This is the page that backs the homepage stance. Plain English. No dark patterns. No 14-page legalese. If we can’t explain a clause to a 22-year-old, we shouldn’t be enforcing it.
What we collect
When you sign up and use SundayApply, we collect:
Account info, email + password (hashed via Supabase Auth, we never see plaintext).
Resume content + job descriptions, exactly what you paste or upload, used to generate tailored applications.
Saved applications, the tailored resume, cover letter, and outreach we generate for you.
Saved contacts, hiring-manager emails you choose to save (only when you click “save”).
Aggregate usage, page views, referrers, browser type. IP-truncated, no fingerprinting.
What we do NOT collect
No browser fingerprinting. No canvas tracking, no audio fingerprinting, no font enumeration.
No session replay tools (no Hotjar, no FullStory, no LogRocket).
No advertising or analytics tool ever receives your resume, applications, or account content. We use Google Analytics and the Meta pixel only to measure, in aggregate, which pages and ads bring students to us.
No data brokers, ever. We don’t buy enrichment data, we don’t sell to data brokers.
No reading of your email inbox. The Gmail OAuth scope we use is gmail.send, send-only, not read.
We do not train on your data
Your resume + JD content is sent to Anthropic’s Claude for inference only. Anthropic’s commercial terms explicitly exclude inputs from training. We do not train any AI on user data, we do not build training datasets from anonymized user data, and we will never sell your inputs to a third party.
This is a direct contrast to some competitors (Kickresume admits to training on “anonymized” user data in their TOS). We don’t want to be a competitor that does that. So we don’t.
How long we keep things
Account data, kept while your account is active.
Saved resumes + applications, kept while your account is active. Deleted within 24 hours of account deletion.
Application logs, 30 days max, then auto-purged. Logs contain request paths and status codes only, no user content.
Anthropic logs, Anthropic’s default retention is 30 days for abuse monitoring, then deleted. We do not request additional retention.
Name, email, and payment details you enter at checkout, handled directly by Razorpay to process a purchase. We never see or store your full card, UPI, or bank details. PCI-DSS Level 1.
When we add a sixth subprocessor, this list updates first, with the effective date bumped.
Security
All traffic is HTTPS (TLS 1.3). HTTP redirects to HTTPS unconditionally.
Database encryption at rest via Supabase (AES-256).
Passwords are hashed with bcrypt (Supabase Auth), never stored in plaintext.
Credentials are stored in environment variables, never committed to source control.
Limited engineer access to production data, audited and time-bound.
International users
SundayApply works for any student and offers extra depth for international students (see our F-1 / OPT page). Your data is processed in the US (Anthropic), Singapore (Supabase Asia), and the EU (Hostinger VPS). Standard contractual clauses apply for cross-border transfer. We do not store data in countries that lack adequate data-protection regimes.
Age
SundayApply is intended for users aged 16 and older (typical college applicants). We don’t knowingly collect data from users under 16. If you believe a child under 16 has signed up, email [email protected] and we’ll delete the account immediately.
Changes to this policy
When we change this policy, we bump the effective date at the top, send a plain-text email to all active users summarizing what changed, and post a diff to our public policy-history repo. We don’t hide changes in fine print.
Contact
Privacy questions, data requests, or anything else go to [email protected]. A real person reads it.