Privacy Policy
GoMatchToApply asks for a resume before it can do anything useful, which makes this the page to read first. What is collected, who else sees it, how long it is kept, and how to get it all back or delete it.
In effect from 30 August 2026.
1. The short version
- Your resume and answers are used to find and prepare your applications, and for nothing else.
- GoMatchToApply does not sell your data, and does not share it for advertising.
- There are no third-party analytics or advertising trackers on this site. None.
- The only cookies are the ones that keep you signed in and protect the forms you submit.
- You can export everything, or delete everything, from your privacy settings at any time.
2. What is collected
Your account. Email address, display name, and a password hash — or, if you sign in with Google or Facebook, the identifier and email address they return. GoMatchToApply never receives your password for those services.
Your resume and profile. The files you upload, the text extracted from them, the structured profile built from that text, your corrections to it, your job preferences, and the reusable answers you save for application questions.
Sensitive answers. Some employer questions ask about work authorization, sponsorship, security clearance, or voluntary demographic information. GoMatchToApply stores these only when you enter and confirm them yourself. They are never generated, inferred, or filled in with a default, and they are redacted from logs before anything is written.
Your applications. The openings you saved, the scores and explanations produced for them, the materials drafted, the state of each application, and a record of what the extension filled on each form.
Mail sent to your applying address. Where you use the address GoMatchToApply issues you to apply with, messages sent to it are received and stored so they appear in your inbox.
Operational records. Request logs, an audit log of security-relevant actions on your account, and counters used to enforce rate limits. Rate-limit counters identify a caller by a hash, not by a readable identifier.
3. What it is used for
- Matching openings to your background, and showing you the reasoning behind each score.
- Drafting resumes, cover letters and answers that cite evidence from your own history.
- Filling supported employer forms, and recording what was filled.
- Running your account: signing in, verifying your address, notifying you, taking payment.
- Keeping the service up and safe — rate limits, abuse prevention, and debugging failures.
GoMatchToApply does not use your material to train models, does not sell it, and does not share it with anyone except the processors listed below and the employers you choose to apply to.
4. Automated processing, and what reaches the model
Scoring and drafting are done by a language model run by a third party. What is sent is the resume text and job description needed to answer that request. Your contact details are not sent, and a sensitive answer is sent only when it is required to fill a specific field on a form you have already approved.
A model produces the first draft; you decide what is used. Nothing drafted reaches an employer without passing in front of you, and no automated decision is made about you that has a legal or similarly significant effect.
5. Who else processes it
GoMatchToApply runs on services operated by other companies. Each receives only what its job requires:
| Processor | What it does | What reaches it |
|---|---|---|
| Vercel | Hosting for the web application | Anything in a request, in transit. Request logs. |
| Convex | Database and file storage | Account records, profile and answers, resumes and generated documents, applications, forwarded mail. |
| DeepSeek | The model that scores openings and drafts materials | Resume text and job descriptions for the request being answered. Never your contact details, and never a sensitive answer unless it is required to fill a field you have approved. |
| Resend | Outbound email — verification, password reset, notifications | Your email address and the message being sent. |
| Cloudflare | Receiving mail sent to the address you apply with | Messages employers and recruiters send to that address. |
| Stripe | Payments and subscription management | Your email address and payment details. Card numbers go to Stripe directly and never reach GoMatchToApply. |
This list changes when the product does. It is the current one, not an illustrative one.
6. Cookies
Three, all necessary, none used for tracking: a session cookie that keeps you signed in, a token that protects forms against cross-site submission, and a short-lived cookie used during a Google or Facebook sign-in to match the response to the request that started it.
There is no analytics cookie, no advertising cookie, and no third-party script that sets one. That is why this site has no cookie banner asking for consent it does not need.
7. The browser extension
The extension runs on employer application pages so it can fill them. On those pages it reads the form — the fields, their labels, and their validation messages — and reports what it filled and what it could not. It does not read pages outside the employer application sites it supports, and it holds a short-lived token scoped to its own API rather than your website session.
It never captures a password you typed. There is no field in GoMatchToApply that accepts one and no code that reads one from a page.
8. How long things are kept
| Data | Kept for |
|---|---|
| Uploaded resumes and generated documents | Until you delete them, or 24 months after the account is closed |
| Automation run logs | 30 days |
| Application events | Life of the account — the tracker is built from them |
| Audit logs | 24 months |
| AI request and response logs | 30 days, with personal details redacted as they are written |
| Billing records | As long as tax and accounting law requires, after everything else is deleted |
9. Your rights
From your privacy settings you can export everything GoMatchToApply holds about you as a machine-readable archive, or delete your account and its contents. Deletion removes your documents, profile and answers, and keeps only the billing records tax and accounting law requires.
Depending on where you live you may also have the right to correct your data, object to or restrict certain processing, or complain to a data protection authority. Ask at support@rolelane.io and we will action it.
10. Security, stated honestly
Traffic is encrypted in transit. Passwords are stored hashed. The password GoMatchToApply generates for an employer portal is encrypted with a key held in the application environment and never sent to the database, so a disclosure of the database does not disclose those credentials. Security-relevant actions are recorded in an audit log.
One limitation worth naming rather than glossing: that encryption key is held in the application environment rather than in a managed key service, so it has none of the rotation and access logging a managed service would provide. It is a known gap, and it is recorded as one.
No system is perfectly secure. If you find a vulnerability, please report it to security@rolelane.io rather than disclosing it publicly, and we will work with you on it.
11. Children
GoMatchToApply is not for anyone under 18 and does not knowingly collect their data. If you believe a child has created an account, tell us and it will be removed.
12. Where data is held
The processors above operate internationally, so your data may be processed outside the country you live in, including in the United States. Where the law requires a transfer mechanism for that, we rely on the terms in our agreements with each processor.
13. Changes, and who to ask
Material changes to this policy will be sent to the email address on your account before they take effect. GoMatchToApply is the controller of the data described here. Questions, requests and complaints go to support@rolelane.io.