Privacy Policy
Last updated: August 10, 2026
BestApply ("we", "our", or "us") provides a human-assisted AI job search service that helps users find roles and complete online job applications. This Privacy Policy explains how we collect, use, share, and protect data when users access our web app, use the BestApply browser extension, hand off applications to the Apply Agent, and optionally connect a supported mailbox to track job-related emails and enable verification-code autofill.
1. Data We Collect
We collect data necessary to deliver core product features, including:
- Account and profile information (your single profile — sign-in data, profile details, and job application preferences).
- Job application context from supported pages (for example job title, company, application questions, and workflow status).
- User-submitted content and AI interactions used to generate autofill, tailored documents, and answer suggestions.
- Optional mailbox-connection data when a user chooses to connect Gmail or Outlook, including the mailbox address, provider account details returned by the provider, encrypted OAuth tokens, and connection-status metadata.
- Email data from connected mailboxes, which varies by the connection mode chosen: in verification-only mode, limited to sender, subject, message identifiers, received timestamp, and extracted verification codes or links; in full mailbox mode, additionally includes email body content, recruiter and company details, interview scheduling information, and other job-application-related metadata extracted from incoming messages.
- Technical and diagnostic data (such as extension version, error logs, and operational telemetry needed to maintain service reliability).
- Marketing attribution data: the campaign (UTM) parameters and referring page from the link that brought you to our site, so we can understand which of our content is useful.
- Screenshots and page snapshots only when required for active application workflows or user-initiated support and troubleshooting.
2. How We Use Data
- To authenticate users and keep profile and sign-in state available across browser tabs and extension service worker restarts.
- To provide BestApply's core features, including job-page detection, application workflow guidance, autofill support, and AI-generated answer assistance.
- To operate the Apply Agent: when you hand off a role, to complete and submit that application on your behalf using your profile.
- If a user chooses to connect a supported mailbox in verification-only mode, to monitor provider notifications, read relevant verification messages, and return verification codes or links inside the product so the user can complete a supported verification step more quickly.
- If a user connects a mailbox in full mailbox mode, to additionally read and classify job-related emails (such as interview invitations, offers, rejections, and recruiter outreach), surface actionable updates on the job-tracking dashboard, send email replies composed by the user directly from within the product, and delete emails at the user's explicit request.
- To improve product quality, safety, and performance, including debugging, reliability monitoring, and abuse prevention.
- To comply with legal obligations and enforce our terms, policies, and security requirements.
3. How and With Whom We Share Data
Your profile is yours alone. BestApply does not share your profile with other users, and there is no third-party network browsing your data. We share data only as needed to operate the service:
- BestApply Agent operations: when you hand off an application, our vetted apply operators act on your behalf to complete and submit it. They use your profile only to perform the applications you request, and never to share or repurpose your data.
- Service providers and infrastructure partners: hosting, analytics, logging, authentication, AI-processing, and email-platform providers that help us deliver features a user chooses to enable, each acting under contractual or technical obligations applicable to their role.
- Legal/compliance disclosures: when required by law, regulation, legal process, or to protect the rights, safety, and security of users and our platform.
We do not sell personal data for third-party advertising, and we do not use connected mailbox data for advertising or unrelated profiling.
4. Cookies and Analytics
We use a small number of first-party cookies and privacy-conscious analytics:
- Sign-in and session cookies: first-party cookies and browser storage that keep you signed in and remember product preferences.
- Attribution cookie: a first-party cookie (
ba_attr, kept for 30 days) that stores the campaign (UTM) parameters and referring page from the link that brought you to our site, so that if you later create an account we know which of our content led you here. It contains no personal information. - Product analytics (Mixpanel): pseudonymous usage events — such as page views, button clicks, and feature usage — shared across bestapply.ai subdomains to help us understand and improve the product. We do not send Mixpanel your resume, application content, or mailbox data.
- Cloudflare Web Analytics: cookieless, aggregate traffic measurement on our website, where enabled.
We do not use third-party advertising cookies or cross-site ad trackers. You can block or delete cookies in your browser settings; core signed-in functionality may require the session cookies above.
5. Browser Extension Permissions and Connected Mailbox Access
The BestApply extension requests browser permissions only for features tied to job-application assistance (for example: detecting supported application pages, updating in-page UI, persisting profile state, copying generated answers, and capturing screenshots during active applications).
If a user chooses to connect Gmail or Outlook, BestApply offers two connection modes:
- Verification-only mode: BestApply requests read-only mailbox access solely to detect and extract verification codes or links from supported job-platform emails, so users can complete verification steps without switching apps. No other email content is read or stored in this mode.
- Full mailbox mode: BestApply requests broader mailbox access (including read, send, and delete permissions) to power the Job Mailbox feature. This allows BestApply to automatically detect and classify job-related emails (interviews, offers, rejections, recruiter outreach), surface them on your job-tracking dashboard, let you send email replies to recruiters directly from within the product, and delete emails at your explicit request. All send and delete actions are initiated directly by the user — BestApply never sends or deletes emails autonomously.
Both modes are optional and user-initiated. The connected mailbox must match the profile email saved in BestApply. Users can switch modes or disconnect at any time from product settings.
Users may also optionally connect a calendar (Google Calendar or Outlook) so BestApply can display upcoming events alongside the job tracker and create or update interview events on the user's behalf. Calendar access is limited to reading events and managing events created through BestApply, and can be disconnected at any time from product settings.
6. Google API Services — Limited Use Disclosure
BestApply's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for Google user data received through the Gmail and Google Calendar APIs, BestApply:
- Uses it only to provide and improve the user-facing features described in this policy — verification-code autofill, the Job Mailbox (email classification, tracking, user-composed replies, and user-requested email management), and calendar sync for interview scheduling — and for no other purpose.
- Does not transfer it to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition after providing notice — and never sells it or transfers it to third parties for their own purposes.
- Does not use or transfer it for serving advertisements, including retargeting, personalized, or interest-based advertising.
- Does not allow humans to read it, unless the user has given explicit permission (for example, during a support request the user initiates), it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized for internal operations.
AI/ML models and Google user data
Some BestApply features apply AI models to connected-mailbox content — for example, classifying job-related emails and drafting replies that the user reviews and sends. We do not use Google user data — whether raw, aggregated, anonymized, or derived — to develop, improve, or train generalized or foundational AI/ML models. Where Google user data is processed by third-party AI infrastructure providers to deliver these features, that processing is configured for zero data retention: the data is used only to generate the requested output in real time, is not retained by the provider, and is never used to train the provider's or any other party's AI/ML models.
7. Data Retention
We retain data for as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods may vary by data type and operational need.
For the optional mailbox connection feature, stored connection tokens and provider-side connection state are removed when a user disconnects the mailbox. Previously extracted verification records and related operational logs may continue to be retained for a limited period to support product functionality, security, fraud prevention, dispute resolution, and legal/compliance needs.
8. Security
We use reasonable technical and organizational safeguards to protect user data, including access controls, monitoring, and encryption of stored mailbox tokens for the optional mailbox-connection feature. No method of transmission or storage is 100% secure, but we continuously work to improve protection measures.
9. User Choices and Rights
Users may update account and profile information through the product. Connecting a mailbox is optional and is not required to use BestApply's general job-application features.
- You may connect, replace, reauthorize, or disconnect a supported mailbox from product settings.
- Disconnecting a mailbox stops future mailbox monitoring and removes the stored connection tokens needed to maintain the live mailbox connection.
- You may request account-related privacy support, including questions about connected mailbox data and deletion requests, by contacting us.
10. Policy Updates
We may update this Privacy Policy from time to time. We will post the latest version on this page and update the "Last updated" date.
11. Contact
For privacy questions or requests, contact us at: support@bestapply.ai