1. Who we are
Applify AI is a resume tailoring service operated by SKomp Studio, a corporation based in Ontario, Canada. In this policy “we”, “us” and “our” mean SKomp Studio. SKomp Studio is the controller of the personal information described here (under Canadian law, the organization accountable for it).
- Service: Applify AI, at www.applify-ai.com
- Person accountable for privacy: Suleyman Kiani
- Contact: admin@applify-ai.com
- Postal location: Hamilton, Ontario, Canada
This policy covers the Applify AI website and application. It does not cover third-party sites we link to, or the job boards and employers you send your resume to.
2. What we collect
2.1 Information you give us
- Account details: first and last name, email address, phone number and country code, and a password (stored only as a bcrypt hash, never in readable form).
- Profile details: location, and any LinkedIn, GitHub or portfolio links you add.
- Resume content: the resumes and LinkedIn PDF exports you upload, and everything inside them — employment history, employer names, dates, education, certifications, skills, projects, and any personal details you have written into the document.
- Job descriptions you paste in to tailor a resume against.
- Support messages sent through the contact form, including your name, email, subject and message.
Please do not upload information you do not want processed. Resumes sometimes contain data that receives special protection under European and UK law — health or disability information, religious or political affiliation, trade union membership, or racial or ethnic origin. Applify AI does not need any of it and does not ask for it. If you include it, it will be processed like the rest of the document, including by the AI providers listed in section 5.
2.2 Payment information
Subscriptions are billed by Stripe. We never see or store your card number. Card details are entered on Stripe’s hosted checkout. We store your Stripe customer and subscription identifiers, your plan, and its status. We send Stripe your email address and name so it can create the customer record.
2.3 Information collected automatically
- Technical and usage data: IP address, browser and device information, pages viewed, and performance measurements, collected through our hosting provider and the analytics described in section 5.
- Diagnostic data: when something breaks, our error monitoring records the error together with your IP address, request headers, cookies, and your user ID and email address. See section 5 for what this means in practice.
- Cookies and local storage: itemised in our Cookie Policy.
2.4 Information from services you connect
If you choose to connect GitHub, we receive an access token, your GitHub username, and metadata and README content for the repositories you select, so we can turn them into resume projects. You can disconnect GitHub at any time; disconnecting clears the stored token.
3. Why we use it, and our legal basis
Where the EU or UK GDPR applies to you, the table below is our Article 6 legal basis for each purpose. Where Canadian or US law applies, the same table describes the identified purposes for which we collect and use your information.
| Purpose | What it involves | Legal basis (EU/UK) |
|---|---|---|
| Providing the service | Creating your account, storing your profile and resumes, parsing uploads, tailoring resumes against job descriptions, and compiling PDFs | Performance of a contract |
| Billing | Taking payment, managing subscriptions, trials, renewals and cancellations | Performance of a contract |
| Account security | Email verification, password reset, session management, rate limiting, and bot protection on the contact form | Legitimate interests (keeping accounts secure) |
| Keeping the service working | Error monitoring, performance measurement, and debugging | Legitimate interests (a reliable, maintainable service) |
| Product analytics | Aggregate page and performance measurement | Legitimate interests (understanding how the product is used) |
| Support | Answering messages you send us | Legitimate interests / performance of a contract |
| Legal and financial records | Keeping transaction records and responding to lawful requests | Legal obligation |
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We run no advertising network, no advertising pixels, and no ad-tech trackers.
4. AI processing of your resume
Applify AI cannot work without sending your content to an external AI provider. This section says plainly what that means.
- What is sent: the resume or LinkedIn PDF you upload (as file content), the text extracted from it, the job descriptions you paste, and — if you connect GitHub — repository metadata and README content. In practice this includes your name, email address, phone number, links, location, and your full employment and education history.
- Who processes it: OpenAI is the default provider for all AI features. Our system can also be configured to route certain job-description and validation steps to Anthropic. Both are US companies.
- Training: we do not train any model on your content. OpenAI and Anthropic both state that data submitted through their business APIs is not used to train their models by default. We rely on those commitments; we cannot independently audit them.
- Provider-side retention: for resume parsing we enable prompt caching with a 24-hour retention window at the provider. Some of our AI requests are sent with provider-side storage disabled; others rely on the provider’s default API retention, which OpenAI documents as a limited period for abuse monitoring. Content sent to an AI provider cannot be recalled by us once sent.
4.1 Automated decision-making
Applify AI does not make automated decisions that produce legal effects or similarly significant effects about you. It does not decide whether you get a job, screen you, rank you against other candidates, or share your resume with employers. It produces suggestions you review — every AI edit is presented for you to accept, reject, or rewrite before it reaches an exported document. Scores and match percentages shown in the product are guidance for you, not a decision about you.
AI output can be wrong. It can also produce claims that sound plausible but are not true of you. You are responsible for reviewing every version you export and submit.
6. How long we keep it
Retention differs by system. These are the actual periods configured in the product, not aspirations.
| Data | Where | Retention |
|---|---|---|
| Account, profile, resumes, versions, tailoring sessions | Database | Kept until you delete your account. There is no automatic expiry and no inactivity purge. |
| Stored resume files (source and compiled PDF) | File storage | Kept indefinitely. These files are not deleted when you delete a resume or your account — see section 7. |
| Background job records, including parsed resume results | Redis | 1 hour |
| Pending-job index | Redis | 24 hours |
| Rate-limit counters (keys include your IP address) | Redis | The length of the rate-limit window, up to 1 hour |
| Payment event de-duplication records | Redis | 3 days |
| Uploaded PDF content inside background job events | Job orchestration provider | The provider’s own retention period; we do not set one |
| Email verification tokens | Database | Until they expire. These rows are keyed by email address and are not removed by account deletion. |
| Prompt content at the AI provider | OpenAI / Anthropic | 24-hour prompt cache on parsing calls, plus the provider’s own retention |
| Error events, traces, session replays | Error monitoring provider | The provider’s retention period for our plan |
| Server and request logs | Hosting provider | The hosting provider’s retention period |
| Billing and transaction records | Stripe and our records | Retained as long as required for tax and accounting purposes, typically seven years in Canada |
7. What account deletion actually does
We would rather tell you the limits than imply a clean erasure we do not perform. You can delete your account from Account settings.
What deletion removes automatically
- Your user record and everything linked to it in the database: profile, resumes, resume versions and snapshots, experiences, projects, education, skills, certifications, tailoring sessions, entitlements, and login sessions.
- Your active subscription is cancelled at Stripe.
What deletion does not remove, today
- Stored resume files. Resume source files and compiled PDFs in file storage are not deleted by account deletion, or when you delete an individual resume.
- Queued and cached job data in Redis and at our job orchestration provider, which expires on the schedules in section 6 rather than on deletion.
- Your Stripe customer record and billing history, which we retain for accounting and legal purposes.
- Error monitoring records already collected, and server logs already written.
- Content already sent to an AI provider, which is outside our control once transmitted and expires under that provider’s retention terms.
- Email verification token rows, which are keyed by email address and expire on their own schedule.
If you want the remaining items erased, email admin@applify-ai.com and we will do it manually and confirm when it is done, within 30 days. We are working on making this automatic.
If you signed in without a password (for example by email link), the in-product deletion flow requires a password and will not work for you. Email us and we will delete the account for you.
8. Your rights, and what we can actually do
Depending on where you live you have rights to access, correct, delete, port, restrict, or object to the processing of your personal information, and to withdraw consent. We honour these rights for every user regardless of location. The table sets out how each one is served today, because some are self-service and some are manual.
| Right | How it works today |
|---|---|
| Access | Your profile and resume data are visible in the app. For a complete copy of everything we hold, email us — this is compiled manually. |
| Correction | Self-service in the dashboard and account settings for profile and resume content. Your account email address is not editable in-product; email us to change it. |
| Deletion | Self-service in Account settings, with the limits described in section 7. Email us for full erasure, or if your account has no password. |
| Portability | Not available in-product. There is no export button. Email us and we will provide a machine-readable copy manually. |
| Restriction and objection | Email us. We will action it and confirm. |
| Withdraw consent | Email us, or stop using the relevant feature. Withdrawing consent does not affect processing already carried out. |
| Non-discrimination | We will not deny service, charge a different price, or reduce quality because you exercised a right. |
Send requests to admin@applify-ai.com. We respond within 30 days. We will ask you to verify your identity — normally by writing from the email address on the account — and we will not charge you unless a request is manifestly unfounded or excessive. You may use an authorised agent where the law allows it.
9. International transfers
We are based in Canada, and the providers in section 5 are largely based in the United States. Using Applify AI necessarily involves transferring your personal information outside your country, including to the United States, where the legal protections and government access powers differ from those in Canada, the EEA or the UK.
For transfers from the EEA, the UK or Switzerland, we rely on our providers’ Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where applicable), which are incorporated into our agreements with them. For transfers under Canadian law, we remain accountable for your information while it is processed by a service provider on our behalf, and it may be accessible to foreign courts and law enforcement under the laws of the country where it is held.
10. Security
We take these measures:
- Traffic is encrypted in transit over HTTPS.
- Passwords are stored only as bcrypt hashes. We cannot read your password and will never ask for it.
- Email verification is required before a password account can sign in.
- Stored resume files are held in private storage and served only through an authenticated route.
- Sensitive actions such as registration and the contact form are rate limited.
- Card data never touches our servers.
Two limitations you should know about: our application logs are not currently filtered for personal information, and one functional cookie stores your working resume document in your browser without the HttpOnly flag (see the Cookie Policy). Both are on our list to fix. No service can promise perfect security, and we do not.
If you believe your account has been compromised, or you have found a security issue, email admin@applify-ai.com. Where a breach creates a real risk of significant harm we will notify you and the applicable regulator as the law requires.
12. Children
Applify AI is for people looking for work and is not directed at children. You must be at least 16 years old to create an account. We do not knowingly collect personal information from anyone under 16, and we do not verify age at registration. If you believe a child has given us personal information, email us and we will delete the account and the data.
13. Regional disclosures
13.1 Canada (PIPEDA)
SKomp Studio is accountable for personal information under its control, including information processed by the service providers in section 5. Suleyman Kiani is the individual accountable for our compliance and is reachable at admin@applify-ai.com. We identify our purposes at or before collection (section 3), limit collection to those purposes, and rely on your consent — implied where you provide information to obtain a feature, and express where the law requires it. You may withdraw consent subject to legal and contractual restrictions, though doing so may mean we can no longer provide the service. You have the right to access your information and to challenge its accuracy and completeness.
13.2 EEA and United Kingdom (GDPR / UK GDPR)
Our legal bases are in section 3. Where we rely on legitimate interests, we have balanced those interests against your rights, and you may object at any time. We have not appointed an EU or UK representative under Article 27 and do not currently have a Data Protection Officer; neither is mandatory for an organisation of our size and processing profile, and Suleyman Kiani handles all privacy requests directly. Providing your resume content is necessary to use the service — without it, the product cannot function.
13.3 California (CCPA / CPRA)
In the past 12 months we have collected the following categories of personal information: identifiers (name, email, phone, IP address, account and customer IDs); customer records (payment-related identifiers, though not card numbers); commercial information (subscription and transaction history); internet and network activity (usage, diagnostics, error events); geolocation inferred at city level from IP address; and professional or employment-related information and education information (your resume content). Sources, purposes and recipients are described in sections 2, 3 and 5.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months, including in relation to anyone we know to be under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA, and we do not use it to infer characteristics about you. We do not offer financial incentives for personal information. You may exercise the rights to know, delete, correct, and to limit the use of sensitive personal information by emailing us as described in section 8; we will not discriminate against you for doing so.
14. Changes to this policy
We will update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects how we handle your information, we will give notice — by email or a prominent notice in the product — before it takes effect, and where the law requires consent for the change we will ask for it.
15. Contact and complaints
Privacy questions and requests go to admin@applify-ai.com, attention Suleyman Kiani, SKomp Studio, Hamilton, Ontario, Canada. General enquiries can go through our contact form.
Please raise a complaint with us first — we would like the chance to fix it. You also have the right to complain to a regulator:
- Canada: the Office of the Privacy Commissioner of Canada, priv.gc.ca
- United Kingdom: the Information Commissioner’s Office, ico.org.uk
- EEA: your national supervisory authority
- California: the California Privacy Protection Agency or the California Attorney General