Content you provide: your resume, profile details, research interests, and any text you enter for email drafts.
- Outreach data: the professors you save, drafts you generate, approvals you make, and tracker entries.
- Gmail authorization and sending: When you connect Gmail, PandaSends receives OAuth authorization credentials and related authorization metadata. PandaSends uses the Gmail API only to send the specific outgoing message that you have reviewed and explicitly approved. PandaSends does not retrieve existing mailbox contents and does not create, read, modify, or delete Gmail Draft resources, existing messages, labels, contacts, attachments, or settings.
- Technical data: basic logs needed to operate and secure the service.
2. How we use your information
- To discover professors from public sources and match them to your background.
- To generate personalized email drafts grounded in the resume and details you provide.
- To send only the individual emails you explicitly review and approve within PandaSends.
- To save your progress, drafts, and outreach history to your account.
- To operate, secure, and improve the service.
3. Google user data and Limited Use
PandaSends's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Read the Google API Services User Data Policy.
Specifically, regarding Gmail and Google account data:
- We request Gmail send access only and use it solely to send an individual email after you review, approve, and confirm that message within PandaSends.
- We do not retrieve, display, or send Gmail message bodies, OAuth tokens, Gmail message IDs, or Gmail API responses to AI providers.
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We do not use Google user data to train generalized or non-personalized AI/ML models.
- We only share Google user data as needed to provide and secure the service, to comply with law, or with your consent.
- Humans do not read your Gmail data except where you give explicit consent for support, where required for security or to comply with law, or in aggregated/anonymized form.
4. AI processing
OpenAI may receive resume text or an uploaded resume document, student profile fields, generated template text, research interests, and public professor information to parse resumes, personalize drafts, or assist professor discovery. Because Google Sign-In can prefill the student profile, these profile fields may include the user’s Google-provided name and email address. Groq receives professor identity, institution, and public faculty-page or search content only for public professor email research. We do not send Gmail mailbox content, OAuth tokens, Gmail message IDs, thread IDs, or Gmail API responses to any AI provider.
5. Service providers
We rely on a small set of providers that process data on our behalf:
- Google — account sign-in and sending individually approved emails from your Gmail account.
- Supabase (PostgreSQL) — secure database storage for your account data.
- OpenAI — resume understanding, draft personalization, and professor research assistance when enabled.
- Groq — public professor email research assistance when enabled.
- Hosting and infrastructure providers used to run the application.
These providers are bound to use your data only to provide their services to us.
6. Data storage and security
Account profiles, extracted resume fields, drafts, tracker records, and Gmail authorization metadata are stored in a managed PostgreSQL database. The active authentication implementation does not write Gmail OAuth access or refresh tokens to PandaSends database tables. Tokens are held in an encrypted, HTTP-only NextAuth session cookie and are decrypted only by authenticated server routes that call Gmail. Database and hosting providers also apply their infrastructure security controls. No system is perfectly secure, but we take reasonable measures to protect your information.
7. Data retention and deletion
We retain account data while your account is active. The uploaded resume file is stored in your browser and can be removed immediately from the Resume page; extracted profile fields remain until you edit them or request account deletion. Deleting a PandaSends draft removes the PandaSends database copy. You can revoke Gmail access from your Google Account permissions page. To request full deletion of your account data, contact us using the email below.
8. Students and minors
PandaSends is designed for high school students. It is not directed to children under 13, and we do not knowingly collect data from children under 13. If you are under 18, please use PandaSends with the involvement of a parent or guardian. If you believe a child under 13 has provided us data, contact us and we will delete it.
9. Your choices and rights
- View and edit your profile, resume file, claims, drafts, and outreach settings in the application.
- Sign out of PandaSends to end the local session.
- Revoke PandaSends’s access from your Google Account permissions page.
- Contact Support@pandasends.com to request deletion of account data. Deletion timing and backup expiration depend on the active hosting and database provider configuration.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Continued use of PandaSends after changes means you accept the updated policy.
11. Contact us
Questions about this policy, or a data deletion request? Email Support@pandasends.com.