Privacy Policy
Last updated: June 18, 2026 · Effective: June 18, 2026
1. Introduction
Villhora LLC ("we," "us," or "our") operates the ApplyOS job search platform at applyoshq.com (the "Service"). ApplyOS is a trademark of Villhora LLC. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have over it.
By using the Service, you agree to the practices described in this Policy. Contact us at privacy@applyoshq.com with any questions.
2. Data We Collect
2.1 Data You Provide Directly
| Data | When | Why |
|---|---|---|
| Name, email address | Account sign-up | Account creation, communications |
| Resume text / PDF | Onboarding | Job matching, tailoring, scoring |
| Career profile (target roles, skills, industries, location) | Onboarding / profile editing | Filtering and scoring jobs |
| Payment information | Subscription checkout | Processed by Stripe — we never store raw card numbers |
2.2 Data Generated by Your Use
| Data | When | Why |
|---|---|---|
| Job records (title, company, match score) | Job sync | Displaying your job feed |
| Feature usage counts (tailors, cover letters per month) | Every feature use | Enforcing plan limits |
| Subscription status, plan tier, billing dates | Checkout / renewals | Plan enforcement, billing |
| IP address, device/browser info | Every request | Security, fraud prevention |
| Session tokens | Authentication | Keeping you logged in |
2.3 Data We Do Not Collect
- We do not collect Social Security Numbers, dates of birth, race, ethnicity, or disability status.
- We do not read your email inbox or other applications.
- We do not collect data from your job applications after you leave our platform.
- We do not sell your data to third parties.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Service (job discovery, scoring, tailoring) | Performance of a contract |
| Processing payments and managing subscriptions | Performance of a contract |
| Enforcing usage limits and plan terms | Performance of a contract |
| Sending transactional emails (receipts, billing failures) | Performance of a contract |
| Detecting fraud and preventing abuse | Legitimate interests |
| Complying with legal obligations | Legal obligation |
| Sending product updates or marketing emails | Consent (opt-in only) |
4. AI Data Processing
ApplyOS uses the Anthropic API to score jobs, tailor resumes, generate cover letters, and prepare interview questions. When you use these features, your resume text and/or career profile is sent to Anthropic's API as part of a prompt, along with the relevant job description.
Anthropic processes this data according to their API Data Use Policy. As of the date of this policy, Anthropic does not use API inputs to train their models for customers on API plans. We recommend reviewing Anthropic's privacy policy at anthropic.com/privacy.
5. Third-Party Services
We share data with the following processors to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Name, email, session tokens |
| Supabase | Database (PostgreSQL) | All user and job data |
| Anthropic | AI processing | Resume, profile, job descriptions |
| Stripe | Payments | Name, email, payment card (via Stripe's PCI vault) |
| Vercel | Hosting & serverless | All request data (logs) |
We do not sell, rent, or broker your personal data to any third party for their own use.
6. Data Retention
| Data | Retention Period |
|---|---|
| Account data (name, email) | Until account deletion |
| Resume text and career profile | Until you delete it or your account |
| Active and reviewed job records | 30 days from posting date |
| Applied and archived job records | Until account deletion |
| Subscription records | 7 years (financial regulation) |
| Usage records | 13 months (billing dispute window) |
| Server access logs | 90 days |
7. Your Rights
All users may:
- Access — Request a copy of your data
- Delete — Delete your account in Settings, or email us to erase your data
- Correct — Edit your profile and resume directly in the app
- Port — Request your data in JSON format
EU/EEA residents (GDPR) also have the right to restrict processing, object to processing based on legitimate interests, and lodge a complaint with your national data protection authority.
California residents (CCPA/CPRA) have the right to know what data we collect, request deletion, and opt out of any sale of personal information (we do not sell data).
To exercise any right, email privacy@applyoshq.com. We respond within 30 days (GDPR) or 45 days (CCPA).
8. Data Security
- All data is transmitted over HTTPS (TLS 1.2+)
- Database access uses service role keys stored as environment variables — never in source code
- Authentication is managed by Clerk, a SOC 2 Type II certified provider
- Payment data is handled by Stripe, a PCI DSS Level 1 certified provider
- We do not store payment card numbers, CVVs, or bank account details
9. Cookies
We use minimal cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Clerk session cookie | Authentication / keeping you signed in | Session / 30 days |
We do not use advertising cookies or behavioral tracking pixels.
10. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact privacy@applyoshq.com and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a notice in the app. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact
For privacy questions, data requests, or complaints:
Email: privacy@applyoshq.com