How we secure your data
"What happens to my resume?" is a fair question. Here is what's built, in plain words. Each line below is something that exists and is checked, not a promise about the future. If something changes, this page changes first.
What we promise, and how it's done
| In plain words | What's actually built |
|---|---|
| We never ask for access to your Gmail. | Sign-in is Google identity only (your name and email address). Every email opens as a prefilled Gmail draft that you send yourself. The app has no permission to send or read your mail. |
| Your data is walled off from everyone else's. | Row-level security is switched on and forced on every table in our database, and the app's own database account can't get around it. Automated tests check before every release that one user can never read or change another user's data. The database's built-in public interface is closed. |
| Your contact details never reach the AI. | Phone numbers, email addresses, postal addresses and links are removed before any text goes to an AI model. Personal data goes only to a provider that doesn't train on it (Google Gemini, paid tier). AI output that adds a fact, a number or a contact you didn't give us is thrown away. You can switch AI off. |
| Nobody on our team can look quietly. | Staff access to your content is "break-glass" only: it needs a written reason, lasts 30 minutes, is recorded, and shows up in your own activity log. |
| Download everything, or delete it all, in one tap. | The Privacy center in Settings gives you a full export (a ZIP file) and a hard delete. Deletion is immediate; our encrypted backups are overwritten within 30 days. |
| We don't sell your data or use it for ads. | No ad trackers and no data sales. The only companies that process your data are listed by name in the privacy policy. |
| Encrypted connections and encrypted backups. | HTTPS everywhere, with HSTS. Nightly backups are encrypted, kept for 30 days, and we have practised restoring them. |
| We keep even our own logs minimal. | Security logs store a one-way hash of your IP address, never the address itself. Error reports have personal data removed. Secrets never appear in logs. |
| Built for India's data protection law. | Written for the Digital Personal Data Protection Act, 2023: consent at sign-up, your rights to access, correct and erase your data, a nominee, a named grievance officer, and same-day acknowledgement of grievances. |
Behind the scenes
- Google sign-in with strictly verified tokens.
- Strict security headers on every page and response (a content security policy, and no framing by other sites).
- Resume uploads are read in a separate sandbox with time and memory limits.
- A guard against server-side request forgery on every link you submit.
- Signed webhooks.
- Bot checks (Cloudflare Turnstile) and rate limits on public forms.
- A secret scanner runs before every change is saved and again in our build checks.
- A recruiter opt-out that's honoured for good.
Found a problem?
Write to support@applyrn.com with the details. We read every report and reply the same day. Please don't access other people's data while testing.