CChapply
Privacy Policy
Effective July 31, 2026
In short: Chapply stores your resume and job preferences to find and fill out job
applications for you. We never sell your data, never send your resume to employers or job boards
ourselves (autofill happens locally in your browser, and you review every field before submitting),
and you can permanently delete everything with one click at any time.
What we collect
- Account: your email address, used only for magic-link sign-in (via Supabase
Auth). We never see or store a password.
- Resume: the file you upload, plus the structured data Claude (Anthropic)
parses from it (name, contact info, work history, education, links, skills). The original file
is kept so the extension can attach it to a job application's resume upload field.
- Job preferences: what you tell us in Settings (target roles, locations,
compensation floor, remote preference, eligibility toggles) — used to match and filter job
postings.
- Match results and history: the job cards we generate for you, and a record
of which postings you've already been shown (so we don't repeat them).
- Billing status: whether you have an active subscription. Stripe handles your
payment details directly — we never receive or store your card number.
How we use it
- Your resume text and job preferences are sent to Anthropic's Claude API to parse your resume
and to write the match rationale on each job card.
- Job postings are fetched from JSearch, Greenhouse, and Lever's public listings — your resume
and preferences are never sent to these sources or to any employer. We only pull job postings
from them, we don't push your data to them.
- The Chrome extension uses your parsed resume, locally in your browser, to fill out job
application forms on sites you visit. Autofill never submits an application on its own — you
review and submit it yourself.
Who else sees it
We use a small set of service providers to run Chapply, each only for the purpose below. None of
them are permitted to use your data for their own purposes.
- Supabase — database and authentication hosting. Your data is encrypted at
rest and access is restricted by row-level security so only your own account can read it.
- Anthropic — resume parsing and job-match generation (see above).
- Stripe — payment processing. We never see your full card number.
- JSearch (RapidAPI), Greenhouse, Lever — job posting sources, queried on your
behalf; your resume/preferences are not sent to them.
We do not sell your data, and we do not share it with anyone else for advertising or marketing
purposes.
How long we keep it
We keep your profile, resume, preferences, and match history for as long as your account exists.
Job postings we've already shown you are kept to avoid repeat matches; postings older than 90 days
simply stop being used for that comparison, though the underlying record isn't separately purged
before you delete your account.
Deleting your data
Open Settings → Account → Delete my account in the extension. This immediately
and permanently deletes your profile, resume, match history, and sign-in — cancels any active
subscription first — and removes your account entirely. There's no waiting period and no need to
email us, though you're welcome to at the address below if anything goes wrong.
Security
All traffic to Chapply is encrypted (HTTPS). Data at rest is encrypted by Supabase's default
database encryption. Access to your data is restricted to your own authenticated session via
row-level security — even our own backend service only bypasses this for the scheduled batch job
that generates your matches.
Contact
Questions about this policy or your data: javina1989@gmail.com