Privacy Policy
Last updated October 6, 2026
The short version
- We store what you give us (your profile, résumé, saved answers and the jobs you track) so HitApply can work. We don't sell it or use it for ads.
- To write your documents, your résumé and job text are sent through OpenRouter to an AI model provider.
- The extension reads only the job pages you open. It doesn't track your browsing.
- AI assistants you connect act only on your instructions. HitApply never submits an application.
- Your data is stored mainly in the United States.
- Delete your account any time in Settings, or email privacy@hitapply.app to see, correct or delete your data.
This summary is here to help you read what follows. It isn't the full agreement; the full text below governs.
1. Who we are
HitApply is operated by John Mark Lecegues, an individual based in Saskatchewan, Canada, who is responsible for your personal information and acts as HitApply's Privacy Officer. Contact: privacy@hitapply.app. We handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). This policy is part of our Terms of Service.
2. What we collect
- Account: your email address. Your password is handled by our sign-in provider (Supabase Auth); we never see it.
- Profile and résumé: what you enter or import, such as your name, contact details, work history, education and skills, plus your writing preferences and templates.
- Autofill answers in your profile: answers you enter for autofill to use. These can include sensitive information, such as work authorization and sponsorship, and optional demographic, disability or veteran self-identification answers. Entering them is optional, and you can change or clear them at any time.
- Your answer library:only if you choose to, the extension saves the questions autofill doesn't recognize and your answers to them (typed by you or suggested by AI and accepted), so it can reuse them. It asks once, and you can change your choice, and see and delete saved answers, on the Extension page in HitApply.
- Jobs and applications: postings you save or queue, application status and dates, and the résumés and cover letters generated for you.
- Settings: job alerts, saved searches and notification preferences. If you add your own OpenRouter key or a Discord webhook, we store it encrypted.
- Connected assistants:which AI assistants you've connected, what access you granted, and when it was used.
- Agreement records: which version of our Terms and Privacy Policy you agreed to, and when.
- Technical data:server logs (such as IP address, time and request details) that we use for security and fixing problems, and anonymous page-view statistics from Vercel Web Analytics, which doesn't use cookies.
3. The browser extension
The extension runs only on supported job boards and application sites, and on other sites only if you grant it access. On those pages it reads the job details and the application form so it can save the job and fill in fields from your profile. It sends HitApply the job details you save and, when you ask for an AI answer, the form question. It does not track or collect your browsing history, and it doesn't read pages you haven't opened.
Autofill ticks an employer's consent or certification boxes only if you turn that on, and the AI never answers demographic, disability or veteran questions. We record these choices, and when you made them.
The extension keeps your sign-in session in your browser's local storage, and its settings (such as which kinds of fields to fill) in browser storage that your browser may sync between your devices. Signing out removes the session.
4. How we use your information
We use your information only to:
- provide the Service: matching jobs, generating documents, autofill, tracking and alerts;
- keep the Service and your account secure and fix problems;
- contact you about your account, such as invitations, password resets, and changes to these policies.
We don't sell your personal information, use it for advertising, or use it to train our own AI models.We don't look at your content except when you ask us to help with a problem, to keep the Service secure, or when the law requires it.
Chrome Web Store Limited Use:HitApply's use of information received from the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements. We use it only to provide the extension's features. We don't transfer it except as described here, don't use it for advertising or creditworthiness, and don't let people read it except with your consent, for security, or as the law requires.
6. AI assistants and submitting applications
An AI assistant you connect acts only on your instructions. If you set one up to fill in or submit applications for you, it should do so only after you confirm. HitApply itself never submits an application. You can see and disconnect connected assistants at any time in Settings.
7. Where your data is stored
Our service providers store and process data mainly in the United States, and AI providers may process requests in other countries. Information stored outside Canada is subject to the laws of those countries and may be accessible to their courts and authorities.
8. How long we keep it, and deleting it
We keep your information while your account is active. To delete your account and its data, use Delete account in Settings, which ends your access immediately, or email privacy@hitapply.appfrom the address on your account. Either way, we delete your data within 30 days, usually within minutes of a Settings request. Copies in our backups are removed as those backups expire, within a further 30 days. Logs and anonymous statistics may be kept longer in a form that doesn't identify you. We keep only the random ID of a deleted account, so that it can't be used again.
9. Your choices and rights
You can see and edit most of your information in HitApply at any time. You can also ask us for a copy of your personal information, to correct it, or to delete it, and you can withdraw your consent by closing your account. Email privacy@hitapply.app, and we'll reply within 30 days. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada.
10. Security
We protect your information with encryption in transit (HTTPS), encryption at rest for secrets such as API keys and webhook URLs, private file storage, and a strict separation of each user's data. Access to production systems is limited to the operator.
No system is perfectly secure. If a breach of your information creates a real risk of significant harm to you, we'll notify you and the Privacy Commissioner as PIPEDA requires. To report a security problem, email privacy@hitapply.app.
11. Age
HitApply is only for people 18 and older. We don't knowingly collect information from anyone younger.
12. Changes to this policy
When we change this policy, we'll update the date at the top. If a change is material, we'll ask you to agree to the new version before you continue using HitApply.