Legal

Privacy Policy

Effective: August 2026

Overview

Xselar ("we", "us", "our") provides an AI-powered job matching and career guidance platform. We are the data controller for the personal data described here. This policy explains what we collect, how we use it, and your rights regarding it.

Questions, or want to exercise a data right? Email privacy@apply.xselar.com.

Data we collect

  • Resume & profile dataYour resume text, work experience, skills, and the preferences you set during onboarding. Used to generate and rank job recommendations.
  • Feedback signalsThumbs up/down reactions, clicks, and application events. Used to improve match quality over time.
  • Job interaction dataWhich roles you view, save, or apply to. Used to personalize future recommendations.
  • Contact informationYour email address, used as your account identifier and for sending match digests.
  • Account & sign-in dataYour password stored as a one-way hash (never in readable form), and the signed token that keeps you logged in.
  • Billing dataOn a paid plan: your plan, subscription status, and the customer reference our payment processor gives us. We never receive or store your full card number.

The Xselar Apply browser extension

The extension fills job application forms for you on employers' websites. It runs on the page in order to do that, so the honest boundary is not what it can see — it's what leaves your browser. Here is everything that does:

  • Nothing, unless you use itFinding a form so it can offer to fill it happens entirely on your device. If you never press "Apply with Xselar", nothing about that page is sent to us — not the employer, not the role, not the address.
  • A usage countWhen it does fill a form we record how many fields it found and filled, which application platform the form runs on (Workday, Greenhouse, …), and the extension version. This is how paid limits are counted. It carries no company, job title, web address or question text — those columns do not exist in our database.
  • Questions it cannot answer from your profileIf the form asks something our matching rules can't map, the question text is sent to us and answered from your saved profile. Answers to stable factual questions ("are you legally authorised to work in the US?") are saved to your profile so the same question is free next time.
  • Drafted answers, with the role they were forWhen you ask Xselar to draft an open-ended answer ("why do you want to work here?"), the question, the job title and the company are sent, because the answer is worthless without them. We keep the drafted answer alongside that role so it can be reused and improved on your next application.
  • A record of the application itselfWhen you press “Apply with Xselar” we record that you applied: the employer, the role, the address of the form and the date, so your Applications page can track it. This is the one thing here that names an employer and is linked to your account. It happens on any site where you invoke the extension, and only where you invoke it.
  • On by default, and yours to switch offApplication tracking is on when you install the extension, and the first-run notice says so. You can turn it off any time in Settings. With it off we stop recording employers, roles and addresses, and we drop the employer attribution from answers we draft for you.
  • What remains if you switch it offThe usage count above, because paid limits are counted from it. It carries no employer, role or address — a number and a date.
  • Which questions are hard to fill — about the form, not about youWhen the extension fills a form we record the employer, the application platform, and which of that form’s questions we managed to fill, so we can fix the ones we get wrong. These records are about the published form itself: they are stored with no link to your account, hold none of your answers, and are running totals rather than a log of individual visits — so they cannot show that you, or anyone, applied anywhere.

What it never does: watch what you do on an employer's site beyond the form it filled, report your browsing, or record a page you didn't ask it to work on. Your answers to voluntary equal-opportunity questions are filled directly into the employer's form and are never sent to our AI assistant.

Forwarding recruiting email to Xselar

You can create a private forwarding address and send us replies from employers, so your application tracker updates itself. It is off until you create that address, and deleting the address turns it off — mail sent afterwards is discarded unread. We never connect to your inbox and can only ever see a message you forward to us yourself.

  • We read the whole email, and keep almost none of itThe message is read once, in memory, to work out what it means — then discarded. We do not store the subject, the body, the sender, or any attachment, and we keep no copy of your correspondence.
  • What we keepThe outcome (interview, offer or rejection), when it arrived, and — when we can't tell which of your applications it refers to — the employer and job title named in it, so we can ask you.
  • It can only ever move an application forwardA forwarded email can mark an application as reaching interview, offer or rejected. It can never mark something as applied — only you and the extension can do that.
  • We ask rather than guessIf you have more than one open application at that employer, or none, we don't choose one. The outcome waits on your Applications page until you say which it belongs to, and you can dismiss it instead.

How your data is processed

Xselar is built on AI. Your resume, profile and the questions you ask are read by AI systems in order to rank jobs against your background, explain why a role fits, and draft answers to application questions. Some of those systems are run by service providers on our behalf, under contract.

  • It ranks and drafts; you decideAI does not make final decisions about you. It orders jobs and suggests wording. Whether to apply, and what to send, is always yours.
  • Not used to train anyone else’s modelsOur providers are contractually barred from using your data to train their models, and we do not use your resume to train models without your explicit consent.
  • Other providers, by categoryWe also use service providers for hosting and data storage, email delivery, payments, and content delivery. They may access your data only as needed to perform those services for us.

Payments

Paid plans are billed through Stripe. Your full card number never reaches our servers — it is entered directly with Stripe, which is certified to handle it. We store only your plan, your subscription status, and the customer reference Stripe gives us. Stripe’s own handling is described at stripe.com/privacy.

How we use your data

We use your data solely to provide and improve the Xselar service: generating match scores, personalizing recommendations, and sending email digests. We do not sell your data to third parties. We do not use your resume to train AI models without explicit consent.

Data retention

Your profile, resume and feedback are kept while your account is active. Application records are kept for 24 months so your tracker stays useful, then removed. Usage counts that back paid limits are kept as billing records. Forwarded emails are never stored at all — only the outcome they resolved to, alongside the application it belongs to.

You can delete an individual application from your Applications page at any time. If you delete your account we remove your profile, resume, feedback and application records within 5 business days.

Your rights

You can request a copy of your data, correct inaccurate information, export it, or ask us to delete it — at any time, and without giving a reason. Email privacy@apply.xselar.com and we will respond within 30 days.

If you are in the EEA or UK, you have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and you may complain to your local supervisory authority. If you are a California resident, you have the rights to know, delete and correct under the CCPA/CPRA, and the right to opt out of sale or sharing — we do not sell or share your personal information, so there is nothing to opt out of.

Security

Your data is encrypted in transit and at rest. Passwords are stored as one-way hashes and never in readable form, sessions use signed tokens, and access to production systems is limited to those who need it. No service can promise perfect security, and we do not — but if a breach ever affects your data we will tell you, and any regulator we are required to notify.

Cookies & local storage

Xselar uses browser local storage to maintain your session (your user ID and email). We do not use third-party advertising or tracking cookies.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice before they take effect.