Privacy policy
Last updated 19 September 2026
Lazy Apply ("the service") is built and operated by Vikash Maddi. It prepares job applications for you: a resume tailored from your own profile and the answers to an application form's questions. This page explains what the service stores, why, and how to remove it.
What we collect
- Account. Your email address and name, through our sign-in provider Clerk. Clerk's own policy covers how it handles sign-in data.
- Profile. The work history, education, projects, skills and achievements you type in or import from a resume. This is the only source of facts the resume writer may use.
- Standing answers. Contact details and answers to common screening questions (work authorization, relocation, notice period, salary expectation, and an optional gender answer for voluntary demographic questions). You control every value.
- Applications. The job links you submit, the posting text we read from the job board, the tailored resume and its PDF, your answers to that form's questions, and status notes. If you use the desktop runner, a screenshot of the filled form.
- Technical. Server logs with request paths and errors, kept briefly by our hosting provider. No advertising trackers.
How we use it
Only to run the service for you: to tailor a resume to a posting, to answer its form, to email you when a resume is ready or a form is filled, and to let an agent you connect act on your account. We do not sell data, share it with advertisers, or use it to train models.
Who processes it
- Vercel hosts the app and stores PDFs and screenshots.
- Turso stores your profile, answers and applications as encrypted-at-rest records.
- Clerk handles sign-in and OAuth for connected agents.
- Cloudflare Workers AI receives the posting text and your profile to write the tailored resume. Inputs are not retained for training under Cloudflare's terms.
- Resend delivers notification emails to the address you choose.
- Job boards (Greenhouse, Lever, Ashby) are read through their public job APIs. We send them nothing; a form is only submitted by you, by your own runner, or by an agent you connected, in a browser.
Connected agents
If you connect an AI agent such as Meta Muse, Claude or ChatGPT, it can read and change your profile, answers and applications, and download your tailored PDFs through a link that expires after 24 hours. It cannot see your API key or runner token. You can disconnect it or revoke your key at any time from the Connect page; the agent's provider has its own privacy policy for what it does with what it reads.
Retention and deletion
Data stays until you delete it. You can delete any application from the app or through a connected agent, which removes its resume and answers. To delete your whole account and everything in it, email maddi.vikash@gmail.com from your account address; it is done within 7 days.
Your rights
You can view and export everything the service holds about you from the Profile, Answers and application pages, or through the API. You can correct it at any time. If you are in the EU, UK or another region with data-protection rights, the same email address handles access, correction, deletion and objection requests.
Changes
If this policy changes in a way that matters, the date above changes and signed-in users see a notice in the app.