Privacy Policy
How ApplyPilot AI handles account, career, document, usage, and billing information
Effective date | July 29,2026 |
Operator | SarDev AI Labs, doing business as SarDev ApplyPilot AI |
Service | https://applypilotai.sardev.io |
Contact | support@sardev.io |
This Privacy Policy describes how ApplyPilot AI collects, uses, discloses, retains, and protects personal information when you use the service.
1. Scope
This Policy applies to ApplyPilot AI websites, applications, support interactions, and related services that link to it. It does not govern an employer’s hiring process, a job site, or another third party’s independent handling of information.
For purposes of applicable privacy law, SarDev AI Labs is the controller or business responsible for personal information processed through ApplyPilot AI, except where a third party acts independently.
2. Information we collect
Account and profile information
We collect information such as email address, display name, authentication and account status, onboarding status, profile settings, and support preferences.
Career and application information
We collect information you provide in resumes, candidate profiles, employment and education history, skills, certifications, projects, compensation and location preferences, work-authorization information, job postings, screening responses, application materials, workflow status, interview or outcome events, and related notes.
Files and generated documents
We process uploaded PDF, DOCX, and TXT resumes and documents generated or stored through the service. Private files may include sensitive personal information. You should upload only information needed for your job search.
AI inputs and outputs
We process instructions, selected career facts, job descriptions, prompts assembled by the service, model responses, confidence or uncertainty indicators, provenance, approval status, and generated drafts. Production logs are designed to exclude prompts, resume text, answers, and other content.
Billing and subscription information
We collect subscription plan, status, usage, renewal and cancellation state, and Stripe customer or subscription identifiers. Stripe processes payment-card and payment-method details; ApplyPilot AI is not designed to store full payment-card numbers.
Technical and usage information
We may collect IP address, browser and device information, timestamps, requested routes, safe status and error codes, performance measurements, provider and model names, correlation identifiers, and limited product events. Current analytics are configured without autocapture or session recording and use a property allowlist intended to exclude names, email addresses, resume or job content, prompts, answers, passwords, tokens, and secrets.
Communications
We collect information you provide in support, privacy, billing, security, and other communications. For your safety, do not send passwords, API keys, or full resume contents by email.
3. Sources of information
- Directly from you, including account forms, uploads, instructions, approvals, and support requests.
- Automatically from your browser or device when you use the service.
- From service providers that support authentication, payments, email, analytics, monitoring, hosting, and AI features.
- From job postings or job sources you choose to import or enter. You are responsible for having permission to provide third-party information.
4. How we use information
- Provide authentication, private storage, candidate profiles, job analysis, matching, document generation, application workflows, notifications, subscriptions, and support.
- Separate verified facts from unverified entries, AI interpretations, generated prose, and items requiring human review.
- Enforce plan entitlements, measure usage, process billing events, prevent duplicate charges, and maintain transaction records.
- Secure the service, prevent fraud and abuse, investigate incidents, debug errors, maintain audit records, and enforce our agreements.
- Analyze safe product events and performance to operate and improve the service without intentionally sending resume text or candidate PII to analytics.
- Comply with law, respond to lawful requests, establish or defend legal claims, and protect users, the public, and the service.
- Communicate service, account, billing, security, policy, and support information.
5. AI processing and automated features
ApplyPilot AI uses server-side AI services to extract candidate facts, structure job requirements, explain matches, and draft resumes, cover letters, and screening assistance. Relevant content may be transmitted to an AI provider to perform the requested feature.
AI outputs are not automatically treated as verified facts. Users must review and approve generated content. ApplyPilot AI is not intended to make employment decisions about other people and does not guarantee any hiring outcome. See the AI and Truth-Boundary Disclaimer and Job-Application Automation Disclaimer for important limits.
6. How we disclose information
Based on the service’s current configuration, we do not sell personal information for money or use it for cross-context behavioral advertising. If these practices change, we will update this Policy and provide any choices required by law.
Service providers
We disclose information as needed to providers that host, secure, authenticate, store, process, transmit, analyze, monitor, or support the service. Current or planned provider categories include Hostinger for hosting; Supabase Auth, PostgreSQL database with Row Level Security, and private Supabase Storage; OpenAI for AI processing; Stripe for billing; Resend for email; PostHog for restricted analytics; and Sentry for redacted monitoring when configured.
Your instructions and third parties
We disclose information when you direct us to create, export, send, or submit materials or interact with a job site or employer. Once information reaches a third party, that party’s terms and privacy practices apply.
Legal, safety, and business events
We may disclose information to comply with law or valid legal process; protect rights, safety, and security; investigate fraud or abuse; obtain professional advice; or complete a financing, merger, acquisition, reorganization, or sale, subject to appropriate safeguards.
7. Cookies and similar technologies
The service may use cookies, local storage, or similar technologies that are necessary for authentication, security, preferences, billing flows, and service operation. Restricted analytics may measure page views and performance when configured.
Browser controls can block or delete cookies, but disabling necessary technologies may prevent authentication or other features from working. Where required, we will provide consent or opt-out controls before using non-essential technologies.
8. Data retention
We retain personal information for as long as reasonably necessary to provide the service, maintain account and transaction records, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud, preserve security and audit evidence, and support backups and disaster recovery. Retention varies by data type and purpose.
When information is no longer needed, we take reasonable steps to delete, de-identify, or isolate it, subject to technical limits, backup cycles, legal holds, and records we must keep. Cancellation of a subscription does not automatically delete an account or all associated data.
9. Security
The service is designed to use authenticated server authorization, user-scoped database access controls, private user-scoped file storage, upload validation, signed and idempotent billing webhooks, server-only secrets, content-redacted logging and analytics, dependency checks, and secret scanning. Production authorization and isolation are enforced through Supabase Auth, PostgreSQL Row Level Security, private user-scoped Storage, and server authorization.
No security measure is perfect. You should use a unique password, protect your device and email account, review downloads before sharing, and contact support@sardev.io promptly if you believe your account or information has been compromised.
10. International processing
We and our providers may process information in the United States and other countries where privacy laws may differ from those in your location. Where required, we use approved legal mechanisms and contractual, organizational, and technical safeguards for cross-border transfers.
11. Your privacy choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or review of certain automated processing, and to appeal a denied request. You may also have the right to complain to a privacy regulator. These rights may be subject to exceptions.
- Email support@sardev.io with the subject “Privacy Request.”
- Describe the request and the account email involved, but do not email a password, API key, or full resume.
- Complete reasonable identity verification. We may request authorization evidence for an agent acting on your behalf.
- We will respond within the period required by applicable law and explain any denial or available appeal.
12. Children
ApplyPilot AI is not directed to children under sixteen. We do not knowingly collect personal information from children below that age. If you believe a child has provided personal information contrary to this Policy, contact support@sardev.io.
13. Changes to this Policy
We may update this Policy to reflect product, provider, legal, or operational changes. We will post the updated version and revise the effective date. If a change materially affects your rights, we will provide additional notice when required by law.
Contact: Send privacy questions and requests to support@sardev.io.
