Skip to main content

Privacy Policy

Last updated: March 2026

1. What data we collect

When you use Aplion, we collect the following information:

  • Email address (for account creation and authentication)
  • Job application data you enter (company names, job titles, stages, notes, URLs)
  • CV files you upload
  • Usage data (pages visited, features used) via PostHog analytics

2. How we use your data

We use your data to:

  • Provide and operate the Aplion service
  • Send notifications you have opted into (follow-up reminders, weekly summaries)
  • Improve the product and fix bugs
  • Process payments if you upgrade to a paid plan

We do not sell your personal data to third parties.

3. Data storage

Your data is stored securely on Supabase (EU region, AWS eu-west-1). All data is encrypted in transit (TLS) and at rest. We use Supabase Row Level Security to ensure users can only access their own data.

4. Data retention

Your data is kept for as long as your account is active. When you delete your account, all associated data (jobs, CVs, activity logs) is permanently removed from our systems.

5. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct any inaccurate data
  • Erasure — delete your account and all associated data
  • Portability — receive your data in a structured format

To exercise any of these rights, contact us at hello@aplion.io.

6. Cookies

Aplion uses essential cookies for authentication sessions. We also use PostHog for product analytics, which sets cookies and uses browser local storage to identify returning visitors, track feature usage, and record anonymised session replays. Input fields and sensitive form data are masked in recordings. We do not use advertising or tracking cookies.

7. Third-party services

We use the following third-party services to operate Aplion:

  • Supabase — database, authentication, and file storage (EU-hosted)
  • Lemon Squeezy — payment processing for paid subscriptions
  • Vercel — application hosting and deployment
  • Resend — transactional and inbound emails
  • PostHog — product analytics, session recording, and feature flags (EU-hosted, eu.posthog.com). PostHog privacy policy: posthog.com/privacy
  • Mapbox — map rendering in the Analytics page

8. Contact

If you have any questions about this privacy policy or your personal data, please contact us at hello@aplion.io.