Version: v2.3 • Last updated: 15 September 2026
AIAPPLY LIMITED (Company No. 15200716, registered office Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE) is the controller for most processing described here.
Contact: [email protected]
Our data protection contact can be reached at [email protected]
Mail: Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE
This Policy covers personal data processed via:
When you request AI-generated text (e.g., a cover letter), we send the minimum necessary prompt data to our model provider(s). We instruct them not to use prompts or outputs to train their models. Returned text is stored in your account only as long as you keep it or as needed to deliver the feature.
Job search and matching. Where your subscription includes job search and matching, we compare available roles against the information in your account and rank them by relevance, producing a Job Fit Score. This is profiling, but it produces no legal or similarly significant effects about you: it decides the order in which roles are shown to you, and you decide which to apply for. With Search Only we do not submit anything on your behalf.
AutoApply. If you enable Auto-Submit (or approve a queued submission), we perform automated ranking, selection and form-filling at your request to execute your instructions. This does not produce legal or similarly significant effects about you by us; it automates tasks you would otherwise perform. To avoid automated decisions, keep Review Mode enabled and decline submissions you do not want sent.
Interview Buddy may use third-party providers for speech-to-text (STT), large language model (LLM) generation, and evaluation/testing. Providers may change over time (for example: STT providers such as Deepgram or others; LLM providers such as OpenAI, Groq or others; and evaluation/testing frameworks similar to Braintrust). We select providers based on accuracy, latency, reliability, security and cost, and may route requests to the best available provider at the time.
Capture & transmission. Audio is captured on-device and streamed to an STT provider solely to create a text transcript.
Raw audio. We do not retain raw audio after transcription.
Transcripts. The text transcript is stored in our backend so that you can review your sessions. Transcripts remain in your account until you delete them or close your account (subject to backup purge timelines).
Purpose limitation. Transcripts are processed only: (i) to generate real-time or post-session suggestions; (ii) to display to you in your account; (iii) for debugging and quality assurance if you report an issue.
Testing & evaluation. For service improvement we may use anonymised, de-identified, or synthetic transcript data in automated tests. Where real transcripts are used for bug reproduction, we apply strict access controls and use the minimum necessary data.
Provider safeguards. Providers act as subprocessors under GDPR-compliant data-processing terms and are contractually prohibited from using your data for their own training or unrelated purposes. These providers are included in the list of service providers in Section 11.
International transfers. Where data leaves the UK, transfers are made under the safeguards described in Section 10.
Provider changes. We may change our service providers from time to time. Where we do, we will update the list in Section 11, and we will give notice of material changes affecting the processing of your personal data.
Your choices. You may delete transcripts at any time from within your account or by closing your account. If you do not want audio processed by STT/LLM providers, please do not enable microphone/transcription.
Application data is transmitted to third-party platforms as provided by you; we do not redact or mask fields on your behalf. Avoid including payment-card data, bank details, government ID numbers, health/biometric data or other special-category data unless a form explicitly requests it and you choose to provide it.
The AutoApply mailbox is retained while you hold any active Paid Service (as defined in our Terms of Service), and for 3 months after your last Paid Service ends or, if later, 3 months after your last successful payment for a Paid Service, and is then permanently deleted (non-recoverable). Save or forward any messages you wish to keep during that period.
We host personal data in the United Kingdom and the European Economic Area. Our hosting and managed database services run in the United Kingdom and Finland regions of Google Cloud, and product analytics are processed on PostHog EU Cloud. Transfers to providers within the European Economic Area are covered by the United Kingdom's adequacy regulations and require no additional safeguard.
Some of our service providers are established outside the United Kingdom and the European Economic Area and may access personal data in the course of providing their services to us. Our US service providers are certified under the UK Extension to the EU-U.S. Data Privacy Framework, and transfers to them are made under the adequacy regulations made under Article 45 of the UK GDPR. Where a provider is not certified under that framework, we rely on the UK Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, as set out in that provider's data processing agreement.
We do not sell or rent personal data. We share personal data with: (i) service providers acting on our instructions (including hosting, analytics, transcription, email delivery, evaluation/testing, and security, fraud-prevention and sanctions-screening providers); (ii) third-party platforms where you submit applications through the Services, whether by approving each match individually or under an authorisation you give us when you select Hybrid mode or Auto mode. This includes applicant tracking systems (ATS), job boards and recruitment platforms. These partners act as independent controllers of your personal data, meaning each platform decides for itself how it uses your data, under their own privacy policies, and not as our service providers; (iii) authorities where required by law or where we reasonably believe it is necessary to comply with legal or regulatory obligations; (iv) parties necessary to protect rights, enforce our terms or detect, investigate and prevent security issues, fraud or abuse; and (v) advertising platforms (currently Google Ads), where you have consented to audience matching, we share hashed identifiers (such as email address) solely to build and maintain advertising audiences. Google processes this data under its Ads Data Processing Terms. Google does not reveal matched identities to us.
Sub-processors. We engage the following service providers to process personal data on our instructions: Google Cloud (hosting and database services, United Kingdom and European Union), Cloudflare (edge protection, TLS and content delivery, United States), Microsoft Azure (large language model services, United States), Stripe (payment and subscription processing, United States), PostHog EU Cloud (product analytics, European Union), Sentry (error and performance monitoring, United States), Intercom (live chat and support, United States), Loops (transactional and marketing email delivery, United States), Migadu (email hosting for the dedicated AutoApply mailboxes, Switzerland and France), and AnyIP (proxy routing for application submissions, Singapore), together with the speech-to-text and model providers described in Section 7.
If you consent to marketing cookies, we may upload your SHA-256 hashed email address to Google through its Data Manager service. Google matches hashed data against its own accounts to place you in an advertising audience. You can withdraw consent at any time in your account settings or by updating your cookie preferences; we will remove your data from the audience on the next sync cycle. For details, see How Google uses Customer Match data.
We use cookies and similar technologies to operate and improve the Services (e.g., session authentication, preferences, analytics). Manage preferences via our cookie banner or your browser. On iOS we use on-device storage/Keychain; the mobile app sets no advertising cookies.
We only send marketing to individuals with consent or where soft opt-in applies (existing customer/negotiations + our own similar products/services + opt-out at collection and in every message). We maintain records of consent (who, when, how, what you were told).
We treat AIApply and The Download as separate lists; each requires its own consent and provides a separate unsubscribe. For corporate subscribers (many B2B addresses), different PECR rules may apply; we include identity and an easy opt-out in every message.
Segmentation and preferences. We may divide our marketing lists using the derived attributes described in Section 3, so that people receive only the communications likely to be relevant to them. Segmentation decides who does not receive a message. It never creates a basis to send one. It produces no legal or similarly significant effect and is not automated decision-making of the kind described in Section 6.
Every marketing email links to a preference page where you can unsubscribe from all AIApply marketing, or keep receiving our updates while excluding invitations to particular programmes. You can also ask us to stop using your profile to decide which emails you are sent, which is a separate request from unsubscribing and can be made at [email protected]. Where we show you information about our programmes inside the product rather than by email, the same controls apply.
Partner opportunities. Where we introduce invitations to services run by partner organisations, these will require their own separate opt-in consent, the partner will always be named in the message, and we will never pass your details to a partner unless you ask us to.
You may request access, correction, deletion, restriction, objection, or portability, and withdraw consent at any time: [email protected]. You may complain to a supervisory authority (UK ICO or your local authority).
We implement reasonable technical and organisational measures (access controls, network protections, encryption where appropriate). No method is infallible; we cannot guarantee absolute security.
The Services are not directed to those defined as minors in your jurisdiction. If you believe a child has provided us with personal data, email [email protected] so we can immediately delete it.
You may complain to us directly about our handling of your personal data. Section 164A of the Data Protection Act 2018 gives you the right to make such a complaint to us, and requires us to acknowledge it within 30 days and to tell you the outcome of our investigation. You can complain by emailing us at [email protected], or by writing to [email protected].
You have the right to lodge a complaint with your local data-protection authority. In the United Kingdom this is the Information Commissioner's Office (ICO). We encourage you to contact us first so we can try to resolve your concern.
We may update this Policy; we will post changes with a new “Last updated” date. Where required by law, material changes will be accompanied by additional notice or consent.
We are not responsible for the content or privacy practices of external sites we link to.