Privacy Policy

Last updated October 6, 2026

The short version

  • We store what you give us (your profile, résumé, saved answers and the jobs you track) so HitApply can work. We don't sell it or use it for ads.
  • To write your documents, your résumé and job text are sent through OpenRouter to an AI model provider.
  • The extension reads only the job pages you open. It doesn't track your browsing.
  • AI assistants you connect act only on your instructions. HitApply never submits an application.
  • Your data is stored mainly in the United States.
  • Delete your account any time in Settings, or email privacy@hitapply.app to see, correct or delete your data.

This summary is here to help you read what follows. It isn't the full agreement; the full text below governs.

1. Who we are

HitApply is operated by John Mark Lecegues, an individual based in Saskatchewan, Canada, who is responsible for your personal information and acts as HitApply's Privacy Officer. Contact: privacy@hitapply.app. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). This policy is part of our Terms of Service.

2. What we collect

  • Account: your email address. Your password is handled by our sign-in provider (Supabase Auth); we never see it.
  • Profile and résumé: what you enter or import, such as your name, contact details, work history, education and skills, plus your writing preferences and templates.
  • Autofill answers in your profile: answers you enter for autofill to use. These can include sensitive information, such as work authorization and sponsorship, and optional demographic, disability or veteran self-identification answers. Entering them is optional, and you can change or clear them at any time.
  • Your answer library:only if you choose to, the extension saves the questions autofill doesn't recognize and your answers to them (typed by you or suggested by AI and accepted), so it can reuse them. It asks once, and you can change your choice, and see and delete saved answers, on the Extension page in HitApply.
  • Jobs and applications: postings you save or queue, application status and dates, and the résumés and cover letters generated for you.
  • Settings: job alerts, saved searches and notification preferences. If you add your own OpenRouter key or a Discord webhook, we store it encrypted.
  • Connected assistants:which AI assistants you've connected, what access you granted, and when it was used.
  • Agreement records: which version of our Terms and Privacy Policy you agreed to, and when.
  • Technical data:server logs (such as IP address, time and request details) that we use for security and fixing problems, and anonymous page-view statistics from Vercel Web Analytics, which doesn't use cookies.

3. The browser extension

The extension runs only on supported job boards and application sites, and on other sites only if you grant it access. On those pages it reads the job details and the application form so it can save the job and fill in fields from your profile. It sends HitApply the job details you save and, when you ask for an AI answer, the form question. It does not track or collect your browsing history, and it doesn't read pages you haven't opened.

Autofill ticks an employer's consent or certification boxes only if you turn that on, and the AI never answers demographic, disability or veteran questions. We record these choices, and when you made them.

The extension keeps your sign-in session in your browser's local storage, and its settings (such as which kinds of fields to fill) in browser storage that your browser may sync between your devices. Signing out removes the session.

4. How we use your information

We use your information only to:

  • provide the Service: matching jobs, generating documents, autofill, tracking and alerts;
  • keep the Service and your account secure and fix problems;
  • contact you about your account, such as invitations, password resets, and changes to these policies.

We don't sell your personal information, use it for advertising, or use it to train our own AI models.We don't look at your content except when you ask us to help with a problem, to keep the Service secure, or when the law requires it.

Chrome Web Store Limited Use:HitApply's use of information received from the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use it only to provide the extension's features. We don't transfer it except as described here, don't use it for advertising or creditworthiness, and don't let people read it except with your consent, for security, or as the law requires.

5. Who we share it with

We share personal information only with service providers that help run HitApply, and only as needed. We remain responsible for your information when our service providers process it: we choose providers with appropriate safeguards and send them only what's needed.

  • Supabase: database, sign-in and file storage (your data and generated documents).
  • Render and Vercel: hosting for our servers and website. Vercel also provides our cookieless page-view statistics.
  • OpenRouter and the AI model provider it routes to: when you generate or edit a document, parse a résumé or ask for an AI answer, the relevant parts of your profile, résumé and the job are sent to an AI model. HitApply never includes your demographic, disability or veteran answers, your screening consents, or the answers you save under “Your Questions” in what it sends to an AI model.We set our AI routing to exclude providers that train on your data. Providers may keep requests for a limited time under their own terms (for example, to monitor abuse). If you use your own OpenRouter key, your OpenRouter account's settings apply instead.

Your information also goes to others only when you choose to send it:

  • Employers and application sites receive what you submit to them, under their own privacy policies.
  • Discord receives job alerts if you add a Discord webhook.
  • AI assistants you connect(such as ChatGPT or Claude) receive the HitApply data you allow them to access. Your saved application answers, including any demographic, disability or veteran answers and screening consents, are shared with an assistant only if you separately grant that access when you connect it. What the assistant's provider does with it is governed by that provider's policies.

We may also disclose information if the law requires it, or to someone who takes over HitApply, who must keep protecting it under this policy.

6. AI assistants and submitting applications

An AI assistant you connect acts only on your instructions. If you set one up to fill in or submit applications for you, it should do so only after you confirm. HitApply itself never submits an application. You can see and disconnect connected assistants at any time in Settings.

7. Where your data is stored

Our service providers store and process data mainly in the United States, and AI providers may process requests in other countries. Information stored outside Canada is subject to the laws of those countries and may be accessible to their courts and authorities.

8. How long we keep it, and deleting it

We keep your information while your account is active. To delete your account and its data, use Delete account in Settings, which ends your access immediately, or email privacy@hitapply.appfrom the address on your account. Either way, we delete your data within 30 days, usually within minutes of a Settings request. Copies in our backups are removed as those backups expire, within a further 30 days. Logs and anonymous statistics may be kept longer in a form that doesn't identify you. We keep only the random ID of a deleted account, so that it can't be used again.

9. Your choices and rights

You can see and edit most of your information in HitApply at any time. You can also ask us for a copy of your personal information, to correct it, or to delete it, and you can withdraw your consent by closing your account. Email privacy@hitapply.app, and we'll reply within 30 days. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada.

10. Security

We protect your information with encryption in transit (HTTPS), encryption at rest for secrets such as API keys and webhook URLs, private file storage, and a strict separation of each user's data. Access to production systems is limited to the operator.

No system is perfectly secure. If a breach of your information creates a real risk of significant harm to you, we'll notify you and the Privacy Commissioner as PIPEDA requires. To report a security problem, email privacy@hitapply.app.

11. Age

HitApply is only for people 18 and older. We don't knowingly collect information from anyone younger.

12. Changes to this policy

When we change this policy, we'll update the date at the top. If a change is material, we'll ask you to agree to the new version before you continue using HitApply.