Your job search stays yours.
This policy explains what ApplyPace stores, why it needs that information, and the controls available to you.
Who is responsible
M-NAC operates ApplyPace and is responsible for the data processing described here. You can contact the service at support@applypace.com.
Information you provide
We store the account details, CVs, documents, links, candidate facts, search preferences, applications, written answers, edits, contacts, outreach records, and outcomes you add to your workspace.
Google account and Gmail
Google sign-in and Gmail access are limited to approved private beta accounts. Google sign-in provides your name, email address, and account identifier. If you connect Gmail, the app requests read-only access so it can find application receipts, recruiting replies, interviews, rejections, and offers. It cannot send, delete, archive, modify, or label your email.
Message headers are checked before message text. When a message passes that screening, its subject and up to 10,000 characters of its cleaned body may be sent to the configured model provider to classify the recruiting event. ApplyPace stores the provider ID, selected headers, a body hash, the evidence excerpt used for classification, and the proposed event. The production service does not store the full message body.
How information is used
Your information is used to build your candidate record, evaluate roles against your preferences, prepare application materials, preserve revisions, link recruiting events to the right application, and show your search history and analytics.
Google user data is used only to provide these visible features. ApplyPace does not use Google user data for advertising or to train a shared model. Its use of Google information follows the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
Selected candidate facts, job text, form questions, and message evidence may be sent to the configured model provider to prepare a draft or classify a recruiting event. The product records the purpose, model, and source record. A model result cannot submit an application, send a message, answer a protected field, or change an unclear application state.
Product use measurement
ApplyPace records optional product analytics only after you allow them in the browser. Your choice is kept in local browser storage and a first-party preference cookie shared across the ApplyPace site. Analytics use a separate signed session that expires after 30 minutes, are not linked to your account or workspace, and are deleted after 30 days. Billing, security, and reliability records needed to operate the service are separate from optional product analytics.
Product analytics contain fixed event names, page categories, coarse device type, language, time zone, a country hint taken from the browser language, and a broad traffic source such as Google, LinkedIn, or direct. Traffic tags and referring sites are reduced to one of those fixed categories in the browser. The records do not contain raw IP addresses, full browser headers, raw referrers, page queries, CV names, company names, role titles, written answers, or email text. ApplyPace does not install a third-party advertising tracker. Google Search Console provides aggregate search performance for the public site.
Anonymous product analytics are currently off in this browser.
Storage and security
Each workspace is isolated in the database. Documents are kept in private object storage. OAuth tokens and optional message bodies are encrypted. Access tokens are stored as hashes. To limit signup and account email abuse, ApplyPace keeps a keyed hash of each normalized recipient address with attempt counts for up to 35 days. The limit table does not keep another plain copy of the address. Administrative access uses short-lived cloud identity rather than downloaded service account keys.
Billing
Stripe processes subscriptions and stores payment details. ApplyPace stores the Stripe customer and subscription identifiers, plan, billing status, renewal date, and cancellation state. ApplyPace does not receive or store your full card number.
Sharing
We use infrastructure, model, email, and payment providers only to operate the product. We do not sell personal information. We do not share a candidate record with an employer. Information reaches an employer only when you use the employer’s own form or messaging channel yourself.
Retention and deletion
You can export your workspace or delete it from Settings. Database records and connected-account tokens are removed when deletion completes. Inactive unverified accounts with no workspace are removed after 30 days. Deleted uploaded files may remain recoverable in private, versioned storage for up to seven days. Database backups are kept for 35 days, and an older version of a deleted backup may remain for up to seven more days. Legal or security records are kept only when required.
Your choices
Gmail and product analytics are optional. You can change the analytics choice above at any time. You can disconnect Gmail, revoke Google access from your Google Account, correct facts, remove documents, reject proposed events, revoke agent tokens, export the workspace, or delete it.
Contact and changes
Email support@applypace.com with a privacy or account question. Material changes to this policy will appear here with a new effective date before they take effect.