Privacy notice
We hold your CVs, your applications and your account, because that is the product. We do not sell any of it and there is no advertising here. Employers see the documents you send them and nothing else about you — not your other applications, not who turned you down. You are not discoverable by employers unless you switch that on yourself, on a page that shows you the exact card they would see. You can export everything or delete your account from your settings, and the deletion is real; the short list of things we have to keep afterwards is set out below, with the reason for each.
1. Who we are
ApplyRole operates ApplyRole and is the data controller for the personal data described here. Our registered postal address is available on request and is included on every commercial email we send. For anything in this notice — a question, a request, or a complaint — write to the contact form linked in the footer.
2. What we hold, and why we are allowed to
Almost everything here you typed in yourself, and we hold it in order to provide the thing you asked for. In data protection terms that is performance of a contract, and it covers:
- Your account — email address, name, password (stored only as a hash, which cannot be reversed to reveal the password), and when you registered.
- Your documents — CVs, cover letters, and everything in them: employment history, education, skills, and anything else you choose to write.
- Your job search — applications you track, jobs you save, saved searches and the alerts you asked us to email you.
- Your subscription, if you have one — the plan, its status and its dates. We never see or store your card number; see section 5.
Two things are held on legitimate interests rather than contract, because they exist to keep the service safe and solvent rather than to deliver a feature you asked for:
- A security log. Sign-ins, password changes, permission changes and administrative actions, with the IP address and browser they came from. It is what lets us tell you whether the sign-in you did not recognise was real, and it is the only durable evidence that an erasure request was genuinely made and genuinely carried out.
- AI usage counts. How many AI actions you have used and roughly what they cost to run — numbers, not content. Without them there is no ceiling on spend and no way to detect a script abusing the feature.
Two things run on consent, and both are off until you turn them on: our mailing list, and being discoverable in employer candidate search. Withdrawing either takes effect immediately. The mailing list is double opt-in: joining sends one confirmation email and nothing else is ever sent to an address that has not clicked it, so a mistyped or malicious signup reaches nobody. We record when you confirmed, from which page, and which version of this wording you agreed to. Discoverability is literal rather than eventual — the search population is read fresh on every request, so an employer holding an older link to your card resolves nothing.
Gender. An optional profile question. If you answer, the value is used only in aggregate counts of the membership ("how many women use ApplyRole") — it is never shown to employers, never used in matching, and leaving it blank is a complete answer.
Ratings. If you rate ApplyRole on the home page we keep the stars, any words you wrote, and the name you gave (for members, your first name and an initial). Quotes we approve are shown publicly on the home page, under that name. We choose which quotes to show and we say so — the page presents them as what people have said, never as an average or a score. Anyone on the page is invited to repeat their review on Google afterwards, whatever they scored; nothing is sent to Google by us. A rating is deleted with your account, and you can ask us to take one down at any time.
3. What happens when you use an AI feature
When you press an AI button — tailor this CV to that job, rewrite this bullet, draft this follow-up — the text needed for that specific task is sent to an AI provider, which generates a response and returns it. Nothing is sent unless you press the button. The AI features are not running in the background over your documents.
If you would rather no part of a document ever left this system, do not use the AI features on it. Everything else — the builder, the templates, exports and the tracker — works without them.
4. What employers can see
This is the part people most want a straight answer on, so here it is in full.
When you apply to a job posted here, that employer receives the documents you attached to that application and the answers you gave on that form. They do not receive your account. They cannot see how many other jobs you have applied to, which employers rejected you, what you have saved, what you have searched for, or anything in your tracker about applications made elsewhere. This is enforced in the code that builds the employer's view, not by a setting.
Candidate search is a separate thing and it is off. Employers can only search for candidates who have opted in. If you opt in, a result shows a headline, a general location, skills and a seniority level — no name, no email, no phone number, and no employer names taken from your work history. An employer who wants to reach you does so through us, and may send you exactly one message; if you do not reply, that is the end of it. Every search an employer runs is logged with the terms they used.
5. Who else receives your data
Only these, and only for the stated purpose. None of them is paid for your data and none of them may use it for their own purposes.
- Our payment processor handles the checkout and the card. Your card number is entered on their systems and never reaches ours — we receive the fact that a payment succeeded, a subscription identifier, and the plan. They act as merchant of record for consumer subscriptions, which means the receipt and the tax on it are theirs.
- Our AI providers receive the text of the specific AI request you made, as described in section 3.
- Our hosting provider stores the database and the files, as any host does.
- Google, but only if you connect your calendar, and only the interview events you choose to sync. Disconnecting revokes our access.
- Employers you apply to, as described in section 4.
Some of these are outside the UK and the EEA. Where that is so, the transfer is covered by the standard contractual clauses or an adequacy decision, as appropriate. We do not sell personal data, we do not share it with data brokers, and there is no advertising network on this site.
6. How long we keep it
While you use your account, we keep what is in it — that is the point of an account. We do not keep it forever on the chance you return. If you have not signed in for 18 months we email you once, telling you the date your account will be deleted; sign in before that date — nothing more — and it stays exactly as you left it. If you do not, it is erased 30 days after the email, by the same process section 7 describes. Nothing is ever deleted quietly: the email comes first, every time. Accounts on a paid plan and employers with a live listing are never treated as inactive.
A sign-up whose email address was never confirmed, and which nothing was ever created in, is removed after 30 days without an email — we do not keep writing to an address nobody proved was theirs. If you want your account gone sooner than any of this, delete it yourself, and section 7 describes exactly what that does.
The security log is kept for as long as it is useful for fraud prevention and for establishing or defending a legal claim. Records of payments are kept for as long as tax law requires, which is generally six years.
7. What deleting your account actually does
Deleting your account is available in your settings and does not require you to ask us. It is a real erasure, run in a single transaction — if any part of it fails, the whole thing rolls back rather than leaving you half-deleted.
It is not a synonym for deleting every row, and we would rather say so here than surprise you. An application an employer already received is that employer's record of their own hiring process; a payment we took is a financial record we are required to keep. Both survive, without you attached where that is possible. This is the full list, taken directly from the code that performs the erasure:
Deleted outright
The rows are gone. Not flagged, not hidden — gone.
- CVs and résumés — Your CVs and résumés. Yours alone; nobody else relies on them.
- CV version history — Every earlier version of your CVs that we kept so you could undo.
- Files attached to applications — Portfolios, certificates and anything else you attached to an application.
- Mailing list — Your place on our mailing list, if you joined it.
- Cover letters — Your cover letters. Yours alone; nobody else relies on them.
- Outbound click log — The record of external job links you clicked.
- Saved jobs — The jobs you saved. A private list.
- Application tracker — Your own record of your job search, including applications you made on other sites. No employer here has ever seen it.
- Ratings and testimonials — Any rating or quote you left about ApplyRole, including one we were showing on the home page. It comes down with your account.
- Messages sent through the contact form — Anything you sent us through the contact form, including the message text. Messages from before you had an account, or sent signed out, are not linked to the account — ask us and we will remove those by email address.
- Replies in contact-form conversations — Our replies to your messages, and yours to ours. They go with the conversation.
- Saved search email alerts — Your saved searches and their email alerts. An alert that kept arriving after you asked to be forgotten is exactly the harm this right exists to prevent.
- In-app notifications — Your in-app notifications. The messages name companies you applied to and carry employer notes, so leaving them would leave a readable history of your job search.
- Feature access flags — Which features the account had access to. What was paid is a separate record and is kept; this is not.
Kept, with you removed from it
The record survives without a person attached to it.
- Interview rounds — Interviews employers scheduled with you. Your name comes off them; their internal notes about their own process remain, no longer connected to you.
- Insight articles authored — Articles you wrote for the Insights section stay published, no longer attributed to you.
- Applications submitted to employers — Applications an employer here received. They keep the record of their own hiring process, including for equal-opportunities reporting — but your identifying details are stripped out of it, so the row survives with no person attached.
- AI usage metering — How many AI actions were used and roughly what they cost. The numbers stay for cost accounting; the link to you is cut.
Kept, transferred to the organisation
It was never personal data about you; ownership moves.
- Job listings posted by this account — Job listings you posted. A listing belongs to the employer, not to the individual who typed it, and deleting them would strand every candidate who applied — so they transfer to the organisation instead.
- Company profiles — Company profiles you created. Corporate information rather than anything about you, so it transfers to the organisation.
Kept in full
We are required to keep it. The reason is stated.
- Billing and plan records — What plan the account was on and when. Kept because tax and accounting law requires a record of money taken.
- Security and activity log — The security log: sign-ins, password changes and administrative actions. Kept for fraud prevention and to defend a legal claim — including, if it ever comes to it, the evidence that this erasure was genuinely requested and genuinely carried out.
- Paid plan and payment records — Records of payments taken. Kept because tax and accounting law requires it — this is a record of money, not a preference.
- Financial transactions — A record of each payment: what was charged, in what currency, and when. Kept because tax law requires a record of money taken, and because a return that cannot be reconciled is a return that cannot be defended.
8. Your rights, and how to use them here
Under the UK GDPR and the EU GDPR you have the rights below. Most of them are buttons in your account rather than a request you have to make and wait on, which is deliberate — a right you have to ask permission to exercise is a slow right.
- Access and portability. Export everything we hold about you as a machine-readable file, from your settings, immediately.
- Rectification. Everything we hold is editable in the product.
- Erasure. From your settings, as described in section 7.
- Objection and restriction. Write to the contact form linked in the footer. If you object to the security log specifically, tell us — we will explain what we rely on it for and you can challenge that.
- Withdrawing consent. Candidate-search visibility is a switch in your account. Every mailing-list email carries a one-click unsubscribe that works without signing in and without confirming — one click and it is done, whether you press the link in the email or the unsubscribe button your mail app shows.
We answer within one month. If you are not satisfied you can complain to your supervisory authority — in the UK that is the Information Commissioner's Office at ico.org.uk; in the EU it is the authority for the country you live in. You are welcome to come to us first, but you do not have to.
9. Cookies
We set a session cookie so that you stay signed in, and a cookie carrying the token that protects forms against cross-site request forgery. Both are strictly necessary for the site to work and neither is used to track you. There are no advertising cookies, no third-party analytics tags and no cross-site trackers, which is why this site does not greet you with a consent banner.
10. Security, and what we would do about a breach
Passwords are stored as salted hashes and are never recoverable in plain text. Changing your password or your email address requires your current password, and a change of email is not applied until the new address is confirmed and the old one has been told. Administrative actions are logged. API keys are stored as hashes, shown once, and revocable instantly.
No system is immune. If we suffered a breach likely to result in a risk to your rights and freedoms, we would notify the supervisory authority within 72 hours and tell you directly and promptly where the risk is high — describing what happened, what data was involved and what to do about it, rather than a paragraph of reassurance.
11. Changes to this notice
When we change it we update the date at the top. If a change materially affects what we do with your data, we will tell you before it takes effect and, where the change requires it, ask you to agree rather than assume you have.