Aply manages personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
Personal Information Aply Collects
- Account information: Name, email address and a securely hashed password.
- Profile and application information: Work history, skills, qualifications, preferences, work rights, saved answers and other information you choose to provide for job applications.
- Documents: Resumes and cover letters that you upload or generate in Aply.
- Job and application activity: Roles matched, approved, skipped, parked or submitted, together with run status and application outcomes recorded in Aply.
- Billing records: Plan, subscription status and payment-provider identifiers. Stripe handles full payment-card details; Aply does not store the full card number.
- Technical and analytics data: Device, browser, IP address, pages viewed, feature interactions, error and security events, and campaign attribution where enabled.
Collection and Storage of Personal Information
Aply collects information directly from you, from activity in your account and extension, from payment and authentication providers, and from the job listings used by the matching workflow. Account and application records are held in Aply's hosted database. Uploaded and generated documents are held in Aply's configured object storage.
A job form may request sensitive information. Aply does not infer an unanswered sensitive response. The extension parks that step for you. If you choose to provide and save a sensitive answer, Aply uses it only for the selected application workflow and related account functions.
AI Auto Apply for Jobs and Third-Party Sites
The Aply Chrome extension can complete and submit supported job applications from your browser. Hands-Free mode submits eligible applications automatically when the required information and approved documents are ready. Optional Review mode pauses before final submission.
Job-site credentials stay in the browser session and are not sent to Aply's API. The extension exchanges the queued job, profile fields, saved answers, document references, run identifiers and completion status required for the selected workflow. When you apply, the destination job site or employer receives the information and documents entered into its form. That recipient's privacy policy also applies.
Use of Personal Information
- Operate accounts, authentication, billing, support and security controls.
- Match jobs against saved preferences and profile information.
- Create role-specific resumes, cover letters and application answers.
- Complete, submit and record supported applications in the selected extension mode.
- Measure reliability, diagnose errors, prevent misuse and improve the product.
- Send account, billing, password-reset and material service communications.
Data Sharing and Overseas Processing
Aply does not sell personal information. Information is disclosed to the job sites and employers you choose to apply to, service providers that operate Aply, professional advisers where required, and authorities when disclosure is required by law.
Current provider categories include hosting and databases, object storage, payment processing, email delivery, analytics and AI processing. These providers may process data outside Australia. Current infrastructure can involve Singapore, the United States and Japan, as well as Cloudflare's global network. Provider locations can change, and Aply reviews this policy when a material processing location changes.
Cookies and Analytics
Essential cookies maintain secure sessions and preferences. When configured, Google Tag Manager and PostHog measure public-site and product interactions. Analytics events should contain workflow identifiers and page context, not resume text, saved answers or job-site credentials.
Data Retention and Security
Aply keeps personal information while the account is active and for the period needed to provide the service, meet legal and financial obligations, resolve disputes and maintain security records. A deletion request removes or de-identifies account data unless a lawful retention obligation applies. Residual backup copies expire through the applicable backup cycle.
Security controls include encrypted transport, hashed passwords, access controls, environment-scoped credentials, session revocation and application-level checks around documents, answers and extension runs. No online service can promise absolute security.
Access, Correction, Deletion and Complaints
You can update profile information in the dashboard. To request access, correction, deletion or a portable account export, or to make a privacy complaint, email privacy@aply.au. Include the email address on the Aply account and enough detail to identify the request. Aply may verify identity before releasing or deleting information.
Aply will investigate a privacy complaint and respond with the outcome or the next step. If you are not satisfied, you can contact the Office of the Australian Information Commissioner.