ApplyPilot Privacy Policy

Effective 6 October 2026

ApplyPilot is operated by Syntheon Technology Private Limited. This policy describes data handled by the ApplyPilot service, website, and plugin.

Data we process

Anonymous application-source fetches and readiness previews are used to answer the current request and are not saved as an ApplyPilot account workspace. When you connect an account and choose persistence, ApplyPilot may process application workspaces, reusable profile or company facts, requirement assessments, answer drafts, reusable answer memory, evidence metadata, supporting files, source hashes, usage counters, account entitlement state, and user-confirmed submission records.

Account identity

Authentication is provided through Auth0. ApplyPilot stores or derives only the account identity needed to keep your data separated from other users and to maintain your session. Passwords and login credentials are handled by the identity provider and are not stored in reusable ApplyPilot profile facts.

Supporting files

For uploaded evidence, ApplyPilot computes a SHA-256 content hash for deduplication and provenance. By default, ApplyPilot retains evidence metadata and that hash rather than a reusable file copy. If you explicitly request retained-file reuse and your account entitlement permits it, ApplyPilot may store an application-encrypted private copy.

Billing and payment data

Paid subscriptions are purchased on ApplyPilot's external website and processed by the payment provider. ApplyPilot may store provider customer and subscription identifiers, plan/status information, billing-period dates, promotional-credit ledger entries, and checkout state needed to provide the service. ApplyPilot does not store full payment-card numbers or card security codes.

Promotional account credit

Eligible verified accounts may receive non-withdrawable promotional ApplyPilot account credit. To limit duplicate grants, ApplyPilot may keep an opaque cryptographic fingerprint derived from the verified email address; the raw email address is not stored in that anti-duplication key.

Sensitive data

ApplyPilot is not designed to store passwords, OTPs, payment-card data, bank credentials, API keys, private keys, recovery phrases, or high-risk identity numbers as reusable profile facts. Do not provide such credentials for storage.

How data is used

Saved data is used to help you prepare, review, continue and track applications; avoid repeatedly entering approved facts; link evidence to requirements; enforce account entitlements; provide billing/account controls; and support export/deletion. ApplyPilot does not sell user data to advertisers.

Product and website analytics

ApplyPilot uses first-party, pseudonymous product analytics to understand activation, time to first recorded value, feature use, reliability, retention, acquisition-to-value and acquisition-to-paid conversion, plan conversion, and subscription lifecycle. Analytics events are restricted to predefined operational event names and small categorical fields such as product surface, plan, application type, result, first-touch source, medium, and campaign category. Raw referrer URLs, advertising IDs and arbitrary campaign text are not stored in the ApplyPilot analytics store. ApplyPilot does not send application answers, evidence contents, source documents, ChatGPT conversation text, names, email addresses, or payment-card data into that store. The first-party browser collector honors supported Global Privacy Control (GPC) and Do Not Track signals. For anonymous website measurement it creates a random same-tab session identifier in sessionStorage; that value is immediately HMAC-pseudonymized server-side and used only in aggregate unique-session counters, while the raw identifier is not persisted. The browser may also keep only categorical first-touch attribution in same-tab session storage long enough to carry it through sign-in. Public pages also use Vercel Web Analytics for privacy-oriented first-party website measurement such as page views and referrers; Vercel states that its Web Analytics uses a request-derived hash rather than cookies for cross-page uniqueness, cannot track a visitor across different sites, and discards that hash after 24 hours. Once an ApplyPilot account is authenticated, operational analytics uses an opaque HMAC-derived account identifier for activation and retention measurement. ApplyPilot does not use advertising pixels or sell analytics data to advertisers.

Storage and security

Private application state is encrypted before persistence. Access to linked-account data requires authenticated authorization. ApplyPilot applies request, file-size, file-type, rate-limit, and network protections to relevant endpoints.

Retention and deletion

Saved data is retained while needed to provide the service or until you delete it, subject to limited backup, fraud-prevention, legal, billing, or security retention where applicable. ApplyPilot exposes controls to export saved data and delete reusable facts, evidence records, application workspaces, or delete all ApplyPilot data for the connected account. Payment-provider records may remain subject to the provider's and applicable legal retention requirements.

Third parties

ApplyPilot infrastructure may rely on hosting, identity, encrypted storage/database, and payment providers. Those providers process data only as needed to deliver their services under their own agreements.

Contact

For privacy, account, billing, or security requests, use ApplyPilot Support.

← ApplyPilot