Privacy Policy
Effective date: 2026-09-26. This policy explains what
data Apply Pilot stores, why each permission is needed, and how you
can delete your data.
What Apply Pilot does
Apply Pilot is a job-search tracker. It helps you
organize job applications, resumes, and follow-ups in one place. It
can optionally read your mailbox to detect status updates about your
applications (interview invites, rejections, offers). It never
applies to jobs for you and never sends email on your behalf.
What data we store
- Account info. Your email address, a salted hash
of your password (never the password itself), and your settings
and preferences.
- Job search data. The jobs you save, your
applications, their statuses and timelines, interviews, offers,
notes, and recruiter contacts you add.
- Profile and resumes. Your profile details and
the resumes you upload or generate, plus your attestations when
you confirm a fact about yourself.
- Browser extension. After it fills a form, the
extension reports how complete the fill was: counts, the kind of
application site and the wording of the form's questions it could
not answer. It never sends the answers you type.
- Connected mailboxes. If you connect a mailbox:
your mailbox address and provider, and an encrypted credential
(app password or OAuth refresh token) used only to read mail.
- What the operator can see. To support you, the
person who runs this Apply Pilot can see your account activity: your
name and email, counts (matches, resumes prepared, applications,
replies, interviews) and the list of roles you track with each role's
company, stage and dates. They cannot see your resume text, cover
letters, form answers or the content of your email from that
view.
- Forwarded mail. If you forward job emails to
your personal Apply Pilot address, those messages arrive in a
mailbox operated by Apply Pilot. Only what you choose to forward
arrives there; it is used only to track your job search.
- Email metadata. For connected mailboxes we
keep subject, sender, date, and a short snippet (first ~500
characters) of messages that look job-related, plus our
classification of them. Full message bodies are not stored, with
one exception: when a recruiter emails you a job requirement, its
text (up to about 6,000 characters) is saved as a job in your
account so it can be matched and applied to. It is never shared
with other users.
Why each permission is
needed
- openid and email (Google sign-in). To identify
you and create your account. Asked at signup/login only.
- profile (Google sign-in). To show your name in
the app. Asked at signup/login only.
- gmail.readonly (Google mailbox, optional).
Lets Apply Pilot read your emails so it can detect job-related
messages and surface application status updates. Connected only
when you explicitly choose to, after login, in a separate
permission screen.
- Mail.Read (Microsoft mailbox, optional). Same
purpose as gmail.readonly, for Outlook mailboxes.
- User.Read (Microsoft mailbox, optional).
Identifies which mailbox belongs to you when connecting it.
- offline_access (Microsoft mailbox, optional).
Lets Microsoft issue a refresh token so the app can keep checking
for new job emails without asking you to sign in every time.
What we do NOT do: we
never send, reply to, forward, or delete your emails. Email content
is scanned locally for job keywords only and is never sent to any
third party. Mailbox permissions are requested separately from
sign-in, only when you connect a mailbox.
How data is protected
Mailbox credentials are encrypted at rest with
Fernet (AES-128-CBC + HMAC). The encryption key is derived from the
server's secret key, so it never sits in the database. Credentials
are decrypted only inside the mail-sync process, used for one
session, and never shown in the app or logs. Only you can see your
data; the app isolates each account completely.
Data retention and
deletion
Your data is kept while your account
exists. You can delete your account and everything in it at any
time: go to Settings → Delete my data and
confirm. Deletion removes your account, resumes, applications,
connected mailboxes and their encrypted credentials, and email
metadata. You can also revoke mailbox access any time in your
Google or Microsoft account security settings.
Contact
Questions about this policy or your data:
support@apply-pilot.fly.dev
See also the Terms of Service.