Applyd ("Applyd", "we", "us", "our") operates Applyd.ie, an AI career copilot built for Irish graduates and job seekers. This policy explains, in plain English, what personal data we collect, why we collect it, who we share it with, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. It applies to the Applyd.ie website, the Applyd web app, our browser extension, and our iOS/Android apps.
We have tried to make this document genuinely complete rather than a generic template — every data partner and processing purpose named below is one we actually use. If anything here seems unclear, email us at privacy@applyd.ie and we'll explain.
Who we are
Applyd is the data controller for the personal data described in this policy — we decide why and how your data is processed. Applyd is based in Ireland and built around Irish and EU hosting, so your data protection supervisory authority is the Irish Data Protection Commission (DPC). Our registered company name, company number, registered office address, and Data Protection Officer contact are set out under "Registered company details" below.
Contact us about anything data-protection related at privacy@applyd.ie. We aim to respond to all data-protection queries within 30 days, as required by GDPR.
What personal data we collect, and where it comes from
We collect only what we need to run the product. Each category below notes its source.
- Account details — name, email address, password hash (or passkey public-key credential if you use passkey sign-in), account status. Provided directly by you at sign-up.
- Profile and CV data — work experience, education, skills, certifications, links, languages, salary and location preferences, work-authorisation/visa status. Provided directly by you, or extracted from a CV you upload using our AI CV-parsing feature (see "AI processing" below).
- Uploaded documents — CVs/résumés you upload, and cover letters, tailored CVs, and other documents Applyd generates for you. Provided by you, or generated by our AI at your request. Stored encrypted on our EU-hosted object storage (see "Security").
- University / student verification data — your university email address, a verification code sent to that address, and (if you choose to add them) your degree programme and module list. Provided directly by you when you verify your student status; module descriptions may be enriched with likely associated skills using AI so we can match you to relevant graduate roles.
- Job applications and tracker data — jobs you save or apply to, application status, timeline events, notes, screening-question answers, interview-prep sessions, and follow-up drafts. Created by you, detected from employer email replies (see below), or generated by our AI on your instruction.
- Inbox-derived employer messages — status-relevant emails from employers, only if you opt in. There are two separate ways this can happen, and they collect different amounts of data:
- Connecting your Gmail or Outlook inbox (optional, revocable in Settings): we request read-only, minimal-scope access (Gmail's `gmail.readonly` scope, or Outlook's `Mail.Read` scope) and only ever pull the sender address, subject line, and a short preview snippet of messages matching application-related keywords (e.g. "interview", "offer", "application"). We do not read, store, or process your full mailbox or full message bodies.
- Forwarding or CC'ing a message to your personal Applyd alias (e.g. `jobs+yourcode@mail.applyd.ie`): if you deliberately forward or CC an employer email to your alias, we do receive and store that full message (including its body) so we can detect the status change and update your tracker. You control what you forward.
- Usage and analytics data — pages viewed, features used, and product events (e.g. viewing a pricing plan, clicking upgrade). Collected automatically as you use the product and stored in our own first-party database — we do not use third-party advertising trackers or Google Analytics.
- Payment and billing metadata — your plan, subscription status, invoice history, and billing address. Provided by our payment processor, Stripe, once you subscribe to a paid plan. We never receive or store your card number — Stripe handles card data directly under its own PCI-DSS certified infrastructure.
- Passkey / authenticator data — a WebAuthn public-key credential (device type, whether it's backed up, a label you choose). Your biometric data (fingerprint/face) never leaves your device and is never sent to Applyd.
- Support and contact data — anything you send us via a support ticket or contact form, so we can help you.
How we use your data, and our lawful basis for each purpose
Under GDPR Article 6, we need a lawful basis for every purpose we process your data for. Here's the mapping:
| Purpose | What we do | Lawful basis |
|---|---|---|
| Account creation, sign-in, passkeys | Authenticate you and keep your account secure | Performance of a contract (Art. 6(1)(b)) |
| Job matching and fit scoring | Compare your profile against job listings to surface relevant roles | Performance of a contract |
| AI-generated CVs, cover letters, and screening answers | Tailor application materials to a specific job, at your request | Performance of a contract |
| Interview prep, negotiation roleplay, outreach drafting | Provide the AI coaching and drafting tools you use in-app | Performance of a contract |
| Auto-apply agent | Fill and (only with your review-first approval) submit application forms on ATS platforms | Performance of a contract, gated by your explicit per-run review and approval |
| Connecting your inbox (Gmail/Outlook) | Detect application status changes from employer replies | Consent (Art. 6(1)(a)) — you opt in and can withdraw at any time in Settings |
| Personal forwarding alias | Detect status changes from emails you choose to forward | Consent — you control what you forward |
| University email verification and modules | Confirm student status and improve module-to-skill matching | Consent / performance of a contract (needed to unlock student-only features) |
| Billing and payment processing | Charge subscriptions, issue invoices | Performance of a contract, and legal obligation (financial record-keeping) |
| Malware scanning of uploads, fraud/abuse prevention, rate limiting | Keep the platform safe | Legitimate interests (Art. 6(1)(f)) |
| Product analytics (aggregate feature usage) | Understand what to build next | Legitimate interests |
| Transactional emails (verification, password reset, application updates) | Operate the service | Performance of a contract |
| Marketing emails | Tell you about new features | Consent — opt-in, with an unsubscribe link in every email |
| Responding to legal requests | Comply with the law | Legal obligation (Art. 6(1)(c)) |
AI processing — Anthropic (Claude)
Applyd's core features — fit scoring, CV tailoring, cover-letter generation, screening-question answers, CV/cover-letter authenticity checks, interview-prep coaching, negotiation roleplay, outreach drafting, email classification, and university-module skill enrichment — are powered by large language models from Anthropic ("Claude"). Anthropic is currently the only AI provider Applyd uses; we do not send your data to any other AI vendor.
What this means in practice:
- When you ask Applyd to tailor a CV, generate a cover letter, or analyse job fit, the relevant text (your profile/CV content, the job posting, and any instructions you give) is sent to Anthropic's API to generate the output.
- Anthropic processes this data as our sub-processor, under its own API terms and data processing agreement. Under Anthropic's published API terms, input and output data submitted through the API is not used to train Anthropic's models, and is retained only for a limited period as needed for abuse and safety monitoring, unless we or you are otherwise required by law to retain it for longer.
- AI output is always assistive, never final, without your review. Fit scores are recommendations, not decisions. Generated CVs, cover letters, and screening answers are drafts you can edit before they're used. Interview coaching and negotiation roleplay are practice conversations, not real correspondence sent to anyone. Outreach drafts are shown to you before sending. The auto-apply agent operates under a review-first policy — it prepares an application for you to check, and (while unattended submission is being rolled out) real submissions require your explicit approval before anything is sent to an employer.
- No fully automated decision with legal or similarly significant effect is made about you by AI (see "Automated decision-making" below).
Sub-processors and data partners
We use a small number of specialist providers to run Applyd. Each only receives the data it needs to do its specific job, under a data processing agreement or equivalent contractual terms. We do not sell your data, and we do not share it with data brokers or advertisers.
| Partner | Role | Data received | Region |
|---|---|---|---|
| Anthropic | AI processing — CV tailoring, fit analysis, cover letters, screening answers, interview/negotiation coaching, outreach drafting, module-skill enrichment, email classification | Profile/CV content, job posting text, application context, email subject lines you send us for classification | Anthropic's API infrastructure; not used to train models (see above) |
| Zoho Corporation (Zoho Mail / ZeptoMail) | Transactional email (verification, password reset, notifications) and marketing email delivery; receiving mail sent to your personal Applyd forwarding alias | Your email address and name; content of transactional/marketing emails we send; content of messages you forward to your alias | EU (Applyd's Zoho account and mail infrastructure are configured on Zoho's EU data centre) |
| Hetzner Online GmbH | Application hosting, database, and object storage for uploaded CVs and generated documents | All account, profile, application, and document data described in this policy | Germany (Falkenstein), EU |
| Stripe | Payment processing, subscription billing, invoicing | Name, email, billing address, card details (held by Stripe, never by us), subscription/plan metadata | Stripe's global, PCI-DSS certified payment infrastructure, with EU entities used for EEA customers where applicable |
| Google LLC (Gmail API) | Only if you connect your Gmail inbox. Read-only detection of application-related emails | Sender address, subject line, and short message snippet of matching emails (never your full mailbox or full message bodies) | Google's global infrastructure |
| Microsoft Corporation (Microsoft Graph / Outlook) | Only if you connect your Outlook inbox. Read-only detection of application-related emails | Sender address, subject line, and short message preview of matching emails (never your full mailbox or full message bodies) | Microsoft's global infrastructure |
Our job search is powered by Typesense, an open-source search engine that we self-host on our own EU infrastructure — it is not a third party and never receives your personal data outside our own systems.
International data transfers
Our default posture is EU-first: your account, profile, application, and document data is hosted on Hetzner's servers in Germany, and our transactional/marketing email runs through Zoho's EU data centre. Data does not leave the EU for these purposes.
Some processing necessarily involves a transfer outside the European Economic Area:
- Anthropic (AI processing) operates infrastructure outside the EEA.
- Stripe (payments) operates global payment infrastructure, with appropriate regional entities used where applicable.
- Google and Microsoft (only if you connect an inbox) operate global infrastructure.
Where personal data is transferred outside the EEA, we rely on the safeguards required by GDPR Chapter V — such as Standard Contractual Clauses and, where the recipient participates, the EU-US Data Privacy Framework — as provided in each partner's data processing terms. If you'd like more detail on the transfer mechanism for a specific partner, contact privacy@applyd.ie.
How long we keep your data
- While your account is active, we retain your account, profile, application, and document data so the product keeps working for you.
- Uploaded CVs and generated documents are deleted from storage when you remove them individually, or when you delete your account.
- Connected-inbox data: we don't retain full email bodies from a connected Gmail/Outlook inbox at all — only the short snippet/subject/sender used to detect a status change is processed, and you can disconnect the connection (and delete everything derived from it) at any time in Settings.
- Forwarded-alias messages: retained so your tracker stays accurate, until you delete the associated application, disable your alias, or delete your account.
- AI task records (the prompts, outputs, and cost metadata behind the features above) are retained for as long as your account is active, both to let us show you your own history and to prevent duplicate AI calls for the same request. They are deleted with your account as described below.
- When you delete your account, we immediately: revoke and delete your inbox connections and everything derived from them, delete your passkeys, delete interview-coaching session transcripts, delete your university verification and module records, and close and anonymise your core account record (your name and email are replaced and your password is removed). Records we are required to keep for accounting and tax purposes — such as invoices and payment history — are retained in anonymised association with the closed account for the period Irish law requires for financial records (generally six years), after which they are also deleted. If you'd like data beyond this deleted sooner, email privacy@applyd.ie and we'll do what the law allows.
Your rights under GDPR
You have the following rights over your personal data, and you can exercise most of them yourself, right now, in the app:
- Right of access — request a copy of the personal data we hold about you. Do this instantly: Settings → Privacy → Export my data, or `GET /api/account` if you use our API, which returns a complete JSON export of your account, profile, applications, documents, AI task history, inbox connections, and billing records.
- Right to rectification — correct inaccurate profile, CV, or account information, directly in your Settings and profile pages.
- Right to erasure ("right to be forgotten") — delete your account and associated personal data at any time via Settings → Privacy → Delete my account, or `DELETE /api/account`. See "How long we keep your data" above for what's deleted immediately versus retained under a legal obligation.
- Right to restrict processing — ask us to pause processing of your data while a dispute is resolved, by emailing us.
- Right to data portability — the export above is provided in structured JSON so you can take your data elsewhere.
- Right to object — object to processing based on our legitimate interests (e.g. product analytics), by emailing us.
- Right to withdraw consent — disconnect your Gmail/Outlook inbox at any time in Settings (this also lets you delete everything derived from that connection in one action), unsubscribe from marketing email via the link in any marketing email, or stop forwarding mail to your alias whenever you like.
- Right to lodge a complaint — if you believe we have mishandled your data, you can complain to the Irish Data Protection Commission at dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — or to your own country's supervisory authority if you live elsewhere in the EEA.
We do not charge a fee to exercise these rights, and we will never ask you to pay to access, correct, or delete your own data.
Security
We take reasonable technical and organisational measures to protect your data, including:
- Encryption in transit (TLS) for all traffic to Applyd, and encryption at rest for stored documents and database records.
- Passkey (WebAuthn) sign-in as a phishing-resistant alternative to passwords — no shared secret is ever transmitted or stored.
- Automatic malware scanning of every uploaded file before it's stored; files that fail scanning are rejected outright.
- Time-limited, signed URLs for document access — no other user can access your uploaded files, and links expire quickly.
- Encrypted storage of connected-inbox OAuth tokens, never your Gmail/Outlook password.
- Minimal-scope, read-only OAuth for inbox connections — we cannot send email as you, delete your mail, or read messages unrelated to job applications.
- EU-hosted infrastructure (Hetzner, Germany) for the core application and your documents.
- Rate limiting and origin/CSRF checks on sensitive account actions (export, deletion, billing), and step-up authentication for administrative access to our systems.
No system is 100% secure, but if we ever become aware of a breach affecting your personal data, we will notify the Data Protection Commission and, where required, you, in line with our obligations under GDPR Articles 33 and 34.
Automated decision-making
Applyd uses AI extensively to assist you, but GDPR Article 22 gives you the right not to be subject to a decision based solely on automated processing where it produces legal effects or similarly significantly affects you. We've designed the product so this right is respected by default:
- Fit scores and recommendations are advisory — you decide which jobs to pursue.
- Generated CVs, cover letters, and screening answers are drafts for you to review and edit.
- The auto-apply agent runs under a review-first policy: it prepares applications for your inspection, and real submission to an employer requires your explicit, per-run approval while the feature is rolled out under this safeguard.
- No AI system at Applyd makes a final hiring, eligibility, or account-status decision about you without a human (you) in the loop.
Cookies and analytics
We use strictly necessary session/authentication cookies to keep you signed in — these aren't optional, since the product can't function without them. We record first-party product-analytics events (like which features you use) in our own database to improve the product. We do not use third-party advertising cookies, Google Analytics, Meta Pixel, or similar cross-site trackers.
Who can use Applyd
Applyd is built for university students and graduates, and is intended for users aged 18 and over. We do not knowingly collect personal data from children under 16 (the digital age of consent under Irish data protection law). If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as Applyd's features or data partners change. If we make a material change, we'll notify you by email or an in-app notice before it takes effect. The "last updated" date below always reflects the current version.
Related pages
For a rights-focused summary and quick links to exercise them, see our GDPR & Data Rights page. For the rules governing your use of Applyd, see our Terms of Service.
Contact
privacy@applyd.ie
Last updated: 6 July 2026
Registered company details
Company details