Privacy Policy
Last updated · September 2026
RabbitApply helps you find UK jobs and prepare applications for them. This notice explains what personal data we collect, why, what we do with it, who else sees it, and the rights you have over it. It is written for the UK GDPR and the Data Protection Act 2018. We never sell your data.
Who we are
The data controller is Biswa Rout, a sole trader based in the United Kingdom, trading as RabbitApply. If you have a question about this notice, or want to exercise any of the rights below, contact privacy@rabbitapply.co.uk. There is no data protection officer; that address reaches the controller directly.
RabbitApply is a UK-only service. It searches UK job postings, reads salaries in pounds, and produces CVs to UK conventions. It is not built for job searches in other countries.
Who can use it
Anyone can sign in with Google, but the service itself is currently limited to invited accounts while it is being built:
- Invited accounts reach the whole app - the dashboard, your CVs, the roles we find. Everything in this notice applies to you.
- Everyone else signs in successfully but has no access to the app. You will see a screen saying so, and the option to join a waitlist. Nothing else in this notice applies to you unless you join, because we hold nothing else about you: only the account your sign-in created, which you can delete from that same screen at any time.
The waitlist
If you sign in without an invite, we offer to tell you when RabbitApply opens to new users. It is an offer, not something that happens automatically, and the difference matters:
- Lawful basis: consent. Nothing is stored and nothing is sent unless you tick the box and press the button. We record the exact wording you were shown, a version for that wording, when you agreed and where - so we can show precisely what you consented to.
- What we store: your name and email address, the record of that consent, and the little we need to run the list - whether you have unsubscribed, and whether your introduction has been sent. No IP address, no browsing behaviour, no advertising identifiers.
- What we send: one introduction email when you join, and one more when the app opens up. Nothing else, ever, and your address is never passed to anyone.
- Unsubscribing: every one of those emails carries a one-click unsubscribe that works without signing in and takes effect immediately. Unsubscribing is suppression - we keep your address on file for the single purpose of honouring that opt-out. If you would rather we deleted it outright, ask us and we will.
- Withdrawing consent is as easy as giving it, and withdrawing it does not affect anything we did while it was valid.
Declining stores no waitlist entry and no consent record. Your sign-in account itself remains - signing in with Google created it - until you delete it. If you change your mind about the waitlist, the offer is there again the next time you sign in.
What we collect, why, and on what legal basis
Everything below is data you give us, or that the service produces from it. We do not buy data about you, and we do not track you across other websites.
| What | Why | Legal basis |
|---|---|---|
| Your Google account details - name, email address, profile picture | To create your account and sign you in | Contract - there is no account without it |
| Your CV - the structured fields you enter or import: contact details, summary, roles, dates, bullets, skills, education | To score jobs against your experience and write tailored applications | Contract - it is the service |
| Your search preferences - job titles, locations and remote rules, salary floor, and your answer bank | To decide which jobs to look for, and which to show you | Contract |
| Jobs we find for you - the posting, its score, your status on it, and any tailored CV or cover letter generated for it | To run your board and let you come back to what we prepared | Contract |
| Email records - that we sent you a new-roles email, and when | To avoid sending you the same roles twice, and to tell whether sending is working at all | Contract, and our legitimate interest in a service that works |
| An encrypted Gmail token, only if you connect Gmail | To read job-related email and update your job statuses | Consent - entirely optional, withdrawable at any time |
| Your waitlist entry, only if you ask to join - your name and email, the consent record, and whether you have unsubscribed | To tell you when RabbitApply opens to new users, and to prove you asked us to | Consent - given by ticking an unticked box, withdrawable in one click |
| Operational logs - pipeline runs, errors and service health | To keep the service up and diagnose failures | Legitimate interest in security and reliability |
Your CV file is not stored
When you create a CV you may upload a PDF or Word file to save yourself the typing. That file is read in memory, turned into the structured fields you then see and edit, and discarded. We never keep the file, and nothing is saved at all until you press save. What we store is the fields - the ones on your screen, as you left them.
Signing in with Google
We use Google Sign-In to authenticate you. It requests basic profile information only - your name, email address and profile picture (the standard openid, email and profile scopes). Signing in does not give us access to your emails, files or contacts.
The optional Gmail connection
You may separately connect Gmail so RabbitApply can keep your application statuses up to date. This is a different consent from signing in, asked for separately, and the service works without it. If you connect it:
- We request Google's read-only Gmail scope (gmail.readonly) - we can read messages, but never send, modify or delete anything.
- We look only at job-related email (application confirmations, recruiter replies, interview invitations and rejections) to update the status of jobs already on your board.
- We store an encrypted access token, not your emails. You can disconnect at any time from Settings, which deletes the token. Because our Google app runs in testing mode, you will be asked to re-confirm access roughly once a week.
RabbitApply's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Automated scoring
We score each job out of 10 against your CV automatically, using a large language model, and we draft application documents the same way. That decides what we show you and what we prepare. It is not a decision about you with legal or similarly significant effects: no employer sees the score, nothing is submitted for you, and you can act on any job whatever we scored it. Scores and drafts can be wrong, which is why you review everything before it goes anywhere.
Who else processes your data
We use the sub-processors below. Each is bound to process your data only on our instructions.
| Who | What they do | Where |
|---|---|---|
| Supabase | Database and authentication - where your data lives | United Kingdom (AWS London) |
| Vercel | Hosts the website and its API | Global edge network, primarily EU and US |
| OpenAI | Scores jobs, turns an uploaded CV file into fields, and writes the tailored CVs and cover letters | United States |
| Trigger.dev | Runs the scheduled discovery and deletion tasks | United States |
| Resend | Sends our email - new roles, deletion confirmations | United States |
| Signs you in, and provides Gmail access if you connect it | Global | |
| Reed | The job board we search. It receives search terms - job titles and locations - never your CV or your identity | United Kingdom |
| Apify | Runs the search that reads the Hiring Cafe job board on our behalf. It receives search terms - job titles and locations - never your CV or your identity | United States |
| Hiring Cafe | A job board we search, through Apify above. It receives the same search terms and nothing else | United States |
As we add job channels this list grows, and this page is updated with them.
Data leaving the UK
Your account and everything attached to it is stored in the United Kingdom. Some processing happens abroad, and it matters enough to say plainly: your CV and the job descriptions we match it against are sent to OpenAI in the United States every time we score a job or generate a document. Our email and scheduling providers are US-based too, as are the job-search services above that receive your search terms. Those are international transfers, made under the UK Addendum to the European Commission's standard contractual clauses, or another lawful transfer mechanism where the provider offers one. If you would rather your CV were not processed in the US, this service is not for you.
How long we keep it
- Your account and its data - for as long as your account exists. There is no automatic expiry: we would rather you decided than have your job history vanish on a timer.
- When you delete your account - your profile, CVs, jobs, generated documents, answer bank, email records, waitlist entry and consent record, and sign-in are permanently deleted. There is no backup copy we can restore from.
- The Gmail token - deleted the moment you disconnect.
- A waitlist entry - up to 12 months from the date you joined, then deleted automatically along with its consent record. This one does expire on a timer, deliberately: consent to be told about something goes stale, and a marketing list kept forever is not one you ever really agreed to. Deleting your account removes it straight away.
- Operational logs - kept briefly for debugging, and they do not contain your CV text.
Security
Your data is isolated per user and that isolation is enforced at the database itself, with row-level security, so one account cannot reach another's rows. Tokens are encrypted at rest, and traffic is over HTTPS. This is a beta run by one person, so we will not claim a formal certification we do not hold.
What we never do
- We never submit an application on your behalf - you always click submit yourself.
- We never sell, rent or share your personal data.
- We never show your CV to employers, recruiters or job boards.
- We never post, send or alter anything in your Gmail account.
Your rights
Under UK data protection law you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where consent is the basis - which means the Gmail connection and the waitlist.
- Access and correction are self-service: your CV, preferences and answer bank are editable in the app at any time.
- Erasure is self-service too. Delete your account from the bottom of Settings - or, if your account is on the waitlist rather than in the app, from the waitlist screen itself. It permanently removes your profile, your CVs, every job we found for you, your answer bank, any waitlist entry and its consent record, and your sign-in; it cannot be undone; we keep no copy to restore from; and we email you to confirm once it is done.
- Withdrawing waitlist consent is the unsubscribe link in any of those emails: one click, no sign-in, immediate. That suppresses further email but keeps your address on file to honour the opt-out - which is not the same as erasure. Ask us and we will delete it outright instead.
- Portability, or anything else - email privacy@rabbitapply.co.uk and we will respond within one month.
Complaints
If you think we have handled your data badly, please tell us first at privacy@rabbitapply.co.uk. You also have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. You do not have to come to us first.
Cookies
We set only what signing in requires: a session cookie so you stay logged in, plus small preferences kept in your own browser (the filters and sort you last used). No advertising cookies, no analytics, nothing that follows you to other sites.
Changes to this policy
We may update this notice as the product evolves. Material changes will be reflected here with a new "last updated" date.