Privacy Policy

Effective date: September 6, 2026 ยท Version 1

This policy explains what EasyApply ([Your legal name], doing business as EasyApply, "we", "us") collects when you use the web application and browser extension (the "Service"), why, who we share it with, and the choices you have. It applies together with our Terms of Service.

In short: the Service exists to fill job applications from a profile you build, so it necessarily handles the personal data you would put on a job application. We use it only to run the Service for you. We do not sell it and we do not use it for advertising.

1. Data we collect

Account data

  • Sign-up details: your name and email address, plus a hashed password if you sign up with email. If you sign in with Google or LinkedIn we receive your name, email, and profile picture from that provider and store the provider's account identifier and access tokens needed to complete sign-in.
  • Session data: when you sign in we record the IP address and browser user agent of the session. Sessions last up to six months unless you sign out.

Profile data you provide

  • Applicant profiles: first and last name, email, phone number, location, LinkedIn/GitHub/website links, skills, years of experience, work history, and education. You can keep several profiles.
  • CVs: the PDF files you upload. We extract the text to pre-fill your profile, and the file itself is attached to applications you fill.

Application and tracker data

  • Form fills: when you ask the extension to fill an application, it reads the structure of the form on the page (field labels, types, and options, not unrelated page content) and sends it with your chosen profile to our servers. We store the request and the generated answers as your fill history.
  • Job posts: the job title, company, URL, description, location, salary information, your application status and date, the answers you submitted, and any notes you write. Job posts are captured automatically when the extension detects that you submitted an application (you can turn this off in the extension), or added by you manually or from a URL.
  • AI processing logs: for each AI request we record the model used, token counts, and cost. If a request fails we also keep the prompt and raw response for debugging.

Data the extension accesses in your browser

The extension requests permission to run on all sites so it can recognise supported application forms wherever they are hosted (currently Ashby, BambooHR, Greenhouse, iCIMS, Lever, and SmartRecruiters). It only acts on pages it recognises as an application form. It does not record your browsing history and does not send page content to us except the form data described above, when you fill or save an application. It reads our own sign-in cookie to authenticate with our servers and stores your extension settings locally in the browser.

Cookies and local storage

We use strictly necessary cookies: a session cookie that keeps you signed in and a companion cookie that lets the web app and extension know whether you are signed in. We store your theme preference in browser storage. We do not use advertising or analytics cookies.

2. How we use data

  • To create and secure your account and keep you signed in across the web app and extension.
  • To fill application forms from your profile and to draft answers to application questions.
  • To extract profile information from your CV and details from job post pages.
  • To keep your application tracker in sync across your devices in real time.
  • To diagnose failures, monitor AI costs, and improve reliability.
  • To respond to your support requests and to notify you of important changes to the Service.

Where the GDPR or similar laws apply, we process your data to perform our contract with you (running the Service), for our legitimate interests in keeping the Service secure and reliable, and, for optional features such as auto-saving applications, on the basis of the settings you choose.

3. Who we share data with

We share data only with providers that help us run the Service, under their data-processing terms:

  • AI providers. To extract CV data, draft form answers, and parse job posts we send the relevant text (CV text, profile details, form structure, and job page content) to large language model providers. We currently use OpenAI, and our systems can also use Anthropic and Google. Under the API terms we use, these providers do not train their models on the data; they may retain it briefly (typically up to 30 days) for abuse monitoring.
  • Hosting and storage. Our database, real-time sync service, and file storage for CVs run on infrastructure in the United States.
  • Sign-in providers. Google and LinkedIn, if you choose to sign in with them.
  • Google Maps. The location field in your profile uses Google's Places autocomplete; the text you type there is sent to Google. The public landing page also loads fonts from Google Fonts.
  • Career sites. When you submit an application, the data goes to the employer's site under that site's own privacy policy, not ours.

We may also disclose data if required by law, or as part of a merger or acquisition (in which case this policy will continue to apply to your data). We do not sell personal data.

4. Retention

  • Account, profile, and tracker data are kept for as long as your account exists.
  • Profiles, CVs, and job posts you delete are removed from the app immediately; CV files may be retained in storage for a short period before permanent deletion.
  • AI processing logs are kept for diagnostics and cost monitoring.
  • When your account is deleted we delete your data within 30 days, except where we must keep it for legal reasons.

5. Your rights and choices

  • You can view and edit your profiles, CVs, and job posts, and delete them, in the app.
  • You can turn off automatic saving of submitted applications in the extension's settings.
  • To access a copy of your data, correct it, or delete your account entirely, email support@easy-apply.com. We will respond within 30 days.
  • Depending on where you live you may have additional rights (for example to object to or restrict processing, to data portability, or to lodge a complaint with a supervisory authority).

6. Security

Data is encrypted in transit. Passwords are stored hashed. Access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.

7. International transfers

Our infrastructure and providers may process data outside your country. Where required we rely on appropriate safeguards such as standard contractual clauses.

8. Children

The Service is not directed to people under 18, and we do not knowingly collect their data.

9. Changes

We will post updates to this policy here and change the effective date. For material changes we will notify you in the app or by email.

10. Contact

Privacy questions or requests: support@easy-apply.com.