Legal
Privacy Policy
Last updated 12 August 2026
Apply Ops handles your resume and, if you connect one, your mailbox. This page sets out exactly what that means in practice.
Who we are
Apply Ops (“we”, “us”) provides software that searches job boards against your resume and helps you send applications from your own email account.
The data controller is Apply Ops, contactable at support@applyops.in. For any privacy question or request, including access and deletion, write to that address.
What we collect
Account data. Your name, email address and authentication identifiers, handled by our authentication provider. We never see or store your password.
Resume content. The PDF you upload and the structured profile extracted from it — job titles, skills, seniority and locations. This is the basis of every search you run.
Job search data. The boards you select, the searches you run, the listings returned, and the status you assign to each application.
Outreach data. The people identified at the companies you are applying to, their work email addresses, and the application emails you draft and send.
Google account data. Only what is described in the next section.
Billing data. Plan, credit balance and transaction records. Card details are handled by our payment processor and never reach our servers.
Usage data. Standard server logs, and Google Analytics with IP anonymisation enabled and advertising signals off.
Google user data
Connecting a mailbox is optional. The service works without it; you simply send the drafts yourself.
If you do connect one, we request exactly one Google permission: the Gmail send scope, https://www.googleapis.com/auth/gmail.send. It allows sending mail as you and nothing else.
What that scope does not permit, and what we therefore cannot do: read your inbox, list your messages, read your drafts, search your mail, see your contacts, or change any Gmail setting. There is no technical route from this permission to the contents of your mailbox.
We also request the basic “email” scope, which returns the address of the Google account you connected. We store it so the app can show you which mailbox it is sending from.
What we store. An encrypted OAuth refresh token (AES-256-GCM), the connected Gmail address, and — for each message we send on your instruction — the recipient, subject, body and the message ID Gmail returns, so you have a record of what was sent.
How we use it. Solely to send the application emails you have reviewed, at the time you choose, and to show you the resulting send history and daily send count.
Automated sending. Where you schedule a campaign, sending happens later without you present. It only ever sends drafts that already existed when you scheduled them; nothing is composed and sent without prior review.
Revoking access. Disconnect from within the app, which revokes the token at Google and deletes it from our database, or revoke it from your Google Account security settings. Either takes effect immediately and stops all sending. Existing send history remains until you delete your account.
Limited Use
Apply Ops's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means: we use Google user data only to provide the sending feature you can see in the product; we do not transfer it to third parties except as needed to provide that feature, for security purposes, or where the law requires it; we do not use it for advertising; we do not sell it; and no human at Apply Ops reads it, except where you have explicitly asked us to for support, where security or law requires it, or on data that has been aggregated and anonymised.
We do not use Google user data to train machine learning or AI models. Application emails are assembled from templates generated from your resume and filled in mechanically — the contents of your mailbox are never involved, because we cannot read them.
Why we use it
To match live job listings against your resume and return them to you.
To draft and send applications you have reviewed, from the mailbox you connected.
To operate your account, apply your credit balance and process payments.
To keep the service working — caching results, diagnosing errors, and preventing abuse.
We do not sell your data, and we do not use your resume to train models for anyone else's benefit.
Who we share it with
We use the following processors to run the service. Each is bound to process data only on our instructions.
Clerk (authentication, United States). Vercel (website hosting, United States). DigitalOcean (resume file storage, United States). Razorpay (payments, India). Redis and PostgreSQL hosting for caching and the application database. Amazon Web Services (scheduling infrastructure for queued sends). Groq (resume parsing, United States). Google (Gemini API for generating your email templates, and Gmail API for sending, United States). Apify (job board collection, Czechia). GetProspect (work email verification). Serper (public web search used to identify people at target companies).
Your Google user data is shared with none of them. It is used only by our own backend to call the Gmail API — the LLM providers above receive your resume and the job listings, never anything obtained from your Google account.
We disclose data to authorities only where legally required.
Where your data goes
Our processors are located in the United States, India, the European Union and the United Kingdom, so your data is transferred internationally.
Where data leaves the EU or UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to each processor.
How long we keep it
Account, outreach and application data is kept while your account is open.
Resumes are kept until you delete them in the app or close your account.
Gmail tokens are deleted the moment you disconnect. Send history is kept while your account is open, as your record of what was sent.
Cached job listings and search results expire automatically, within days.
On account deletion we remove your data from live systems within 30 days, and from backups within a further 60 days.
Your rights
You can request a copy of your data, correct it, or have it deleted. You can delete your resume yourself in the app, and disconnect your mailbox at any time from within the app or from your Google Account security settings — either immediately stops us sending on your behalf.
To delete your account entirely, email support@applyops.in. We will acknowledge within 5 working days and complete the request within 30 days.
If you are in the EU, UK or a similar jurisdiction, you also have the right to object to processing, to request portability, and to complain to your data protection authority.
Children
The service is not intended for anyone under 18, and we do not knowingly collect data from them. If you believe a child has given us data, write to support@applyops.in and we will delete it.
Security
Data is encrypted in transit. Google OAuth refresh tokens are additionally encrypted at rest with AES-256-GCM, under a key held separately from the database.
Access to production systems is limited to the people who need it, and service-to-service calls inside our infrastructure are authenticated and signed.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator as required by law.
Changes
If we change this policy materially we will update the date above and, where the change is significant, tell you by email.
