JobApply Beta

Privacy Policy

Last updated: August 2026

1. Controller

2. Purpose of the service and data processed

JobApply is used to organise a personal job search. Depending on the features used, the service processes account and profile data, application data, interview data, notes, linked Telegram identifiers, Google OAuth tokens, Gmail message data, backup metadata, and technical security and log data.

For Gmail, this may include sender, recipient, subject, timestamps, Gmail and thread IDs, excerpts and message text. Messages are read during a manual sync or, when enabled by the user, through automatic Gmail checks. Attachments are not sent to AI analysis.

3. Google OAuth, Gmail and Google Drive

Sign-in uses Google OAuth. JobApply requests the Google permissions required for enabled features, including profile data, email address, read-only Gmail access and limited drive.file access for Google Drive backups.

Gmail is used only to provide user-facing JobApply features for reviewing the user’s own messages. For Google Drive, JobApply creates, lists, updates, downloads and deletes only files and folders to which the granted drive.file permission applies, including personal JobApply backups in the user’s Drive.

OAuth access and refresh tokens are stored server-side and encrypted in the JobApply database. Google access can be revoked at any time in Google Account settings. Revoking access at Google does not automatically remove data already stored in JobApply; that data can be removed by deleting the JobApply account or by making a deletion request.

JobApply’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is not sold, used for advertising, or used to train general-purpose models.

4. Optional AI analysis with OpenAI

AI analysis is optional and is used only for accounts that enable it. Sanitised sender information, subject and bounded email text may be sent to OpenAI. Attachments are not sent. JobApply uses store=False for these API requests.

OpenAI does not use API inputs and outputs to train its general-purpose models by default. Depending on the data controls applicable to the OpenAI account in use, security and abuse-monitoring logs may nevertheless be processed for a limited period.

The analysis produces suggestions and classifications. By default, the user reviews changes before they are applied. If the user explicitly enables automatic acceptance of trusted updates, JobApply may automatically apply narrowly limited, low-risk status changes with a verified match. Rejections, offers, interviews, required actions, newly created applications and uncertain matches remain subject to manual review.

5. Telegram

Telegram is optional. When a user links Telegram to JobApply, JobApply processes the Telegram chat/user identifiers needed for the link and may send user-enabled notifications through the Telegram Bot API. The content of each notification is transmitted to Telegram. The connection can be removed in JobApply settings.

6. Cloudflare Turnstile

JobApply uses Cloudflare Turnstile to protect sign-in and publicly reachable features from automated abuse. A Cloudflare-provided script or widget evaluates technical browser and device signals used to distinguish automated traffic. JobApply sends the resulting Turnstile token to Cloudflare for server-side validation. This processing is used for service security and abuse prevention.

7. Technical delivery, CDN and logs

Hosting infrastructure and server logs are used to operate JobApply. Such logs may include IP address, timestamp, requested URL, HTTP status, referrer and user-agent. They are processed for operation, security, troubleshooting and abuse prevention.

JobApply currently loads certain frontend resources through jsDelivr. When those resources are requested, the browser connects directly to the relevant CDN and transmits technically necessary connection data, including the IP address and request metadata.

8. Recipients and international transfers

Depending on the enabled feature, recipients or processors may include the hosting provider, Google (OAuth, Gmail and Drive), OpenAI, Telegram, Cloudflare and jsDelivr/CDN infrastructure.

Where data is processed outside the EU/EEA, transfers are made only on the basis of the applicable safeguards under Chapter V GDPR, such as an adequacy decision or appropriate contractual safeguards, where required.

9. Legal bases

Account, application, interview, Gmail and backup data is processed, where necessary for the JobApply features requested by the user, under Art. 6(1)(b) GDPR. Optional features based on explicit activation, in particular AI analysis, are processed under Art. 6(1)(a) GDPR where consent is required. Security, abuse prevention, troubleshooting and technically necessary logging are based on Art. 6(1)(f) GDPR.

10. Retention and deletion

Account, application, interview, Gmail and settings data is generally retained while the JobApply account exists or until the relevant data is deleted, unless legal retention duties apply. Server logs are retained for 14 Days.

A user can delete the JobApply account from account settings. This removes the user account and associated data held in the JobApply application database. Files previously written to the user’s personal Google Drive may remain in the Google account independently and may need to be deleted there separately.

Temporary demo accounts, including application, interview and note data created inside them, are retained for no longer than 12 hours and are then deleted automatically. The exact period is controlled by DEMO_ACCOUNT_TTL_HOURS.

11. Cookies and local settings

JobApply uses technically necessary session, CSRF, language and security functionality. Where this stores or reads information in the browser, it is used only where necessary to provide a service explicitly requested by the user. No analytics or advertising cookies are used. Acknowledgement of the cookie notice is stored as jobapply_cookie_notice for 180 days.

12. Automated decisions

JobApply does not make solely automated decisions producing legal or similarly significant effects within the meaning of Art. 22 GDPR. AI classifications assist with organising the user’s job search. The optional automatic acceptance of trusted, low-risk status updates only changes data inside the user’s personal JobApply workspace.

13. Your rights

You may have rights of access, rectification, erasure, restriction of processing, data portability and objection. Consent can be withdrawn at any time with effect for the future. Contact p95maxde@gmail.com.

You may also lodge a complaint with a data protection supervisory authority. The responsible authority is usually the authority where you live or work, or where the alleged infringement took place. Controller’s authority: [Bitte zuständige Datenschutz-Aufsichtsbehörde eintragen].