1. Who we are; contact

AIAPPLY LIMITED (Company No. 15200716, registered office Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE) is the controller for most processing described here.

Contact: [email protected]
Our data protection contact can be reached at [email protected]
Mail: Suite 4, New Humberstone House, 40 Thurmaston Lane, Leicester, United Kingdom, LE5 0TE

2. Scope

This Policy covers personal data processed via:

  • the Website, web/desktop apps, and mobile apps,
  • the browser extension,
  • Interview Buddy (transcription/real-time suggestions),
  • job search and matching (including Search Only), and AutoApply (automated applications and submissions),
  • marketing communications (including AIApply updates, invitations to optional AIApply programmes, and The Download newsletter).

3. Data we collect

  • Account & contact data: name, email, country, preferences.
  • Job-search materials: CVs/résumés, cover letters, job descriptions, role preferences.
  • Interview Buddy data: audio streams (real-time), transcripts, session metadata.
  • AutoApply data: prompts, drafts, submissions, application content, mailbox contents and metadata, including correspondence sent to you by employers and recruiters.
  • Technical/usage data: device/browser, IP address, event logs, diagnostics.
  • Marketing preferences: brand-level opt-ins (AIApply / The Download), unsubscribes, programme-level exclusions, and objections to profiling.
  • Derived attributes: limited, non-sensitive indicators of the professional or technical field you work in or are looking for work in, of your level and subject of qualification, and of whether your background includes research experience, for example whether the job titles, skills, qualifications, employers, institutions or industry preferences held on your account fall within a science, technology, engineering or mathematics discipline. These come from the structured details held in your account, whether you entered them yourself or they were taken from your CV, all of which we show in your account where you can review, edit or delete them. For this purpose we use only those structured account fields. We never use for this purpose: your Interview Buddy transcripts; the free-text parts of your CV or cover letters; or anything you have told us about your health or disability, ethnicity, nationality, sexual orientation, gender identity, veteran status or employment situation.

4. How we use data; legal bases

  • Provide and secure the Services (contractual necessity; legitimate interests).
  • Job search and matching (contractual necessity): we compare available roles against your CV, job titles, locations and filters, rank them by relevance, and show or send you the results. This applies to every subscription that includes job search and matching, including Search Only.
  • AutoApply automation (contractual necessity): where you use AutoApply, automated ranking, selection and form-filling at your direction; see Section 6.
  • Interview Buddy (contractual necessity/legitimate interests): generate suggestions; create and display transcripts for your account.
  • Improve reliability & abuse-prevention (legitimate interests): we may use aggregated/de-identified telemetry (e.g., error rates, provider responsiveness, anonymised prompt patterns).
  • Marketing (consent or soft opt-in, where permitted; legitimate interests for corporate subscribers).
  • Deciding which marketing is relevant to you (legitimate interests): where you already receive marketing from us, we may use the derived attributes described in Section 3 to decide which of our optional communications are relevant to you, so that you receive fewer and better-targeted messages rather than everything we send. This creates no new permission to market to you. If you have not opted in, we do not send you marketing, and this has no effect on you. You may object to this use at any time by writing to [email protected], and you may unsubscribe from marketing at any time whether or not you object.
  • Creating anonymous information (legitimate interests): we may convert personal data we hold into anonymous information, such as aggregate statistics about roles, skills, salaries and hiring trends. Before treating information as anonymous we assess whether anyone could reasonably identify an individual from it, alone or combined with other information they are likely to have, and we document that assessment. Once information is genuinely anonymous it is no longer personal data, this Policy no longer applies to it, and we may use and share it, including commercially. We do not sell personal data.
  • Advertising audience matching (consent): with your consent (via our cookie banner), we share your hashed email address with Google Ads to include you in advertising audiences. This allows us to show you relevant ads or exclude you from acquisition campaigns. You may withdraw consent at any time via your account settings or by updating your cookie preferences.
  • Compliance, security and fraud prevention (legal obligations and legitimate interests): including detecting, investigating and preventing misuse of the Services, identity misrepresentation, identity rental, sanctions-related risks, export-control violations, automated abuse, suspicious activity and security incidents. For these purposes, we may process technical and usage data such as IP address, approximate location, device information, timestamps and behavioural patterns.

5. Model providers; AI processing

When you request AI-generated text (e.g., a cover letter), we send the minimum necessary prompt data to our model provider(s). We instruct them not to use prompts or outputs to train their models. Returned text is stored in your account only as long as you keep it or as needed to deliver the feature.

6. Automated matching & profiling (job search and AutoApply)

Job search and matching. Where your subscription includes job search and matching, we compare available roles against the information in your account and rank them by relevance, producing a Job Fit Score. This is profiling, but it produces no legal or similarly significant effects about you: it decides the order in which roles are shown to you, and you decide which to apply for. With Search Only we do not submit anything on your behalf.

AutoApply. If you enable Auto-Submit (or approve a queued submission), we perform automated ranking, selection and form-filling at your request to execute your instructions. This does not produce legal or similarly significant effects about you by us; it automates tasks you would otherwise perform. To avoid automated decisions, keep Review Mode enabled and decline submissions you do not want sent.

7. Audio capture, speech-to-text & model providers (Interview Buddy)

Interview Buddy may use third-party providers for speech-to-text (STT), large language model (LLM) generation, and evaluation/testing. Providers may change over time (for example: STT providers such as Deepgram or others; LLM providers such as OpenAI, Groq or others; and evaluation/testing frameworks similar to Braintrust). We select providers based on accuracy, latency, reliability, security and cost, and may route requests to the best available provider at the time.

Capture & transmission. Audio is captured on-device and streamed to an STT provider solely to create a text transcript.

Raw audio. We do not retain raw audio after transcription.

Transcripts. The text transcript is stored in our backend so that you can review your sessions. Transcripts remain in your account until you delete them or close your account (subject to backup purge timelines).

Purpose limitation. Transcripts are processed only: (i) to generate real-time or post-session suggestions; (ii) to display to you in your account; (iii) for debugging and quality assurance if you report an issue.

Testing & evaluation. For service improvement we may use anonymised, de-identified, or synthetic transcript data in automated tests. Where real transcripts are used for bug reproduction, we apply strict access controls and use the minimum necessary data.

Provider safeguards. Providers act as subprocessors under GDPR-compliant data-processing terms and are contractually prohibited from using your data for their own training or unrelated purposes. These providers are included in the list of service providers in Section 11.

International transfers. Where data leaves the UK, transfers are made under the safeguards described in Section 10.

Provider changes. We may change our service providers from time to time. Where we do, we will update the list in Section 11, and we will give notice of material changes affecting the processing of your personal data.

Your choices. You may delete transcripts at any time from within your account or by closing your account. If you do not want audio processed by STT/LLM providers, please do not enable microphone/transcription.

8. “As-provided” transmission; restricted data

Application data is transmitted to third-party platforms as provided by you; we do not redact or mask fields on your behalf. Avoid including payment-card data, bank details, government ID numbers, health/biometric data or other special-category data unless a form explicitly requests it and you choose to provide it.

9. Mailbox retention (AutoApply)

The AutoApply mailbox is retained while you hold any active Paid Service (as defined in our Terms of Service), and for 3 months after your last Paid Service ends or, if later, 3 months after your last successful payment for a Paid Service, and is then permanently deleted (non-recoverable). Save or forward any messages you wish to keep during that period.

10. International transfers

We host personal data in the United Kingdom and the European Economic Area. Our hosting and managed database services run in the United Kingdom and Finland regions of Google Cloud, and product analytics are processed on PostHog EU Cloud. Transfers to providers within the European Economic Area are covered by the United Kingdom's adequacy regulations and require no additional safeguard.

Some of our service providers are established outside the United Kingdom and the European Economic Area and may access personal data in the course of providing their services to us. Our US service providers are certified under the UK Extension to the EU-U.S. Data Privacy Framework, and transfers to them are made under the adequacy regulations made under Article 45 of the UK GDPR. Where a provider is not certified under that framework, we rely on the UK Addendum to the EU Standard Contractual Clauses, or the International Data Transfer Agreement, as set out in that provider's data processing agreement.

11. Sharing

We do not sell or rent personal data. We share personal data with: (i) service providers acting on our instructions (including hosting, analytics, transcription, email delivery, evaluation/testing, and security, fraud-prevention and sanctions-screening providers); (ii) third-party platforms where you submit applications through the Services, whether by approving each match individually or under an authorisation you give us when you select Hybrid mode or Auto mode. This includes applicant tracking systems (ATS), job boards and recruitment platforms. These partners act as independent controllers of your personal data, meaning each platform decides for itself how it uses your data, under their own privacy policies, and not as our service providers; (iii) authorities where required by law or where we reasonably believe it is necessary to comply with legal or regulatory obligations; (iv) parties necessary to protect rights, enforce our terms or detect, investigate and prevent security issues, fraud or abuse; and (v) advertising platforms (currently Google Ads), where you have consented to audience matching, we share hashed identifiers (such as email address) solely to build and maintain advertising audiences. Google processes this data under its Ads Data Processing Terms. Google does not reveal matched identities to us.

Sub-processors. We engage the following service providers to process personal data on our instructions: Google Cloud (hosting and database services, United Kingdom and European Union), Cloudflare (edge protection, TLS and content delivery, United States), Microsoft Azure (large language model services, United States), Stripe (payment and subscription processing, United States), PostHog EU Cloud (product analytics, European Union), Sentry (error and performance monitoring, United States), Intercom (live chat and support, United States), Loops (transactional and marketing email delivery, United States), Migadu (email hosting for the dedicated AutoApply mailboxes, Switzerland and France), and AnyIP (proxy routing for application submissions, Singapore), together with the speech-to-text and model providers described in Section 7.

Google Ads Customer Match

If you consent to marketing cookies, we may upload your SHA-256 hashed email address to Google through its Data Manager service. Google matches hashed data against its own accounts to place you in an advertising audience. You can withdraw consent at any time in your account settings or by updating your cookie preferences; we will remove your data from the audience on the next sync cycle. For details, see How Google uses Customer Match data.

12. Cookies & similar technologies

We use cookies and similar technologies to operate and improve the Services (e.g., session authentication, preferences, analytics). Manage preferences via our cookie banner or your browser. On iOS we use on-device storage/Keychain; the mobile app sets no advertising cookies.

13. Marketing (AIApply & The Download); consent records

We only send marketing to individuals with consent or where soft opt-in applies (existing customer/negotiations + our own similar products/services + opt-out at collection and in every message). We maintain records of consent (who, when, how, what you were told).

We treat AIApply and The Download as separate lists; each requires its own consent and provides a separate unsubscribe. For corporate subscribers (many B2B addresses), different PECR rules may apply; we include identity and an easy opt-out in every message.

Segmentation and preferences. We may divide our marketing lists using the derived attributes described in Section 3, so that people receive only the communications likely to be relevant to them. Segmentation decides who does not receive a message. It never creates a basis to send one. It produces no legal or similarly significant effect and is not automated decision-making of the kind described in Section 6.

Every marketing email links to a preference page where you can unsubscribe from all AIApply marketing, or keep receiving our updates while excluding invitations to particular programmes. You can also ask us to stop using your profile to decide which emails you are sent, which is a separate request from unsubscribing and can be made at [email protected]. Where we show you information about our programmes inside the product rather than by email, the same controls apply.

Partner opportunities. Where we introduce invitations to services run by partner organisations, these will require their own separate opt-in consent, the partner will always be named in the message, and we will never pass your details to a partner unless you ask us to.

14. Data retention (summary)

  • Account data: life of the account; key logs up to 12 months; security logs up to 24 months.
  • Derived marketing attributes: life of the account, or until you object, whichever is sooner.
  • Interview Buddy transcripts: until you delete them or close your account (backups purge within +30 days).
  • AutoApply mailbox: kept while any Paid Service is active, then 3 months after your last Paid Service ends, or your last payment for a Paid Service if later, then deleted.
  • Backups: deleted within +30 days after primary deletion unless required by law.

15. Your rights (UK/EEA)

You may request access, correction, deletion, restriction, objection, or portability, and withdraw consent at any time: [email protected]. You may complain to a supervisory authority (UK ICO or your local authority).

16. Security

We implement reasonable technical and organisational measures (access controls, network protections, encryption where appropriate). No method is infallible; we cannot guarantee absolute security.

17. Children

The Services are not directed to those defined as minors in your jurisdiction. If you believe a child has provided us with personal data, email [email protected] so we can immediately delete it.

18. Complaints

You may complain to us directly about our handling of your personal data. Section 164A of the Data Protection Act 2018 gives you the right to make such a complaint to us, and requires us to acknowledge it within 30 days and to tell you the outcome of our investigation. You can complain by emailing us at [email protected], or by writing to [email protected].

You have the right to lodge a complaint with your local data-protection authority. In the United Kingdom this is the Information Commissioner's Office (ICO). We encourage you to contact us first so we can try to resolve your concern.

19. Changes to this Policy

We may update this Policy; we will post changes with a new “Last updated” date. Where required by law, material changes will be accompanied by additional notice or consent.

20. Third-party links

We are not responsible for the content or privacy practices of external sites we link to.