Privacy Policy

Last updated: 19 August 2026

This document is a draft.

Placeholders marked TODO below have not been filled in yet, and it has not been reviewed by a lawyer. It describes how the service actually handles data, but it is not yet a binding policy.

A job search is one of the more private things a person does. This document says exactly what Applied stores, what leaves for somebody else's servers, and how to make all of it go away.

The short version: your board is yours, we do not sell it, and the one thing worth knowing before you use the AI features is that the text of your resume is sent to OpenAI when you press one of those buttons. The detail is in section 6.

1. Who runs this service

Applied is operated by TODO: legal name of the operator, reachable at TODO: privacy@your-domain. That address is the one to use for anything in this document, including deletion requests and complaints.

2. What we collect

Everything below is either typed in by you or produced by using the product.

Account

  • Your email address, and a password stored as a hash — the password itself is never visible to us.
  • If you sign in with Google: your name, email address, profile picture, and the fact that Google was the provider.

Your job search

  • Applications: company, role, link to the posting, salary range with its currency and period, location, work mode, employment type, stage, tags, and the dates you record for applying, interviews, deadlines and follow-ups.
  • The full text of job postings you save, and the keywords extracted from them.
  • Your notes, including rejection reasons and anything you write about a company.
  • Contacts you record against an application: a recruiter's name, email, LinkedIn or Telegram.
  • A history of stage changes — when each application moved from one column to another.

Documents

  • Resumes and cover letters in full: name, contact details, employment history, education, skills, projects and certifications.
  • Frozen copies of the resume that went out with a particular application, so you can see later what you actually sent.

Profile

  • Optional details: experience level, years of experience, specialisation, country, remote preference and desired salary range.

Technical

  • A session cookie that keeps you signed in.
  • Counters of how often you have used the features that cost money, so that a runaway client cannot spend without limit.
  • If you connect Google: access and refresh tokens, encrypted before storage, plus which permissions you granted and which Google account they belong to.
  • Error reports when something breaks — see section 5.

3. Why we process it

  • To provide the service you asked for. Storing your board, showing it back to you, and running the features you press. Under GDPR this is performance of a contract.
  • To keep the service working and safe. Rate limiting, error monitoring and abuse prevention. This is our legitimate interest, and it is limited to what that requires.
  • Because you asked us to. Connecting Google, using an AI feature, or creating a share link happen only when you choose them. That is consent, and you can withdraw it.

4. What we do not do

  • We do not sell your personal data. Not to advertisers, not to recruiters.
  • We do not run an employer-facing product. There is no version of this where a company looks you up.
  • We do not use advertising or analytics trackers.
  • We do not read your board to build a profile of you for anything beyond the statistics we show back to you.

5. Who else your data reaches

Running this service means using other companies' infrastructure. Each one below receives only what is listed, and only for the stated purpose.

Supabase

What leaves: Everything in section 2 — this is the database and the account system.

Why: Storage. Rows are isolated per account at the database level, so one account cannot read another's data even knowing its identifier.

Vercel

What leaves: Requests to the site, including IP address and browser, in server logs.

Why: Hosting.

OpenAI

What leaves: The text of a resume, a cover letter or a job posting — whichever the feature you pressed operates on.

Why: The sparkle actions in the CV Builder (improving a bullet, writing a summary, scoring a resume against a job, tailoring it, drafting a cover letter), importing a resume from a PDF or Word file, and filling a card from a job link when the page carries no structured data of its own.

Google

What leaves: Only if you connect it: events written to your calendar, and spreadsheets created in your Drive.

Why: Calendar sync and spreadsheet export. Nothing reaches Google unless you connect an account, and disconnecting revokes our access.

Adzuna

What leaves: A job title and a country. No name, no account identifier, nothing tying the query to you.

Why: The market salary benchmark on the Statistics page.

Sentry

What leaves: Error reports: the message, where in the code it happened, the page you were on, and the browser.

Why: So that we find out when something breaks for you, instead of waiting for a message that never comes. Request bodies and cookies are stripped before an error is sent, specifically so that a crash cannot carry a resume out with it.

Several of these companies are based in the United States, so using Applied means your data is transferred there. Those transfers rely on the standard contractual clauses each provider offers.

6. The AI features, specifically

This section exists because it is the part people are most likely to be surprised by, and preventing that surprise is what a privacy policy is for.

When you press one of the sparkle buttons, import a resume from a file, or auto-fill a card from a link whose page carries no structured data, the relevant text is sent to OpenAI and processed on their servers. For a resume that means your full name, your employers, your education, and whatever else the document contains. The model used is gpt-4o-mini.

OpenAI states that data submitted through its API is not used to train its models by default, and is retained for a limited period for abuse monitoring. Those are their terms rather than ours and they can change; if this matters to you, read them directly.

None of this is automatic. Nothing is sent to a model because you opened a page or saved a card. It happens when you press a button that says it will. If you never press one, no resume of yours ever leaves for OpenAI.

7. Cookies

We use cookies for one thing: keeping you signed in. They are strictly necessary for the service to function, which is why there is no banner asking you to consent to them.

There are no advertising cookies, no analytics cookies and no third-party trackers. If that ever changes, this section changes first, and you will be asked.

8. How long we keep it, and how to make it stop

Your data stays for as long as your account does. There is no background archive and no copy kept aside.

You can delete your account yourself, from the bottom of the Profile page. It is immediate and it is not reversible: the account, every board and application, every resume and cover letter, your profile and your stage history all go at once, and your Google connection is revoked at Google in the process. We keep no copy and cannot restore it for you afterwards.

Two things survive on purpose, and both are outside our systems. Events already written into your Google Calendar stay in your calendar, and spreadsheets exported to your Drive stay in your Drive — they are yours, in your account, and emptying them is not ours to do. Delete them there if you want them gone.

Server logs and error reports age out on the providers' own schedules, measured in weeks rather than years.

9. Your rights

If you are in the EU, the UK or Ukraine, the law gives you the rights below. We apply them to everyone rather than checking where you are.

  • See what we hold. The board and the CV Builder show it directly, and Profile has a full export.
  • Correct it. Everything in the product is editable.
  • Take it with you. Export the board to Excel, CSV or Google Sheets, and your profile and resumes as JSON or Excel.
  • Delete it. The button described in section 8, no request needed.
  • Object, or ask us to restrict processing. Write to TODO: privacy@your-domain.
  • Withdraw consent. Disconnect Google, stop using the AI features, or revoke a share link — each is a switch inside the product.
  • Complain. If we handle a request badly, you can take it to your national data protection authority.

We answer requests within one month, which is the deadline GDPR sets.

10. Anonymised statistics

We intend, in future, to produce statistics about the job market — figures such as a median salary range for a role in a country, or how many applications typically precede an offer — built from data across accounts, and to publish or sell them as reports.

This is written here now, before any of it exists, because consent is given for a stated purpose and cannot be applied backwards to data collected under a different one.

If and when it happens, it will work as follows.

  • It is opt-in. A switch in your profile, off by default. Declining costs you nothing: no feature is withheld for it.
  • Only aggregates leave. Never a row, never a document, never a company name attached to a person.
  • Small groups are not published. A figure covering too few people identifies them by arithmetic, so any slice below a minimum group size is suppressed rather than shown.
  • Names, emails and contacts are never part of it, in any form, aggregated or otherwise.

The switch is in your profile now, under "Anonymised market statistics", and it is off until you turn it on. No reports exist yet and nothing is being aggregated today — what the switch records is permission for when that changes. Turning it off later removes you from anything published afterwards.

11. Security

Data is isolated per account at the database level rather than only in application code, so a bug in a page cannot show one user another user's board. Google tokens are encrypted before storage. All traffic runs over HTTPS. Access to the production database is limited to the operator.

No system is perfect, and claiming otherwise would be the first untrue sentence in this document. If we discover a breach affecting your data, we will tell you and the relevant authority — within 72 hours of becoming aware of it, where the law requires it.

12. Children

The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has created an account, write to TODO: privacy@your-domain and we will remove it.

13. Changes to this policy

When this document changes, the date at the top changes with it. If a change actually affects you — a new company receiving your data, a new purpose — we will say so, rather than relying on you to notice a date.