GDPR & DATA PROTECTION

Privacy Policy

Effective August 23, 2026 · EasyApply, Dublin, Ireland

We do not sell candidate resumes, Gmail content, or application history.

Contact legal@easyapply.ie for privacy requests.

1. Who controls your data

EasyApply is the controller for personal data processed through easyapply.ie. Privacy and data-rights requests can be sent to legal@easyapply.ie.

2. Data we process

  • Account information, authentication identifiers, preferences, and security events.
  • Resumes, career history, application records, notes, and generated career materials.
  • Subscription, transaction, and support information needed to provide paid services.
  • Device, request, diagnostic, and usage data needed for security and reliability.
  • When you opt in to Gmail sync, job-related message metadata and relevant message content needed to detect application or interview status changes.

3. Optional Gmail status sync

Gmail sync is voluntary and uses the Google gmail.readonly permission. It cannot send, edit, or delete your email. EasyApply analyzes job-related messages to update application statuses and records sync diagnostics.

OAuth tokens are encrypted at rest. You can disconnect Gmail in EasyApply settings; the service then revokes access where Google permits and stops future synchronization.

4. ChatGPT and Codex plugin

EasyApply's public job-search tools receive search filters and return public listing data and application links without requiring an account. Standard request and security logs may be retained to keep the service reliable and prevent abuse.

Account tools require a separate OAuth authorization. Once authorized, the plugin may read and add records in your own application tracker. Auto-apply is split into a review step and a separate confirmation step; no external automation run is queued by the review step alone. OAuth access can be revoked, and EasyApply validates the linked identity on every protected request.

5. Why we process data

We process data to perform our contract with you, act on your consent for optional features, protect the service and users through legitimate interests, and comply with legal obligations. You can withdraw consent for an optional integration without affecting earlier lawful processing.

6. Service providers and transfers

We use vetted infrastructure, authentication, payment, email-delivery, and storage providers such as Render, Supabase, Google, Stripe, Resend, and AWS where applicable. Providers process only the data needed for their role. Where data leaves the EEA, we use an available lawful transfer mechanism and contractual safeguards.

7. Retention and deletion

We retain account and career data while your account is active and for limited periods needed for recovery, fraud prevention, disputes, and legal compliance. Integration tokens are retained only while the integration is connected. You may request account deletion or a data export at any time. Backups expire according to their normal protected retention cycle.

8. Your GDPR rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability, or objection, and may complain to the Irish Data Protection Commission. We may need to verify your identity before completing a request.

9. Security, children, and updates

We use access controls, encryption, rate limits, and monitoring proportionate to the service. EasyApply is not intended for children under 16. We may update this policy as the service or law changes and will publish the revised effective date here.