Avely
Privacy Policy
Last updated September 20, 2026
What Avely is
Avely is an applicant tracking system (ATS) used by recruiting teams to manage jobs, candidates, and hiring pipelines. This policy covers the account owner (the company using Avely) and its staff users (recruiters, hiring managers), and — separately, where noted — the candidates and contacts whose information staff users add to the system.
Google user data — what we access and why
When a staff user connects their own Google account in Avely's Settings, we request exactly three scopes, each used for exactly one purpose:
- Send email on your behalf (gmail.send) — used only when you explicitly click "Send" on a message you composed inside Avely (a candidate email or a questionnaire link). We never read, search, or store the contents of your Gmail mailbox — Avely does not request Gmail's read scope at all, so it has no technical ability to see any email other than the ones it sends for you.
- See, edit, share and permanently delete calendars (calendar) — used only to create, update, or cancel a single calendar event when you schedule, reschedule, or cancel an interview through Avely, and to check for scheduling conflicts before booking. The conflict check deliberately requests only free/busy time ranges — never the subject, attendees, or location of your other calendar events. Avely does not read, modify, or delete any event it did not itself create.
- See your primary Google Account email address (userinfo.email) — used only to show you which Google account is connected, in Avely's own Settings page.
How we store this
Your Google access and refresh tokens are stored encrypted at rest in our database (Supabase/Postgres), in a table with no direct read or write access from the browser — every use of your tokens happens through a server-side request you initiated (a send, a schedule, a reschedule, or a cancel). You can disconnect your Google account at any time from Settings, which immediately and permanently deletes both the tokens and the connection record.
Limited Use disclosure
Avely's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not allow humans to read it except as necessary for security, legal compliance, or with your explicit consent, and do not transfer it to any third party outside of providing the Avely service itself.
Microsoft (Outlook) connection
Avely also supports connecting a Microsoft/Outlook account instead of Google, for the same two purposes (sending candidate email, calendar scheduling) with the same scope of access — a staff user connects one provider at a time.
Candidate and contact data
Staff users add candidate information (name, contact details, CV, application history, notes) to Avely as part of running their hiring process. This data belongs to and is controlled by the company using Avely, not by Avely itself — we act as a data processor. Candidates should direct any request about their personal data to the specific company they applied to.
Data retention
Data is retained for as long as the company's Avely account is active. A staff user's Google or Microsoft connection and its tokens are deleted immediately on disconnect, and are not retained afterward for any purpose.
Contact
Questions about this policy or how your data is handled can be sent to
daniel@placeup.net.