AutoApply Privacy Policy
Effective date: August 18, 2026
AutoApply is built to be local-first: your job-search data lives on your computer, not on our servers. This policy explains exactly what data stays local, what leaves your machine and why, and what choices you have. AutoApply is operated by Paul Colombo ("we", "me"). Contact: [email protected].
1. The short version
- Your resume, profile, applications, and job data are stored on your machine. We don't have a copy. That includes the answers you've saved from past applications, even the EEO/demographic ones (Section 2).
- When the app drafts something with AI, the relevant text is sent through our server to an AI model provider (Anthropic or Google) to generate the draft. We don't store the content of those requests on our servers — we record usage metadata (token counts, model, feature, timestamp) for billing and abuse prevention.
- We know who you are only as an email address and account ID. Payments are handled by Stripe; we never see your card number.
- We don't sell your data, and we don't use your data to train AI models. There are no ads inside AutoApply. We do advertise it on other platforms, and the website measures which ads work (Section 6).
2. Data that stays on your device
The app stores its working data locally (on Windows, under your user profile's application data folder). This includes:
- your profile (name, contact details, education, work history, and similar application answers);
- your resume files and generated documents (tailored resumes, cover letters);
- discovered job listings, drafted applications, and your application tracker;
- learned corrections and preferences.
Your saved answers, including the sensitive ones. When you answer a question on an application, the app saves that answer locally so you don't have to type it again. That includes the demographic questions employers ask for EEO reporting (race, ethnicity, gender, veteran status, disability status, pronouns) if you chose to answer them. Those answers sit in the app's local database and nowhere else of ours. They are never stored on our servers, and they are never contributed to the shared signals described in Section 3: that cache only ever receives standard field names and the wording of the questions, never the values you typed.
Your saved answers travel with every drafting request, not only the ones that match the page. The app sends your most recent saved answers (currently up to 40) with each fill so the model can reuse them, so a demographic answer you saved earlier can be included in a request for a form that never asks about it. Those requests pass through our server without being stored (Section 3).
Your mailbox, if you connect it. You can connect a Gmail account so the app can pick verification codes out of the confirmation mail employer sites send, and follow your application status. The access is read-only: the app can read mail, never send, delete, or change it. It reads the sender, subject, and a short snippet of your recent messages, and for the few messages it flags as job-related or as carrying a verification link, it reads that message's full text. The access tokens live in your operating system's credential store, and you can disconnect at any time in the app, which deletes them.
Site passwords. If you have the app create or use accounts on employer sites, those passwords are kept in your operating system's credential store (Windows Credential Manager, macOS Keychain), not in our database and not in the app's own files. They are never included in anything sent to an AI model, and password boxes are stripped out of the page snapshots the app takes.
This data never leaves your machine except as described in Section 3. Deleting the app's data folder, or uninstalling and removing app data, removes it. We cannot delete it for you because we don't have it.
3. Data that leaves your device
AI drafting requests. When an AI feature runs (drafting answers, tailoring a resume, scoring a listing, and similar), the text needed for that task is sent to our server. Usually that is because you pressed a button. Some of it runs on a schedule in the background while the app is running, which Section 9 describes; either way the rules below are the same. For filling a form that means your profile as the app holds it (contact details, address, education, GPA, work history, projects, skills, custom fields), plus your most recent saved answers, whether or not they match the questions on that page, the fields on the page, and an excerpt of the job posting. For resume and cover-letter work it means your resume text and the job description. Your instructions go with it. All of that is sent to our server, which forwards it to the AI model provider (currently Anthropic's Claude models and Google's Gemini models) and returns the result to your app. Our server acts as a metering proxy: it verifies your account, counts usage, and passes content through. It does not persist the content of requests or responses. What it does record per request: your account ID, timestamp, model used, feature tag, and token counts.
Model providers process this content to generate your draft, subject to their own terms. We use their standard API offerings, which (as of the effective date) do not use API content to train their models.
Account data. Sign-in is handled by Firebase Authentication (a Google service). We store your account ID, email address, invite/pass status, and administrative records about your account (for example, purchases, granted credits, support notes).
Usage and product telemetry. The app reports small structured events to our server so the product works and improves: usage metadata as above, app version, feature-level events (for example "a draft was created", "an application was recorded" — as counts and statuses, not content), and error categories. It also reports shared signals so other users' apps benefit: a hashed identifier of a job URL, the wording of form questions paired with the standard profile field they map to, and for a listing that turned out to be dead, the plain job URL so we can check the report. The answers you typed are never part of this.
Your mailbox, if you connect it. If you connect Gmail (Section 2), the app reads recent messages straight from Google's mail API on your machine. It does that on a repeating schedule, roughly every 10 minutes while the app is running, not only when you open the tracker. Verification codes are matched on your computer. Two things go to an AI model through the same metering server described above, and are not stored there either: when the app can't tell from wording alone what an application-status email means, that message's sender, subject, and snippet; and when a message looks like a job alert or recruiter mail, its sender, subject, and full text, so the app can pull the openings out of it.
Feedback. If you send feedback through the app or email, we receive what you write.
Payments. Purchases go through Stripe. Stripe collects your payment details under its own privacy policy; we receive confirmation of the purchase, the tier, and a payment reference — never your card number.
4. What we use data for
- Operating the Service: authenticating you, metering usage, delivering AI results.
- Billing and fraud/abuse prevention: enforcing quotas, detecting attempts to game usage, handling refunds and disputes.
- Improving the product: aggregate feature usage, error rates, and cost accounting.
- Support: answering your emails.
We do not sell personal data and we do not use your content to train AI models. Ad platforms only ever receive the website conversion signals described in Section 6, never your content or your identity.
5. Who we share data with
Service providers we use:
- Anthropic and Google (AI model APIs) — receive drafting-request content as described above.
- Google Firebase — authentication.
- Google (Gmail) — two separate things. Our outbound mail goes out through a Gmail account, so Google handles delivery of those messages and the addresses they go to. Separately, if you connect your own mailbox (Sections 2 and 3), the app reads it through Google's mail API with read-only access.
- Stripe — payments.
- Hetzner — hosts our server infrastructure in the EU.
- Cloudflare (website only) — sits in front of applyforpeople.com and caches the public pages and the app download files at its edge, so it handles those requests and the connection details that come with them, such as your IP address. The API address the app and the extension talk to is deliberately not routed through Cloudflare, so nothing from inside the app passes through it.
- Google Fonts (website only) — the website's pages load their two typefaces from Google's font servers, so Google receives the request for those files and the connection details that come with it, such as your IP address. The app and the extension do not load anything from Google Fonts.
- Google Analytics (website only) — visit and click statistics, as described in Section 6.
- Reddit (website only) — visit and ad-conversion signals from the advertising pixel on the site, as described in Section 6.
We may disclose information if required by law, or to protect the Service and its users (for example, investigating abuse). If AutoApply is ever acquired or transferred, account data would transfer with it under the same protections, and we'd tell you first.
6. The website and the launch list
This section covers applyforpeople.com only. The desktop app does none of this, and the website never sees your resume, your applications, or anything else from inside the app.
Analytics. The website uses Google Analytics to count visits and see which pages and buttons get used (page views, download clicks, demo plays, pricing views, signup clicks). Google sets identifiers in your browser and receives technical data such as your IP address and rough location as part of providing this service. We look at aggregate numbers, not identified individuals.
Ad measurement. We advertise AutoApply on other platforms (for example Reddit). If you arrive from an ad or a tagged link, the link's tags (a campaign label and a click id) are saved in your browser's local storage so we can tell which ad or post brought you here; if you later download the app or join the launch list, that source label is attached to the event. The site's home page and the resume-score page load Reddit's advertising pixel for every visitor, whether or not you arrived from an ad. It reports that a visit happened, plus two conversions (joining the launch list, and starting a download), tied to Reddit's click id when there is one, so we can tell which ads are worth running. Reddit processes that data under its own privacy policy.
Launch list and product updates. If you leave your email in the "tell me at launch" box on the website, or tick the optional product-updates checkbox in the app, we store that address plus where the signup came from (a campaign label, or the app). We use it only to send the updates you asked for. The list is never shared or sold.
Unsubscribing. Every email we send to that list carries an unsubscribe link that is unique to you. One click is the whole process: no account, no sign-in, no reply needed. Clicking it stops all future mail from us, and clicking it again changes nothing. The same instruction also travels in the message's headers, so your mail app's own unsubscribe button works. To come back later, email [email protected] from that address and we'll put you back on. Re-typing your address in the website box won't undo an unsubscribe, so nobody else can put you back on the list either. To have the address removed from our records altogether rather than marked as unsubscribed, email [email protected] and we'll delete it.
7. The browser extension
The AutoApply browser extension (Chrome) stores your profile and resume in your browser's extension storage, not on our servers. Matching your saved details to the boxes on a form happens in your browser. Your resume file never leaves your machine: the extension hands it straight to the page's own upload box.
When the extension uses AI to work out what belongs in a form, it sends a snapshot of that page together with your profile, through the same metering server described in Section 3. That snapshot is more than the single field being answered, so here is exactly what it contains:
- your profile as the extension holds it: name, contact details, address, education, work experience, projects, skills, any custom fields you added, and answers you typed on earlier applications that the extension saved to reuse;
- the form's fields and whatever values are currently sitting in them, plus any visible messages the page is showing (for example "enter a valid phone number");
- the address of the page you are on;
- an excerpt of the job description for the role you are applying to.
Password fields are the exception: they are stripped out before the request leaves your browser, so the model never receives them. The request passes through our server to the model provider and the answer comes back the same way. The content is not stored on our server; Section 3 describes the usage metadata that is recorded.
The extension sends a small fill report so we can keep quality up: the job site's hostname, how many fields were filled, asked, or failed, and how long the fill took. It never includes your answers, your profile, or the content of the form. The extension also periodically fetches a small remote configuration flag (a safety kill switch); that request carries no personal data.
The extension is installed with access to Greenhouse, Lever, and Ashby job pages plus our own two addresses. It can ask for access to other sites when you want it to work somewhere else; Chrome shows you that request and it only gets what you approve.
If you link the extension with the AutoApply desktop app, the desktop app hands it your profile, your custom fields, your resume, and your saved answer library, which as Section 2 explains can include EEO and demographic answers from earlier applications. If you separately grant the extension access to your saved site logins, it can also ask the desktop app for the login for the site you are on; that request returns one site's login, not the whole vault. That handoff happens directly between the two programs on your machine, over a local connection. It does not pass through our servers. Passes bought in the extension use the same account and Stripe checkout as everything else. The extension never submits an application for you.
8. Retention
Server-side records (account data, usage metadata, purchase records, feedback) are kept while your account exists and as long as needed for accounting, security, and legal obligations. AI request content is not stored on our servers, so there is nothing to retain. Local data on your device is yours and persists until you delete it.
Our control-plane database (accounts, passes, usage records) is snapshotted every night and the most recent 14 snapshots are kept on that same server, so a record we delete for you can still exist in a backup for up to two weeks afterward before it ages out.
9. Your choices and rights
- Access or delete your server-side data: email us and we'll show you what we have or delete your account and its records (purchase records may be retained where the law requires).
- Local data: it's on your machine and under your control.
- AI features, including the ones that run on their own: most AI work happens when you ask for it, but not all of it. While the app is running it also does AI work on a schedule: if you connected your mailbox, it checks your mail about every 10 minutes and sends a model the messages it can't sort out from the wording alone; if you turned autopilot on, it scores listings and drafts applications for you to review without you watching; and at most once a day it asks a model which employers to go look at next. All of that follows the same rules as the rest of this policy: the content goes through our metering server, we don't store it, and it isn't used to train models (Section 3). It only happens on your own computer, and only while AutoApply is running. Closing the window does not stop it by default: AutoApply keeps running in the tray so scheduled work keeps working. To stop all of it, quit from the tray icon, or turn background mode off in Settings so closing the window quits for real. Autopilot is off until you turn it on, and you can turn it back off in Settings; disconnecting your mailbox stops the mail reading. Our Terms of Service describe the same behavior from the other side, in the part about what the app does without you watching.
Depending on where you live (for example, the EU/EEA, UK, or California), you may have additional legal rights to access, correct, delete, or port your data, and to object to certain processing. Email us and we'll honor them.
10. Security
Traffic between the app, our server, and providers is encrypted in transit (HTTPS). Server access is restricted and administrative actions are logged. Your local data is protected by your operating system account — we recommend full-disk encryption and a strong OS password, as with any application that stores personal documents.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify you without undue delay.
11. Children
AutoApply is not directed to children under 16, and we do not knowingly collect data from them.
12. Changes
If this policy changes materially, we'll post the new version with a new effective date and note it in the app or on the website. Continued use after that means you accept the updated policy.
13. Contact
[email protected] — privacy questions, data requests, or anything else. I read every email.