Version: v2.3 • Last updated: 15 September 2026
AIAPPLY LIMITED (Company No. 15200716, registered office Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE) is the controller for most processing described here.
Contact: [email protected]
Our data protection contact can be reached at [email protected]
Mail: Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE
This Policy covers personal data processed via:
When you request AI-generated text (e.g. a cover letter), we send minimal prompt data to our model provider(s). We instruct them not to use prompts or outputs to train their models. Returned text is stored in your account only whilst you keep it or as needed to deliver the feature.
Job search & matching. Where your subscription includes job search & matching, we compare available roles against the info in your account & rank them by relevance, producing a Job Fit Score. This is profiling, but produces no legal or similarly significant effects about you: it decides the order roles are shown to you, & you decide which to apply for. With Search Only we don't submit anything on your behalf.
AutoApply. If you enable Auto-Submit (or approve a queued submission), we perform auto ranking, selection & form-filling at your request to execute your instructions. This doesn't produce legal or similarly significant effects about you by us; it automates tasks you'd otherwise perform. To avoid auto decisions, keep Review Mode enabled & decline submissions you don't want sent.
Interview Buddy may use third-party providers for speech-to-text (STT), large language model (LLM) generation, and evaluation/testing. Providers may change over time (for example: STT providers such as Deepgram or others; LLM providers such as OpenAI, Groq or others; and evaluation/testing frameworks similar to Braintrust). We select providers based on accuracy, latency, reliability, security and cost, and may route requests to the best available provider at the time.
Capture & transmission. Audio is captured on-device and streamed to an STT provider solely to create a text transcript.
Raw audio. We do not retain raw audio after transcription.
Transcripts. The text transcript is stored in our backend so that you can review your sessions. Transcripts remain in your account until you delete them or close your account (subject to backup purge timelines).
Purpose limitation. Transcripts processed only: (i) for real-time/post-session suggestions; (ii) to display in your account; (iii) for debugging/QA if you report an issue.
Testing & evaluation. For service improvement we may use anonymised, de-identified, or synthetic transcript data in automated tests. Where real transcripts used for bug reproduction, strict access controls apply & we use minimum necessary data.
Provider safeguards. Providers act as subprocessors under GDPR-compliant data-processing terms & are contractually prohibited from using your data for their own training or unrelated purposes. These providers are included in the list of service providers in Section 11.
International transfers. Where data leaves the UK, transfers are made under the safeguards described in Section 10.
Provider changes. We may change our service providers from time to time. Where we do, we'll update the list in Section 11, & we'll give notice of material changes affecting the processing of your personal data.
Your choices. Delete transcripts anytime from your account or by closing it. If you don't want audio processed by STT/LLM providers, don't enable microphone/transcription.
Application data transmitted to third-party platforms as you provide; we don't redact/mask fields on your behalf. Avoid including payment-card data, bank details, govt ID nos., health/biometric data or other special-category data unless a form explicitly requests it & you choose to provide it.
The AutoApply mailbox is retained whilst you hold any active Paid Service (as defined in our Terms of Service), & for 3 months after your last Paid Service ends or, if later, 3 months after your last successful payment for a Paid Service, & is then permanently deleted (non-recoverable). Save or forward any messages you wish to keep during that period.
We host personal data in the UK and European Economic Area. Our hosting and managed database services run in the UK and Finland regions of Google Cloud, and product analytics are processed on PostHog EU Cloud. Transfers to providers within the European Economic Area are covered by the UK's adequacy regulations and require no additional safeguard.
Some of our service providers are established outside the UK and European Economic Area and may access personal data in the course of providing their services to us. Our US service providers are certified under the UK Extension to the EU-U.S. Data Privacy Framework, and transfers to them are made under the adequacy regulations made under Article 45 of the UK GDPR. Where a provider is not certified under that framework, we rely on the UK Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, as set out in that provider's data processing agreement.
We don't sell or rent personal data. We share personal data with: (i) service providers acting on our instructions (incl. hosting, analytics, transcription, email delivery, evaluation/testing, and security, fraud-prevention and sanctions-screening providers); (ii) third-party platforms where you submit applications through the Services, whether by approving each match individually or under an authorisation you give us when you select Hybrid mode or Auto mode. This includes applicant tracking systems (ATS), job boards and recruitment platforms. These partners act as independent controllers of your personal data, meaning each platform decides for itself how it uses your data, under their own privacy policies, and not as our service providers; (iii) authorities where required by law or where we reasonably believe it's necessary to comply with legal or regulatory obligations; (iv) parties necessary to protect rights, enforce our terms or detect, investigate and prevent security issues, fraud or abuse; and (v) advertising platforms (currently Google Ads), where you've consented to audience matching, we share hashed identifiers (such as email address) solely to build and maintain advertising audiences. Google processes this data under its Ads Data Processing Terms. Google doesn't reveal matched identities to us.
Sub-processors. We engage the following service providers to process personal data on our instructions: Google Cloud (hosting and database services, UK and European Union), Cloudflare (edge protection, TLS and content delivery, United States), Microsoft Azure (large language model services, United States), Stripe (payment and subscription processing, United States), PostHog EU Cloud (product analytics, European Union), Sentry (error and performance monitoring, United States), Intercom (live chat and support, United States), Loops (transactional and marketing email delivery, United States), Migadu (email hosting for the dedicated AutoApply mailboxes, Switzerland and France), and AnyIP (proxy routing for application submissions, Singapore), together with the speech-to-text and model providers described in Section 7.
If you consent to marketing cookies, we may upload your SHA-256 hashed email to Google via its Data Manager service. Google matches hashed data against its accounts to place you in an ad audience. Withdraw consent anytime in account settings or by updating cookie preferences; we'll remove your data from the audience on next sync. For details, see How Google uses Customer Match data.
We use cookies & similar tech to operate and improve Services (e.g. session authentication, preferences, analytics). Manage preferences via our cookie banner or browser. On iOS we use on-device storage/Keychain; mobile app sets no ad cookies.
We only send marketing to individuals with consent or where soft opt-in applies (existing customer/negotiations + our own similar products/services + opt-out at collection and in every message). We maintain records of consent (who, when, how, what you were told).
We treat AIApply and The Download as separate lists; each requires its own consent and provides a separate unsubscribe. For corporate subscribers (many B2B addresses), different PECR rules may apply; we include identity and an easy opt-out in every message.
Segmentation & preferences. We may divide marketing lists using derived attributes from Section 3, so people receive only relevant communications. Segmentation determines who doesn't receive a message—it never creates a basis to send one. It produces no legal or similarly significant effect & isn't automated decision-making as described in Section 6.
Every marketing email links to a preference page where you can unsubscribe from all AIApply marketing or keep receiving updates whilst excluding invitations to particular programmes. You can also ask us to stop using your profile to decide which emails you're sent—a separate request from unsubscribing, made at [email protected]. Where we show information about our programmes inside the product rather than by email, the same controls apply.
Partner opportunities. Where we introduce invitations to services run by partner organisations, these will require their own separate opt-in consent, the partner will always be named in the message, and we will never pass your details to a partner unless you ask us to.
You may request access, correction, deletion, restriction, objection, or portability, and withdraw consent at any time: [email protected]. You may complain to a supervisory authority (UK ICO or your local authority).
We implement reasonable technical and organisational measures (access controls, network protections, encryption where appropriate). No method is infallible; we cannot guarantee absolute security.
The Services are not directed to those defined as minors in your jurisdiction. If you believe a child has provided us with personal data, email [email protected] so we can immediately delete it.
You may complain to us directly about our handling of your personal data. Section 164A of the Data Protection Act 2018 gives you the right to make such a complaint to us, and requires us to acknowledge it within 30 days and to tell you the outcome of our investigation. You can complain by emailing us at [email protected], or by writing to [email protected].
You have the right to lodge a complaint with your local data-protection authority. In the United Kingdom this is the Information Commissioner's Office (ICO). We encourage you to contact us first so we can try to resolve your concern.
We may update this Policy; changes posted with new "Last updated" date. Material changes will include extra notice/consent where legally required.
We're not responsible for external sites' content or privacy practices.