Privacy notice
This notice covers the four anonymous ApplyArc career tools delivered as an OpenAI plugin in ChatGPT and Codex. ApplyArc does not require an account, save tool inputs or results, add browser tracking, or use submitted content for advertising.
Who is responsible
ApplyArc Ltd is the data controller. It is registered in England and Wales (Company Number 16619519) and with the Information Commissioner's Office (ICO Reference ZC027406). Contact privacy@applyarc.com.
Data and purpose
The plugin receives only the content needed for the tool you choose: a job posting, resume or CV text, an optional tone or hiring manager name, and, for resume scoring, one optional digital PDF or DOCX resume. A file request also includes temporary file metadata such as its name, type, size, OpenAI file reference and download URL.
ApplyArc processes that content to provide the analysis, score, grounded cover letter or interview preparation you requested. It processes minimal network, security and platform metadata to deliver, protect and monitor the service. It does not build user profiles, assign a persistent user identifier or reconstruct the wider conversation.
Attached resume files
OpenAI stores the file and supplies a temporary HTTPS download URL for the selected tool call. Microsoft Azure AI Document Intelligence extracts its text. ApplyArc requests early deletion of the analysis data; Microsoft deletes the submitted document and result within 24 hours at the latest. ApplyArc keeps neither the file nor its extracted text after the call finishes.
Recipients
- OpenAI sends the selected inputs, receives the result, and may retain the conversation or widget state under your OpenAI settings and data controls.
- Microsoft Azure Container Apps hosts the runtime.
- Microsoft Azure OpenAI processes the model request.
- Microsoft Azure AI Document Intelligence extracts text only when you attach a supported resume file.
- Microsoft Azure platform services deliver and secure network requests and hold limited reliability and security diagnostics.
Retention
- The ApplyArc runtime does not persist tool inputs or results.
- Custom per-tool usage telemetry is disabled on the public production endpoint.
- Microsoft retains standard Azure platform metrics, such as health, latency, failure and scaling values, for 93 days. These pre-aggregated numeric metrics do not contain job or CV text, file contents, quotes or tool output.
- Career MCP service logs and historical aggregate operational rows in the Azure monitoring workspace expire after 30 days. ApplyArc does not write job or CV text, file contents, quotes or tool output into those records.
-
Microsoft's built-in
UsageandAzureActivityworkspace metadata tables, when populated, keep data for at least 90 days under Azure defaults. They describe Azure usage and resource-management activity; the app does not write submitted job or CV text or tool output into them. -
Azure OpenAI requests set
store: falseto disable Responses API application-state storage for the request. This does not disable Microsoft's separate abuse-monitoring process. Flagged prompts and completions may be temporarily retained for human review. Microsoft's current public documentation does not publish a fixed maximum; it states that this data is kept only as long as necessary for abuse detection, investigation and service protection under Microsoft's Product Terms and Data Protection Addendum.
Where processing happens
The Azure OpenAI resource is in Sweden Central, but its Global Standard deployments may route inference to other Microsoft datacentres for availability and performance. Microsoft states that abuse review for this EEA resource is carried out by authorised employees located in the EEA. OpenAI processes plugin data under OpenAI's own terms and privacy controls.
What the plugin returns
Results contain the requested guidance and the exact quotes, offsets and evidence IDs needed to connect claims to supplied text. They do not include ApplyArc account, session, trace, request, timestamp, model or token data.
Restricted data
Do not provide passwords, access keys, payment card details, government identifiers or health records. ApplyArc refuses detected credentials, payment cards, government identifiers and common patient record identifiers before a model call. Detection cannot catch every sensitive document, so do not submit patient records or other special category data. Describing your own professional experience is fine.
Your controls and rights
You choose what the plugin receives. You can stop using it and delete the conversation in ChatGPT or Codex. ApplyArc cannot retrieve or delete that conversation because the plugin has no account link and does not retain its own copy.
Depending on your location, you may have rights to access, correct, erase, restrict, object to or receive personal data. Email privacy@applyarc.com. ApplyArc may need enough information to verify and locate data, but cannot provide data it never retained. UK users can also complain to the Information Commissioner's Office.