Privacy Policy
Last updated: August 30, 2026
SmartApply.now (“SmartApply.now”, “we”, “us”) provides an AI-assisted job-hunting tool at smartapply.now. This policy explains what we collect, how we use it, who we share it with, and the choices you have.
Information we collect
- Account details — your email address and name, and (for social login) the basic profile and avatar shared by Google, GitHub, or Facebook.
- Profile you build — work history, skills, education, languages, personal projects, cover-letter preferences, and any resume file you upload.
- Job and application data — jobs you search for, save, or import, their match scores, generated cover letters and resumes, and application status.
- Network data — if you import a LinkedIn connections file, we store those connections to suggest warm introductions. The raw file itself is parsed in your browser and not retained.
- Your AI provider key(s) — you supply your own key for whichever AI provider(s) you use (Gemini, Claude, Mistral, OpenAI, and/or Grok). Each is encrypted before storage and never shown back to you or to administrators (see “Security”).
- Usage data — product analytics events and basic technical logs used to operate and improve the service.
How we use your information
- To provide the service: search jobs, score matches, research companies, and generate tailored cover letters and resumes.
- To run AI features on your own AI provider account using whichever key you provide for that feature — see “AI processing” below.
- To send transactional emails (account verification, approval, and notifications).
- To understand product usage and improve the app.
We do not sell your personal data.
AI processing (your own key)
Every AI feature runs on your own key for the AI provider it uses — Google (Gemini) by default, or Anthropic (Claude), Mistral, OpenAI, or xAI (Grok) if you choose one of those for a given feature in Settings. When you generate a match score, cover letter, resume, or company research, the relevant profile and job text is sent to that provider under your own account and is governed by that provider's own terms and privacy policy. We do not use your data to train models.
Service providers we share data with
We use trusted processors to run the service. Each receives only the data needed for its function:
- InsForge — database, authentication, and file storage (hosting your account, profile, and resume files).
- Google (Gemini), Anthropic (Claude), Mistral, OpenAI, xAI (Grok) — AI generation, via your own API key for whichever provider you use.
- PostHog — product analytics.
- Resend — transactional email delivery.
- Google, GitHub, Facebook — optional social sign-in.
- Job-board providers (e.g. Adzuna, Jooble, CareerJet) — to return search results when you search for jobs.
Chrome extension
The SmartApply.now Chrome extension saves the job posting on your current tab to your SmartApply.now pipeline. It only reads the page you are on when you click the extension's icon (using Chrome's activeTab permission) — it does not run in the background or read any other tabs.
- What it reads — the URL of the active tab, and, only if SmartApply.now's server cannot fetch that page itself (e.g. it requires login or blocks automated access), the visible text of that one page.
- What it sends — that URL (and, when needed, the page text) to SmartApply.now's import endpoint, exactly like pasting a job URL into the web app.
- What it stores — your sign-in session (access and refresh tokens) in Chrome's local extension storage, on your device only. Signing in with Google uses SmartApply.now's existing Google sign-in flow; the extension never sees your Google password.
The extension does not track your browsing, does not read pages you have not explicitly imported, and shares data with the same processors listed above — no additional third parties.
Cookies
We use strictly necessary cookies to keep you signed in and to remember your session and approval status — these are always on and disabling them will prevent sign-in. Analytics cookies (PostHog) are set only if you accept them in the cookie banner on your first visit; you can change that choice any time via the “Cookie settings” link in the footer, or through your browser settings.
Data retention and deletion
We keep your data for as long as your account is active. You can permanently delete your entire account and all associated data yourself at any time from Settings → Danger Zone → Delete account — this takes effect immediately, with no waiting period. If you cannot sign in, you may request deletion by contacting us at admin@smartapply.now. If you remove SmartApply.now from your Facebook account, Facebook notifies us and we act on that de-authorization.
Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact admin@smartapply.now.
Security
Data is protected with row-level security so each user can only access their own records. Your Anthropic API key is encrypted with AES-256-GCM before it is stored and is never returned to the browser or visible to administrators. No system is perfectly secure, but we take reasonable measures to protect your information.
Children
SmartApply.now is not directed to children under 16, and we do not knowingly collect their personal data.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the date at the top of this page.
Contact
Questions about this policy or your data? Email admin@smartapply.now.