Privacy Policy
How Md Mosharof Hossain, doing business as Applying Agent (“Applying Agent,” “we,” “us”), handles personal information in the web app and Mac desktop agent.
What we collect
- Account email and password hash
- Profile, resume files, job criteria, and saved application answers (including EEO or work-authorization answers you choose to save)
- Application status and agent operational logs (heartbeats, failures)
- Optional IMAP credentials, stored encrypted, if you connect email for verification codes
Where the service runs
The web app is hosted by Render in Oregon, in the United States. Account information is stored in a PostgreSQL database on Render in that same region. Resume files and other stored files are kept in Cloudflare R2 in its Western North America (WNAM) location.
How we use it
We use this information to run your account, match jobs, fill and submit applications you start, and keep the Mac agent paired. We do not use connected email for advertising.
Employers and ATS sites
When you apply, we send your profile, resume, and saved answers (including EEO answers you provided) to that employer and their ATS (for example Greenhouse or Workday). If auto-apply is on, we also send answers configured as defaults. When a job’s office location is missing or unclear, that can include a yes to a required commute-or-relocate question. To finish an application, the agent may accept that employer’s required privacy notice, terms, and arbitration acknowledgments. Those companies use the information under their own policies.
AI
Job matching uses local scoring. Optional or paid AI features may send resume text, career stories, answers, and job descriptions to Groq (free tier) or Anthropic (paid). We do not use EEO answers to target ads.
Email (optional)
If you enable IMAP, the agent reads recent inbox messages only to extract an employer verification code. We do not store message bodies. You can disconnect email at any time.
Cookies and online tracking
The web app uses a session cookie for login. We do not currently use third-party advertising or analytics cookies. Applying Agent does not track your activity across other websites.
Public pages load fonts from Google Fonts and icons (and, on some pages, scripts) from jsDelivr. Your browser sends those requests to those hosts, which receive your IP address and ordinary request data.
We do not respond to browser Do Not Track signals. The site behaves the same way whether or not your browser sends one.
Sale of data
We do not sell personal information to data brokers and do not share it for cross-context advertising. If that changes, we will update this policy.
Retention and deletion
We keep account and application data while your account is open. You can delete your account from Account settings (password required).
Deleting your account removes the live copy of your account, profile, and application data from the production database. That includes your profile, saved credentials, answers, and apply history.
Resume files stored for that account in Cloudflare R2 are deleted as part of the same cleanup. If that deletion does not succeed at the time, we keep a minimal internal record and automatically retry until those resume files are confirmed deleted. The record does not contain your resume contents.
The production database is PostgreSQL on Render. Render currently keeps point-in-time recovery data for that database for up to 3 days. Information removed from the live database may therefore remain recoverable in that provider-managed recovery data for up to 3 days, and then ages out.
Deleting your Applying Agent account cannot recall information already submitted to an employer or their applicant-tracking provider. It also does not remove local Applying Agent files or browser data from your Mac, including the pairing secret and browser profile.
Security
Account passwords are stored as bcrypt hashes. Before certain profile values are written to the database, the application encrypts them with AES-256-GCM. That covers phone number, address, salary, and sensitive profile answers such as work authorization, demographic and EEO answers, veteran and disability status, and similar sensitive profile values. The name of each field is stored in plaintext. This is encryption of those fields by the application. It is not encryption of the entire database, and it does not cover resume files or every other value we store.
When the credential key is configured, employer-site passwords and optional IMAP app passwords are encrypted by the application before they are stored. Production traffic between your browser or the Mac agent and our service uses HTTPS. In production the login session cookie is HTTP-only and is sent only over HTTPS. You must be signed in to view or change your account. The Mac pairing secret may be stored on your computer; protect that device.
Children
Applying Agent is for adults 18 and over. We do not knowingly collect information from children.
California
If you are a California resident, you may request access, correction, or deletion of personal information on the Contact Us / Privacy Request page.
Contact
For legal, privacy, and support inquiries, use the Contact Us / Privacy Request page. We email that request to our support inbox and do not add it to your account record. Md Mosharof Hossain, doing business as Applying Agent.