IntoScrubs homeCreate an account

Privacy Policy

Effective date: September 13, 2026 · Last updated: September 13, 2026

1. About this policy

IntoScrubs is operated by Ryan Voytek, who is responsible for the personal information described in this policy. Contact rrvoytek@gmail.com with privacy questions or requests.

This policy describes how IntoScrubs at intoscrubs.com handles information when you create an account, explore shadowing, research, or clinical work opportunities, connect Gmail, organize outreach, and record your experiences. It covers information you provide, information obtained through Google, and records created while providing these features.

Google sign-in and connecting Gmail are separate actions. Signing in with Google does not, by itself, authorize IntoScrubs to read or send your email. Gmail access requires a separate Google permission screen.

2. Information you provide and service records

  • Account and profile: name, email address, account identifier, school or educational background, premed or pre-PA interests, and profile information you choose to save.
  • Preferences and experiences: home and school locations, travel preferences, time zone, availability, specialties, research topics, job preferences, experience notes, and hours or attendance records.
  • Outreach: campaign settings, recipients, message drafts, approvals, sent messages, replies, referrals, scheduling details, outcomes, and related delivery and synchronization records.
  • Billing: selected plans, quotes, purchases, credits, allowances, transaction identifiers, payment status, and billing history. Payment details submitted to a payment provider are handled through that provider's checkout.
  • Operations: account actions, request and error records, timestamps, device or browser information, and connection information used to run, secure, and troubleshoot the service. Our hosting and network providers may process IP addresses and request metadata.

IntoScrubs also uses public professional and research sources to find people and organizations relevant to your preferences. These records can include names, professional contact information, institutions, specialties, publications, and source links. Do not submit patient information or confidential medical records.

3. Google account information and permissions

When you choose Google sign-in, our authentication service receives Google account information needed to identify you, such as your account identifier, email address, and any name or profile image Google supplies. We use this information to create or authenticate your IntoScrubs account and maintain your sign-in session. IntoScrubs does not receive your Google password.

When you connect Gmail, IntoScrubs requests openid, email, and https://www.googleapis.com/auth/gmail.modify. We receive your Google account identifier, verified email address, granted permissions, access tokens, refresh tokens, and connection status. Tokens let the service perform authorized Gmail operations, including while you are not actively using the website.

The Gmail permission is broad: Google allows it to read and modify mailbox messages and send email. IntoScrubs uses it for campaign correspondence, reply synchronization, campaign labels, and selective archiving. IntoScrubs does not request the full https://mail.google.com/ scope and does not permanently delete Gmail messages. Existing send-only grants support sending; they do not enable reply synchronization or organization.

4. How IntoScrubs accesses and uses Gmail data

IntoScrubs sends authorized outreach and replies from your connected Gmail address. It records message and thread identifiers, recipients, subjects, message text, and delivery information so correspondence can be displayed and tracked in your workspace.

For recorded IntoScrubs campaign threads, synchronization can obtain sender and recipient headers, subjects, message text, timestamps, message and thread identifiers, labels, and attachment metadata such as filename, content type, and size. Message text stored by Gmail as a separate MIME body part may be retrieved to display the message; attachment metadata does not mean every attached file is downloaded.

Automatic synchronization, when enabled, checks Gmail change history. Change history can include identifiers and label changes for messages outside IntoScrubs campaigns; IntoScrubs uses it to find changes associated with its recorded campaign threads. This is not a general inbox import. It retrieves campaign-thread content to update correspondence, identify replies, and show outcomes.

Campaign organization can create or apply campaign labels and archive eligible declined conversations according to your settings. Archiving removes a conversation from the inbox; it does not permanently delete it. Gmail data and derived records are used for the outreach, organization, reporting, and follow-through features described here.

5. AI-assisted features

When the corresponding AI features are enabled, IntoScrubs uses the OpenAI API to classify replies and prepare reply drafts. Reply classification sends the subject and incoming reply text. Reply drafting sends the student's name, conversation stage, subject, and relevant message text. Generated classifications and drafts are stored with the associated workflow. Research summaries and topic suggestions can separately send public research material or topic inputs.

These requests are for the feature being provided. IntoScrubs requests that API responses not be stored for later retrieval; that request does not mean the provider retains no data for security, abuse prevention, or legal purposes. The provider's applicable service terms and data controls also govern processing.

IntoScrubs does not use Google user data, including email content or derived data, to train or improve generalized AI or machine-learning models, and does not authorize its service providers to use that data for that purpose. Before Google data is transferred for an AI feature, users must receive the relevant disclosure and consent to that use. A generated draft is distinct from authorization to send a message.

6. Sharing and service providers

We do not sell or rent your personal information. IntoScrubs shares information as needed to provide the features you use:

  • Recipients: when outreach or a reply is sent on your behalf, recipients receive the sender identity, message content, and any other information included in that communication.
  • Google: authenticates your Google connection and processes Gmail operations you authorize.
  • Infrastructure: Hetzner hosts the application; Supabase provides account authentication and database services; Cloudflare provides network delivery and protection. These services process information necessary for their respective functions.
  • OpenAI: processes the inputs described in the AI-assisted features section when those features are enabled.
  • Payment providers: the provider identified at checkout processes payment and related transaction information. IntoScrubs receives records needed to reconcile billing and provide purchased services.

Access by staff or contractors must be limited to their role and the service being provided. Human access to Google user data requires your affirmative agreement to view specific data, unless access is necessary for security or applicable law, or is limited to aggregated data used for internal operations as permitted by Google's policy.

Google user data may be disclosed when necessary for security, to comply with applicable law, or as part of a business transfer with your explicit prior consent. IntoScrubs does not sell Google user data or provide it to data brokers, information resellers, or advertising platforms. It does not use that data for targeted or personalized advertising, creditworthiness, or lending decisions.

7. Google API Limited Use

IntoScrubs's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. These limits apply to raw Google data and information derived from it. Google data is used only to provide or improve the prominent user-facing features described in this policy. Service providers and personnel handling that data must follow the same restrictions.

8. Storage and protection

Account, campaign, correspondence, and experience records are stored on the server. IntoScrubs uses HTTPS for connections to the public website and Google APIs. Google access and refresh tokens are encrypted in the database using authenticated encryption, with encryption keys kept separately from the database. Account and role permissions restrict access to application records.

Your browser also stores your sign-in session, preparation checklist, and recoverable form drafts. Protect access to your device, especially on shared computers. Clearing browser storage can remove these local items and sign you out; it does not erase records already stored on the server.

9. Retention and deletion

We keep personal information only for as long as needed to provide the service, fulfill the purposes in this policy, resolve disputes, protect the service, and meet legal obligations. Our retention rules are:

  • Account, profile, campaign, correspondence, and experience records: retained while your account is active and needed for the service. After we verify a request to close your account or delete these records, we will delete or de-identify them from active systems within 30 days, subject to the limited exceptions below. De-identifying Google data does not remove Google's Limited Use restrictions.
  • Google connection credentials: removed from IntoScrubs's active credential store when you disconnect Gmail. Disconnecting does not erase messages and other records already saved in your workspace.
  • Backup copies: deleted information may remain in restricted backups for up to 90 days after removal from active systems. Backup copies are used for recovery and security, not ordinary product use. If a backup is restored, applicable deletion requests must be reapplied.
  • Billing and legal records: we may retain the minimum records needed for tax, accounting, dispute resolution, or legal compliance for up to seven years, or longer where a specific legal obligation requires it. This exception does not justify retaining unrelated Gmail message content.
  • Security and request records: we may keep limited records needed to investigate abuse, enforce account restrictions, or document how we handled a privacy request for as long as needed for that purpose. Any longer retention is limited to the information and period required by the specific issue or legal obligation.

To request deletion, email rrvoytek@gmail.com from the address associated with your account. You can also record a request in Account → Account data. Ryan Voytek reviews and processes requests manually. We will acknowledge your request, verify ownership where necessary, and confirm completion or explain any information we must retain. We aim to respond to privacy requests within 30 days and will explain any extension permitted by applicable law.

Submitting a request does not immediately erase your account or pause active campaigns. Pause campaigns and disconnect Gmail separately to stop those activities while your request is processed. Deleting a record in IntoScrubs does not recall delivered messages or delete copies in Google or a recipient's mailbox.

10. Your choices and requests

You can review and edit the profile and preferences available in your workspace, pause campaigns, change available Gmail organization or synchronization settings, and disconnect Gmail in Connections. You can also remove IntoScrubs's access through Google Account connections. Removing access at Google does not delete previously stored IntoScrubs records.

On disconnect, IntoScrubs clears its stored Gmail credentials and asks Google to revoke the grant. If Google does not confirm revocation, the interface reports that result; you can revoke access directly at Google. Gmail-dependent features cannot continue without a valid connection.

You may request access to, correction of, or deletion of your personal information. We may need to verify account ownership to protect your information. Email rrvoytek@gmail.com; you do not need to sign in to make a request. Depending on the law that applies to you, you may also have rights to a copy of your data, to restrict or object to processing, to withdraw consent, or to complain to a data protection authority. We will handle requests under the applicable law and will not penalize you for exercising your privacy rights.

11. Browser storage and third-party pages

IntoScrubs uses browser storage to keep you signed in and preserve workspace state and drafts. Authentication, payment, and infrastructure providers may also use cookies or similar technologies for login, checkout, security, and delivery. Their own notices apply on their pages. Blocking essential storage can prevent sign-in or disrupt these features.

12. Processing locations

Information may be processed in the countries where IntoScrubs and its service providers operate. These may differ from the country where you live. When information is transferred internationally, we use the safeguards required by applicable law, including appropriate contractual protections where required. You can contact us for more information about the providers and safeguards relevant to your data.

13. Children's privacy

IntoScrubs is intended for students exploring healthcare education and work and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.

14. Changes and contact

We will publish changes to this policy with an updated date and provide additional notice of material changes through the service or by email where appropriate. Before we use Google user data for a new purpose, we will explain the change and obtain the required consent.

Operator and privacy contact: Ryan Voytek
Service: IntoScrubs, intoscrubs.com
Email: rrvoytek@gmail.com

Return to IntoScrubs