Legal
Privacy Policy
Effective: August 2026
Overview
Xselar ("we", "us", "our") provides an AI-powered job matching and career guidance platform. We are the data controller for the personal data described here. This policy explains what we collect, how we use it, and your rights regarding it.
Questions, or want to exercise a data right? Email privacy@apply.xselar.com.
Data we collect
- Resume & profile data — Your resume text, work experience, skills, and the preferences you set during onboarding. Used to generate and rank job recommendations.
- Feedback signals — Thumbs up/down reactions, clicks, and application events. Used to improve match quality over time.
- Job interaction data — Which roles you view, save, or apply to. Used to personalize future recommendations.
- Contact information — Your email address, used as your account identifier and for sending match digests.
- Account & sign-in data — Your password stored as a one-way hash (never in readable form), and the signed token that keeps you logged in.
- Billing data — On a paid plan: your plan, subscription status, and the customer reference our payment processor gives us. We never receive or store your full card number.
The Xselar Apply browser extension
The extension fills job application forms for you on employers' websites. It runs on the page in order to do that, so the honest boundary is not what it can see — it's what leaves your browser. Here is everything that does:
- Nothing, unless you use it — Finding a form so it can offer to fill it happens entirely on your device. If you never press "Apply with Xselar", nothing about that page is sent to us — not the employer, not the role, not the address.
- A usage count — When it does fill a form we record how many fields it found and filled, which application platform the form runs on (Workday, Greenhouse, …), and the extension version. This is how paid limits are counted. It carries no company, job title, web address or question text — those columns do not exist in our database.
- Questions it cannot answer from your profile — If the form asks something our matching rules can't map, the question text is sent to us and answered from your saved profile. Answers to stable factual questions ("are you legally authorised to work in the US?") are saved to your profile so the same question is free next time.
- Drafted answers, with the role they were for — When you ask Xselar to draft an open-ended answer ("why do you want to work here?"), the question, the job title and the company are sent, because the answer is worthless without them. We keep the drafted answer alongside that role so it can be reused and improved on your next application.
- A record of the application itself — When you press “Apply with Xselar” we record that you applied: the employer, the role, the address of the form and the date, so your Applications page can track it. This is the one thing here that names an employer and is linked to your account. It happens on any site where you invoke the extension, and only where you invoke it.
- On by default, and yours to switch off — Application tracking is on when you install the extension, and the first-run notice says so. You can turn it off any time in Settings. With it off we stop recording employers, roles and addresses, and we drop the employer attribution from answers we draft for you.
- What remains if you switch it off — The usage count above, because paid limits are counted from it. It carries no employer, role or address — a number and a date.
- Which questions are hard to fill — about the form, not about you — When the extension fills a form we record the employer, the application platform, and which of that form’s questions we managed to fill, so we can fix the ones we get wrong. These records are about the published form itself: they are stored with no link to your account, hold none of your answers, and are running totals rather than a log of individual visits — so they cannot show that you, or anyone, applied anywhere.
What it never does: watch what you do on an employer's site beyond the form it filled, report your browsing, or record a page you didn't ask it to work on. Your answers to voluntary equal-opportunity questions are filled directly into the employer's form and are never sent to our AI assistant.
Forwarding recruiting email to Xselar
You can create a private forwarding address and send us replies from employers, so your application tracker updates itself. It is off until you create that address, and deleting the address turns it off — mail sent afterwards is discarded unread. We never connect to your inbox and can only ever see a message you forward to us yourself.
- We read the whole email, and keep almost none of it — The message is read once, in memory, to work out what it means — then discarded. We do not store the subject, the body, the sender, or any attachment, and we keep no copy of your correspondence.
- What we keep — The outcome (interview, offer or rejection), when it arrived, and — when we can't tell which of your applications it refers to — the employer and job title named in it, so we can ask you.
- It can only ever move an application forward — A forwarded email can mark an application as reaching interview, offer or rejected. It can never mark something as applied — only you and the extension can do that.
- We ask rather than guess — If you have more than one open application at that employer, or none, we don't choose one. The outcome waits on your Applications page until you say which it belongs to, and you can dismiss it instead.
How your data is processed
Xselar is built on AI. Your resume, profile and the questions you ask are read by AI systems in order to rank jobs against your background, explain why a role fits, and draft answers to application questions. Some of those systems are run by service providers on our behalf, under contract.
- It ranks and drafts; you decide — AI does not make final decisions about you. It orders jobs and suggests wording. Whether to apply, and what to send, is always yours.
- Not used to train anyone else’s models — Our providers are contractually barred from using your data to train their models, and we do not use your resume to train models without your explicit consent.
- Other providers, by category — We also use service providers for hosting and data storage, email delivery, payments, and content delivery. They may access your data only as needed to perform those services for us.
Payments
Paid plans are billed through Stripe. Your full card number never reaches our servers — it is entered directly with Stripe, which is certified to handle it. We store only your plan, your subscription status, and the customer reference Stripe gives us. Stripe’s own handling is described at stripe.com/privacy.
How we use your data
We use your data solely to provide and improve the Xselar service: generating match scores, personalizing recommendations, and sending email digests. We do not sell your data to third parties. We do not use your resume to train AI models without explicit consent.
Data retention
Your profile, resume and feedback are kept while your account is active. Application records are kept for 24 months so your tracker stays useful, then removed. Usage counts that back paid limits are kept as billing records. Forwarded emails are never stored at all — only the outcome they resolved to, alongside the application it belongs to.
You can delete an individual application from your Applications page at any time. If you delete your account we remove your profile, resume, feedback and application records within 5 business days.
Your rights
You can request a copy of your data, correct inaccurate information, export it, or ask us to delete it — at any time, and without giving a reason. Email privacy@apply.xselar.com and we will respond within 30 days.
If you are in the EEA or UK, you have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and you may complain to your local supervisory authority. If you are a California resident, you have the rights to know, delete and correct under the CCPA/CPRA, and the right to opt out of sale or sharing — we do not sell or share your personal information, so there is nothing to opt out of.
Security
Your data is encrypted in transit and at rest. Passwords are stored as one-way hashes and never in readable form, sessions use signed tokens, and access to production systems is limited to those who need it. No service can promise perfect security, and we do not — but if a breach ever affects your data we will tell you, and any regulator we are required to notify.
Cookies & local storage
Xselar uses browser local storage to maintain your session (your user ID and email). We do not use third-party advertising or tracking cookies.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice before they take effect.
