Privacy & Data Protection
Last Updated: August 30, 2026

Privacy Policy

At TezApply, your privacy, data sovereignty, and security are foundational. This Privacy Policy details the types of personal data we collect, how it is processed and protected, and our retention policies, including identity preservation for platform safety and abuse prevention.

Transparent Notice on Identity Data & Post-Account Deletion Retention:

When you delete your account, your uploaded resumes, cover letters, and connected email tokens are deleted from active databases. However, to prevent cyclic abuse, free-tier/trial exploitation, fraud, and circumvented suspensions, TezApply permanently retains your verified email address, mobile phone number, account creation/deletion timestamps, and security audit logs in an isolated anti-abuse ledger.

1Overview & Data Controller

This Privacy Policy applies to all personal data collected through the TezApply platform, website, mobile-responsive interfaces, and related software tools.

TezApply operates as the Data Controller for your account information, billing records, and platform security logs. In connection with the content of your job application emails and resume documents dispatched to prospective employers, TezApply operates as a service provider and technical processor acting strictly on your instructions.

2Information We Collect

We collect information necessary to provide, protect, and optimize our automated career services:

A. Identity & Contact Information

When you register, we collect your full name, verified email address, country calling code, and verified mobile phone number. These data points are mandatory to authenticate your identity, prevent spamming, and secure your account.

B. Connected Email & OAuth Tokens

When you connect your email account (such as Gmail or Outlook), we receive and securely store encrypted OAuth access and refresh tokens. These tokens enable the platform to send outbound application emails and track delivery message IDs on your behalf.

C. Career & Application Content

We store PDF resumes you upload, parsed resume metadata, AI-generated cover letters, job description text you input, recruiter contact email addresses, and your job application status history.

D. Billing & Transaction Records

When you purchase a subscription, our payment processor (Razorpay) handles payment details. We store transaction IDs, subscription status, plan tier, amount paid, and invoice numbers. We do not store credit card numbers or banking PINs on our servers.

E. Technical, Audit & Usage Logs

We automatically log IP addresses, browser user agent strings, device identifiers, login timestamps, error logs, and transactional email dispatch records to safeguard platform stability and audit system integrity.

3How We Use Personal Data & Legal Grounds

We process your personal information under the following legal bases:

  • Contractual Performance: To create your account, generate AI drafts, connect your email, scan resumes for malware, dispatch job outreach emails, and fulfill subscription entitlements.
  • Legitimate Interests: To detect and prevent fraud, block spamming, prevent multiple account exploitation, safeguard server stability, and maintain anti-abuse ledgers.
  • Legal & Regulatory Compliance: To maintain financial accounting books, verify billing transactions, comply with tax laws (e.g. GST in India), and cooperate with authorized legal requests.
  • User Consent: For specific optional features, such as opting into product update digests and onboarding tips.

4Google API Services User Data Policy Compliance

Strict Adherence to Google Limited Use Policy:

TezApply's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do NOT read, scrape, or store your personal incoming inbox emails.
  • We do NOT sell your Google user data to advertisers or data brokers.
  • We do NOT use or transfer Google user data to train generalized AI models or large language models without your express opt-in.
  • We access Gmail API strictly under the https://www.googleapis.com/auth/gmail.send scope to transmit outgoing job applications that you review and trigger.

5Data Retention & Post-Deletion Anti-Abuse Ledger

We maintain transparent and strict policies regarding the retention and deletion of your data:

What Is Purged Upon Account Deletion:

When you delete your account, your uploaded resume files, parsed resume text, AI cover letter drafts, application tracker history, and connected OAuth refresh tokens are permanently purged from active operational tables within thirty (30) days.

What Is Retained for Platform Safety & Anti-Abuse:

To safeguard the platform, prevent bad actors from evading administrative bans, block the cyclic recreation of accounts to exploit free daily quotas or promotional offers, and fulfill mandatory statutory tax and accounting retention rules:

  • Primary Identity Markers: We permanently retain your verified email address and mobile phone number in our restricted security registry.
  • Security & Abuse Logs: We retain account creation/deletion timestamps, referral fraud markers, and anti-abuse verification hashes.
  • Financial Records: Transaction logs and invoice records are preserved for the statutory period required under applicable tax and financial legislation (up to 7 years in India).

Retained identity markers in the security ledger are isolated from operational marketing workflows and are strictly used for identity deduplication, anti-fraud enforcement, rate limiting, and legal defense.

6Third-Party Subprocessors

We engage vetted third-party service providers to support our operations under strict confidentiality and data protection agreements:

Partner / SubprocessorPurposeData Handled
ClerkAuthentication & User Session ManagementEmail, Phone Number, Password Hashes, Session IDs
RazorpayPayment Gateway & Recurring SubscriptionsPayment Tokens, Billing Address, Transaction Status
PostgreSQL / Cloud DBCore Application & Security DatabaseEncrypted Application Records, User Identity
AWS S3 / Cloud StorageEncrypted Resume Document StorageUser-Uploaded PDF Resumes
OpenAI / AI EngineAI Resume Parsing & Cover Letter GenerationUser-provided job descriptions, resume snippets

7Data Security & Encryption Safeguards

We employ defense-in-depth technical and organizational measures to safeguard your personal data:

  • AES-256-GCM Token Encryption: All third-party OAuth access and refresh tokens are encrypted at rest using industry-standard AES-256-GCM algorithms with isolated master encryption keys.
  • TLS 1.3 in Transit: All data transmitted between your browser and our servers is secured with HTTPS and modern TLS encryption.
  • Automated Malware & Virus Scanning: Uploaded resumes undergo automated security checks to prevent malware distribution.
  • Access Controls: Database access is restricted to authorized personnel under least-privilege principles and multi-factor authentication.

8Your Data Protection Rights

Subject to applicable data protection laws (including the Digital Personal Data Protection Act / DPDP and GDPR), you possess the following rights:

  • Right to Access & Portability: Request a copy of the personal data we hold about you in a structured format.
  • Right to Rectification: Request correction of inaccurate or incomplete personal details.
  • Right to Erasure: Request deletion of your active account data, resumes, and connected tokens (subject to our anti-abuse and statutory retention exceptions outlined in Section 5).
  • Right to Revoke Consent: Disconnect your Google or Outlook account at any time through your account settings, which immediately revokes our access to external mail servers.

9Cookies & Local Storage

We use essential HTTP cookies and browser local storage strictly to authenticate your session, maintain security tokens, store UI preferences (such as light/dark mode), and prevent CSRF attacks. We do not deploy third-party cross-site advertising trackers.

10Children's Privacy

TezApply is intended solely for adult job seekers (18 years of age or older). We do not knowingly collect personal data from minors. If you believe a minor has registered for an account, please contact us immediately for removal.

11Contact & Grievance Officer

For questions regarding this Privacy Policy, data subject access requests, or grievance redressal under the DPDP Act, please contact our Data Protection Officer:

Grievance Officer: Data Protection Officer, TezApply

Email: [email protected]

Jurisdiction: Ahmedabad, Gujarat, India

Related: Review our Terms of Service or learn more on our About Page.