Back to Home

Privacy Policy

Last updated: July 23, 2026

1Introduction

ApplyArc is operated by ApplyArc Ltd, a company registered in England and Wales (Company Number: 16619519), registered with the Information Commissioner's Office (ICO Reference: ZC027406). We ("we", "our", "us") are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our job tracking application. We comply with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Data We Collect

Account Information

Email, name, profile picture (via Microsoft sign-in)

Job Data

Jobs saved, notes, application status, reminders

Resume Data

Resume/CV content you upload, stored securely to power the AI tools (matching, cover letters, resume analysis). Delete anytime from Settings.

Usage Data

Pages visited, features used, session duration

Device Data

Browser type, IP address, device type

Payment Data

Processed by Stripe (we don't store card details)

Lawful Basis for Processing (GDPR)

  • Contractual Necessity: To provide the job tracking service you signed up for
  • Consent: For optional analytics, marketing emails, and AI features
  • Legitimate Interest: For security, fraud prevention, and service improvement

Analytics & Tracking

Microsoft Clarity

We use Microsoft Clarity to see how you use and interact with ApplyArc through behavioral metrics, heatmaps, and session replay, so we can improve our product. This data is captured using first- and third-party cookies and other tracking technologies, and we use it for site optimization and security. We do not sell it or use it for advertising. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

Error Tracking (Sentry)

We use Sentry to monitor application errors and improve reliability. Sentry collects technical data about errors including stack traces, browser information, and user actions leading to the error. No personal content is captured. For more information, see Sentry's Privacy Policy.

Performance Monitoring (Azure Application Insights)

We use Azure Application Insights to monitor application performance and reliability. This collects technical telemetry including page load times, API response times, and error diagnostics. No personal content is captured. For more information, see the Microsoft Privacy Statement.

Data Storage & Security

Your data is stored securely in Microsoft Azure data centers (Europe region). We implement industry-standard security measures:

  • Encryption in transit and at rest
  • Authentication via Microsoft Entra ID (formerly Azure AD)
  • Regular security audits and vulnerability scanning
  • Data breach notification within 72 hours (GDPR requirement)

Data Retention

  • Account Data: Retained while your account is active, deleted within 30 days of account deletion
  • Job Data: Retained while your account is active
  • Analytics Data: Aggregated data retained for 2 years. Microsoft Clarity session replays are retained for up to 13 months for product analytics, fraud prevention, and to defend against payment disputes or chargebacks, after which they are automatically deleted by Microsoft.
  • Billing & Dispute Records: Retained for 7 years for tax and legal compliance. Where a payment dispute or chargeback is filed, we may retain and share the relevant transaction logs, session recordings, product usage logs, and customer communications with payment processors (Stripe), card networks, issuing banks, and any arbitrator, for as long as necessary to defend the dispute. This processing is necessary for our legitimate interests in establishing, exercising or defending legal claims (UK GDPR Article 6(1)(f) and Article 9(2)(f)).
  • Inactive & deleted accounts: Accounts that stay inactive for an extended period, or that are removed from our sign-in provider, may have their data deleted by our routine cleanup. Your account is identified by your Microsoft sign-in, not your email address alone, so registering again creates a new account rather than restoring the old one. Once data is deleted it is generally unrecoverable, so export anything you want to keep from Settings. We are not a backup service.

Your Rights (GDPR & CCPA)

Access

Request a copy of your data (Settings → Export Data)

Deletion

Delete your account and data (Settings → Delete Account)

Portability

Export your data in a machine-readable format

Opt-Out

Disable analytics tracking in Settings

California Residents (CCPA): You have the right to know what personal information is collected and to request deletion. We do not sell or share your personal information with third parties for monetary consideration. To exercise your rights, contact privacy@applyarc.com.

UK & EU residents: You also have the right to lodge a complaint with a data protection supervisory authority. In the UK that is the Information Commissioner's Office (ICO) at ico.org.uk. We would genuinely rather put it right ourselves first, so please email privacy@applyarc.com and give us the chance.

Third-Party Services

  • Microsoft Azure: Cloud hosting, authentication, and data storage
  • Microsoft Clarity: Website analytics, heatmaps, and session replay
  • AI Services (Microsoft Azure OpenAI): AI-powered features (cover letters, emails, interview prep). Data is processed via Microsoft Azure's OpenAI Service and is subject to Microsoft's Data Privacy Policy. Your data is not used to train AI models. We do not retain AI conversation logs.
  • Stripe: Payment processing (PCI-DSS compliant)
  • Sentry: Error monitoring and application reliability
  • Azure Application Insights: Performance telemetry and error diagnostics

International Data Transfers

Your data is primarily stored in the EU (Azure West Europe). When data is transferred outside the EU (e.g., for AI processing), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate data protection.

ApplyArc in ChatGPT (Apps SDK)

The ApplyArc app in ChatGPT runs anonymously on Azure Container Apps. There is no account or login, and the app does not connect a tool request to an ApplyArc profile.

Categories and purpose

The app receives the job posting, resume or CV text you choose to send, and an optional tone or hiring manager name. It uses that text only to run the tool you requested.

What it returns

The result contains the requested guidance and the exact quotes, offsets and evidence IDs needed to link claims to your pasted text. It does not return account, session, trace, request, timestamp, model or token data.

Recipients

OpenAI sends the selected tool inputs and receives the result inside ChatGPT. Microsoft Azure Container Apps hosts the server, and Microsoft Azure OpenAI processes the model request.

Retention

The ApplyArc runtime does not persist tool inputs or results. Azure OpenAI requests set store: false. ApplyArc does not add browser analytics, cookies or advertising telemetry to the card.

Restricted data

Do not paste passwords, access keys, payment card details, government IDs or health records. The tools refuse detected credentials, payment cards and government IDs before a model call.

Your controls

You choose what text ChatGPT sends. You can stop using the app or delete the conversation in ChatGPT. ApplyArc cannot retrieve or delete a ChatGPT conversation because the app has no account link.

Support requests should name the tool and describe the problem without copying the job posting, CV, generated result or restricted data into email. See our support page.

Contact Us

For privacy inquiries or to exercise your rights: privacy@applyarc.com

We will respond to all legitimate requests within 30 days.