Privacy Policy
This Privacy Policy explains how Jobapply.io ("we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you use the Jobapply.io website and application (the "Service").
Last updated: August 7, 2026 · Effective: August 7, 2026
1. Summary
Here is a high-level overview of our data practices. Details follow in the sections below.
- We collect only the data needed to provide and improve the Service.
- We use your data to deliver the Service, process payments, ensure security, and improve reliability.
- We do not sell your personal data. We do not use your resume content for advertising.
- We name the current service providers that help us operate the platform below.
- You can download current application account data in Account Settings and request broader access, correction, or deletion.
- Provider-by-provider storage regions and international-transfer safeguards are still under operational and legal verification; this draft does not assert a final transfer mechanism.
2. Data Controller
Controller publication status:
Owner facts pending confirmation: the registered controller name, service address, and CVR number are unknown and are not asserted in this draft.
Privacy contact: hello@jobapply.io
The missing registered details must be supplied and verified by the owner before this policy can close LEGAL-05 or DQ-06.
3. What Personal Data We Collect
3.1 Data You Provide Directly
- Account data: name, email address, authentication identifiers (including magic-link tokens), profile preferences, and timezone.
- Document content: resume/CV text, cover letter text, work experience, education history, skills, language proficiency, certifications, and any other information you add to your documents.
- Profile photo: if you choose to upload a photo for your resume/CV.
- Billing data: subscription plan, billing cycle, invoice metadata, and payment method information (processed and stored by our payment provider; we do not store full card numbers).
- Support communications: messages, attachments, email address, name if provided, and widget/session metadata from support requests you submit, including through PostHog support chat.
- Feedback and surveys: any responses you provide when we ask for feedback on the Service.
The Google tag and Google Ads SDK do not load or send measurement requests before Advertising consent. After you enable Advertising, Google Ireland Limited may receive campaign, conversion, device, page, and referral data as described in our Cookie Policy.
3.2 Data Collected Automatically
- Usage data: pages visited, features used, actions taken (such as document creation, template selection, and exports), timestamps, and session duration.
- Device and browser data: device type, operating system, browser type and version, screen resolution, and preferred language.
- Network data: IP address, approximate geographic location (city/country level), and referral URL.
- Cookies and similar technologies: see our Cookie Policy for details.
3.3 Authentication Data
Current sign-in uses email magic links. We receive the email address you enter and the authentication and session identifiers returned by Supabase Authentication. We do not currently offer Google or LinkedIn sign-in.
4. How We Use Your Data
We use your personal data for the following purposes:
- Provide the Service: create and manage your account, save and render your documents, apply templates, generate PDF exports, and deliver AI-assisted writing features.
- Process payments: handle subscriptions, renewals, invoices, and refunds through our payment provider.
- Communicate with you: send account notifications, billing confirmations, security alerts, support responses, support ticket continuity, and product updates.
- Ensure security: detect and prevent fraud, abuse, unauthorized access, and other harmful activities.
- Improve the Service: analyze usage patterns, measure feature performance, identify bugs, and develop new features.
- Comply with legal obligations: meet accounting, tax, and regulatory requirements.
- Enforce our Terms: investigate and address violations of our Terms of Service and Acceptable Use policies.
5. Legal Bases for Processing (EU/EEA)
If you are located in the EU/EEA, we rely on the following legal bases under the General Data Protection Regulation (GDPR):
- Contract performance (Art. 6(1)(b)): processing necessary to provide the Service, manage your account, process payments, and deliver your documents.
- Legitimate interests (Art. 6(1)(f)): improving the Service, ensuring security, preventing fraud, and analyzing usage to enhance product quality. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)): where required, such as for optional analytics cookies, marketing emails, and certain AI features. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): processing required to comply with applicable laws, such as tax and accounting regulations.
6. Who We Share Data With
We do not sell your personal data. The table below names the service providers configured in the current Service and describes the data involved in each service.
Current service providers and subprocessors
| Provider | Service | Data involved |
|---|---|---|
| Vercel | Marketing website and web application hosting | Page requests, device and network metadata, and assets needed to serve the web surfaces. |
| Railway | API hosting | Account requests and the profile, document, billing-status, or AI-request data sent to the API. |
| Supabase | PostgreSQL database and authentication | Account email and authentication identifiers, sessions, profiles, documents, and application records. |
| PayPal | Subscription checkout and billing | Checkout can send your JobApply user ID, account email, full name, mobile phone, locale, and subscription or transaction identifiers, status, amount, and currency. PayPal collects payment details directly. |
| Twilio SendGrid | Transactional account email | Recipient email address, message content, and delivery metadata. |
| PostHog | Consent-gated product analytics and support chat | After Analytics consent, the raw JobApply account ID and account email when you are signed in, plus usage, device, network, and page metadata. Support messages and widget session metadata you submit are also processed. |
| Google Ireland Limited | Advertising measurement after Advertising consent | After Advertising consent, campaign, conversion, device, page, and referral data. The Google tag and SDK are not loaded and no advertising-measurement request is forwarded before that consent. |
| OpenRouter | AI inference gateway | The resume/CV, job-description, cover-letter, or image content needed for the AI feature you request. OpenRouter forwards that content to the configured downstream model provider. |
| OpenAI | Current default downstream AI model provider through OpenRouter | The current default route is openai/gpt-5.6-terra. It receives the resume/CV, job-description, cover-letter, or image content needed for the AI feature you request. The configured route may change. |
Other recipients may include:
- Legal and regulatory authorities: if required by law, legal process, or government request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy commitments.
7. International Data Transfers
Provider-by-provider storage regions, processing locations, and transfer mechanisms are not yet verified for launch. This draft does not claim that an adequacy decision, Standard Contractual Clauses, the EU-U.S. Data Privacy Framework, or another particular safeguard currently applies.
Before release, the controller must complete the provider data map, verify each applicable transfer mechanism and supporting agreement, and make the resulting information available. Until then, international-transfer disclosure is an explicit provider and legal blocker.
8. Data Retention
The exact retention schedule for account and document data, billing records, support communications, analytics, server logs, and backups is not yet operationally verified. No specific retention period is asserted in this draft.
The current Account Settings flow requests deletion of current JobApply application account records and removes the local browser workspace after local cleanup can complete. Provider-held records, backups, logs, and any legally required billing or tax retention are not proven by this local source audit. The final data map, deletion procedures, and retention periods remain an explicit operational, provider, and legal blocker before release.
9. Data Security
This local source audit establishes code-level boundaries for consent, server-only secrets, fixed-authority proxy routes, and browser-data cleanup. It does not establish provider encryption at rest, organizational access controls, recurring vulnerability assessments, operational monitoring, or incident-response procedures, and this draft does not assert that those controls are in place.
The final technical and organizational control set must be verified and documented before release. Until then, these operational security claims are an explicit provider and legal blocker. No method of transmission or storage can be guaranteed to be completely secure.
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention requirements.
- Right to restrict processing: request that we limit how we use your data in certain circumstances.
- Right to data portability: request a copy of your data in a structured, commonly used, and machine-readable format.
- Right to object: object to processing based on legitimate interests, including profiling and direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: you have the right to file a complaint with a data protection supervisory authority, such as the Danish Data Protection Agency (Datatilsynet).
While signed in, open Account Settings, then under Your Subscription use Download my data to download current account, document, AI-session, sync, and billing data stored in the JobApply application database as JSON. This self-service download does not include records held only by payment, authentication, email, analytics, AI, or hosting providers, or operational server logs.
To request access to those additional records, or to exercise any other right, contact us at hello@jobapply.io with the email address associated with your account. We will respond within 30 days (or sooner if required by law). We may ask for verification of your identity before processing certain requests.
11. Children's Privacy
The Service is not directed to individuals under the age of 16 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us.
12. AI Features and Data Processing
When you use AI-assisted features (such as CV import, content suggestions, or rewriting tools), the Service sends content needed for the requested feature to OpenRouter, which forwards it to the configured downstream model provider.
- AI requests may include document text and images you submit. If that content contains your name, email address, phone number, or other personal data, those details may be sent as part of the request.
- We do not use your document content to train Jobapply-owned AI models.
- Provider training terms, retention, processing locations, and applicable agreements have not yet been verified for release. This draft does not assert those operational facts.
- You may choose not to use AI features; they are optional and do not affect core document functionality.
13. Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal effects or significantly affects you. AI suggestions are recommendations only and require your review and approval before use.
14. Do Not Track
Some browsers offer a "Do Not Track" signal. There is no uniform standard for how websites should respond to this signal. We currently do not respond to DNT signals but respect opt-out choices made through cookie settings and our consent mechanisms.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date. If changes are material, we will provide prominent notice (for example, by email or an in-app notification) before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us:
Registered controller details pending owner confirmation. No legal name, service address, or CVR number is asserted in this draft.
Email: hello@jobapply.io
Website: https://jobapply.io
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Denmark, this is the Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk.