Privacy Policy
Effective September 25, 2026
ApplyPilot AI (“ApplyPilot”, “we”, “our”) takes data minimisation seriously. This policy describes what we collect, why, and what you can do with it. The short version: your profile data is used only to fill your applications. We never store your employer credentials, and we never sell your data.
1. What we collect
Account information
Your name, email address, and (if you signed up with a password) a hashed copy of it. If you sign in with Google, GitHub, or LinkedIn, we receive your name and email from that provider and store no password at all.
Profile information
The information you enter into your profile: work experience, education, skills, certifications, personal information (phone, address, LinkedIn URL, etc.), and work authorisation status. This is the data ApplyPilot uses to fill application forms.
Resumes
Files you upload (PDF, DOCX, or TXT). They are stored in encrypted object storage. When you upload a resume, its text is extracted and sent to our AI provider (Anthropic) to produce a structured profile — the extracted data is shown to you for confirmation before it touches your profile. You can delete any resume at any time.
Application activity
A record of jobs you have analysed and applications you have tracked in ApplyPilot. This is used to show your dashboard and detect duplicate applications.
Session data
When you sign in, we create a session token (stored as a hash — the raw token is only in your browser cookie). We record the IP address and browser agent for security purposes. We also store short-lived, separately-revocable tokens for the browser extension.
Audit log
We record significant account actions (sign-in, resume upload, data deletion) with a timestamp and origin. The log records which fields were touched, never their values.
2. What we do not collect
- Employer credentials. The extension never asks for, reads, or stores your password or session on any employer or ATS site. ApplyPilot works inside your existing browser session and never touches those credentials.
- Form values from employer pages. The extension reads the structure and labels of application forms. It sends only field labels to our server — never the values you or the employer has already filled in.
- Payment information. ApplyPilot is free. We do not collect or store payment card details.
3. How we use your data
- To fill application form fields with your profile information, when you ask us to.
- To classify form fields and draft answers using AI (see Section 4).
- To detect duplicate applications and recommend resumes.
- To send you transactional emails (password reset, email verification).
- To maintain security and audit logs for your account.
We do not use your data to train AI models, run advertising, or profile you for any purpose outside of filling your job applications.
4. AI providers
ApplyPilot uses Anthropic’s Claude to classify application form fields, parse resume text, and (when you have enabled it) draft answers to screening questions from your profile material. When these features run:
- Resume text is sent to Anthropic for parsing when you upload a resume.
- Application field labels are sent to Anthropic when the rule-based classifier cannot identify a field.
- Your profile content (work history, skills, saved answers) is sent to Anthropic when drafting a screening question answer — you review every draft before it can be used.
Anthropic’s data processing is governed by their privacy policy. We use their API; your data is not used to train their models under our agreement.
5. Third-party services
- Email (Resend): Used to send password reset and verification emails. Your email address is shared with Resend for delivery.
- Object storage (Cloudflare R2): Resume files are stored encrypted. The storage key is recorded in our database; the file is never stored in the database itself.
- Database (Neon PostgreSQL): All structured data (profile, applications, sessions) is stored in a managed PostgreSQL database with encryption at rest.
- Hosting (Vercel): The web application and API run on Vercel. Requests pass through Vercel’s infrastructure.
- OAuth providers (Google, GitHub, LinkedIn): If you sign in with a social provider, we receive your name and email from that provider. We do not receive or store your password for any of these services.
6. Data retention
We retain your data for as long as your account is active. You can delete individual resumes at any time, or delete all your data (keeping your account) or your entire account from the privacy dashboard.
When you delete your account, your profile, resumes, applications, and sessions are permanently removed. A deletion audit record (the fact that a deletion occurred, with no personal data) is retained for legal compliance.
7. Your rights
Depending on your location, you may have the right to:
- Access a copy of the data we hold about you (export from the privacy dashboard).
- Correct inaccurate profile data (edit your profile at any time).
- Delete your data or your account (privacy dashboard).
- Object to processing or withdraw consent.
To exercise any of these rights, use the privacy dashboard or contact us through the help center.
8. Cookies and tracking
ApplyPilot uses a single session cookie to keep you signed in. It is marked HttpOnly, Secure, and SameSite=Lax so it cannot be read by scripts or sent cross-site. We do not use advertising cookies, tracking pixels, or third-party analytics.
9. Security
Passwords are hashed with scrypt before storage — we never see or store raw passwords. Session tokens are stored as SHA-256 hashes. Resume files are encrypted at rest. All traffic is encrypted in transit over TLS.
The extension uses a separate, short-lived token from your web session so that disconnecting the extension does not sign you out of the website, and vice versa. Each browser connection is individually revocable from your account settings.
10. Changes to this policy
We may update this policy from time to time. The effective date at the top reflects when the current version came into force. Material changes will be communicated by email.
11. Contact
Questions about privacy? Reach us through the help center.