Back to Home

Privacy Policy

Last updated: August 28, 2026

1Introduction

ApplyArc is operated by ApplyArc Ltd, a company registered in England and Wales (Company Number: 16619519), registered with the Information Commissioner's Office (ICO Reference: ZC027406). Our only website is applyarc.com; this policy does not apply to applyarc.io, an unrelated service with no connection to ApplyArc Ltd. We ("we", "our", "us") are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our job tracking application. We comply with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Data We Collect

Account Information

Email, name, profile picture (via Microsoft sign-in)

Job Data

Jobs saved, notes, application status, reminders

Resume Data

Resume/CV content you upload, stored securely to power the AI tools (matching, cover letters, resume analysis). Delete anytime from Settings.

Usage Data

Pages visited, features used, and session duration when you accept optional analytics

Device Data

Browser type, IP address, device type

Payment Data

Processed by Stripe (we don't store card details)

Product Feedback

Notes you send through the in-product 'Something wrong? Tell us' form, plus whether you asked for a reply and where you sent it from: the surface, page, and tool you were using. Kept with your account regardless of your analytics choice, included in your data export, deleted when you delete your account.

Lawful Basis for Processing (GDPR)

  • Contractual Necessity: To provide the job tracking service you signed up for
  • Consent: For optional analytics, marketing emails, and AI features
  • Legitimate Interest: For security, fraud prevention, and service improvement

Analytics & Tracking

Optional analytics stay unloaded until you accept them. First-party storage needed for sign-in, security, saved work, caching, and preferences remains on because it supports features you request.

Google Analytics

If you accept analytics, Google Analytics measures page views, sessions, and product events using first-party cookies and pseudonymous browser identifiers. For signed-in users, we may send an internal account ID and plan attributes to understand feature use across sessions. We disable advertising storage, Google signals, and ad personalisation. The Google tag is not loaded before consent.

Microsoft Clarity

We use Microsoft Clarity to see how you use and interact with ApplyArc through behavioral metrics, heatmaps, and session replay, so we can improve our product. Clarity stays unloaded until you accept analytics. After consent it may use pseudonymous browser identifiers and, for signed-in users, an internal account ID plus account name or email to link a replay for support, security, and product analysis. We send advertising storage as denied. We do not sell this data or use it to serve ads. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

Error Tracking (Sentry)

We use Sentry to monitor application errors and improve reliability. Sentry collects technical data about errors including stack traces, browser information, routes, and user actions leading to the error. For signed-in users, we attach the internal account ID, not the account name or email, so related faults can be investigated. We scrub sensitive URL parameters and do not intentionally send CV, job, or AI output content in error events. For more information, see Sentry's Privacy Policy.

Azure Application Insights

If you accept analytics, Application Insights records page views, feature interactions, clicks, API performance, and error diagnostics. It uses pseudonymous request and session identifiers and may receive an internal account ID for signed-in users. Its SDK cookie storage is disabled. For more information, see the Microsoft Privacy Statement.

Data Storage & Security

Your data is stored securely in Microsoft Azure data centers (Europe region). We implement industry-standard security measures:

  • Encryption in transit and at rest
  • Authentication via Microsoft Entra ID (formerly Azure AD)
  • Regular security audits and vulnerability scanning
  • Data breach notification within 72 hours (GDPR requirement)

Data Retention

  • Account Data: Retained while your account is active, deleted within 30 days of account deletion
  • Job Data: Retained while your account is active
  • Analytics Data: Aggregated data retained for 2 years. Microsoft Clarity session replays are retained for up to 13 months for product analytics, fraud prevention, and to defend against payment disputes or chargebacks, after which they are automatically deleted by Microsoft.
  • Billing & Dispute Records: Retained for 7 years for tax and legal compliance. Where a payment dispute or chargeback is filed, we may retain and share the relevant transaction logs, session recordings, product usage logs, and customer communications with payment processors (Stripe), card networks, issuing banks, and any arbitrator, for as long as necessary to defend the dispute. This processing is necessary for our legitimate interests in establishing, exercising or defending legal claims (UK GDPR Article 6(1)(f) and Article 9(2)(f)).
  • Inactive & deleted accounts: Accounts that stay inactive for an extended period, or that are removed from our sign-in provider, may have their data deleted by our routine cleanup. Your account is identified by your Microsoft sign-in, not your email address alone, so registering again creates a new account rather than restoring the old one. Once data is deleted it is generally unrecoverable, so export anything you want to keep from Settings. We are not a backup service.

Your Rights (GDPR & CCPA)

Access

Request a copy of your data (Settings → Export Data)

Deletion

Delete your account and data (Settings → Delete Account)

Portability

Export your data in a machine-readable format

Opt-Out

Change optional analytics choices from the Cookie Policy

California Residents (CCPA): You have the right to know what personal information is collected and to request deletion. We do not sell or share your personal information with third parties for monetary consideration. To exercise your rights, contact privacy@applyarc.com.

UK & EU residents: You also have the right to lodge a complaint with a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ICO) at ico.org.uk. We would genuinely rather put it right ourselves first, so please email privacy@applyarc.com and give us the chance.

Third-Party Services

  • Microsoft Azure: Cloud hosting, authentication, and data storage
  • Google Analytics: Optional page, session, and product usage analytics
  • Microsoft Clarity: Optional website analytics, heatmaps, and session replay
  • AI Services (Microsoft Azure OpenAI): AI-powered features (cover letters, emails, interview prep). Data is processed via Microsoft Azure's OpenAI Service and is subject to Microsoft's Data Privacy Policy. Your data is not used to train AI models. We do not retain AI conversation logs.
  • Stripe: Payment processing (PCI-DSS compliant)
  • Sentry: Error monitoring and application reliability
  • Azure Application Insights: Optional product usage, performance, and error telemetry

International Data Transfers

Your data is primarily stored in the EU (Azure West Europe). When data is transferred outside the EU (e.g., for AI processing), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.

ApplyArc in ChatGPT (Apps SDK)

The ApplyArc app in ChatGPT runs anonymously on Azure Container Apps. There is no account or login, and the app does not connect a tool request to an ApplyArc profile.

Categories and purpose

The app receives the job posting, resume or CV text you choose to send, an optional tone or hiring manager name, and, for the resume score tool, one attached PDF or DOCX resume if you provide one. It uses that content only to run the tool you requested.

Attached resume files

When you attach a PDF (up to 10 pages) or DOCX (up to 4 MB) resume, ChatGPT stores the file and the app downloads it from OpenAI's file storage over HTTPS only for that tool call. Microsoft Azure AI Document Intelligence extracts the text and the app requests early deletion of the analysis data. Microsoft automatically deletes the submitted document and results within 24 hours at the latest. The app keeps neither the file nor the text once the tool call finishes. The restricted-data refusals below apply to file text the same as pasted text.

What it returns

The result contains the requested guidance and the exact quotes, offsets and evidence IDs needed to link claims to the text you supplied, whether pasted or extracted from your attached resume. It does not return account, session, trace, request, timestamp, model or token data.

Recipients

OpenAI sends the selected tool inputs and receives the result inside ChatGPT. Microsoft Azure Container Apps hosts the server, Microsoft Azure OpenAI processes the model request, and Microsoft Azure AI Document Intelligence extracts text from an attached resume file when you provide one.

Retention

The ApplyArc runtime does not persist tool inputs or results. Public production does not emit custom per-tool usage events. Azure keeps standard platform health, latency, failure and scaling metrics; they do not include submitted job or CV text or tool output. Previously collected aggregate operational records age out under the Log Analytics workspace's 30-day retention. Azure OpenAI requests set store: false to disable Responses API application-state storage for the request. ApplyArc does not add browser analytics, cookies or advertising telemetry to the card.

Card state in ChatGPT

ChatGPT may keep the rendered result in its own widget state so reopening the conversation can redraw the card. That state lives inside ChatGPT under OpenAI's data controls. ApplyArc's servers never receive or retrieve it.

Where the model runs

The Azure OpenAI resource is in Sweden Central, but the deployments are Global Standard, and Microsoft routes Global inference to datacentres outside the home region for speed and availability. Prompts may therefore be processed in any geography where Microsoft deploys the model. Only the location of processing changes; Microsoft's data protection and compliance commitments still apply.

Microsoft abuse monitoring

store: false does not disable Microsoft's separate abuse monitoring. Content that Microsoft's safety systems flag may be placed in a separate abuse-monitoring store and reviewed by a small number of authorised Microsoft employees. Because the resource sits in the European Economic Area, Microsoft states that any such review is carried out by employees located in the EEA.

Restricted data

Do not paste passwords, access keys, payment card details, government IDs or health records. The tools refuse detected credentials, payment cards, government IDs and text carrying a common patient record identifier such as an MRN or NHS number, before a model call. Detection is pattern-based and cannot catch every clinical note, so do not paste patient information. Describing your own healthcare career is fine; a patient's record is not.

Your controls

You choose what text ChatGPT sends. You can stop using the app or delete the conversation in ChatGPT. ApplyArc cannot retrieve or delete a ChatGPT conversation because the app has no account link.

Support requests should name the tool and describe the problem without copying the job posting, CV, generated result or restricted data into email. See our support page.

Contact Us

For privacy inquiries or to exercise your rights: privacy@applyarc.com

We will respond to all legitimate requests within 30 days.