Privacy Policy

Last updated: June 18, 2026 · Effective: June 18, 2026

1. Introduction

Villhora LLC ("we," "us," or "our") operates the ApplyOS job search platform at applyoshq.com (the "Service"). ApplyOS is a trademark of Villhora LLC. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have over it.

By using the Service, you agree to the practices described in this Policy. Contact us at privacy@applyoshq.com with any questions.

2. Data We Collect

2.1 Data You Provide Directly

DataWhenWhy
Name, email addressAccount sign-upAccount creation, communications
Resume text / PDFOnboardingJob matching, tailoring, scoring
Career profile (target roles, skills, industries, location)Onboarding / profile editingFiltering and scoring jobs
Payment informationSubscription checkoutProcessed by Stripe — we never store raw card numbers

2.2 Data Generated by Your Use

DataWhenWhy
Job records (title, company, match score)Job syncDisplaying your job feed
Feature usage counts (tailors, cover letters per month)Every feature useEnforcing plan limits
Subscription status, plan tier, billing datesCheckout / renewalsPlan enforcement, billing
IP address, device/browser infoEvery requestSecurity, fraud prevention
Session tokensAuthenticationKeeping you logged in

2.3 Data We Do Not Collect

  • We do not collect Social Security Numbers, dates of birth, race, ethnicity, or disability status.
  • We do not read your email inbox or other applications.
  • We do not collect data from your job applications after you leave our platform.
  • We do not sell your data to third parties.

3. How We Use Your Data

PurposeLegal Basis (GDPR)
Providing the Service (job discovery, scoring, tailoring)Performance of a contract
Processing payments and managing subscriptionsPerformance of a contract
Enforcing usage limits and plan termsPerformance of a contract
Sending transactional emails (receipts, billing failures)Performance of a contract
Detecting fraud and preventing abuseLegitimate interests
Complying with legal obligationsLegal obligation
Sending product updates or marketing emailsConsent (opt-in only)

4. AI Data Processing

ApplyOS uses the Anthropic API to score jobs, tailor resumes, generate cover letters, and prepare interview questions. When you use these features, your resume text and/or career profile is sent to Anthropic's API as part of a prompt, along with the relevant job description.

Anthropic processes this data according to their API Data Use Policy. As of the date of this policy, Anthropic does not use API inputs to train their models for customers on API plans. We recommend reviewing Anthropic's privacy policy at anthropic.com/privacy.

5. Third-Party Services

We share data with the following processors to operate the Service:

ProviderPurposeData Shared
ClerkAuthenticationName, email, session tokens
SupabaseDatabase (PostgreSQL)All user and job data
AnthropicAI processingResume, profile, job descriptions
StripePaymentsName, email, payment card (via Stripe's PCI vault)
VercelHosting & serverlessAll request data (logs)

We do not sell, rent, or broker your personal data to any third party for their own use.

6. Data Retention

DataRetention Period
Account data (name, email)Until account deletion
Resume text and career profileUntil you delete it or your account
Active and reviewed job records30 days from posting date
Applied and archived job recordsUntil account deletion
Subscription records7 years (financial regulation)
Usage records13 months (billing dispute window)
Server access logs90 days

7. Your Rights

All users may:

  • Access — Request a copy of your data
  • Delete — Delete your account in Settings, or email us to erase your data
  • Correct — Edit your profile and resume directly in the app
  • Port — Request your data in JSON format

EU/EEA residents (GDPR) also have the right to restrict processing, object to processing based on legitimate interests, and lodge a complaint with your national data protection authority.

California residents (CCPA/CPRA) have the right to know what data we collect, request deletion, and opt out of any sale of personal information (we do not sell data).

To exercise any right, email privacy@applyoshq.com. We respond within 30 days (GDPR) or 45 days (CCPA).

8. Data Security

  • All data is transmitted over HTTPS (TLS 1.2+)
  • Database access uses service role keys stored as environment variables — never in source code
  • Authentication is managed by Clerk, a SOC 2 Type II certified provider
  • Payment data is handled by Stripe, a PCI DSS Level 1 certified provider
  • We do not store payment card numbers, CVVs, or bank account details

9. Cookies

We use minimal cookies:

CookiePurposeDuration
Clerk session cookieAuthentication / keeping you signed inSession / 30 days

We do not use advertising cookies or behavioral tracking pixels.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact privacy@applyoshq.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a notice in the app. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

12. Contact

For privacy questions, data requests, or complaints:
Email: privacy@applyoshq.com