🔒 Legal Documents

Privacy Policy

How Mvungi collects, uses, and protects your personal information — including AI features, Gmail integration, and your data rights.

📅 Last updated: May 2026 🏢 Mvungi Masters · BRN-M7SRLJG 📍 Blantyre, Malawi
📋

About This Policy

Who we are and what this document covers

This Privacy Policy explains how Mvungi Masters (trading as Mvungi Job Masters, Registration Number BRN-M7SRLJG, "we," "us," or "our"), based in Blantyre, Malawi, collects, uses, shares, and protects your personal information when you use the Mvungi platform (the "Service").

Mvungi Job Masters is an AI-powered job application platform that helps job seekers in Malawi find and automatically apply for relevant job opportunities — including generating tailored CVs and cover letters and, optionally, sending applications directly from the user's own Gmail account.

ℹ️
By accessing or using the Service, you confirm you have read and agree to this Privacy Policy. If you do not agree, please do not use our platform. This policy should be read alongside our Terms of Service.
🗄️

1. Information We Collect

What personal data Mvungi collects and why

1.1 Information You Provide Directly

CategoryExamplesWho
Identity & ContactFull name, email address, phone number, physical addressAll users
Professional ProfileCV, work history, education level, qualifications, skills, job preferencesJob seekers
Uploaded DocumentsCV files (PDF/DOCX), qualification certificates, supporting documentsJob seekers
Gmail Integration DataGmail address, OAuth access token, refresh tokenJob seekers (optional)
Account CredentialsUsername, hashed password, subscription planAll users
Business InformationCompany name, registration number, job postingsEmployers, Consultants

1.2 Automatically Collected Data

  • IP address, browser type, device type, and operating system
  • Pages visited, features used, session duration, and access times
  • Referral source and navigation path through the platform

1.3 Data From Third Parties

  • Google OAuth: If you sign in with Google or connect your Gmail, we receive your email address, name, and profile picture from Google — and, if you grant the gmail.send scope, OAuth tokens to send emails on your behalf
  • Payment processors: Transaction confirmation and subscription status — we do not store raw card or mobile money details

1.4 Sensitive Data

We do not intentionally collect sensitive personal data (such as health information, religion, or political views). If you voluntarily include such information in your CV, it is processed only to the extent necessary to deliver the Service.

⚙️

2. How We Use Your Information

The purposes for which your data is processed

2.1 Core Service Delivery

  • Creating and managing your account and profile
  • AI-powered matching of your profile to suitable job vacancies
  • Generating tailored cover letters and ATS-optimized CVs on your behalf
  • Automatically submitting job applications to matched employers
  • Sending job application emails via your connected Gmail account, if you have authorized this
  • Displaying consultant profiles to prospective clients and employers

2.2 Gmail Data — Strict Limited Use

🔒 Gmail API — Limited Use Statement

We request the gmail.send scope solely to send job application emails on behalf of users who have explicitly authorized access to their Gmail account. This data is used exclusively as follows:

  • To compose and send job application emails to employers and recruiters selected through our platform
  • Nothing else — absolutely no other use of Gmail data occurs

Our use of information received from Google APIs complies fully with the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • Gmail data is not used to develop, improve, or train generalized AI or machine learning models
  • Gmail data is not used for advertising or marketing purposes of any kind
  • Gmail data is not transferred to or shared with any third party for any purpose
  • Gmail data is not sold under any circumstances
  • A more limited scope is not sufficient because our service requires sending application emails directly from the user's authenticated Gmail account so employers can identify and reply to the applicant

2.3 Platform Improvement

  • Training and improving our AI matching models using anonymized data only — individual identifiable data is never used for model training
  • Fraud detection, security monitoring, and abuse prevention
  • Aggregated analytics to improve the user experience

2.4 Communications

  • Always sent: Service updates, application status notifications, security alerts
  • Opt-out available: Platform news and feature announcements
  • Opt-in only: Marketing communications and promotional content

2.5 Legal Compliance

To comply with applicable Malawian laws and regulations, including data protection requirements, and to respond to lawful requests from public authorities.

🔗

3. Sharing & Disclosure

Who we share your information with and why

3.1 With Employers

When we submit a job application on your behalf, we share the application materials with the relevant employer — including your name, email address, CV, generated cover letter, qualification certificates, and any other supporting documents you have uploaded. You are copied on all application emails.

3.2 With Trusted Service Providers

We share data with carefully selected third-party providers who help us deliver the Service, including cloud hosting, AI processing (OpenAI), email delivery, and payment processors. All providers are bound by strict confidentiality agreements and are prohibited from using your data for any purpose other than delivering services to us.

3.3 Google Gmail API

🔐 Google API Data — What We Share and What We Do Not

When you connect your Gmail account, our interaction with Google's APIs is strictly limited:

  • We transmit only the outbound application email you have authorized — no other Gmail data is accessed, stored, or exchanged
  • We do not read your inbox, messages, or email history
  • We do not access your contacts, labels, drafts, threads, or calendar
  • We do not modify or delete any existing emails
  • Your Gmail address and OAuth tokens are stored securely and encrypted at rest
  • OAuth tokens are never shared with any third party for any purpose
  • Our use complies fully with the Google API Services User Data Policy including Limited Use requirements

3.4 Legal Requirements

We may disclose your information where required by Malawian law, court order, or to protect the rights, property, or safety of Mvungi, our users, or the public.

3.5 Business Transfers

If Mvungi Masters is involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide reasonable notice before your data becomes subject to a different privacy policy.

🛡️
We do not sell your personal data to any third party for marketing, commercial, or any other purpose, ever.
✉️

4. Gmail Integration — Scope & Purpose

Why we request Gmail send permission and how it works

4.1 What We Request and Why

Mvungi requests the gmail.send scope — the narrowest permission available for outbound email — solely to send job application emails on behalf of users who have explicitly authorized this through Google's secure OAuth 2.0 flow. This feature is entirely voluntary.

Users voluntarily connect their Gmail account and grant permission for Mvungi Job Masters to submit applications using their own email address. This allows employers to identify the applicant clearly and reply directly to them — which would not be possible if applications were sent from our platform email address alone.

4.2 Why a More Limited Scope Is Not Sufficient

A more limited scope is not sufficient because our service requires sending application emails directly from the user's authenticated Gmail account. This is necessary so that:

  • Employers can identify the actual applicant by their real email address
  • Employers can reply directly to the applicant without Mvungi as an intermediary
  • Applications appear professional and credible to hiring managers
  • Users receive replies in their own inbox without depending on our forwarding

4.3 What This Permission Does NOT Allow

🔒 Strict Scope Boundaries
  • We do not read your inbox, received messages, or sent mail history
  • We do not modify or delete any of your existing emails
  • We do not access your contacts, labels, drafts, calendar, or any other Gmail data
  • We do not store any content from your Gmail account beyond the tokens needed to authenticate
  • We send only the specific application emails you have triggered through our platform

4.4 Data Stored for Gmail Integration

  • Gmail email address: Stored to identify your connected account and display it in your profile settings
  • OAuth access token: Short-lived token used to authenticate each email send, refreshed automatically
  • OAuth refresh token: Long-lived token stored securely and encrypted at rest, used only to obtain new access tokens when needed
  • All token data is stored on our secured servers, encrypted at rest, and never shared with any third party
📜

5. Google API Limited Use Compliance

Our formal statement of compliance with Google's user data policies

5.1 Formal Limited Use Statement

Mvungi Job Masters' use of information received from Google APIs strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements. The following applies without exception:

  • Gmail API data is used only to send the specific job application emails explicitly requested and authorized by the user through our platform
  • Gmail API data is not used to develop, improve, or train any generalized artificial intelligence or machine learning model
  • Gmail API data is not used for advertising, retargeting, or profiling purposes of any kind
  • Gmail API data is not transferred to, sold to, or shared with any third party — human or automated — for purposes other than sending the authorized application emails
  • Humans at Mvungi do not read user Gmail data unless required for security investigation of a reported abuse incident, and only with the user's express consent
🛡️
Our commitment: Gmail access is used exclusively to send job application emails you have explicitly authorized. We never read your inbox, access your email history, or use your Gmail data for any purpose beyond the single authorized send action.
🔓

6. Revoking Gmail Access

How to disconnect your Gmail account at any time

6.1 Two Ways to Disconnect

You may revoke Gmail access at any time through either of the following methods:

  • From your Mvungi profile settings: Navigate to Settings → Connected Accounts → click "Disconnect Gmail"
  • Directly from Google: Visit your Google Account Permissions page and remove Mvungi's access

6.2 What Happens After Revocation

  • All future application sends will automatically fall back to our platform SMTP email system
  • Your OAuth tokens are deleted from our database immediately upon disconnection
  • No further Gmail access will occur after revocation
  • Previously sent application emails are not affected or recalled
⚠️
If you revoke access directly through Google without disconnecting via Mvungi settings first, our fallback email system will activate automatically on the next matching run. Your account and applications will continue to function normally.

7. Your Data Rights

Control over your personal information

7.1 Rights You Hold

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data at any time
  • Deletion: Request deletion of your account and all associated personal data
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing for specific purposes such as marketing
  • Gmail Disconnection: Revoke Gmail access at any time via profile settings or directly through your Google Account

To exercise any right, contact us at info@mvungi.com. We will respond within 30 days.

7.2 Limitations

Some rights may be limited in specific circumstances — for example, we cannot delete data that is required for an active subscription period or that we are legally obligated to retain. We will always explain any limitation clearly when responding to your request.

🔒

8. Security & Data Retention

How we protect and how long we keep your data

8.1 Security Measures

  • All data is encrypted in transit using HTTPS/TLS
  • Sensitive data including OAuth tokens and passwords are encrypted at rest
  • Access to personal data is restricted to authorized personnel only on a need-to-know basis
  • We conduct regular security reviews and vulnerability assessments
  • Uploaded documents are stored in access-controlled server directories
⚠️
No system is completely secure. If you suspect unauthorized access to your account, contact us immediately at info@mvungi.com.

8.2 Retention Periods

Data TypeRetention Period
Active account dataRetained while account is active
Inactive account dataUp to 12 months of inactivity, then deleted
Gmail OAuth tokensDeleted immediately upon disconnection
Application recordsRetained for 24 months for dispute resolution
Anonymized analyticsIndefinitely (no personal identifiers retained)
Legal compliance dataAs required by Malawian law

You may request full account and data deletion at any time. We will complete deletion within 30 days of your verified request.

🍪

9. Cookies & Tracking

How we use cookies and similar technologies

9.1 Types of Cookies We Use

  • Essential cookies: Required for the platform to function — including session management and authentication. These cannot be disabled.
  • Analytics cookies: Track usage patterns to help us improve the Service — such as pages visited and features used. Anonymized.
  • Preference cookies: Remember your settings such as language and display preferences.

9.2 Managing Cookies

You can manage or disable non-essential cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the platform.

👶

10. Children's Privacy

Our platform is not for minors

10.1 Age Restriction

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at info@mvungi.com and we will delete it promptly.

📝

11. Changes to This Policy

How we handle updates to our privacy practices

11.1 How We Notify You

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users by email before the changes take effect
  • Display a prominent notice on the platform where appropriate

Continued use of the Service after changes take effect constitutes your acceptance of the updated Policy.

Get in Touch

Questions about this Privacy Policy, your data, the Gmail integration, or to exercise any of your data rights? Our team is here to help.

📍
Address Off Sigerege Road, Chilomoni
Blantyre, Malawi
📞
Phone +265 882 659 516
+265 998 599 647
✉️
🌐
Website www.mvungi.com