Privacy Policy

Effective date: 2026-09-26. This policy explains what data Apply Pilot stores, why each permission is needed, and how you can delete your data.

What Apply Pilot does

Apply Pilot is a job-search tracker. It helps you organize job applications, resumes, and follow-ups in one place. It can optionally read your mailbox to detect status updates about your applications (interview invites, rejections, offers). It never applies to jobs for you and never sends email on your behalf.

What data we store

Why each permission is needed

What we do NOT do: we never send, reply to, forward, or delete your emails. Email content is scanned locally for job keywords only and is never sent to any third party. Mailbox permissions are requested separately from sign-in, only when you connect a mailbox.

How data is protected

Mailbox credentials are encrypted at rest with Fernet (AES-128-CBC + HMAC). The encryption key is derived from the server's secret key, so it never sits in the database. Credentials are decrypted only inside the mail-sync process, used for one session, and never shown in the app or logs. Only you can see your data; the app isolates each account completely.

Data retention and deletion

Your data is kept while your account exists. You can delete your account and everything in it at any time: go to Settings → Delete my data and confirm. Deletion removes your account, resumes, applications, connected mailboxes and their encrypted credentials, and email metadata. You can also revoke mailbox access any time in your Google or Microsoft account security settings.

Contact

Questions about this policy or your data: support@apply-pilot.fly.dev

See also the Terms of Service.