Privacy Policy
AutoStant handles your resume, your job applications and the answers you give employers. This page describes what happens to all of it.
Last updated 17 September 2026
1. Who this policy covers
This policy applies to the AutoStant mobile app and to this website. The service is operated by [TO BE SUPPLIED — The legal or business entity that publishes AutoStant and is the data controller.], at [TO BE SUPPLIED — A business or contact address, if one is required for the jurisdiction the entity is registered in.].
AutoStant has not yet been released publicly on the App Store or Google Play. This policy describes the behaviour of the software as it is built today.
2. What we collect
Account information
Your email address, and either a hashed password or the account identifier your sign-in provider gives us when you use Google or Apple to sign in. If you sign in with Apple, we also store the credential Apple requires us to keep in order to revoke your authorisation when you delete your account.
Your Master Resume
The file you upload is held in private object storage by our file-storage provider. It is not publicly reachable and has no public URL. We extract the text from it on our servers and store that text, along with the structured sections derived from it — your work history, education, skills and anything else your resume contains.
Jobs and applications
The job postings you capture, including the URL, the posting text, the role and employer, the analyses run against them, the status you give each application, and any images or documents you capture a posting from.
Documents AutoStant generates
Tailored resumes and cover letters, each kept as its own version attached to one application.
Answers to application questions
When AutoStant fills an application form, it stores the answers you give so that the next form does not ask you the same thing again. This includes ordinary candidate facts such as work authorisation, sponsorship requirements, notice period, salary expectations, relocation and work arrangement.
It does not include demographic answers. See section 5, which describes exactly which answers stay on your phone and which do not.
Subscription information
Which plan you are on, how much of your monthly allowance you have used, and the subscription and transaction records our billing provider sends us. We never see your card details; Apple and Google handle payment and do not give them to us.
Technical and error information
When something goes wrong, our error-tracking provider receives a report that can include the request that failed and the account identifier associated with it. Our servers also keep operational logs.
AutoStant contains no advertising SDK and no analytics SDK, and this website runs no analytics, no cookie banner and no third-party script. We do not track you across other apps or websites and we do not sell personal data.
This website sets no cookies. The only thing it stores in your browser is the light-or-dark theme you pick with the switch in the header, saved under the key autostant-theme so the page does not change colour on you the next time you open it. It is never sent to us, it is not joined to anything, and clearing your browser data removes it.
3. Why we process it
- To create and secure your account, and to verify your email address.
- To read a job posting you captured and extract its requirements.
- To score your Master Resume against a specific job.
- To generate a tailored resume or cover letter for a specific job.
- To propose answers to an application form’s questions, which you then review.
- To enforce the allowances of your plan and to record your subscription state.
- To find and fix errors, and to protect the service from abuse.
4. AI processing, and what is sent where
This is the section most likely to matter to you, so it is stated plainly: preparing an application means sending your personal information to a third-party AI provider.
What is sent, and when:
| When | What is sent | Who receives it |
|---|---|---|
| You capture a job | The text of the job posting. | Our AI provider. |
| You upload a resume | The text extracted from your resume, so it can be structured into sections. | Our AI provider. |
| You capture a posting as an image, or upload a scanned resume | The image itself, so the text in it can be read. | Our text-extraction provider. |
| You run an ATS analysis | The job posting and the relevant contents of your Master Resume. | Our AI provider. |
| You generate a resume or cover letter | The job posting and the relevant contents of your Master Resume. | Our AI provider. |
| AutoStant drafts an answer to a form question | The question as the form asks it, and the parts of your profile needed to answer it. | Our AI provider. |
AutoStant uses a third-party AI provider for all of the above. Which one is active is a server configuration rather than something you choose in the app, and it may change; what does not change is the list above of what is sent and when. We do not permit a provider to train models on your information, and we require each one to protect it to the standard described on this page.
You can ask which provider is in use at any time, through the contact route in section 12.
Demographic answers are never part of any of this — they are not sent to our servers at all, so they cannot reach an AI provider. See the next section.
5. Answers that stay on your phone
Gender, race or ethnicity, disability, veteran status and pronouns are the one category of answer AutoStant keeps entirely on your device. They are never sent to our servers, and our servers refuse to store them even if one were.
Some applications ask those questions voluntarily. When you answer one, AutoStant can save the answer so it does not have to ask you again. If you allow that:
- The answer is stored in your device’s secure storage.
- It is never sent to AutoStant’s servers.
- Our servers independently refuse to store answers of this kind, even if one were sent — this is enforced on the server as well as on the device.
- It is removed when you sign out.
- You can delete every saved answer at any time from Privacy in the app’s settings.
This protection is narrow and we will not describe it as wider than it is. It covers demographic and equal-opportunity questions and pronouns. It does not cover nationality, citizenship, work authorisation, visa or sponsorship requirements, or security clearance. Those are mandatory, eligibility-determining questions that you have to answer to be considered at all, and AutoStant treats them as ordinary application data stored on our servers.
6. Service providers
We use service providers to run AutoStant. They are listed here by what they do and what they receive, which is what determines your exposure; each receives only what its role needs, and none is permitted to use it for anything else.
| What they do | What they receive |
|---|---|
| AI processing | Job postings, resume text, profile facts and application questions — as set out in section 4 |
| Reading text out of images | Images you capture or upload |
| Cloud hosting and file storage | Your uploaded resume file, and the data the service stores to operate |
| Authentication | The sign-in exchange, if you sign in with Google or Apple |
| Subscription management | Your account identifier and your purchase events |
| Payment | Your payment details, handled by Apple or Google and never shared with us |
| Transactional email | Your email address and the contents of the emails we send you |
| Error monitoring and security | Error reports, which can include the request that failed and the account identifier associated with it |
We do not sell personal data, we do not share it for advertising, and AutoStant carries no advertising or analytics SDK.
7. Where your data is processed
Our providers operate internationally, and the production AI provider is outside the country many of our users will be in. Your information is therefore processed across borders.
NOT YET WRITTEN — this section is incompleteWhich countries AutoStant serves, and therefore whether GDPR/UK GDPR/CCPA-style transfer disclosures and rights sections are required. The AI provider in production is Alibaba Cloud Model Studio (Qwen), so personal data already crosses borders. Whether that needs a transfer-mechanism disclosure depends on where users are, which has not been decided.8. How long we keep it
We keep your account information, resume, jobs, generated documents and saved answers for as long as your account exists. Deleting your account removes them immediately — see the next section.
NOT YET WRITTEN — this section is incompleteHow long database backups and error/security logs are kept before they are overwritten. Account deletion removes live records immediately — that is code-verified. How long a deleted row survives in a backup is an infrastructure fact, not a code fact, and no retention window is configured or documented.9. Deleting your account
You can delete your account from inside the app, under Profile → Account. Deletion is immediate. There is no grace period and no scheduled job — the records are gone when the request returns.
Deleting your account removes:
- Your account record, email address and stored credentials.
- Your Master Resume, including the file held by our storage provider.
- Every tailored resume and cover letter AutoStant generated for you.
- Every captured job, application and ATS analysis.
- Your saved application answers and usage records.
- Your subscription and transaction records held by AutoStant.
Your access tokens stop working immediately, because every request re-reads the account they belong to. If you signed in with Apple, we also ask Apple to revoke your authorisation.
Two things do not disappear, and we would rather say so than not:
- A record of what the app stores told us. We keep the subscription events our billing provider sent us, so that there is a record of what was purchased and refunded. The link to your account is severed, but the event still contains the account identifier the store used at the time, and the store’s own message.
- Your subscription provider’s own copy. The provider that manages subscriptions for us keeps its own customer record on its side. Deleting your AutoStant account does not delete that record.
If you no longer have the app installed, see Delete your account.
10. Security
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. Your resume file is held in private storage that our servers fetch on your behalf and that has no public address. Requests for your data are scoped to your own account — there is no endpoint through which one account can read or delete another.
No system is perfectly secure, and we do not claim otherwise.
11. Your choices
- Edit or replace your Master Resume, or delete generated documents, at any time.
- Delete every demographic answer saved on your device, from Privacy in the app’s settings.
- Delete your entire account, as described above.
- Manage or cancel your subscription through Apple or Google.
Depending on where you live you may have further rights over your personal data, such as access, correction, or objection.
NOT YET WRITTEN — this section is incompleteThe address for privacy questions and data-rights requests, and whether a DPO must be named. May be the same as the support channel or may need to be separate; that depends on the entity and on which privacy regimes apply.12. Age
NOT YET WRITTEN — this section is incompleteThe minimum age for an AutoStant account, and the corresponding store age ratings. The app assumes adult job seekers but states no policy anywhere, and both stores ask for one explicitly.13. Changes to this policy
If we change how AutoStant handles your information, we will update this page and the date at the top of it. Where a change is significant, we will tell you in the app rather than relying on you to notice.
14. Contact
Questions about this policy, or about your data, should go to [TO BE SUPPLIED — The address for privacy questions and data-rights requests, and whether a DPO must be named.].