1. Information We Collect
We collect information you provide directly, information generated while using the platform, and limited data from approved integrations.
- Account data: Name, email, profile preferences, optional career profile details.
- Resume and career documents: Uploaded resumes/CVs and parsed profile signals used for tailoring and matching.
- Job pipeline data: Applications, interview stages, notes, recruiter contacts, and status history.
- Gmail integration data: Read-only processing of job-related emails for pipeline updates. Email bodies are processed and not permanently stored.
- LinkedIn integration data: OAuth-authorized posting and profile scopes needed for LinkedIn automation features.
- Extension activity: Job-page extraction and application-assist interactions on supported job sites.
- Company account data: Company name, owner/admin details, team structure, and role-level access metadata.
- Billing metadata: Subscription and customer identifiers from Stripe (no raw card storage by us).
- Usage telemetry: Feature usage, analytics events, and diagnostics for product reliability and improvement.
2. How We Use Data
- Provide job discovery, tracking, and workflow automation features.
- Generate AI-assisted resume, email, and outreach drafts that you can review before sending.
- Power recruiter discovery and role matching flows, including C2C workflows.
- Operate connected integrations (Gmail, LinkedIn, extension features).
- Send essential service communications, alerts, and support responses.
- Maintain security, prevent abuse, and improve platform quality.
3. AI Features and Agent Usage
Apply&Connect uses Google Gemini models for content generation and classification tasks. AI features include:
- Resume tailoring and cover-letter draft generation.
- C2C role classification and recruiter outreach draft generation.
- LinkedIn post draft generation and publishing assistance.
- Career assistant chat and context-based suggestions.
AI output is presented for review. No outbound message is sent without explicit user action.
4. Third-Party Services
We use trusted third-party service providers to operate and deliver our platform features, including:
- Authentication and identity: Secure sign-in and account management services.
- AI and language models: Content generation, classification, and intelligent assistance.
- Cloud infrastructure: Hosting, data storage, and application services.
- Payment processing: Subscription and billing operations (no raw card data stored by us).
- Email delivery: Transactional and service communication delivery.
- Job data sources: Aggregated public job listings for discovery features.
- Connected integrations: Gmail and LinkedIn APIs used only when you grant OAuth access.
All providers are selected for their security practices, compliance posture, and data handling standards.
5. Sharing and Disclosure
We do not sell personal data. We only share data when required to run the service, comply with law, or when you direct us to do so.
6. Browser Extension Permissions
The extension requests permissions needed to operate job-page assistance (active tab, scripting, storage, tabs, notifications, and supported job-site host permissions).
7. Data Security
We apply standard security controls including encrypted transport, encryption at rest through providers, role-based access controls, and authenticated API access.
8. Data Retention
Data is retained while your account remains active and for a limited period as needed for legal, security, and operational requirements. You may request deletion from Settings.
9. Your Rights and Controls
- Access and correction of account information.
- Account deletion requests.
- Integration revocation for Gmail/LinkedIn.
- Communication preferences and opt-out controls.
10. Company Accounts and Team Access
Company owners can provision team users. Role-based access is enforced. Personal career artifacts for individual users are not broadly exposed to all team members by default.
11. International Transfers
Data may be processed in the United States on cloud infrastructure operated by our service providers.
12. Children's Privacy
Our services are intended for professional users and not directed to children under 13.
13. Policy Updates
We may update this policy periodically. Material changes will be communicated through in-app or email notice where required.