Privacy Policy
Last updated: March 2026
The short version: We only access your Gmail to send emails on your behalf. We never read, store, or share your emails or personal data.
1. What we collect
ApplyPilot collects only the minimum information necessary to operate:
- Your name and target job role (entered by you)
- Your resume file (processed temporarily to extract skills — never stored)
- Your Gmail OAuth access token (stored in your browser session only)
- Email addresses of HR contacts (generated by AI based on your search)
2. How we use your data
We use the information you provide solely to:
- Extract skills and experience from your uploaded resume
- Find companies and HR contacts matching your profile
- Generate personalized email templates using AI
- Send those emails from your Gmail account on your behalf
We do not use your data for advertising, analytics, or any purpose beyond the core functionality described above.
3. Gmail access
ApplyPilot uses Google OAuth 2.0 to request permission to send emails on your behalf. Specifically, we request the https://www.googleapis.com/auth/gmail.send scope.
- We can only send emails — we cannot read, delete, or modify your inbox
- We never store your Gmail credentials or OAuth tokens on our servers
- Your access token lives only in your browser session and is cleared when you disconnect
- You can revoke access at any time via Google Account Permissions
4. Data storage
ApplyPilot does not maintain a database of user information. All data you enter (name, resume, preferences) exists only in your browser session and is lost when you close the tab. We do not store any personal information on our servers.
5. Third-party services
ApplyPilot uses the following third-party services to operate:
- Google OAuth & Gmail API — for authentication and sending emails
- AI providers (OpenRouter / Anthropic) — for resume parsing and email generation. Only the text content you submit is sent; no personal identifiers are included
- Vercel — for hosting and serverless functions
6. Cookies
ApplyPilot does not use tracking cookies. We use browser sessionStorage to temporarily hold your OAuth token during your active session. This is cleared automatically when you close the browser tab.
7. Children's privacy
ApplyPilot is not directed at children under 13. We do not knowingly collect personal information from children.
8. Changes to this policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the date at the top of this page.
9. Contact
If you have any questions about this Privacy Policy, please contact us at: osama.nawaid@gmail.com