1. Summary
Cookies are small files a site stores in your browser. We use a small number of first-party cookies for signing in, security, and remembering your working document. We do not use advertising cookies, marketing pixels, Google Analytics, or Facebook/Meta tracking. Nothing on this site profiles you for advertising.
This policy sits alongside our Privacy Policy, which explains the wider picture of what we collect and who receives it.
2. Strictly necessary cookies
These make signing in and staying signed in possible, and protect against cross-site request forgery. The Service cannot work without them, so they are set without consent, as the law permits.
| Cookie | Purpose | Lifetime |
|---|---|---|
next-auth.session-token( __Secure- prefixed over HTTPS) | Keeps you signed in. Holds your signed session token. | Session |
next-auth.csrf-token | Protects sign-in and sign-out against cross-site request forgery. | Session |
next-auth.callback-url | Returns you to the right page after signing in. | Session |
github_oauth_state | One-time value that protects the GitHub connection flow. Only set if you connect GitHub. | 10 minutes |
3. Functional cookies
| Cookie | Purpose | Lifetime |
|---|---|---|
current_resume_template | Holds the working copy of the resume document you are editing, so previews and edits stay in sync. | 24 hours |
github_token | Your GitHub access token, so we can read the repositories you select. Set only if you connect GitHub; cleared when you disconnect. | 8 hours |
github_installation_id | Identifies your GitHub app installation. Set only if you connect GitHub; cleared when you disconnect. | 14 days |
One disclosure worth making directly. The current_resume_template cookie stores the source of the resume you are working on, which contains your personal details, and it is not marked HttpOnly — meaning scripts running on the page can read it. It is a first-party cookie and is not sent anywhere other than our own server, but we would rather you knew. Narrowing this is on our fix list.
4. Browser storage
The app also keeps working data in your browser’s local and session storage. This never leaves your device unless you save the work to your account, and you can clear it by clearing site data.
| Item | Purpose |
|---|---|
resumeBuilderData | Your in-progress resume builder form, including name, email and phone, so a refresh does not lose your work. Kept until you clear it. |
| Customize draft | The job description and tailoring state of an in-progress customization. |
summaryOptimizerState | An in-progress professional summary, for the current tab only. |
applify_target_pages | Your preferred resume page count. |
galleryInfoDismissed | Remembers that you dismissed the gallery introduction. |
githubAuthReturnUrl, fromGitHubAuth | Returns you to the right page after connecting GitHub. |
5. Analytics
We use Vercel Web Analytics and Vercel Speed Insights to count page views and measure loading performance. Vercel states that Web Analytics does not use cookies and identifies visitors with a temporary hash rather than a persistent identifier. We do not use Google Analytics or any other analytics product.
6. Third-party embeds that set their own cookies
| Embed | Where it appears | What it does |
|---|---|---|
| Google reCAPTCHA | The contact form | Tells humans from bots. Google receives your IP address and interaction signals and may set its own cookies. |
| YouTube video player | Pages with tutorial or demo videos | Plays embedded videos. Google receives your IP address and referring page, and the standard YouTube player may set cookies including advertising cookies. |
| flagcdn.com | The country selector on phone number fields | Serves flag images. Receives your IP address; sets no cookies of its own. |
These cookies are controlled by Google, not by us, and are governed by Google’s privacy policy.
7. Consent status — an honest note
Applify AI does not currently display a cookie consent banner or a preference centre. Our own cookies are limited to the strictly necessary and functional ones listed above, which in most jurisdictions do not require prior consent. However, the Google reCAPTCHA and YouTube embeds in section 6 can set non-essential cookies before you have had the chance to refuse them. If you are in the EEA or the UK, that falls short of what the ePrivacy rules expect, and we are addressing it. Until then you can avoid those cookies by not visiting the contact page and not playing embedded videos, or by using the browser controls in section 8.
An earlier version of this page described a cookie banner and preference centre that did not exist, and documented Google Analytics and Meta advertising cookies that this site has never set. Both were wrong and have been corrected.
8. How to control cookies
Every major browser lets you block or delete cookies. Blocking our strictly necessary cookies will stop you from signing in.
- Chrome: Settings → Privacy and security → Third-party cookies
- Safari: Settings → Privacy
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Edge: Settings → Cookies and site permissions
To clear the browser storage in section 4, clear site data for www.applify-ai.com in your browser settings.
9. Contact
Questions about this policy go to admin@applify-ai.com.