Privacy
Last updated 28 September 2026
Applause helps you run a job search: it turns your career history into a profile, tracks your applications, watches careers pages you choose, and drafts résumés, cover letters and screening answers from your profile. This page says what we collect, what we do with it, who else touches it, and how to get rid of it. It is written to be read, not skimmed past.
Applause is run by Starling Labs, a company registered in Brazil, which is responsible for your data under Brazil’s LGPD and, where it applies to you, the GDPR. Write to hello@applausejobs.com for anything about your data.
What we collect
- Account: your email address and a password hash (or your Google account id if you sign in with Google). Held by Supabase Auth.
- Your profile: whatever you paste, upload, or type: résumés, LinkedIn exports, work history, skills, preferences. Uploaded files are read into text and the file itself is not kept.
- Your applications and documents: the jobs you track, notes you write, and every draft we generate for you, with its versions.
- Careers pages you follow: the addresses you give us and the public postings we fetch from them.
- Usage: which features you use and how much you generate, so we can run the free tier, bill Pro, and improve the product. We use PostHog for product analytics and Sentry for error reports.
- Your own API key, if you add one: encrypted at rest with a key we hold separately. We can use it on your behalf; we cannot read it back to you.
The browser extension
The Applause Jobs extension for Chrome works with your Applause account and sends data only to applausejobs.com. It uses your existing Applause sign-in; it never reads or stores passwords.
- Pages it reads: on each page it runs a quick check in your browser. It sends a short summary of the page (its address, title, headings and job-link text) to Applause only when the page already looks job-related, to confirm it is a job posting, application or careers page (known job sites skip this step). You can pause the extension on any site from its panel, and turn automatic detection off in its settings: then it acts only on known job sites and on pages where you open the panel. On a page it recognises as a single job posting, the fit X-ray sends the posting’s requirement lines and text to score them against your profile, and draws the scores on the page; nothing is stored. You can turn the X-ray off in the extension (the switch on the X-ray card, the panel, or its settings). The full posting is otherwise sent only when you open the panel on it or press a button, to check your fit, save the job or write your application. Other pages are not sent.
- Forms it fills: when you press Autofill, it sends the labels of the form’s fields (not their contents) to decide what goes where, then fills them in your browser. It never submits a form.
- Answers it remembers: when you type or correct an answer on an application form, that answer is saved to your account so the next form can fill itself. You can see, edit and delete these in Settings, Autofill. Passwords, ID numbers, financial details and dates of birth are never saved. Self-identification answers (gender, race and ethnicity, veteran and disability status) are saved only if you turn that on. Field labels, without anyone’s answers, help everyone’s autofill place fields correctly.
- Context you add: what you type, say, link or select to add experience is turned into a line in your profile and treated like the rest of it. Voice is converted to text by Chrome; no audio reaches us.
- Applied tracking: when a page says your application was received, it moves that job to Applied in your account.
We do not sell this data or use it for anything other than helping you apply for jobs.
How we use it
To do what you asked: build your profile, rank postings against it, draft and fact-check documents, and email you when you turned a notification on. We also look at usage to understand what works: product events are tied to a random account id, never to your name, email, or the content of your profile and documents, and no analytics cookies are set.
AI processing: read this part
Drafts are written by Anthropic’s Claude models. To draft a document we send your profile and the job posting to Anthropic’s API; to fact-check it we send the draft and your profile again. Anthropic does not use API inputs to train models. If you add your own Anthropic key, those requests are made with your key and appear in your Anthropic account.
To measure and improve the quality of our prompts we record generation traces: the prompt we sent (which includes your profile text and the posting), the model’s output, and quality scores such as fact-check findings and your thumbs up or down. They are stored in Braintrust, a prompt-observability service. These traces are visible to the Applause team for the purpose of improving drafts. If you would rather your generations were not recorded this way, tell us at hello@applausejobs.com and we will exclude your account.
Who else processes your data
- Supabase: database and sign-in (US East).
- Vercel: hosting.
- Anthropic: AI drafting and fact-checking.
- Braintrust: generation traces and quality scores.
- Resend: email, only for notifications you turn on.
- Stripe: payments, if you subscribe. We never see your card number.
- PostHog and Sentry: product analytics and error reporting.
We do not sell your data and we do not share it with recruiters, employers, or job boards. Following a careers page fetches public postings from that site; it does not send anything about you to it.
Your choices
- Edit or remove anything in your profile at any time.
- Every email has a one-click unsubscribe, and each kind can be switched off in Settings.
- Delete your account from Settings. That removes your profile, applications, documents, followed pages, and key, and your sign-in. Generation traces already recorded in Braintrust are deleted on request.
- Ask us for a copy of your data, or for corrections, at hello@applausejobs.com.
Retention and security
We keep your data while you have an account. Passwords are hashed; your API key is encrypted; data is encrypted in transit and at rest by our providers. Access is limited to what the product needs and to the people who run it.
Changes
If this page changes in a way that matters, we will say so in the app before it takes effect.
This page describes our practices plainly; it is not legal advice.