Privacy Policy

TheEasyApply handles resumes, which are among the most personal documents most people own. This explains exactly what happens to yours.

Last updated 2 September 2026

The short version: your resume is stored so you can edit it, and its text is sent to third-party AI providers when you ask us to tailor it. We do not sell anything, we do not advertise, and you can export or delete everything yourself from Settings → Data & privacy.

1. Who is responsible

TheEasyApply is run by two individuals rather than a company, and the two of us are jointly responsible for your data:

For anything about your data, write to privacy@theeasyapply.com, which reaches both of us. Our postal address is available on request.

2. What we collect

Almost all of it is content you typed or uploaded. We do not buy data about you and we do not track you across other websites.

WhatWhere it comes from
Account identity — email, name, sign-in methodClerk, our authentication provider. It is not copied into our own database.
Resume content — name, email, phone, location, links, work history, education, skillsThe PDF you import, or the guided intake you fill in.
Job descriptions and company namesPasted by you when tailoring or tracking an application.
Applications — stage, dates, notes, the version you sentEntered by you in the tracker.
Recruiter contact details and a short email excerptFrom an email you paste in when logging an application.
Job preferences — target roles, countries, excluded companiesYour job-search settings.
Subscription status and Stripe identifiersCreated when you subscribe. Card details are handled by Stripe; we don't receive or store them.
IP address and browser user-agentSent by your browser. Used for rate limiting, abuse prevention and server logs.

If you use the signed-out demo, the resume you paste is stored temporarily and unattached to any account. See clause 7.

3. What we use it for

We use your data only to run the service, keep it secure and prevent abuse, process payments, and keep records we are required to keep.

Email. We may send service announcements to account holders, and product news only if you opt in. Every email has a way to stop receiving them.

4. AI providers — please read this one

When you tailor a resume, run a match score, use the coach, or parse a pasted recruiter email, the relevant text — which can include your full resume and your name and contact details — is sent to a third-party AI provider for processing.

We use whichever of the following is configured at the time. This list is accurate as of the date above, and we will update it when it changes:

ProviderWhere it processes data
xAI (Grok) — currently the defaultUnited States
Anthropic (Claude)United States
OpenAIUnited States
Google (Gemini)United States
DeepSeekChina
Moonshot AIChina

Two of these providers process data in China. If that is not acceptable to you, do not use the AI features or AI-assisted importing. Manual editing, exporting and application tracking never call a model, and they remain fully usable.

We rely on each provider's standard terms, which for the vendors above state that API content is not used to train their models. We do not have separate negotiated agreements with them, and we cannot audit them. We are telling you this rather than implying a guarantee we are not in a position to give.

We never send your data to a model for any purpose you did not initiate, and we do not use your resumes to train anything of our own.

5. Who else touches your data

These are our sub-processors. They act on our instructions, and we do not sell or rent personal data to anyone.

ServiceWhat it doesWhere
ClerkAuthentication and account managementUnited States
MongoDB AtlasThe database holding your resumes and applicationsUnited States
Google CloudRuns the API; receives server logs including IP addressesUnited States
VercelHosts the website; optional analyticsUnited States
CloudflareTurnstile anti-bot check on signed-out pages; receives your IPGlobal
StripePayments and subscriptions; card details are handled by Stripe, not by usUnited States
SentryCrash reports, with request bodies and credentials stripped firstUS or EU, depending on Sentry's hosting region
AI providersSee clause 4US and China

6. How long we keep it

DataKept for
Resumes, applications, preferencesUntil you delete them, or until you delete your account
Guided-interview drafts30 days, then deleted automatically
Job leads90 days, then deleted automatically
Signed-out demo drafts24 hours, then deleted automatically
Uploaded PDF filesDeleted from disk immediately after parsing
Server logsAs retained by Google Cloud Logging, currently 30 days
Crash reportsA limited period, then deleted by Sentry
Invoices and payment recordsAs long as tax law requires, typically 6–7 years

Deleting your account removes everything in the first row immediately. Residual copies in backups and logs expire on their normal schedule. Invoices are the exception — we are required to keep those, so your Stripe customer record and its invoice history survive deletion even though the subscription is cancelled.

7. The signed-out demo

You can paste a resume at /demo without an account. That text is stored against a random token, is never indexed or searchable, is not linked to an email address, and deletes itself after 24 hours. If you then create an account, you are offered the chance to claim it — at which point it becomes a normal resume covered by the rest of this policy.

8. Your rights

You can, at any time:

  • Get a copy — Settings → Data & privacy → Export. One JSON file with everything we hold.
  • Delete everything — Settings → Data & privacy → Delete account. Immediate and irreversible. Residual copies in backups and logs expire on their normal schedule.
  • Correct it — edit any resume or application directly, or email us.
  • Object or restrict — email us and we will stop the processing in question or explain why we cannot.
  • Withdraw consent — cookie preferences are re-openable from the footer of any page.

We aim to respond promptly. If you're unhappy with how we handled a request, tell us; you may also be able to complain to your local data protection authority.

9. Security

Traffic is encrypted in transit. Passwords are handled by Clerk; we don't receive or store them. Card details are handled by Stripe; we don't receive or store them. Crash reports have request bodies, cookies and authorisation headers removed before they are sent.

We are two people, not a security department. We are not going to claim a certification we do not have. If you find a vulnerability, email privacy@theeasyapply.com and we will take it seriously.

10. Children

TheEasyApply is for people looking for work and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has an account, tell us and we will delete it.

11. Changes

If we change this in a way that materially affects you — a new category of data, a new purpose, a new AI provider in a new country — we will try to let you know in advance, not only by editing this page.