AutoApply Privacy Policy
Effective date: July 28, 2026
AutoApply is built to be local-first: your job-search data lives on your computer, not on our servers. This policy explains exactly what data stays local, what leaves your machine and why, and what choices you have. AutoApply is operated by Paul Colombo ("we", "me"). Contact: [email protected].
1. The short version
- Your resume, profile, applications, and job data are stored on your machine. We don't have a copy.
- When the app drafts something with AI, the relevant text is sent through our server to an AI model provider (Anthropic or Google) to generate the draft. We don't store the content of those requests on our servers — we record usage metadata (token counts, model, feature, timestamp) for billing and abuse prevention.
- We know who you are only as an email address and account ID. Payments are handled by Stripe; we never see your card number.
- We don't sell your data, and we don't use your data to train AI models. There are no ads inside AutoApply. We do advertise it on other platforms, and the website measures which ads work (Section 6).
2. Data that stays on your device
The app stores its working data locally (on Windows, under your user profile's application data folder). This includes:
- your profile (name, contact details, education, work history, and similar application answers);
- your resume files and generated documents (tailored resumes, cover letters);
- discovered job listings, drafted applications, and your application tracker;
- learned corrections and preferences.
This data never leaves your machine except as described in Section 3. Deleting the app's data folder, or uninstalling and removing app data, removes it. We cannot delete it for you because we don't have it.
3. Data that leaves your device
AI drafting requests. When you use an AI feature (drafting answers, tailoring a resume, scoring a listing, and similar), the text needed for that task — for example the job posting, the relevant parts of your resume or profile, and your instructions — is sent to our server, which forwards it to the AI model provider (currently Anthropic's Claude models and Google's Gemini models) and returns the result to your app. Our server acts as a metering proxy: it verifies your account, counts usage, and passes content through. It does not persist the content of requests or responses. What it does record per request: your account ID, timestamp, model used, feature tag, and token counts.
Model providers process this content to generate your draft, subject to their own terms. We use their standard API offerings, which (as of the effective date) do not use API content to train their models.
Account data. Sign-in is handled by Firebase Authentication (a Google service). We store your account ID, email address, invite/pass status, and administrative records about your account (for example, purchases, granted credits, support notes).
Usage and product telemetry. The app reports small structured events to our server so the product works and improves: usage metadata as above, app version, feature-level events (for example "a draft was created", "an application was recorded" — as counts and statuses, not content), and error categories. It also reports anonymized shared signals, such as a hashed identifier of a job URL that turned out to be a dead link, so other users' apps can skip it.
Feedback. If you send feedback through the app or email, we receive what you write.
Payments. Purchases go through Stripe. Stripe collects your payment details under its own privacy policy; we receive confirmation of the purchase, the tier, and a payment reference — never your card number.
4. What we use data for
- Operating the Service: authenticating you, metering usage, delivering AI results.
- Billing and fraud/abuse prevention: enforcing quotas, detecting attempts to game usage, handling refunds and disputes.
- Improving the product: aggregate feature usage, error rates, and cost accounting.
- Support: answering your emails.
We do not sell personal data and we do not use your content to train AI models. Ad platforms only ever receive the website conversion signals described in Section 6, never your content or your identity.
5. Who we share data with
Service providers we use:
- Anthropic and Google (AI model APIs) — receive drafting-request content as described above.
- Google Firebase — authentication.
- Stripe — payments.
- Hetzner — hosts our server infrastructure in the EU.
- Google Analytics (website only) — visit and click statistics, as described in Section 6.
- Reddit (website only, while ad campaigns run) — ad conversion signals, as described in Section 6.
We may disclose information if required by law, or to protect the Service and its users (for example, investigating abuse). If AutoApply is ever acquired or transferred, account data would transfer with it under the same protections, and we'd tell you first.
6. The website and the launch list
This section covers applyforpeople.com only. The desktop app does none of this, and the website never sees your resume, your applications, or anything else from inside the app.
Analytics. The website uses Google Analytics to count visits and see which pages and buttons get used (page views, download clicks, demo plays, pricing views, signup clicks). Google sets identifiers in your browser and receives technical data such as your IP address and rough location as part of providing this service. We look at aggregate numbers, not identified individuals.
Ad measurement. We advertise AutoApply on other platforms (for example Reddit). If you arrive from an ad or a tagged link, the link's tags (a campaign label and a click id) are saved in your browser's local storage so we can tell which ad or post brought you here; if you later download the app or join the launch list, that source label is attached to the event. While a Reddit ad campaign is running, a Reddit pixel on the site reports those conversions back to Reddit, tied to Reddit's click id, so we can tell which ads are worth running. Reddit processes that data under its own privacy policy.
Launch list and product updates. If you leave your email in the "tell me at launch" box on the website, or tick the optional product-updates checkbox in the app, we store that address plus where the signup came from (a campaign label, or the app). We use it only to send the updates you asked for. Every email includes a way to opt out, and you can email [email protected] anytime to be removed. The list is never shared or sold.
7. Retention
Server-side records (account data, usage metadata, purchase records, feedback) are kept while your account exists and as long as needed for accounting, security, and legal obligations. AI request content is not stored on our servers, so there is nothing to retain. Local data on your device is yours and persists until you delete it.
8. Your choices and rights
- Access or delete your server-side data: email us and we'll show you what we have or delete your account and its records (purchase records may be retained where the law requires).
- Local data: it's on your machine and under your control.
- AI features: they run only when you use them; there is no background AI processing of your data.
Depending on where you live (for example, the EU/EEA, UK, or California), you may have additional legal rights to access, correct, delete, or port your data, and to object to certain processing. Email us and we'll honor them.
9. Security
Traffic between the app, our server, and providers is encrypted in transit (HTTPS). Server access is restricted and administrative actions are logged. Your local data is protected by your operating system account — we recommend full-disk encryption and a strong OS password, as with any application that stores personal documents.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you without undue delay.
10. Children
AutoApply is not directed to children under 16, and we do not knowingly collect data from them.
11. Changes
If this policy changes materially, we'll post the new version with a new effective date and note it in the app or on the website. Continued use after that means you accept the updated policy.
12. Contact
[email protected] — privacy questions, data requests, or anything else. I read every email.