JOIN US FOR TECH WEEK 2026
San Francisco - October 5-11More
JOIN US FOR TECH WEEK 2026
More

On this page

Data controller

The controller of your personal data is DIASSET spółka z ograniczoną odpowiedzialnością (a Polish limited liability company) with its registered office in Kraków, ul. Św. Filipa 23/4, 31-150 Kraków, Poland, KRS 0000806751, Tax Identification Number (NIP) 6762571939, REGON 384507610 (“DIASSET”, “AplikAI”, “we”, “us”, “our”).

Contact details for privacy matters and exercise of data-protection rights:

  • e-mail: support@aplik.ai,

  • address: DIASSET sp. z o.o., ul. Św. Filipa 23/4, 31-150 Kraków, Poland.

If we appoint a Data Protection Officer in the future, the relevant contact details will be published in this Policy.

Who and what this Policy applies to

This Policy applies to persons who:

  • create or hold an AplikAI Account,

  • use job-search, CV/résumé, matching, Application Kit, Autopilot, Apply Agent, Tracking Board or other AplikAI features,

  • connect AplikAI with Google or LinkedIn,

  • purchase a Subscription or Tokens,

  • contact support,

  • use aplik.ai and, where they provide the required consent, analytics and marketing technologies.

AplikAI is intended only for persons who are at least 18 years old.

Personal data we process

Depending on the features used, we may process the following categories of personal data.

Account and authentication data

  • first and last name,

  • e-mail address,

  • password in cryptographically protected form,

  • Account identifier,

  • data provided by Google or LinkedIn during sign-in, to the extent accepted by the user,

  • session, login and security data.

Professional profile and CV/résumé data

  • CV/résumé and files uploaded by the user,

  • employment history, roles, projects and achievements,

  • education, skills, languages and certificates,

  • preferences regarding type of work, location, salary, work mode and experience level,

  • photograph, date of birth and citizenship if the user chooses to provide them,

  • Public Profile data if the user enables publication.

AplikAI is not designed to collect special categories of personal data within the meaning of Article 9 GDPR, such as health data, religious beliefs, political opinions, ethnic origin, trade union membership or data concerning sex life. Please do not include such information in your CV/résumé or other materials unless it is necessary. We do not use such data for Match Score or candidate assessment.

Job-offer and application-process data

  • saved job offers and search preferences,

  • Match Score, Match Insights and the user’s actions concerning job offers,

  • Autopilot and Apply Agent settings,

  • Application Kits, job-tailored CVs/résumés, cover letters, follow-ups and other materials,

  • application statuses, notes, reminders and activity history,

  • employer or contact data associated with an application,

  • recruitment-consent settings and historical snapshots of applied settings,

  • data associated with an Application Page.

AI data

  • user prompts and instructions,

  • content sent to a model in order to perform a specific feature,

  • model output,

  • technical information about the model used, version, execution time, cost and operation status,

  • user feedback concerning AI output.

Google data

Depending on the features accepted by the user, AplikAI may process:

  • basic Google Account data required for sign-in, such as an identifier, name, e-mail address and profile picture,

  • permission to send e-mail on the user’s behalf through Gmail,

  • if the user enables reply synchronisation: message content, headers and metadata to the extent required to handle e-mail threads initiated through AplikAI.

AplikAI does not use Gmail access to generally scan the user’s mailbox. Product logic limits processing to messages and threads required for features expressly enabled by the user, in particular threads initiated through AplikAI.

As of the publication date of this version of the Policy, Google Calendar synchronisation is not part of the active Google Integration. If it is enabled in the future, the relevant access will be requested separately in the context of that feature, and this Policy and the notice shown before authorisation will be updated accordingly.

Payment and billing data

  • selected Plan, billing period and Subscription history,

  • purchase and use of Tokens,

  • payment and transaction identifiers,

  • data required to issue accounting documents,

  • payment-status information.

Payment-card data is generally handled by Stripe and does not need to be stored by DIASSET in full.

Technical, security and support data

  • IP address,

  • device, operating-system and browser information,

  • event and error logs,

  • timestamps and technical identifiers,

  • information concerning suspicious logins, abuse and security,

  • support correspondence.

Marketing and analytics data

After obtaining the required consent, we may process cookie identifiers and similar data related to use of the website or Application through tools such as Google Analytics, Google Ads, Meta Pixel and PostHog. The scope depends on the user’s consent settings and the relevant tool configuration.

Data received from Google Workspace APIs, including Gmail data, is not transmitted to Meta Pixel, Google Ads, Google Analytics, PostHog or other advertising platforms for ad targeting.

Purposes and legal bases for processing

Purpose

Example data

Legal basis

Creating and maintaining the Account, sign-in and onboarding

Account data, profile

Article 6(1)(b) GDPR – performance of a contract

Providing AplikAI features, CV/résumé functions, matching, Application Kit, Autopilot, Apply Agent and tracking

profile, CV/résumé, preferences, job-offer data, application materials

Article 6(1)(b) GDPR

Sending an application or message to an employer at the user’s request

CV/résumé, message content, contact data

Article 6(1)(b) GDPR

Google and Gmail Integration

Google data, OAuth token, threads and messages within the relevant feature

Article 6(1)(b) GDPR and the user’s conscious grant of the relevant OAuth permissions

Processing payments, Subscriptions and Tokens

transaction data, billing data

Article 6(1)(b) GDPR

Accounting, taxes and legal obligations

billing and accounting data

Article 6(1)(c) GDPR

Security, abuse prevention and protection of legal claims

logs, IP address, security events

Article 6(1)(f) GDPR – legitimate interests of the controller

Support and complaint handling

Account data, correspondence

Article 6(1)(b), (c) or (f) GDPR, depending on the matter

Publishing a Public Profile and Application Page

data selected by the user

Article 6(1)(b) GDPR – performance of a feature enabled by the user

E-mail marketing and newsletter

e-mail address, consent records

Article 6(1)(a) GDPR and the required consent to marketing communications

Analytics and marketing based on cookies/similar technologies

device identifiers, activity

Article 6(1)(a) GDPR and the relevant consent to use non-essential technologies

Information about product use in aggregated or anonymised form

statistical data

where personal data is involved: Article 6(1)(f) GDPR; after effective anonymisation the GDPR does not apply

Where we process data on the basis of legitimate interests, we assess whether those interests are overridden by the rights and freedoms of the data subject.

Profiling, Match Score and automated actions

  1. AplikAI uses profiling within the meaning of the GDPR to the extent it analyses CV/résumé, profile, preference and job-offer data in order to calculate fit and rank job offers.

  2. Match Score concerns the fit between a job offer and the user’s profile and settings. It is not an employer-side candidate score, an employability assessment or a prediction of an employer’s decision.

  3. The user may set a minimum Match Score. For example, if the user sets a threshold of 90, offers below that threshold may not be displayed. The user may change this setting at any time, including setting it to 0 in order to display all available offers.

  4. Apply Agent may perform actions automatically in accordance with rules set by the user. This is automation of the user’s instructions, not an AplikAI decision to grant or deny employment.

  5. AplikAI does not make solely automated decisions concerning the user that produce legal effects or similarly significantly affect the user within the meaning of Article 22 GDPR. Recruitment decisions are made by independent employers.

Artificial intelligence and Amazon Bedrock

  1. AplikAI uses AI systems made available through Amazon Bedrock. Depending on the feature and availability, the user may be able to choose from several supported models.

  2. For users in the EU, we configure available models and inference profiles so that AI processing takes place in supported AWS regions located within the European Union, unless, before a particular feature is used, the user receives clear information about another processing region and the required transfer mechanism.

  3. We send to the model only data necessary to perform the specific feature, for example a fragment of a CV/résumé, the user’s profile, a job description or the user’s instruction.

  4. We do not use users’ CVs/résumés, Gmail data, applications, prompts or outputs to train or improve general-purpose AI models. We do not sell this data to model providers.

  5. We may retain limited technical logs concerning AI operations for security, billing, diagnostics, auditing and product improvement purposes, in accordance with the retention periods described below.

  6. Current information about the use of AI may additionally be presented in the AplikAI interface or on a dedicated AI transparency page.

Google Connect – detailed rules for Google user data

This section applies when the user connects an AplikAI Account with Google.

Access we may request

Depending on the feature, AplikAI may request:

  • standard Google sign-in permissions (openid, email, profile),

  • https://www.googleapis.com/auth/gmail.send – to send e-mail messages on the user’s behalf,

  • https://www.googleapis.com/auth/gmail.readonly – only if the feature for reading replies in threads associated with applications initiated through AplikAI is active.

If a feature is not necessary, we should not request the corresponding scope. The scopes displayed on the Google OAuth screen are controlling for the specific connection.

How we use Gmail data

We use Gmail data only for user-facing features, in particular to:

  • send a message approved by the user or perform automation configured by the user,

  • associate a reply with a specific job application,

  • display in AplikAI the status, content and next actions associated with that thread,

  • prepare a follow-up or another feature concerning a specific application if the user enables it.

We do not use Gmail read permissions to review unrelated messages or to build an independent copy of the user’s mailbox.

What we do not do with Google data

Data received from Google Workspace APIs is:

  • not sold,

  • not provided to data brokers,

  • not used for advertising, retargeting or advertising profiling,

  • not provided to Meta Pixel, Google Ads, Google Analytics or other advertising tools,

  • not used to train, create or improve general-purpose AI or ML models,

  • not made available to employees for manual review except where the user expressly requests support concerning specific data, where manual access is necessary for security, or where required by law.

We may provide Google user data only to service providers acting on our behalf where this is necessary to provide the user with a specific, user-facing feature and is consistent with Google Limited Use requirements and applicable law.

Limited Use

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google’s policy is available at:
https://developers.google.com/terms/api-services-user-data-policy

Revoking access and deleting Google data

  1. The user may disconnect Google in AplikAI settings and may revoke AplikAI access in the security settings of their Google Account.

  2. After the account is disconnected, OAuth tokens and Google authentication credentials are deleted or invalidated without undue delay.

  3. Data obtained solely from Google Workspace APIs and stored by AplikAI for purposes of an active integration is, as a rule, removed from active systems within 24 hours after disconnection or Account deletion, unless further processing is necessary to complete an operation expressly requested by the user, handle a security incident or comply with a legal obligation.

  4. Content originally created in AplikAI by or for the user, such as a cover letter generated in AplikAI, does not become “Google data” merely because it was subsequently sent through Gmail.

  5. We do not create an independent, permanent archive of the Gmail mailbox.

Who we disclose data to

Data may be provided to service providers only to the extent necessary for a specific purpose. Our current setup may include:

Recipient / category

Purpose

Amazon Web Services (AWS), including Amazon Bedrock

hosting, storage, backend processing, AI, security

Stripe

payments, Subscriptions, transaction processing

Google

sign-in, Gmail, reCAPTCHA and – after consent – analytics/marketing tools

LinkedIn

sign-in or authentication if selected by the user

Cloudflare

security, traffic protection, CDN and network services

PostHog

product analytics in accordance with configuration and required consents

MailerLite

e-mail marketing and newsletters after obtaining the required consent

SMSAPI

SMS delivery where the user uses a feature that requires SMS

Meta

Meta Pixel and advertising activities only after the required consent

Framer

hosting or operation of the marketing website

employers / recruiters selected by the user

receipt of an application, CV/résumé or Application Page in accordance with the user’s instruction

advisers, accountants, lawyers and public authorities

legal obligations, settlements, protection of rights and legal claims

We do not provide Google Workspace API data to advertising platforms or analytics providers for advertising purposes.

Transfers of data outside the EEA

  1. AplikAI’s primary application data is stored on AWS infrastructure in the eu-central-1 (Frankfurt) region.

  2. For AI processing of EU users, we aim to use models and inference profiles restricted to EU regions.

  3. Some providers, such as Google, Stripe, Meta, Sentry, MailerLite, LinkedIn or their subprocessors, may process certain data outside the European Economic Area.

  4. Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism provided by the GDPR, such as an adequacy decision, participation of the recipient in a recognised transfer mechanism, or Standard Contractual Clauses together with supplementary safeguards where required.

  5. Gmail data and other Google user data is processed subject to the additional Google restrictions described in Section 7.

How long we retain data

We apply the storage-limitation principle. Typical retention periods are as follows:

Category

Retention period

Account, profile, CV/résumé, preferences, jobs, boards, Application Kits, applications, notes

while the Account remains active; after Delete Account, deletion or irreversible anonymisation from active systems generally within 24 hours

Google Workspace API data required for an active integration

only for as long as needed for the relevant feature; after disconnect/delete, deletion from active systems generally within 24 hours

OAuth access/refresh tokens

while the connection remains active; removed/invalidated without undue delay after disconnect

Raw AI diagnostic logs containing prompt/output content, where necessary

generally no longer than 30 days; where possible we use shorter retention or logging without full content

AI audit metadata without the full CV/résumé content

up to 12 months where needed for audit, billing and security

Security and audit logs

generally up to 12 months, unless an incident requires longer retention

Sentry diagnostic data

generally 30–90 days depending on configuration

Support data

up to 24 months after the case is closed, unless longer retention is required for legal claims

Accounting, tax and billing documents

for the period required by law, generally until expiry of the applicable tax-liability limitation period

Evidence of marketing consents

for the duration of reliance on the consent and thereafter for the period needed to demonstrate compliance or defend claims, generally up to 3 years after withdrawal unless longer retention is necessary

Analytics/cookie data

in accordance with tool settings and consent; we aim for no more than 14 months for identifiable user analytics

Backups

on a rotating basis, generally no longer than 35 days

Data export file prepared for the user

no more than 7 days after preparation, after which it is deleted

Where specific data is necessary to establish, exercise or defend legal claims, we may restrict its use and retain it until expiry of the applicable limitation period.

Account deletion

  1. The user may delete the Account through the Application where that functionality is available or by sending a request to support@aplik.ai.

  2. Once deletion is confirmed, product data is, as a rule, deleted or irreversibly anonymised from active systems within 24 hours.

  3. Exceptions include data that we must retain due to a legal obligation, settlements, security or legal claims, as well as rotating backups.

  4. Deleting the Account does not delete data that the user previously sent to an independent employer. The user may exercise their rights directly against that employer.

Data export and portability

  1. The user may request access to their data and, where provided by law, portability of the data in a commonly used, machine-readable format.

  2. Until a self-service Export my data feature is made available, requests may be submitted to support@aplik.ai.

  3. The planned export feature should include profile data, the user’s CV/résumé and files, saved job offers, application history, Application Kit materials, settings, User Content and other data that may lawfully be exported without infringing third-party rights.

  4. An export does not include AplikAI technical secrets, system prompts, keys, other users’ data or content whose disclosure would infringe third-party rights.

Public Profile and Application Page

  1. The profile is private by default. The user decides whether to publish it.

  2. If a separate setting for search-engine indexing is available, it should be independent from the public-availability setting itself and disabled by default.

  3. An Application Page is protected by a unique link/hash and PIN and has an expiry date.

  4. The user may at any time use Revoke now, which invalidates further access before the original expiry date.

  5. A person or company to whom the user provides an Application Page or an application may become an independent controller of the received data.

Cookies, Google Analytics, Google Ads, Meta Pixel and PostHog

  1. Technologies necessary for security, sign-in and operation of the Application may be used without consent where permitted by law.

  2. We enable analytics or marketing cookies and similar technologies after obtaining the required consent.

  3. The consent interface should allow at least the categories Necessary, Analytics and Marketing, and it should be as easy to reject optional technologies as to accept them.

  4. The user may change or withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

  5. Data obtained from Gmail or other Google Workspace APIs is not used for advertising, retargeting or building marketing profiles.

Electronic marketing

  1. Transactional and product messages necessary to perform the contract, such as registration, payment, security or feature-operation confirmations, may be sent without marketing consent where they are necessary to provide the Service.

  2. Newsletters, promotions and other commercial communications are sent after obtaining the required consent.

  3. Consent may be withdrawn at any time, for example through an unsubscribe link or by contacting support@aplik.ai.

Security

We use technical and organisational measures appropriate to the risk, including access controls, encryption in transit, secrets management, environment separation, monitoring, backups and abuse-detection mechanisms.

Authentication data and OAuth tokens should be protected at rest, and transmission takes place using current secure protocols. Personnel access to user data is limited to persons and situations where such access is necessary to perform their duties.

No system can provide absolute security. If a personal-data breach occurs, we apply procedures required by the GDPR and other applicable laws.

User rights

Depending on the circumstances, the user may have the right to:

  • access personal data and obtain a copy,

  • rectify personal data,

  • erase personal data,

  • restrict processing,

  • data portability,

  • object to processing based on legitimate interests,

  • withdraw consent at any time where processing is based on consent,

  • lodge a complaint with a supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO). The user may also contact the competent data-protection authority in the EU country where they live or work, or where they believe an infringement has occurred.

Requests may be submitted to support@aplik.ai. We may request additional identity verification where necessary to protect personal data from disclosure to an unauthorised person.

Objection to legitimate-interest processing

Where we process data on the basis of Article 6(1)(f) GDPR, the user may object on grounds relating to their particular situation. We will stop processing unless we demonstrate compelling legitimate grounds that override the user’s interests and rights, or unless the data is required for the establishment, exercise or defence of legal claims.

In the case of direct marketing, an objection is effective without the user having to provide any reason.

Changes to this Policy

We may update this Policy, in particular in connection with changes to features, providers, laws, AI models or data-processing practices.

If a change materially affects how personal data is used, we will inform users in an appropriate manner, and where a new purpose requires consent, we will obtain it before beginning such processing.

The current version is available at https://aplik.ai/legal/privacy.

Contact

Questions concerning privacy, Google user data, Account deletion, access to or export of data may be directed to:

DIASSET sp. z o.o.
ul. Św. Filipa 23/4
31-150 Kraków, Poland
support@aplik.ai

READY FOR BETTER MATCHES?

Start with opportunities that fit your goals.

Build your profile once and see the roles worth reviewing first.