Privacy policy
Out of a job posting you have open, this browser extension makes an adapted resume, a cover letter and a short list of people at that company.
What is collected
- Account. Your email address, and your name if you sign in through Google.
- Resume and profile. The file you upload and the profile taken out of it: employers, titles, dates, skills, education, links and the achievements you claimed.
- Job postings you run. The description text, the role title, the company and the page address, sent when you press Adapt my application.
- Results. The adapted resume, the cover letter, the requirement match and the people found for that posting.
- Preferences and settings. Target roles, location, work authorisation, output language, resume template, tone of the letter.
- Usage counters. How many runs you have used this month, so the free limit works.
- Diagnostics. The error text when a run fails or an upload cannot be opened, with no page address and nothing from your resume. Until you turn it on, the switch stays off, and with it off only the fact that it happened is kept.
- Plan. Free or Pro, and the date it changed. No payment provider is connected yet, so no card is asked for and none is held.
What is never collected
- Never your browsing history, and never the content of pages that are not job postings.
- Nor the personal email addresses and phone numbers of the people shown on the People tab.
- From a page you have open, no profile of anybody else is taken.
- While you are signed out, nothing at all, apart from three things about the sign-in code. Fifteen minutes later the address you typed is deleted with the code. Beside it stand two one-way hashes, one of that address and one of the address the request came from. They are there to count how many codes go out, and both are swept within the hour.
Why each item is needed
Behind every item above stands one purpose: building your application for the posting in front of you. Your resume becomes the rewrite and the letter. Counters run the free limit, and the diagnostics show which board changed its markup this week.
Whatever arrives through the Chrome Web Store is used in line with the Chrome Web Store User Data Policy, the Limited Use requirements included. From Google APIs the same holds: their User Data Policy applies, again with its Limited Use requirements.
Who else sees it
- Language model provider. Three things go there: the text of the resume file when it is read, the posting, and the parts of your profile a run needs. The file is read by the model, so its whole text is sent - including anything in it you would not have typed into the profile yourself. Which provider it is depends on the server this copy is pointed at, and what a provider does with what it receives is set by the agreement with them.
- Hosting. The company that runs the machine the service sits on. Errors are written to the service's own database and go to nobody else.
- The company you are applying to. When the People tab runs, the service fetches pages of that company's own website, and the text of those pages goes to the model so it can find the names on them. Nothing about you is sent to the company.
- A search index, where one is set up. The server may ask a search provider for public profiles matching the company and the role. That query carries the company name and the job title, and nothing about you.
People shown on the People tab
The names, the job titles and the links come from the posting itself, from pages the company publishes, and from a search index where one is set up. Personal contact details stay out of scope on every plan. Where a page does not belong to the company, or does not name it, it is dropped rather than shown.
How long it is kept
- Profile and resume. Until you delete them or the account is closed.
- Past runs. Kept until you delete the account.
- Diagnostics. The error text of a failed run or upload, kept until you delete the account.
- Backups. None yet, so a deletion removes the only copy.
Deleting your data
The delete data page removes the profile, the uploaded file, every past run and the account itself. At any time you can remove the extension from Chrome, and removing it stops all collection immediately.
Security
Resumes and profiles sit in a database on the service's own machine, reachable only by the account they belong to. When a person looks at them at all, it is to investigate a fault you reported or a case of abuse.
Between your browser and the server, traffic runs over TLS. At rest, the stored files are not encrypted.
Your rights
Write to hello@applyready.ai and the answer comes within 30 days.
- California residents may ask what is held, ask for a copy, ask for correction and ask for deletion, and may not be treated differently for asking.
- Nothing here is sold or shared for cross-context behavioural advertising.
- Residents of the European Economic Area and the United Kingdom hold the equivalent rights of access, correction, deletion, restriction, objection and portability.
Children
Nobody under 16 may use this service, and no account is knowingly created for anyone younger than that.
Changes
Should this policy change, it appears here with a new date. Anything that widens what is collected is announced by email before it takes effect.
Contact
hello@applyready.ai