ApplicantSpace Back to site
Privacy

What we hold, and what we will never do with it.

A job search is the most sensitive thing most people put into a piece of software. This page is the whole of it, in the order it matters.

Last updated 2 August 2026·Effective immediately on publication
On this page
01What we collect02How we use it03AI processing and model training04Automated scoring and profiling05What your institution can see06Who we share it with07Your rights and choices08Retention and deletion09How we protect it10International transfers11Children's privacy12Changes to this policy
01

What we collect

Next Chapter Skills Private Limited is the data controller — the data fiduciary, under India's Digital Personal Data Protection Act, 2023 — for the personal data described here. We collect only what the product needs in order to work for you, and we set out below what each category is for and how long we keep it.

WhatWhyKept
Account detailsSign-in and billingWhile active
Career ProfileTailoring applicationsUntil deleted
Captured job postsFit scores and verdicts24 months
Generated documentsYour history and reuseUntil deleted
Usage eventsQuota and reliability13 months

Where your access comes from an institution, we also receive from that institution the roster details it holds about you — typically your name, email address, mobile number, student or roll number, and academic standing such as CGPA — so that your seat can be created without you having to re-enter it.

A resume can contain special category or sensitive personal data — for example information revealing health or disability, religious or philosophical belief, trade union membership, or racial or ethnic origin, and in some formats a photograph, date of birth or marital status. We do not ask for that information, we do not extract it into your structured Career Profile, and we do not use it to score or rank you. If it appears in a document you upload, it is stored only as part of that document and is deleted when the document is.

In plain termsWe keep what the copilot needs to write for you, and nothing that would let us post or message on your behalf.
02

How we use it

We use your personal data to provide the service you have asked for, which is the performance of our contract with you; to keep the service secure, lawful and working, which is our legitimate interest and in some cases a legal obligation; and, where consent is required, only on the basis of consent you have given and may withdraw at any time.

To operate the product: building your Career Profile, scoring job fit, generating tailored resumes, cover letters, outreach messages and application answers, and tracking your pipeline.
To run your account: authentication, billing, receipts, service notices, and support when you contact us.
To keep things working and safe: diagnosing faults, preventing abuse and fraud, enforcing usage limits, and protecting the service and its users.
To improve the product in aggregate: understanding which features are used and where they fail, using data that does not identify you.
To meet legal obligations: tax and accounting records, and responding to lawful requests.

We do not sell your personal data, we do not share it with advertisers, and we do not use it to build advertising profiles. We do not use your Career Profile or your generated documents to advertise to you.

In plain termsWe use your data to run the product for you, keep it working, and meet the law. That is the whole list.
03

AI processing and model training

Generating a tailored document requires sending relevant parts of your Career Profile and the job description to a third-party AI model provider. We route different tasks to different providers according to what each task needs, and we send only the content required for that task.

Microsoft Azure OpenAI Service — document generation, analysis of job descriptions, parsing of uploaded resumes, and classification of application form fields.
Google Cloud Vertex AI — generation of numerical embeddings used to match your profile against job postings.
Anthropic — generation of tailored resumes, cover letters and other long-form material, where enabled.

These providers act as our processors under contract. They are permitted to process your content only to return a result to us, and they are not permitted to use it to train their models. We do not license your data to any third party for model training, and we do not train models of our own on your Career Profile or your generated documents.

Our providers may retain content briefly for abuse monitoring as described in their own terms. Current providers and any material change to this list are reflected on this page.

In plain termsYour resume and generated documents are never used to train third-party models. Processing happens per request and the content is not retained by the provider.
04

Automated scoring and profiling

The service produces automated assessments about jobs, not about you as a candidate on behalf of any employer. Fit scores, verdicts, rankings, skill-gap analysis and interview readiness indicators are generated by a combination of deterministic rules and AI models, and are shown to you alone as decision support.

No employer, recruiter or institution receives these scores about you, and no automated decision made by this service has any legal or similarly significant effect on you. You decide which jobs to pursue and what to submit; we draft and you send. You can ask us for an explanation of how any score was reached, disagree with it, and correct the underlying profile data at any time.

Where public data is displayed — for example an employer's historical visa sponsorship filings — it is presented as information with its source, may be incomplete or out of date, and is never presented as advice about your eligibility.

In plain termsThe scores are for you, not about you. Nobody else sees them, and nothing here decides anything on your behalf.
05

What your institution can see

If your seat was provided by a college, university or training provider, that institution has a legitimate interest in knowing whether its programme is working. It can see that you claimed your seat, when you were last active, how many applications you are tracking and at what stage, and any outcome you choose to record. Aggregate figures across a cohort are also available to it.

It cannot see the content of your Career Profile, any resume or cover letter generated for you, the jobs you have viewed or applied to by name, your screening answers, your interview preparation, or any score or verdict about you. This boundary is enforced in our systems, not merely by policy, and the full list of what is visible is shown to you inside the product before you begin.

Your institution is a separate controller for the roster data it supplies to us. Its own privacy notice governs how it collects and uses that data, and questions about it should be directed to your institution.

In plain termsYour college sees that you are using it and how it is going. It never sees what you wrote or where you applied.
06

Who we share it with

We share personal data only with service providers who process it on our behalf under written contract, only for the purposes described here, and only to the extent each provider needs. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Payment processing — Stripe and Razorpay, for the charge only. We never receive or store your full card number.
Model inference — Microsoft Azure OpenAI, Google Cloud Vertex AI and Anthropic, under zero-retention terms and no permission to train.
Hosting and infrastructure — Google Cloud Platform, including compute, managed database and cache.
Email delivery — Microsoft Azure Communication Services, for transactional and service email.
Support and error monitoring — stack traces and diagnostics, scrubbed of document content.
Your institution, where your seat is institutional — limited strictly to the activity and outcome fields listed above.

We may also disclose personal data where required by law, to respond to a valid legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets — in which case we will give you notice and the choices available to you.

In plain termsA short list of suppliers who help us run the product, and nobody else. No advertisers, no data brokers, no sale.
07

Your rights and choices

You can access, correct, export and delete your data directly from your account settings. Export returns your profile, documents and pipeline in a machine-readable format. Deletion begins the erasure process described in the next section. We do not charge for these, and using them does not affect the service you receive.

Depending on where you live, you may also have the right to object to or restrict certain processing, to withdraw consent where processing is based on it, to nominate another person to exercise your rights on your behalf, and to complain to a supervisory authority. Under the UK and EU GDPR that is your local data protection authority; under India's DPDP Act it is the Data Protection Board of India; under the CCPA and CPRA, California residents have rights to know, delete, correct, and to opt out of sale or sharing, and not to be discriminated against for exercising them.

We respond to requests within 30 days. We may need to verify your identity first, and we will tell you if a request is one we cannot fully action and why.

Grievance Officer: Behara Venkata Satya Prasad, satyaprasadbehara@gmail.com. Our representative in the United Kingdom and European Union for the purposes of Article 27: Behara Venkata Satya Prasad, satyaprasadbehara@gmail.com.

In plain termsExport or delete your data yourself, any time, from settings. If you would rather ask a person, write to us and one will answer.
08

Retention and deletion

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires. The table above sets out the periods for each category. When a period ends, or when you delete something, the data is removed from our live systems and from backups within the ordinary backup rotation.

When you request erasure, we confirm the request by email before acting, so that a lost password or a compromised inbox cannot cause irreversible deletion. Once confirmed, the deletion is permanent and cannot be undone.

In plain termsDeleting your account removes your profile, documents and pipeline within 30 days. Invoices are kept for seven years because tax law requires it.
09

How we protect it

We encrypt personal data in transit and at rest, restrict internal access to those who need it for a defined purpose, log administrative actions, and require authentication for every request that touches your data. Payment card details are handled entirely by our payment processors and never reach our systems.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within the period the law requires, and notify you without undue delay, telling you what happened, what data was involved and what you should do.

In plain termsEncrypted, access-controlled, and monitored. If something goes wrong we tell you promptly and plainly.
10

International transfers

We are established in India, and our providers operate infrastructure in the United States, the European Union and elsewhere. Using the service therefore involves transferring your personal data across borders, including from your country to India and from India to our providers.

Where we transfer personal data out of the United Kingdom or the European Economic Area, we rely on the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and by additional technical measures including encryption in transit and at rest. Copies of the relevant clauses are available on request at admin@applicantspace.com.

In plain termsYour data crosses borders because our suppliers do. Standard contractual protections travel with it.
11

Children's privacy

The service is for adults conducting their own job search and is not directed at children. You must be at least 18 to create an account or claim an institutional seat, and we do not knowingly collect personal data from anyone under 18.

If we learn that we hold data belonging to a person under 18, we delete it promptly. If you believe a child has provided us with personal data, tell us at admin@applicantspace.com and we will act on it.

In plain termsEighteen and over only. If we find data from anyone younger, we delete it.
12

Changes to this policy

We update this policy when the product changes, when we add or replace a provider, or when the law requires it. The date at the top of this page always reflects the current version.

Where a change materially affects how we handle your personal data — for example a new category of data, a new purpose, or a new recipient — we will notify you by email before it takes effect, and where the law requires your consent we will ask for it rather than assume it.

In plain termsIf something material changes, you hear it from us by email first, not by noticing a new date on this page.
Questions about your data?

Write to our data protection contact and you will get a person, not a ticket number.

admin@applicantspace.com
ApplicantSpaceNext ChapterA product of Next Chapter Skills Private Limited, Bangalore · © 2026
AboutPrivacyTermsContact