Privacy

Private candidate data, secure resume matching, least-privilege recruiter access, and submission evidence without credential collection.

Uploading or saving a resume authorizes secure automated processing for job matching; provider details remain an internal service concern.
Resume files should use encrypted private object storage.
Do not collect job-board passwords, authentication cookies, government identifiers, full birth dates, or financial details.
Recruiters see only the candidate information needed for the assigned application.
Audit application transitions and AI generations without logging raw secrets, credentials, or resume content.
For service quality and account security, ApplyPilot keeps a best-effort record of recent sign-in outcomes for 30 days. Only authorized administrators can review account display names, public codes, roles, times, browser families, and response status; passwords, reset links, session tokens, raw failed email identifiers, and IP addresses are not shown.
Users can delete scans, resumes, and account data.