Privacy Policy
Last updated: August 2026
SpotApply ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. What data we collect
- Account data: Email address and name provided at sign-up via Supabase Auth or Google OAuth.
- Resume data: The resume file you upload and the structured profile fields extracted from it (name, skills, experience, education, etc.).
- Application data: Job listings discovered, matching scores, tailored documents generated, and application statuses.
- Usage data: API request logs, pipeline run timestamps, and error events used for debugging and improving the service.
- Email content (only if you turn on Email Sync): when you enable Email Sync in the browser extension, it reads job-related messages from the webmail page you have open and sends the sender, subject, date and message body to SpotApply. We use them to detect employer replies, rejections and interview invitations, and to add applications you made outside SpotApply. Message bodies we cannot match to a known application are stored with that application record. Email Sync is off unless you enable it, and turning it off stops any further reading.
2. How we use your data
- To discover, rank, and match job listings to your profile.
- To generate tailored resumes and cover letters for each application.
- To auto-fill job application forms on your behalf.
- To send you in-app notifications about new matches and your applications.
- To maintain your application history and pipeline state.
Your data is never sold, licensed, or shared with third parties for advertising purposes.
3. Data storage
Your data is stored in Supabase (PostgreSQL database and file storage) on AWS infrastructure in the United States (us-east-1), and the application runs on Railway. If you are outside the United States, using SpotApply means your data is transferred to and processed there. Resume files are stored in Supabase Storage and are accessible only to your account; application data is stored in a private PostgreSQL database.
4. Third-party services
- Supabase (US) — authentication, database and resume file storage.
- Railway (US) — hosting for the application itself.
- Anthropic (Claude) (US) — the model that scores jobs against your resume and writes your tailored resume and cover letters. It receives your resume text and the job posting. Governed by Anthropic's data processing terms.
- OpenAI (US) — the cheap first-pass model that pre-screens jobs before Claude sees them, and a fallback for one fact-checking step. It receives an extract of your resume (about the first 4,000 characters) and the job title, company and description. Governed by OpenAI's API data policy. This runs on essentially every job we score for you, so in practice your resume text reaches both providers.
- Stripe (US) — payment processing. Not active yet; when it is, Stripe receives only what is needed to take a payment, and we never see or store your card details.
None of these providers is permitted to use your data to train their models under the API terms we use. We do not sell or license your data, and we do not share it for advertising.
5. Where job listings come from
We read job postings from public sources only: company applicant-tracking boards that publish an open API or feed (Greenhouse, Lever, Ashby, Workday, SmartRecruiters, Workable and similar), public job-board feeds and APIs, and licensed aggregators. We respect robots.txt.
We do not scrape LinkedIn or Indeed and we never log in to them on your behalf. Listings that originate there reach us through a paid third-party aggregator API or a public feed, and we show them to you as a link you open yourself. Auto-fill runs only on the application form you choose to open, and nothing is ever submitted without you clicking Submit.
6. Your rights (GDPR / CCPA)
You have the right to:
- Access your data — request a copy of all data we hold about you.
- Correct your data — update your profile at any time from the dashboard.
- Delete your data — request full account deletion from Settings → "Delete my account". This permanently removes all your jobs, applications, profile data, and uploaded files.
- Export your data — download your application history as CSV from the dashboard.
To exercise any of these rights, email us at privacy@spotapply.ai or use the in-app delete flow.
7. Data retention
We retain your data for as long as your account is active. If you delete your account, all data is permanently removed within 30 days.
8. Cookies
SpotApply does not use tracking cookies. Authentication tokens are stored in your browser's localStorage and in a strictly-necessary session cookie (sb_token) — both are used only to maintain your session, never for tracking or advertising.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you via email or an in-app notice for material changes.
10. Who is responsible for your data
SpotApply is operated by its founder as the data controller. For any privacy question, or to exercise the rights in section 6, email privacy@spotapply.ai and we will respond within 30 days.