Privacy Policy
Last updated: March 3, 2026
1. Overview
ApplyAI ("we", "our", or "us") operates the website apply-ai-extension.vercel.app and the ApplyAI Chrome browser extension (collectively, the "Service"). This Privacy Policy explains what data we collect, how we use it, and your rights regarding your data.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Data We Collect
2a. Account & Profile Information
When you create an account, we collect your email address and authentication credentials. Through the profile page you may optionally provide: full name, phone number, location (city, state, country), LinkedIn / GitHub / portfolio URLs, work authorization status, visa sponsorship preferences, and demographic information (gender, race, veteran status, disability status).
This information is used solely to pre-fill job application forms on your behalf via the browser extension.
2b. Resume
If you upload a resume (PDF, DOC, or DOCX), we store the file securely in Supabase Storage and parse it using an AI model (Google Gemini) to extract structured data: summary, skills, experience, education, certifications, and projects. This parsed data is stored in your profile and used to generate autofill answers.
2c. Job Application Data
When you use the extension to extract a job description, we store the job title, company, URL, and parsed job details (skills, requirements, keywords) in your account. We also store autofill run history (which fields were filled and with what values) for tracking and debugging purposes.
2d. Page Content (Temporary)
When you trigger a job extraction or autofill, the extension captures the HTML content of the active browser tab and sends it to our backend API for processing. This DOM content is used only to extract the job description or identify form fields, and is not stored permanently beyond what is needed to generate the autofill plan.
2e. Extension Authentication Token
A JWT authentication token is stored in chrome.storage.local on your device to keep you logged in to the extension. This token is never shared with third parties.
3. How We Use Your Data
- To authenticate you and secure your account
- To pre-fill job application forms using AI, based on your profile and resume
- To parse and store job descriptions you extract while browsing
- To score your resume against job descriptions
- To track your application pipeline (extracted → autofilled → applied)
- To improve autofill accuracy over time through internal analysis of run results
4. Third-Party Services
We use the following third-party services to operate the Service:
- Supabase — Database, authentication, and file storage. Data is stored in a Supabase-hosted PostgreSQL database and object storage.
- Google Gemini (generative AI) — Used to extract job description data from HTML, parse uploaded resumes, and generate autofill answers. Content sent to Gemini is subject to Google's Privacy Policy.
- Vercel — Hosts the web application. Subject to Vercel's Privacy Policy.
We do not use any third-party analytics, advertising, or tracking services (e.g. Google Analytics, Mixpanel, Facebook Pixel).
5. Data Sharing
We do not sell, trade, or transfer your personal data to third parties. Your data is only shared with the third-party service providers listed in Section 4, and only to the extent necessary to operate the Service.
6. Remote Code
The ApplyAI browser extension does not execute any remote code. All JavaScript executed by the extension is bundled within the extension package itself — no external scripts are loaded or evaluated at runtime.
7. Data Retention
We retain your data for as long as your account is active. You may delete your account at any time by contacting us (see Section 9). Upon deletion, your profile, resume, and job application data will be removed from our systems within 30 days.
8. Security
We use industry-standard security practices: HTTPS for all data in transit, Row Level Security (RLS) enforced at the database level so users can only access their own data, and short-lived JWT tokens for session management. No system is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
You have the right to access, correct, or delete the personal data we hold about you. To exercise these rights, or if you have any questions about this policy, please contact us at:
ApplyAI Team
Website: apply-ai-extension.vercel.app
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes your acceptance of the revised policy.