Privacy Policy
Last updated 6 October 2026
1.Who is responsible
ApplyCruise is the Data Fiduciary for the personal data described here. Our grievance contact is on the Contact page.
2.What we collect
Account data. Your email address, a salted hash of your password (never the password itself), email-verification and password-reset tokens, and sign-in timestamps.
Your résumé and profile. The résumé file you upload and the text extracted from it; your name, phone number, location, years of experience, skills, current and expected salary, notice period, and the target roles you enter during onboarding. This is the data submitted to employers on your behalf.
Application activity. Which postings we found, how each was scored, whether an application was submitted, and the answers given to employer questionnaires — including answers you supply yourself, which we keep so the same question is not asked twice.
Job-site sessions. See clause 3.
Payment data. Plan, amount, period, and the Razorpay order and payment identifiers. Card numbers, UPI handles and bank credentials are handled entirely by Razorpay and never reach our servers.
Technical data. IP address and request metadata, used for rate-limiting and abuse prevention, and server logs of the automation so failures can be diagnosed. Those logs may contain job titles, employer names and page screenshots from your applications.
3.Job-site sign-ins and the sessions we store
We don't keep your job-site password — but we do hold your session
When you connect a job site, we open that site’s own login page in a browser running on our server and show it in your browser tab. You type your password into the job site’s page: your keystrokes are passed to that browser as you type, over an encrypted connection. We do not record or store them, and no member of our team can see your password.
What we do store is the signed-in session that results — the cookies and browser profile for that site, held on our server so the automation can act as you. Anyone with access to that profile could use your job-site account. We protect it as described in clause 7. You can revoke it at any time: disconnecting a site deletes that site’s session from the profile, and deleting your account deletes the whole profile.
Some sign-in data lives outside the cookies. A few sites set sign-in cookies that expire when the browser closes (Shine does), so we keep a separate copy of them to keep you signed in between runs; and some sites keep part of their sign-in in the browser’s site storage (Hirist does). Disconnecting a site removes all of it: that site’s cookies, the data it stored in the browser (such as its local storage and databases), and our separate copy of its cookies.
If Autopilot is running on the site you disconnect, we stop it first, so it can’t keep using that site. The separate copy is deleted at once, and the rest moments later. If our browser has your profile open at that moment (for example, Autopilot is working on your other sites) or the clean-up fails, it is retried the next time our browser opens your profile, before it visits any site, and every time after that until it succeeds.
4.Why we process it
- To provide the service you asked for: finding, screening and submitting job applications, and answering employer questions on your behalf. This is processing for a specified purpose to which you consented at sign-up.
- To operate your account: authentication, email verification, password reset, and support.
- To take payment and enforce plan limits.
- To keep the service safe: rate-limiting, fraud and abuse prevention.
- To meet legal obligations, including tax and accounting records.
We do not sell personal data, we do not share it for advertising, and we do not use your résumé or your answers to train our own models.
6.Processing outside India
The AI providers we use to answer employer questionnaires and tailor résumés operate outside India. Using the service means résumé extracts and job descriptions are transmitted to them for processing. We send only what the task needs, and we do not permit them to use your content to train their models where their terms allow us to make that election.
Resend, which sends our emails, and Cloudflare, whose network carries every request to and from the site, also operate outside India, so your email address and the data in your requests may be processed outside India too.
7.How we protect it
- Traffic is served over TLS.
- Passwords are stored as PBKDF2 hashes; verification codes and reset tokens are stored hashed and compared in constant time.
- Résumé text and uploaded résumé files are encrypted at rest. The plaintext copy the automation needs exists only while a run is in progress and is removed when it ends.
- Each account's data — application history, answers, job-site profile — lives in its own directory, and an automation run is started with only that account's information in its environment.
- Sign-in streaming is gated by a short-lived token bound to one account and one site, revoked as soon as the attempt ends.
- Sign-up, sign-in, verification and password reset are rate-limited per IP address and per account.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board as the DPDP Act requires.
8.How long we keep it
- Account and profile data: until you delete your account.
- Résumé and application history: until you delete them, or your account.
- Job-site sessions: a site's cookies, the data it stored in the browser and our copy of its sign-in cookies, until you disconnect it (clause 3 says when each is removed); the rest of the browser profile, until you delete your account.
- Automation logs and diagnostic screenshots: pruned automatically, typically within 7 days.
- Payment and tax records: retained as long as Indian tax law requires, even after account deletion.
Deleting your account removes your personal data from live systems promptly. Backups are rotated and any residual copy ages out with them.
9.Your rights
Under the DPDP Act you may:
- Ask what personal data we hold about you and how it has been processed.
- Have inaccurate or incomplete data corrected or completed.
- Have your data erased, unless we must keep it by law.
- Withdraw consent — which means we stop applying on your behalf, and you can delete your account.
- Nominate someone to exercise these rights if you die or become incapacitated.
- Complain to our Grievance Officer, and escalate to the Data Protection Board of India if unsatisfied.
Most of this is self-service in the app: your résumé and profile are editable, sites can be disconnected, and the account can be deleted. For anything else, write to our Grievance Officer — see Contact. We respond within 30 days.
11.Children
The service is not for anyone under 18 and we do not knowingly process a child’s data. If you believe a child has created an account, contact us and we will delete it.
12.Changes
We will post any update here and change the date at the top. Material changes will be notified by email or in the app before taking effect.
The other policies