Privacy Policy
Last updated: May 31, 2026
Data controller: BlueScroll Inc. (operating as Ballista.jobs)
1. Who We Are
Ballista is a product of BlueScroll Inc., a company operating under the brand name Ballista.jobs ("Ballista," "we," "us"). BlueScroll Inc. is the data controller responsible for the personal information described in this policy. We decide why and how your data is processed when you use Ballista.jobs.
Ballista is an independent product. BlueScroll Inc. operates other products under separate brands, but Ballista does not jointly control your personal data with those products and does not share your Ballista data with them. Each product maintains its own data and its own privacy policy.
2. Who This Policy Covers
Ballista is a tool for job seekers. The people whose data we process fall into two groups, and we treat them differently:
- Job seekers (our users): People who create an account to send physical job applications. This is the bulk of the personal data we hold, and some of it is sensitive (see Section 3).
- Recipients (third parties): The hiring managers, recruiters, and companies that a job seeker chooses to mail. We process recipient contact details only to address and deliver mail on the job seeker's behalf.
3. Job Seeker Data We Collect
Some of this data is sensitive. Resumes and cover letters routinely reveal employment history, education, and other personal details, and may reveal special categories of data (for example, information that implies health, religion, ethnicity, or political views) depending on what you upload. We process this data only to provide the service you asked for.
Information You Provide
- Account information: Email address for authentication
- Resume files: PDF documents you upload (may contain sensitive personal data)
- Cover letters: Text you write or generate
- Recipient information: Company names, hiring manager names, and mailing addresses you enter
- Payment information: Processed by Stripe; we never store full card details
- Gift information: When you purchase a gift, we collect your name, the recipient's email and first name, and an optional personal message
Automatically Collected Information
- Usage data (pages visited, features used)
- Device information (browser type, operating system)
- IP address and general location
- Cookies for authentication and session management
4. Recipient & Employer Data
When you address an application, you give us the recipient's name, company, and mailing address. We treat this data narrowly:
- We use recipient data only to print, address, and deliver the mail you asked us to send.
- We do not build marketing profiles of recipients, sell recipient data, or contact recipients for our own purposes.
- Recipients are not Ballista account holders. If a recipient wishes to access or remove their information, they can contact us at privacy@bluescroll.io.
5. How We Use Your Information
- Service delivery: Print and mail your resumes and cover letters to the recipients you specify
- Generated content: Produce optional personalized cover letters and brand designs (see Section 8 on automated processing)
- Communication: Send order confirmations, delivery updates, and support responses
- Payment processing: Process credit purchases via Stripe
- Service improvement: Analyze anonymized usage patterns
- Security: Detect and prevent fraud, abuse, and security issues
6. Sub-Processors We Share Data With
We share your information only with vendors that help us run the service. Each receives the minimum data needed for its function and is bound by a data processing agreement.
- Supabase: Database, file storage, and authentication (identity provider). Stores your account, resumes, and application data.
- Vercel: Application hosting and analytics
- PostGrid: Printing and mailing partner. Receives resume content, cover letters, and recipient addresses.
- Stripe: Payment processor. Receives payment information.
- Resend: Transactional email delivery. Receives your email address.
- Anthropic: AI model provider for optional cover letter and brand generation. Receives the inputs you submit for generation.
- Google Places API: Address autocomplete. Receives partial addresses you type.
- Sentry: Error monitoring and performance tracking. Receives technical error data and anonymized usage metrics.
We never sell your personal information, share resume content with anyone except the recipient and our printing partner, or hand data to third parties for their own purposes.
7. Data Retention
- Resumes: Stored until you delete them or close your account
- Sent applications: Order history retained for 2 years for support and tracking
- Account data: Retained while your account is active
- Payment records: Retained for 7 years for tax and legal compliance
8. Automated Processing & AI Generation
Ballista uses AI (provided by Anthropic) to optionally generate cover letters and brand designs from inputs you provide. This processing is a drafting aid that you request, review, and control.
Ballista does not rank, score, or filter candidates, and does not make automated decisions that produce legal or similarly significant effects about you. We do not perform automated decision-making within the meaning of GDPR Article 22. Hiring decisions are made by the recipients you choose to contact, not by Ballista.
You can decline AI generation entirely and write your own cover letters.
9. Your Rights & How to Exercise Them
Depending on where you live, you may have the right to access, correct, delete, port, or object to the processing of your personal data, and to opt out of the "sale" or "sharing" of personal information. You have these rights regardless of where you live, to the extent the law provides them:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information in your dashboard
- Deletion: Delete your account and associated data (except records we must keep by law)
- Portability: Export your data in a machine-readable format
- Objection / restriction: Object to or restrict certain processing, and opt out of marketing
To make a data subject access request (DSAR) or exercise any of these rights, email our shared privacy contact at privacy@bluescroll.io. We will respond within the timeframe required by your local law. We will not discriminate against you for exercising your rights.
10. International Data Transfers
BlueScroll Inc. is based in the United States, and your data is processed there and by our sub-processors. If you are in the European Economic Area, the United Kingdom, or another region with cross-border transfer rules, your data is transferred to the US under appropriate safeguards. Employment-related data can carry stricter transfer requirements, and we apply them where they govern.
11. Cookies & Tracking
We use cookies for authentication and session management, and we may use analytics and advertising technologies to understand usage and reach new users. Where consent is required, any cookie consent banner will identify the controller as BlueScroll Inc. (operating as Ballista.jobs) and let you accept or reject non-essential cookies.
12. Data Security
- All data transmitted over encrypted connections (HTTPS/TLS)
- Files stored in secure cloud storage with access controls
- Authentication tokens stored in httpOnly cookies
- Regular security reviews and updates
- Employee access limited to necessary personnel only
13. Children's Privacy
Ballista is not intended for users under 18. We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us immediately and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or dashboard notification and update the "Last updated" date above. Continued use of the service after changes take effect constitutes acceptance.
15. Contact Us
Formal privacy requests and DSARs: privacy@bluescroll.io
Product privacy questions: privacy@ballista.jobs
Data controller: BlueScroll Inc. (operating as Ballista.jobs)