ApplyIntended LogoApplyIntended
HomeSetup guidePricingFAQ
Add to Chrome instantly
HomeSetup guidePricingFAQ
Add to Chrome instantly — Free

Privacy

What we collect, and what we deliberately do not

ApplyIntended sits between a job link and an application. That is a sensitive position, so this policy is specific about the small amount of data it takes to do the job — and blunt about the data we never touch.

Last updated July 21, 2026

We never see the application

No name, email, resume, or answers. Applications are submitted on your ATS, not on us.

We do not store IP addresses

An IP is read in-flight to derive country and network, then dropped. It is never written down.

No cookies, no ad tech

A random ID in browser storage, scoped to us alone. Nothing follows anyone across the web.

We never sell data

Not to advertisers, data brokers, model trainers, or anyone else. There is no version of this we do.

Contents

Who this coversWhat we collect from applicantsWhat we collect from recruitersHow we use itWho else touches itHow long we keep itYour rightsSecurityChildren's dataChanges to this policy

01Who this covers

Two different people meet ApplyIntended, and they are treated differently.

  • Recruiters — customers who install the extension and protect job links. You hold an account with us.
  • Applicants — people who click a protected link. They have no account, are never asked for anything, and pass through in a moment.

Where a recruiter is an employer subject to data-protection law, the recruiter is the controller of applicant data and ApplyIntended acts as a processor on their instructions.

02What we collect from applicants

When someone opens a protected link, we record a single event so the link’s owner can see traffic and so we can decide whether to mark the visit. That event holds:

  • A random visitor ID and session ID, generated in the browser and stored in local and session storage. They are meaningless outside ApplyIntended and identify no one by name.
  • Browser user agent and a coarse device class — mobile, tablet, or desktop.
  • Referrer and any UTM parameters already present on the link, so a recruiter can see which channel sent the visit.
  • Approximate location and network — country, region, network operator, and whether the request came from a datacenter.
  • Our own conclusion — whether we marked the visit as likely human, a confidence score, the reason, and the time.
We do not store IP addresses. The IP is visible only while the request is being handled, is used to look up the country and network above, and is never written to our database. There is no column for it.

We do not receive an applicant’s name, email address, phone number, resume, cover letter, or any answer they give. Those go straight from the applicant to your ATS. We are not in that path.

03What we collect from recruiters

  • Account details — your email address and authentication credentials, handled by our authentication provider.
  • Your links — the job URLs you protect, their status, and their event history.
  • Subscription details — your plan, billing status, and invoice history.
  • ATS credentials, if you connect one. API keys are encrypted at rest and readable only by the account that stored them.
Card details never reach our servers. Payments run through Stripe, which handles the card directly; we see only the brand, last four digits, and expiry.

04How we use it

  • To forward every visitor to the job application they asked for.
  • To decide whether a visit looks human, and to attach that marking to the application in your ATS.
  • To show you traffic and results for the links you protect.
  • To operate the service — billing, support, security, and abuse.
  • To improve detection in aggregate. We do not build profiles of individual applicants, and we do not use anyone’s data to train external models.

05Who else touches it

We use a small set of vendors to run the service. Each gets only the data it needs.

  • Supabase — database, authentication, and backend functions.
  • Vercel — hosting for this site and the redirect gate.
  • Stripe — subscription billing and card processing.
  • Resend — transactional email.
  • IPinfo — receives an IP address to return a country and network. We store the answer, not the question.
  • Your ATS — receives the marking we set on applications you own.

Beyond that, we disclose data only when the law requires it, or to protect the service and its users from abuse. We do not sell personal data, and we do not share it for advertising.

06How long we keep it

  • Visit events — kept while the link exists so you can see its history, and deleted with the link.
  • Account data — kept while your account is open.
  • Billing records — kept as long as tax and accounting rules require, even after you close your account.

Delete your account and we remove your links and their event history. Anything already written into your ATS is yours and stays there — only you can remove it.

07Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to certain processing, or to complain to a regulator. Write to privacy@applyintended.com and we will act on it.

If you are an applicant and want to know what a visit recorded, tell us the job link and roughly when you clicked it. Because we hold no name or email, that context is the only way to find the event.

08Security

Data is encrypted in transit and at rest. Access to each account’s data is enforced in the database itself with row-level security, not only in application code. Stored ATS credentials are encrypted. Internal access is limited to what is needed to run and support the service.

09Children's data

ApplyIntended is a tool for employers and is not directed at children. We do not knowingly collect personal data from anyone under 16.

10Changes to this policy

If we change what we collect, we will update this page and move the date at the top. Material changes get notice to account holders before they take effect.

Questions: privacy@applyintended.com.

ApplyIntended LogoApplyIntended

Human intent, filterable in Greenhouse.

Add to Chrome instantly — Free
ProductSetup guidePricingFAQ
LegalPrivacyTerms

© 2026 ApplyIntended

Works in Chrome, Safari, Firefox, Edge, Brave, Arc, and Opera.