XpertApply home

Privacy policy

Last updated September 26, 2026

Scope and purpose

This policy covers the XpertApply web app and Chrome extension. XpertApply helps you prepare, fill, and track job applications using information you provide and information from job and application pages you choose to use with XpertApply. You review and submit applications yourself.

Information you provide

When you create an account, we process account identifiers such as your name, email address, internal user ID, and authentication or session information. Your profile may include contact details, work history, education, skills, preferences, professional links, work authorization and sponsorship answers, and answers you save for applications. Optional demographic information is handled separately from matching and resume generation.

If you choose Google sign-in, XpertApply may receive and retain the authentication provider, Google account identifier, provider email address, whether Google reports the email as verified, and a display name where provided. We use this metadata to authenticate you, maintain account identity and security, and link Google to an existing XpertApply account only after you explicitly authorize linking.

If you choose to save a Workday application password, XpertApply stores it encrypted on the service. For a Workday application session, the service can send the password to the extension to fill the relevant account-creation fields on that application site. You can remove the saved password in your profile. The stored credential is excluded from AI processing.

You may upload a resume and create resumes, cover letters, application answers, and exports. We process the source material, generated content, document snapshots and provenance needed to prepare and manage those documents. You may also save jobs, employers, job URLs, application statuses, tracker history, prepared answers, confirmation state, and application sessions.

Application pages and browser activity

When you start an application workflow, the extension may request access to that employer or application site, including a site reached through an application redirect or embedded form. With access, it reads relevant page and form information such as the page URL, form labels, questions, options, field state, and application context to identify fields, prepare assistance, and fill information you have provided or confirmed. Relevant information may be sent to the XpertApply service for requested application features, including answer preparation. Job and application URLs and related workflow records may be saved in your account.

When you choose to fill an employer or application form, the information placed in that form is available to that site and its application provider under their own practices. You review and submit the final application yourself.

The extension uses tab and navigation information to keep the selected application workflow bound to the correct page, including necessary redirects and new tabs. This is application-workflow activity; the feature does not require a general browser-history feed or monitoring unrelated tabs. You can decline or revoke an employer-site permission through Chrome, although filling on that site will then be unavailable.

Extension storage

The extension uses Chrome session storage for temporary application handoffs, tab bindings, prepared packages, answers and progress, including session-sensitive information. Session storage survives service-worker suspension but is cleared when the browser restarts or the extension reloads; workflow state is also cleared when sessions end or account authority changes. Chrome local storage holds limited configuration and sanitized runtime or identity metadata. The extension does not use Chrome sync storage. Chrome manages the site permissions you grant.

How information is used and shared

We use this information to authenticate your account; maintain your profile, documents and application tracker; prepare and assist with applications; discover professional contacts when you ask; and operate, secure and troubleshoot these features. Information is sent to the XpertApply service as needed for these actions.

  • Google provides optional account authentication using only the openid, email, and profile scopes. Google sign-in does not give XpertApply access to Gmail, Drive, Calendar, Contacts, or unrelated XpertApply job and application data. Authentication credentials and temporary authorization data may be processed to complete sign-in, but Google access, refresh, and ID tokens are not retained as persistent XpertApply account data.
  • OpenAI processes relevant profile, career, job, document, question, answer or outreach context for requested AI-assisted features such as profile import, resume, cover-letter and application-answer generation, and optional outreach improvement. Stored Workday credential ciphertext and credential-shaped keys are excluded from AI payloads.
  • People Data Labs and Apollo may receive employer and professional search criteria, such as company domain, role, seniority and location, for user-requested recruiter or professional-contact discovery. Apollo may also receive provider person identifiers.
  • Hunter may receive professional names, employer domains and discovered work email addresses for user-requested professional-email discovery or verification.
  • Hostinger provides hosting infrastructure for the XpertApply service.

Professional-contact providers are used for that requested feature, not for every ordinary application workflow. We do not promise that third-party providers retain or delete data on XpertApply's schedule.

Retention and deletion

Account and profile information, including retained Google identity metadata, saved applications and documents remain available while you use the account unless you edit or delete them or a specific lifecycle rule applies. Rejected and withdrawn application trackers are scheduled for deletion after a seven-day grace period; you can undo that scheduled deletion. Related application sessions are cleaned up with that lifecycle. Other application statuses have no universal seven-day deletion rule.

You can use the web app's privacy controls to export account data or delete your account. Account deletion removes account-owned database records, including linked identity metadata, and XpertApply-controlled materialized generated-document files. Editing, deleting or re-exporting a generated document also removes superseded files under XpertApply's control. These statements do not set a deletion schedule for third-party processors or for copies you have downloaded or submitted to employers.

Your controls and security

You can review and edit profile information and application answers, manage documents and trackers, export your data, delete your account, and manage Chrome site access. The extension does not submit an employer application for you. XpertApply uses access controls and secure connections for its service and limits application-page access to the selected workflow. No internet service can guarantee absolute security.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension-derived information to provide or improve the disclosed job-application assistance purpose and related security and reliability functions. We do not sell it, use or transfer it for personalized advertising, transfer it to data brokers or information resellers, or use it to assess creditworthiness or for lending.

Changes and contact

We may update this policy as the service changes. The date above identifies the current version. For privacy questions, contact privacy@xpertapply.com.