Aplyr Legal
This policy explains what personal data we collect, why we collect it, how it is used, who we share it with, how long we keep it, and the rights you have — including under the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Nigeria Data Protection Act 2023 (NDPA).
Account & identity: full name; email address; password (hashed — never stored in plain text); Google account data if you sign in with Google (name, email; the Google profile photo is not used — we generate an avatar); phone number (optional); community handle (a public pseudonym); avatar seed.
Academic & application profile: GPA, major, graduation year, application cycle, degree sought, preferred countries, priorities, country/state of residence, standardized test scores (e.g., GRE, GMAT, TOEFL, IELTS, SAT, ACT — name and score).
Application tracker data: schools and programs you track — university, program, degree, department, country, location type, term, format, program length, application deadlines, application/decision/funding statuses, offer types, application fee amounts, fee-waiver status, professor-of-interest name/email and contact status, program and portal URLs, free-text notes, requirements checklists, custom flow diagrams, shortlisted institutions/professors, and time spent per school entry.
Uploaded documents ("Vault"): files you upload — CVs/resumes, statements of purpose, letters of recommendation, personal statements, transcripts, writing samples, and any other file types. Files are stored with our file-storage provider (Cloudinary) under a per-user folder; we retain file names, types, sizes, and URLs.
AI features content: chat messages and AI responses (full transcripts are stored), gap-analysis text/document contents, CV text and research parameters used for school pairing and professor matching, and AI-generated results (match scores, analyses, requirements, recommendations).
Browser-extension autofill profile ("Autofill Profile"): the most extensive set of data we store, used to autofill application portals. If you use the extension you may provide:
Community content: posts (title, body, images, optional document attachments), comments/replies, votes, saved posts, reports (reason and optional details), best-answer marks, and moderation outcomes. Your community handle and generated avatar identify you publicly.
Payments: we do not collect card details. Payment data (plan, interval, currency, amounts, provider customer/subscription references, card-expiry notifications) is processed and relayed by our payment processor, Paystack.
Communications: notification preferences (push/email/digest on/off, reminder lead days), email delivery logs, and the content of emails we send you (deadlines, digest statistics, plan notices).
We process personal data for the following purposes. The legal bases rely on (where applicable): contract (performance of the service agreement / Terms of Use), legitimate interests (operating, securing, and improving the Service), consent (marketing communications, special-category data, optional features), and legal obligation.
| Purpose | Data categories | Proposed legal basis |
|---|---|---|
| Account creation, authentication, and security | Account, session, IP/UA | Contract; legitimate interest (security) |
| Providing the core tracker (schools, requirements, deadlines, documents, exports) | Tracker data, documents | Contract |
| Personalizing and providing AI features (chat, pairing, professor matching, gap analysis, requirements generation, extraction) | AI content, profile, documents, CVs, page extracts | Contract; legitimate interest |
| Autofill via browser extension | Autofill Profile (incl. special categories) | Contract; explicit consent for special categories |
| Notifications and reminders (deadline, trial, inactivity, weekly digest) | Notification prefs, tracker data, contact | Consent (preferences); legitimate interest (transactional) |
| Transactional email (OTP, password reset, receipts, payment notices, admin broadcasts) | Contact, account, payment | Contract; legal obligation |
| Payments and billing | Payment records, subscription | Contract; legal obligation (tax/financial records) |
| Community and moderation (posts, comments, flags, AI moderation, bans) | Community content, flags, moderation metadata | Contract; legitimate interest (safe community); legal obligation |
| Abuse prevention and security (rate limiting, IP bans, fraud detection) | IP, device tokens, activity logs | Legitimate interest |
| Analytics and product improvement (time tracking, usage, AI token metering) | Usage data, activity logs | Legitimate interest |
| Legal compliance and audits | Activity logs, financial records | Legal obligation |
| Data-subject rights requests and account deletion | All data | Legal obligation |
We retain personal data only as long as necessary for the purposes in Section 4, applying the periods below. Where no specific period is stated, we retain data for the duration of your account plus a short period unless a longer period is required by law.
| Data | Retention (as implemented) |
|---|---|
| Session tokens / JWTs / auth cookies | 7 days |
| OTP codes, password-reset links | 10 minutes / 1 hour |
| Purchase-intent, OAuth-state, invite cookies | 10 minutes |
| Offline edit queues (IndexedDB) | discarded when older than 24 hours |
| Page-extraction cache (URL-keyed facts) | refreshed after 7 days |
| Push device tokens | deleted after 90 days inactive |
| Stale pairing/professor jobs | marked failed after 24 hours |
| Email dedup/rate-limit logs | 5-day window (log rows persist) |
| Free trial | 14 days |
| Account after deletion request | permanent deletion requested within 30 days |
| AI chat transcripts, CV text, activity logs, token usage, time heartbeats, autofill profile, documents on Cloudinary | Retained for the life of your account; data older than 1 year is automatically purged on a rolling basis. All data is deleted when your account is deleted. |
Deletion requests are processed as described in the Terms of Use (Section 5) and Section 11 below.
We share personal data only with the following categories of recipients, as needed to operate the Service. All are contractually bound as data processors (or independent controllers where noted) and are required to implement appropriate technical and organizational measures.
| Recipient | Role / what data | Purpose | Location |
|---|---|---|---|
| Google (Gemini AI, Google Search, OAuth, Calendar, College Scorecard) | Processor / separate controller | AI generation, web research, sign-in, calendar sync, enrichment | USA |
| Cloudinary | Processor | File storage (documents, images, avatars) | USA |
| Resend | Processor | Transactional and marketing email delivery | USA |
| Paystack | Processor (separate controller for card data) | Payment processing, subscriptions, billing portal | Nigeria |
| Upstash (Redis) | Processor | Caching, rate limiting | USA/EU |
| Inngest | Processor | Background job orchestration | USA |
| Firebase (Google) | Processor | Push notifications (FCM) | USA |
| Vercel | Processor | Hosting and infrastructure | USA |
| OpenAlex, Semantic Scholar, ROR, Wikidata, US College Scorecard | Independent controllers (queries only) | Research-data enrichment (institution/professor facts) | Various |
| Internal personnel (Admins, Moderators) | Internal | Support, moderation, enforcement, analytics — access limited by role-based access control and logged | — |
Community visibility. Content you publish in the community is visible to other users (Section 9). AI-generated school matches and your community handle/avatar may be visible to other users on public institution pages.
We do not sell personal data, and we have no knowledge of selling or sharing personal information of minors under 16 (CCPA). We do not engage in cross-context behavioral advertising.
Send a request to support@useaplyr.com with the subject "Privacy Request". We will verify your identity (we may ask for information matching your account, and may use two-factor verification) and respond within the time required by law (typically 30 days under GDPR/NDPA; 45 days under CCPA, extendable). You may authorize an agent to make requests on your behalf. We do not charge a fee except where the law permits (e.g., manifestly unfounded or excessive requests).
We implement appropriate technical and organizational measures to protect personal data, including:
While we take reasonable measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal-data breach, we will: (a) assess risk to data subjects; (b) where required, notify the relevant supervisory authority within 72 hours (GDPR) or as required by applicable law (NDPC 72-hour notification under NDPA); (c) notify affected individuals without undue delay where the breach creates a high risk to their rights and freedoms; and (d) document the breach and remedial measures.
We will post any changes on this page and, where required, notify you by email or in-app notice before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.