Privacy

Privacy policy

Last updated 10 July 2026

WhimApply is a UK job search platform. To do its job it holds some of the most personal documents you have: your CV, your work history, and the record of where you are applying. This policy explains exactly what we collect, why, who touches it, and the rights you have over it. It is written to be read, not skimmed past.

The short version: we collect what the product needs to work, we do not sell your data, recruiters cannot buy access to it, and you can ask for a copy or deletion of everything at any time by emailing support@whimapply.com.

1. Who we are

WhimApply (“we”, “us”) operates whimapply.com and is the data controller for the personal information described here. We are based in the United Kingdom. For anything in this policy, contact support@whimapply.com. When the operating company is formally incorporated, this section will be updated with its registered name and number.

2. What we collect

Everything we hold comes from you or from your use of the product:

  • Account details. Your email address, and a password if you set one. Passwords are stored only as cryptographic hashes; we cannot read them. If you sign in with Google or Microsoft we receive your email address from them, never your password.
  • Your CV and profile. The CV file you upload and the structured profile extracted from it: work history, education, skills, links, phone number, location, target role and salary. You can edit or remove any of it.
  • Equal opportunities answers.The optional monitoring answers on your profile (used to autofill UK application forms) can include information about ethnicity, disability or similar. This is special category data under UK law: we store it only with your explicit consent, every field defaults to “Prefer not to say”, and you can clear it whenever you like.
  • Job search activity. Your searches, saved and applied roles, watched companies and settings, so the product can do what it says.
  • Technical information. IP addresses and request logs, kept briefly for security (rate limiting, abuse prevention) and debugging.

3. How we use it

  • To run the product: matching live UK job postings to your profile, tracking your applications, autofilling forms, and generating tailored CVs and letters.
  • To sign you in and talk to you: one-time codes, security notices and service emails. We do not send marketing email without asking first.
  • To keep the service safe: rate limiting, abuse detection and security logging.
  • To improve the product: aggregate usage analytics (see section 7).

Our legal bases under UK GDPR are: performing our contract with you (running the product), legitimate interests (security, improvement), and consent (equal opportunities answers, and analytics where consent is required). We do not sell personal data, and recruiters and employers cannot buy access to your CV, your search history, or anything else.

4. AI processing of your CV

When you upload a CV, its text is processed by an AI model (Anthropic’s Claude) once, to extract the structured profile you then review and edit. Under the commercial terms we use, Anthropic does not use this data to train its models. The extraction is the only per-document AI step; job matching itself is deterministic scoring on our own servers.

5. Who we share it with

No one buys your data. We use a small set of service providers (processors) to run the product, each receiving only what their job requires:

  • Supabase: database, authentication and CV file storage.
  • Vercel: application hosting.
  • Resend: sending sign-in codes and service email.
  • Anthropic: the CV extraction described above.
  • Mixpanel: product analytics (section 7).
  • Upstash: rate-limit counters for security.
  • Job data partners: when you search, the search terms are sent to the job boards that supply our listings. Your identity, profile and CV are not; they see a query, not you.

We would also disclose information if the law genuinely required it, and we would tell you unless legally prevented.

6. International transfers

Some of the providers above process data in the United States. Where data leaves the UK, the transfer is protected by recognised safeguards: the UK extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Agreement / standard contractual clauses.

7. Cookies

We set essential cookies only for signing you in: the encrypted session cookies that keep you logged in. They are httpOnly (script cannot read them) and are strictly necessary, which is why there is no cookie banner.

If analytics ever requires non-essential cookies (section 7), we will ask for consent before setting them, and this section will list them.

8. Analytics

We use Mixpanel to understand how the product is used: which features are opened, where people get stuck, what to fix first. Events describe actions (“search run”, “CV uploaded”), not the content of your CV, documents or search terms. For a signed-in account we also keep a small profile of non-content usage facts (when you signed up, how you sign in, your plan, and whether you have finished setup), tied to your account identifier, never to your CV content. We configure analytics data minimisation wherever the tool allows, and you can object to analytics processing at any time via support@whimapply.com.

9. How long we keep things

  • Your account, profile and CVs: for as long as your account exists. Delete your account and they are removed from live systems, with short-lived backups expiring on their own schedule.
  • Sign-in codes: valid for ten minutes, single use.
  • Security and request logs: kept briefly, then discarded.

To delete your account and everything in it, email support@whimapply.com from your account address; we act within one month, normally much faster.

10. Your rights

Under UK data protection law you can:

  • ask for a copy of everything we hold about you (access, portability);
  • correct anything inaccurate (and most of it you can edit yourself);
  • have it deleted (erasure);
  • restrict or object to particular processing, including analytics;
  • withdraw any consent you gave, at any time.

Email support@whimapply.comto exercise any of these. If you are unhappy with how we handle it, you can complain to the UK Information Commissioner’s Office at ico.org.uk.

11. Security

Everything travels over encrypted connections. Passwords and sign-in codes are stored only as hashes. Sessions live in httpOnly cookies. CV files sit in private storage reachable only through short-lived signed links tied to your account. Every endpoint checks who you are on the server and is rate limited against brute force. No system is perfectly secure, but if a breach ever affects your data we will tell you and the regulator as the law requires.

12. Children

WhimApply is for people old enough to work in the UK and is not intended for anyone under 16. We do not knowingly hold data about under-16s; if you believe we do, email support@whimapply.com and we will remove it.

13. Changes to this policy

If this policy changes in any way that matters, we will update the date at the top and, for significant changes, tell you by email or in the product before they take effect.

14. Contact

Questions, requests, complaints: support@whimapply.com.