Privacy Policy
Last updated: 13 June 2026
Your privacy is a trust. This policy explains what data the Tomooh platform collects, how we use and protect it, who we share it with, and your rights over it. It is prepared in line with the Personal Data Protection Law (PDPL) of the Kingdom of Saudi Arabia, its Implementing Regulations, and the rules on transferring personal data outside the Kingdom.
1. Who we are (the data controller)
The controller of your personal data is Hassan Mujahid Ibrahim Alqaisi, an individual working in a self-employed (freelance) capacity under Freelance Work Document No. FL-137313884 issued by the Ministry of Human Resources and Social Development, based in Riyadh, who operates the Tomooh platform. For anything related to your privacy, contact us at privacy@tomooh.io.
2. Data we collect
- Account data: name, email, mobile number, and password (encrypted; we cannot see it), or your Google or Microsoft account identifier when you sign in with them.
- Career Vault: the experience, education, skills, certifications, and projects you enter yourself, and what the platform extracts from a CV you upload.
- Files: CVs generated by the platform, your profile photo, and generated banner images. A CV you upload is processed in memory only to extract its text and is not stored on our servers; only the information extracted from it is saved to your Career Vault.
- Connection data: when you connect with Google sign-in we store encrypted access tokens only. If you connect Gmail with an app password, we store that app password encrypted (AES-256) and never see your main account password.
- Mailbox access: with Google sign-in we request send-only access (gmail.send) and do not read your mailbox. With an app-password connection we have full mailbox access, used solely to send your applications and to detect replies and bounces to them; we do not read or store your other messages.
- Usage and technical data: essential logs to operate and secure the platform (such as application history, message status, and IP/device data for security), retained for up to 12 months.
- Payment data: processed by the licensed payment provider; we do not store your card numbers in our systems.
3. How we use your data and the legal basis
We process your data for the following purposes, on the legal bases set out in the PDPL:
- Performing the service you requested: matching you with jobs, generating CVs and emails from the facts in your Vault, and sending applications after your approval.
- Based on your consent: connecting your inbox, AI processing, and optional features such as profile-photo enhancement.
- Our legitimate interest: operating, improving, and protecting the platform from fraud and abuse, without prejudice to your rights.
- Legal obligation: keeping financial records and responding to binding legal requests.
We do not sell your personal data to any third party, and we do not use it for advertising.
4. AI processing
Tomooh uses AI models from external providers (such as OpenAI) to write CVs and emails, provide consultation, and optionally enhance images. Only the data needed for the task is sent to these models, under processing agreements that prohibit using it to train their models. Our fixed principle: the AI writes, it never invents, and everything written about you comes from your own data.
5. Automated processing (matching)
The platform uses automated processing to rank and suggest the jobs that best fit your profile. These suggestions are assistive only; the platform does not make a solely automated decision that produces a legal effect on you. The decision to apply to any job remains entirely yours.
6. Email permissions (Google and Microsoft)
- We use the send permission (gmail.send) only to send the applications you approved. We do not request any permission to read your mail.
- We request only one Google permission: sending email (gmail.send) on your behalf after your approval. We do not request read access, so we never read your inbox.
- Tomooh's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not use your mail content for any advertising purpose, do not transfer it to parties not necessary to run the service, and do not use it to train AI models.
- When Microsoft Outlook connection becomes available in future, we will request equivalent permissions only, to send and track your applications.
- You can disconnect your inbox at any time from Settings, or directly from your email account settings.
7. Who we share your data with
We share your data minimally and only with specific categories of recipients:
- Employers: receive the CV and application email you approved for sending.
- Infrastructure, hosting, and database providers (such as Supabase) to store your data and run your account.
- AI providers (such as OpenAI) to generate text outputs and images.
- Email providers (Google and Microsoft) to send and track your applications, and the transactional email provider (Brevo) for system emails such as signup confirmation and password reset.
- The payment provider (Dodo Payments) to process payments and issue invoices.
- Providers that collect public job data and verify hiring contacts (such as Apify and Hunter); these do not receive your personal data, only public job and company data.
- Authorities: upon a binding legal request under the laws of the Kingdom.
We bind our processors by contracts that keep your data confidential and limit its use to providing the service.
8. Transfer of data outside the Kingdom
Some service providers (such as OpenAI, Supabase, Google, Microsoft, and Brevo) may process your data outside the Kingdom of Saudi Arabia, and the database is hosted in the European Union (EU) region. Where they do, we comply with the rules on transferring personal data outside the Kingdom issued by the Saudi Data and AI Authority (SDAIA), and we apply appropriate safeguards such as standard contractual clauses or equivalent to protect your data.
9. Payment data
Your payments are processed by a licensed payment provider (Dodo Payments), which may act as Merchant of Record, and its processing of your data is subject to its own privacy policy. We keep the invoice and balance records needed for accounting and legal compliance, without your bank card numbers.
10. Storage and security
- Data is stored with a secure cloud infrastructure provider, with encryption in transit and at rest and least-privilege access on our internal systems.
- Email access tokens are stored encrypted with independent keys.
- Even so, no method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
11. Personal data breach notification
If a material incident affecting your personal data occurs, we will take the necessary steps to contain it, and we will notify the competent authority (SDAIA) and inform you in accordance with the timelines and requirements set out in the PDPL, its regulations, and the breach-incident guidance.
12. Your rights
Under the PDPL you have the following rights:
- To be informed: to know what we collect about you and how we process it (this policy is part of that).
- Access and copy: to request a copy of your personal data in a readable format.
- Correction: to fix any inaccurate data; most of it is directly in your hands in the Career Vault and Settings.
- Destruction (deletion): to request deletion of your account and personal data.
- Withdrawal of consent: to withdraw any consent previously given, including disconnecting your inbox, without affecting prior processing.
To exercise any of these rights, email privacy@tomooh.io and we will respond within a reasonable period consistent with statutory timelines. If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Saudi Data and AI Authority (SDAIA).
13. Data retention
- We keep your data for as long as your account exists, to provide the service.
- When you delete your account, your personal data, Career Vault, and files are deleted within 30 days, except what we must retain by law (such as financial records).
- Technical logs are kept for up to 12 months, and backups are purged periodically according to the backup schedule.
14. Cookies
We use essential cookies only: for login, session security, and language preference. We currently use no analytics tools or advertising trackers, and we share no browsing data with ad networks. If we add optional analytics tools in future, we will seek your consent where required.
15. Minors
The platform is intended for people of working age and may not be used by anyone under 18. If we learn that data was collected from someone younger, we will delete it.
16. Updates to this policy
We may update this policy from time to time. For any material change we will notify you through the platform or by email before it takes effect, and the last-updated date always appears at the top of this page.
For any question or request about your privacy and data, email us at: privacy@tomooh.io - the Operator Hassan Mujahid Ibrahim Alqaisi, Kingdom of Saudi Arabia.