Privacy Policy
ApplyCandid — Chrome extension
Short version: Deterministic form-filling (name, email, phone, work authorization, etc.) never leaves your browser. Resume text and job/project descriptions go to the AI server you connect in Settings, so it can draft cover letters, proposals, and scores — you never enter an AI provider key yourself, the operator running that server does. An optional, off-by-default toggle can also send anonymized usage counters; see Section 2. This website itself uses Google Analytics for page-view counts, which is separate from the extension — see Section 7.
1. What's stored, and where
- Resume text — Chrome's local storage on your device, and the AI server you've connected (encrypted at rest there).
- AI server connection (server URL + an opaque access token) and job preferences — Chrome's synced storage.
- Application history — Chrome's local storage on your device only, never sent anywhere.
2. What's sent to the AI server
Deterministic autofill (name, email, phone, work authorization, etc.) is filled entirely in-browser and never sent anywhere. What does leave your browser, sent only to the AI server you've connected: your resume, the job/project description being scored or drafted against, and (for the shared field-pattern map) an unrecognized field's label text. That server is whichever instance of this project's service/ backend you've pointed the extension at — run by the operator/distributor you chose, not an unrelated third party.
Settings also has a "Help improve this tool" toggle, on by default and switchable off at any time. While it is on, the extension additionally sends a job's relevance score, a run's applied/skipped/failed counts, and a handful of product milestones — first successful fill, finishing setup, hitting a free-tier limit, clicking an upgrade link, activating a license — each tagged only with which screen raised it. No job title, company, resume field, or anything identifying which user sent it. Nothing is stored individually: the server immediately folds each signal into an anonymous daily total (a score range such as "60–79", or a count per milestone), combined across every user who has this on, and discards the rest. These totals are never shared with any third party and are automatically deleted within 30 days.
While the same toggle is on, the extension also reports a short list of product events so the parts that fail quietly can be found: a run started, stopped, or finished (with how many applications it completed, as a range), a page fill and how many fields it matched, an onboarding step reached, a limit card shown, a license activation attempted. Each is a name and a screen — no job, no company, no URL, no field contents — and each is stored only as a daily total.
2a. Your email address (optional)
Onboarding offers to take an email address, and Settings lets you add, change, or delete one later. It is always optional — every feature works without it.
It is used for exactly three things: sending your license key (including re-sending it if you lose it), warning you if a renewal payment fails before Pro stops working, and one single email if a run is cut short by the free-tier cap. There is no newsletter, no drip sequence, and it is never sold, rented, or shared with an advertiser.
It is stored twice and never in the clear: as a one-way hash (so a request to re-send your key can be matched against it) and as an encrypted copy (so mail can actually be addressed). "Delete my data on the AI server" in Settings erases both, along with the stored resume and cached drafts.
3. LinkedIn, ATS, and freelance-platform site access
The extension reads job listing pages on LinkedIn and fills forms on external career portals (Greenhouse, Lever, Workday, etc.) only when you click "Start Run." It also reads and fills freelance-platform project pages (Upwork, Freelancer.com, Guru, PeoplePerHour, or any other page) when you click "Fill This Page" — on a recognized freelance platform, this includes reading a project posting's custom client questions to draft answers to them, the same way LinkedIn/Naukri screening questions are answered. No background access outside an active run or an explicit "Fill This Page" click.
4. What the extension doesn't collect
No crash reporting, and no analytics inside the extension beyond the opt-in counters in Section 2. The extension developer never sees your resume, application history, or server connection details — that data goes to the AI server you connect, not to us. This covers the extension only; what this marketing website measures is set out in Section 7.
5. Retention & deletion
Your profile, settings, resume and application history are stored locally in your browser profile until you remove them: "✕ Remove" (Resume tab), "🗑 Clear All" (Tracker tab), or uninstalling the extension. What the AI server holds — the uploaded resume, cached drafts, and your email address if you gave one — is erased by "Delete my data on the AI server" in Settings. Anonymous analytics totals aren't tied to you and auto-delete within 30 days regardless of the toggle.
6. Payments and subscriptions
ApplyCandid Pro is sold through a merchant of record — the payment provider is the seller for the transaction and handles the checkout, card details, invoicing, and any sales tax or VAT. Your card number never reaches us and is never stored on our servers. What the provider tells us, via a signed webhook, is limited to what an entitlement check needs: a subscription identifier, its status (active, cancelled, payment failed, expired), and the date the paid period ends.
Your license key is stored only as a one-way hash, so a copy of our database contains no usable keys. The extension checks that hash against the subscription status when a run starts; a successful check is cached on your own device so Pro keeps working while you are offline. Cancel at any time through the provider's customer portal, linked from your purchase receipt — Pro features continue until the end of the period you have already paid for.
Where the payment provider can tell us the buyer's email address, we store it the same way as in Section 2a (hashed plus encrypted) so a lost license key can be re-sent and a failed renewal can be flagged to you. Purchases are also counted against which screen the checkout was opened from — an aggregate daily total per screen, with no buyer, amount, or identifier attached.
7. This website
applycandid.com uses Google Analytics 4 to count page views and see which pages people arrive on. It records the usual web-analytics signals — page URL, referrer, approximate location derived from a truncated IP address, and device/browser type — and stores an identifier in your browser to tell a returning visit from a new one. IP addresses are anonymized by Google before storage, and we never upload anything about you to it: no name, no email, no resume, and nothing the extension holds.
Alongside that, the site sends a small set of first-party events to our own server: which page was viewed, which sections were scrolled into view, how far down the page you got (in quarters), roughly how long the page was open (in seconds), which FAQ entries were opened, and which buttons were clicked. No identifier is attached to any of them — not a cookie, not a session id, not an IP address. Each one is immediately folded into an anonymous daily total (and any number is stored only as a range), so what exists afterwards is "43 people reached the pricing section today", never a trail belonging to one visitor. This exists because a large share of visitors block Google Analytics entirely, which silently under-reports exactly the privacy-conscious people this product is built for.
If you arrive from a campaign link, its utm_* tags are kept for that browser tab only (in sessionStorage, never a cookie) and passed along to the checkout page if you buy, so a sale can be credited to the campaign that produced it. They are discarded when the tab closes and are never shared with an advertiser.
This applies to the website only. It is separate from the extension, which ships no analytics beyond the opt-in counters in Section 2. To opt out, use your browser's tracking protection, any content blocker, or Google's Analytics opt-out add-on — nothing on the site depends on it, and blocking it changes nothing about how the site works.
8. Other
Not directed at children under 13. Material policy changes are noted in the extension's update changelog. Questions: support@applycandid.com