Skip to main content

Privacy Policy

Last updated: July 17, 2026

1. Data Controller

ApplyScope ("we," "us," or "our") is a product operated by Willian Pinho Tech LTDA, a company organized under the laws of the Federative Republic of Brazil, registered under CNPJ 20.993.975/0001-75 (the "Controller"). Willian Pinho Tech LTDA is an umbrella company that operates several products; ApplyScope is a product operated by it and is not itself a separate legal entity.

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the ApplyScope platform (the "Service"). It is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the Brazilian Lei Geral de Proteção de Dados (LGPD).

For privacy inquiries, contact our data protection contact at [email protected]. Under LGPD Art. 41, our appointed data protection contact ("Encarregado") is Willian Pinho, reachable at the same address above.

2. Data We Collect

Information you provide

  • Account information: name, email address, and hashed password.
  • Professional profile: skills, experience, salary preferences, target positions, and location.
  • Resume content: uploaded resume text used for AI matching, screening, and cover letter generation.
  • Job search activity: saved jobs, application status, notes, pipeline stage, evaluations, and cover letters.
  • Payment information: billing details are processed directly by Stripe. We do not store full card numbers; we retain a non-sensitive customer identifier, last four digits, and subscription metadata.
  • Support and feedback correspondence: messages you send through our live chat or support channels, submissions to our in-product feedback and NPS widget (your rating or score, any free-text comment, and the page you were on), and questions you type into our AI support chatbot.
  • Ambassador program data (only if you apply to and are accepted as an ambassador): phone number, personal or business website, a tax/identity document number and its issuing country (for example a CPF or CNPJ in Brazil, or your local equivalent), commission terms, and a Stripe Connect account identifier used to pay you.
  • Referral data: if you refer another user, or are referred by one, we record the referral link between the two accounts and any bonus evaluation credits it grants.
  • Beta waitlist and invite data: if you join the waitlist or receive an invite, we collect your email address, name, how you heard about us, who referred you, and your current role level.
  • Newsletter subscription: your email address and name, if you choose to subscribe.
  • Demo submissions: if you use our demo analysis form without an account, the job description and any resume or profile text you paste into it. This is held only in a bounded, short-lived in-memory cache (up to 500 entries, expiring after one hour) and is never written to our database.

Information collected automatically

  • Usage data: pages visited, features used, and product interactions (via PostHog, gated on consent).
  • Technical data: IP address, browser type, device information, and operating system.
  • Log data: request timestamps, API endpoints accessed, and error logs for debugging, security, and performance.
  • Aggregated site analytics: anonymous visit counts, referrers, and page views (via Plausible, cookieless).

3. Purposes and Legal Basis for Processing

Under GDPR Art. 6 and LGPD Art. 7, we process personal data on the following legal bases:

  • Performance of a contract (GDPR Art. 6(1)(b) / LGPD Art. 7(V)): operating your account, evaluating job postings against your profile, generating cover letters and screening answers, parsing and managing your resumes, managing your pipeline, processing subscription payments and add-on purchases, running the refer-a-friend bonus, and operating the ambassador program for accepted ambassadors — including using the tax/identity document number you give us to confirm you are eligible to be paid.
  • Legitimate interest (GDPR Art. 6(1)(f) / LGPD Art. 7(IX)): securing the Service, preventing fraud and abuse, improving product quality through aggregated analytics, debugging errors, and answering your questions through our support channels and AI support chatbot. It also covers keeping the prompt and response content of your own AI evaluations to monitor and improve evaluation quality; this uses your individual evaluation content rather than an aggregate. You may object to processing based on legitimate interest at any time.
  • Consent (GDPR Art. 6(1)(a) / LGPD Art. 7(I)): product analytics cookies (PostHog), joining the beta waitlist, newsletter subscription and marketing communications, submitting a demo analysis without an account, and any processing that is not strictly necessary to operate the Service. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legal obligation (GDPR Art. 6(1)(c) / LGPD Art. 7(II)): retaining records required by applicable tax, accounting, or data-protection law, including ambassador payout records and the tax/identity document number (CPF or CNPJ) we must report against.

4. Sub-Processors and Third Parties

We engage the following sub-processors to deliver the Service. For Anthropic, OpenAI, Stripe, Cloudflare, and Resend, a data processing agreement — including Standard Contractual Clauses or an equivalent transfer mechanism where applicable — is incorporated by reference into the standard terms that govern our use of each of those services.

Several observability and support services are self-hosted by us on infrastructure we rent and operate ourselves, rather than being provided by the branded vendor's own cloud service — these are marked below. The companies behind those self-hosted services do not receive your data. That infrastructure is rented from Hetzner and is physically located in the United States (see Section 5).

  • Anthropic (PBC, USA) — AI evaluation provider (Claude). Purpose: scoring job postings, generating cover letters and screening answers. Data shared: job descriptions and your profile/resume content. Anthropic does not use API inputs to train its models.
  • OpenAI, L.L.C. (USA) — contingent AI evaluation provider used only if and when a failover path is enabled. Purpose and data shared: same as Anthropic, when active. OpenAI API data is not used for training by default.
  • Stripe, Inc. (USA / global) — payments processor. Purpose: subscription checkout, billing, and invoicing. Data shared: your billing details are processed directly by Stripe; we receive only non-sensitive metadata (customer identifier, last four card digits, subscription status). Stripe is PCI DSS Level 1 certified.
  • Resend (USA) — transactional email delivery. Purpose: account verification, password reset, billing receipts, and product notifications. Data shared: your email address and the content of the transactional message being sent.
  • Cloudflare, Inc. (USA / global) — CDN and web application firewall (WAF). Purpose: content delivery, DDoS/bot mitigation, and edge security in front of the Service. Data shared: request metadata (IP address, headers, URLs requested) as it passes through the network edge.
  • Plausible (self-hosted) — cookieless site analytics, self-hosted by us on our own Hetzner infrastructure (not Plausible Insights OÜ's hosted service). Purpose: aggregate traffic measurement. Data shared: no personal identifiers are collected.
  • PostHog Inc. (USA) — product analytics and session replay. Purpose: understanding in-product usage to improve the Service. Data shared: in-product events and usage patterns; cookie-based and enabled only after explicit consent.
  • Chatwoot — customer support chat and inbox, self-hosted by us on our own Hetzner infrastructure (not Chatwoot Inc.'s hosted SaaS). Purpose: handling support requests. Data shared: messages you send through support channels.
  • Hetzner Online GmbH (Germany; servers in the USA) — the cloud provider we rent our servers from. Those servers run the Service, our database, our MinIO S3-compatible object storage, our backups, and every self-hosted service listed here. Hetzner is a German company, but the server we rent sits in its Ashburn, Virginia (USA) region, so the data above is stored in the United States. Purpose: application hosting and data storage. Data shared: all Service data at rest, encrypted.
  • GlitchTip — error and performance monitoring, self-hosted by us on our own Hetzner infrastructure (Sentry-SDK-compatible; not the Sentry / Functional Software, Inc. hosted service). Purpose: debugging and reliability. Data shared: stack traces and request context; sensitive fields are scrubbed before transmission.
  • LangFuse — LLM observability, self-hosted by us on our own Hetzner infrastructure (not LangFuse's hosted cloud). Purpose: traces of AI evaluations for debugging and quality monitoring. Data shared: evaluation inputs and outputs; retained on our own schedule and deleted with your account data.
  • Listmonk — newsletter and email-campaign management, self-hosted by us on our own Hetzner infrastructure (not a hosted SaaS). Purpose: managing newsletter subscriptions, drip campaigns, and unsubscribe handling. Data shared: your email address and name, only if you subscribe to our newsletter.

We do not sell, rent, or share your personal data with third parties for their own marketing purposes.

5. International Data Transfers

We are established in Brazil. The servers that run the Service and store your account, profile, resume, evaluation, and backup data are rented from Hetzner Online GmbH and are physically located in Ashburn, Virginia, in the United States. If you are located in the EU/EEA, the UK, or Brazil, your personal data is therefore transferred to and stored in the United States. The self-hosted services listed in Section 4 run on those same servers.

Some sub-processors (notably Anthropic, OpenAI, PostHog, Cloudflare, Stripe, and Resend) are likewise established in the United States or otherwise process data outside Brazil. For Anthropic, OpenAI, Stripe, Cloudflare, and Resend, the data processing agreement incorporated into their standard terms includes the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or an equivalent mechanism such as the EU-US Data Privacy Framework, for transfers of this kind.

For transfers involving Brazil, LGPD Art. 33 and the ANPD's international-transfer rules apply (ANPD Resolução CD/ANPD n. 19/2024, including its own standard contractual clauses). If you want to know which transfer safeguard applies to a specific provider, ask us and we will tell you what is in place for that provider — write to [email protected].

6. Data Retention

  • Account and profile data: retained for the lifetime of your account, plus up to 90 days in encrypted backups after account deletion, after which it is purged.
  • Resume content: retained on the same schedule as account data.
  • Job evaluations, cover letters, and pipeline records: retained while the account is active; deleted on the same schedule as account data.
  • Identifiable product analytics events (PostHog): retained for 12 months, then deleted or anonymized.
  • Aggregated site analytics (Plausible): anonymous by design; retained indefinitely at the aggregate level.
  • Billing records: Stripe is the system of record for billing history and invoices, which are retained for the period required by applicable tax and accounting law (commonly 5-10 years).
  • Application and security logs: retained between 30 and 90 days depending on log type, then rotated.

7. Security Measures

We implement technical and organizational measures appropriate to the risk, including:

  • TLS 1.2+/HTTPS for all data in transit.
  • Encryption at rest for databases and object storage.
  • Row-Level Security (RLS) and role-based access control (RBAC) to isolate tenant data.
  • Hashed passwords (never stored in plain text), secure session tokens, and short-lived API credentials.
  • Rate limiting, audit logging, and automated monitoring to detect anomalies.
  • Least-privilege access for employees and contractors, with access reviews at least annually.
  • Regular encrypted backups with a defined retention window and tested restoration.

No system is completely secure. You are responsible for maintaining the confidentiality of your account credentials and for notifying us promptly of any suspected compromise.

8. Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, in accordance with GDPR Art. 33. Where the breach is likely to result in a high risk, we will also notify affected users without undue delay in accordance with GDPR Art. 34. LGPD Art. 48 and CCPA/CPRA notification duties are met in parallel.

9. Your Rights

Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, LGPD), you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data ("right to be forgotten"). We delete your data from our production systems within 30 days of a verified request. Encrypted backups are purged on our standard rotation window (up to 90 days — see Section 6) rather than immediately, since backups cannot be selectively edited. Third-party sub-processors that already received your data before your request — notably Anthropic (AI evaluation) and Stripe (payments) — retain and delete it under their own schedules and our data processing agreements with them, not on our internal timeline. Records we are legally required to keep, such as billing and tax documentation held via Stripe, are retained for the legally-required period (commonly around five years under applicable Brazilian and other tax law) and cannot be deleted early even on request.
  • Portability — receive your data in a structured, machine-readable format (a self-service JSON export is available from your account settings).
  • Restriction — request that we limit processing in specific circumstances.
  • Objection — object to processing based on legitimate interests or direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Non-discrimination — CCPA-protected right not to receive discriminatory treatment for exercising your rights.
  • Lodge a complaint — with your local supervisory authority (e.g., the Irish DPC, the ANPD in Brazil, or the California Attorney General / CPPA).

You can exercise several of these rights directly in the app, without contacting us: use the self-service JSON export in your account settings to access and download your data, and Delete Account in Settings to erase your account and data. For any other request, or if you would rather write to us, contact us at [email protected] or through the support chat inside the app. We will respond without undue delay and in any event within one month of receipt, extendable by up to two further months for complex or numerous requests, consistent with GDPR Art. 12(3).

10. Cookies and Similar Technologies

We use the following cookies and local storage:

  • Strictly necessary — authentication tokens stored in localStorage to keep you signed in, and minimal session preferences (e.g., saved filters and view settings). These are required for the Service to function and do not require consent.
  • Site analytics (Plausible) — cookieless and GDPR-compliant; no personal identifiers are collected.
  • Product analytics (PostHog) — sets cookies to identify distinct users and record in-product actions for product improvement. This is loaded only after you grant consent via our cookie banner and respects the Do Not Track (DNT) header.

You may opt out of product analytics at any time through the cookie banner or your account settings; opting out does not affect your core account functionality. We do not use advertising cookies or cross-site tracking cookies.

11. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, please contact [email protected] and we will take reasonable steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email and in-product at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For questions or concerns about this Privacy Policy or our data practices, contact the Controller, Willian Pinho Tech LTDA (CNPJ 20.993.975/0001-75), at [email protected]. For EU/UK residents, you may also contact our LGPD Encarregado / data protection contact, Willian Pinho, at the same address.

Privacy Policy | ApplyScope