Privacy Policy
Last updated September 30, 2026
Auto Apply (autoapply.mikelcrump.com) is a job application tracker with a companion Chrome extension. This policy explains what information the service handles, why, and what control you have. It is written to be read, so it is short.
What we collect
- Your Google account basics. When you sign in with Google we receive your name, email address and profile picture. We use them to identify you and show your name in the app.
- Jobs you track. Company, title, location, pay, links, notes, status and dates that you enter, import from a spreadsheet, or send from the Chrome extension.
- Your extension profile, only if you connect the extension. Contact details, work history, education, references (people you list, so ask them first), skills, saved answers and resume files that you keep in the Chrome extension. See the Chrome extension section below.
- Access tokens you create. We store only a one-way hash of each token, so we cannot read it back.
- Gmail information, only if you connect Gmail. See the next section.
The person who runs Auto Apply has an admin page that shows account details (name, email, when you joined and last signed in) and simple counts, such as how many jobs you track and whether Gmail or an access token is connected. It does not show your job details, notes or email content.
Gmail access (optional)
Connecting Gmail is your choice and can be turned off at any time. If you connect it, we ask Google for read-only access. We use it for one purpose: to find replies about jobs you applied for (for example an interview invitation or a rejection) and update that job's status on your board.
- We read the sender, subject, date and a short preview of matching messages. We do not read attachments and we never send, delete or change your email.
- We do not keep the message text. We keep the sender, subject, date, the status we detected and a link to the job it changed, so you can see why a status changed.
- Your Google refresh token is encrypted before it is stored.
- Email content is not used for advertising, is not sold, and is not used to train AI models. Nobody at Auto Apply reads your email.
- When you disconnect Gmail we revoke our access with Google and delete the stored token.
Auto Apply's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Chrome extension
Without an account connection, your profile, resumes and saved answers stay in your browser. When you connect the extension to your account, it sends the jobs you track (title, company, location, link, match score, status, description and pay) and, unless you turn it off in the extension's Website tab, keeps your profile in step with the website: contact details, work history, education, references (people you list, so ask them first), skills, saved answers, resume files and cover letter settings. That lets a new install, or a new extension folder, pick everything up again.
- Everything synced is encrypted before it is stored, and only your account or an extension token you created can read it. Tokens made for bots and scripts cannot.
- Voluntary self identification answers (such as gender, race or veteran status) sync by default and can be turned off. AI keys never sync unless you turn that on.
- You can view, edit or remove all of it on the Profile page, and deleting your account removes it too.
Who else handles your data
- Supabase stores the database and handles sign-in.
- Vercel hosts the website.
- Google provides sign-in and, if you connect it, Gmail.
We do not sell your information and we do not share it with advertisers.
Your control
- Edit or delete any job at any time, and export your data by reading it through your own API token.
- Disconnect Gmail in Settings.
- Delete your account in Settings. This removes your profile, jobs, history, tokens and Gmail connection right away.
Security
Data is stored in a database where every row is tied to your account and other users cannot read it. Connections use HTTPS. No system is perfectly secure, so please use a strong Google account password and two-step verification.
Children
The service is not intended for anyone under 16.
Changes and contact
If this policy changes in a meaningful way we will update the date above. Questions or requests: mikelcrump611@gmail.com.