Privacy Policy

1. Scope and accountability

This Privacy Policy explains how Application Engine Inc. (“Application Engine,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use the Application Engine application, website, and related services (collectively, the “Service”).

Application Engine is responsible for personal information under its control. We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable privacy laws. We have designated a Privacy Officer to oversee our privacy program, respond to questions and complaints, and manage access and correction requests.

Privacy Officer, Application Engine Inc.
3050 Erin Centre Boulevard, Unit 146, Mississauga, Ontario L5M 0P5, Canada
Telephone: (647) 402-4633
Email: welcome@applicationengine.ca

2. Personal information we collect

The information we collect depends on how you use the Service and the choices you make.

Information you provide

Information collected automatically

Information received from others

We do not intentionally collect a complete payment-card number through our own application systems. We do not knowingly collect personal information from anyone under 18.

3. Why we use personal information

We identify the purpose for collecting personal information at or before collection. We use information for the following purposes:

We will not use personal information for a new purpose that is incompatible with the purpose identified at collection unless we first identify that purpose and obtain consent where required by law.

4. Consent and choices

We seek consent in a form appropriate to the sensitivity of the information and the reasonable expectations of the individual. Some processing is necessary to provide a feature you request. Optional processing, if offered, will be presented separately so that you can make a meaningful choice.

Before you first submit resume or career content to an AI feature, we will provide a concise notice identifying the information sent, the AI provider, the purpose, relevant cross-border processing, and any meaningful residual risk. We will request express consent where appropriate because resume information may be sensitive.

You may withdraw consent, subject to legal or contractual restrictions and reasonable notice, by contacting the Privacy Officer or using available account controls. We will explain the consequences. Withdrawal may prevent us from providing a feature that requires the information, but it will not affect processing that occurred lawfully before withdrawal.

We do not condition the Service on consent to collect, use, or disclose information beyond what is reasonably necessary for legitimate, identified purposes.

5. AI processing

When you use an AI feature, the resume or career content and instructions needed to answer the request are transmitted to Anthropic for processing. The output is returned to the Service and may be stored with your account so that you can review or revise it.

We do not use resume or career content to train our own general-purpose AI models. Anthropic states that, for its commercial products and API, customer inputs and outputs are not used to train generative models by default unless the customer expressly opts in, including through a development-partner program. We will not opt in without first updating this Policy and obtaining consent where required. Provider retention, abuse monitoring, and possible human review still depend on the contracted service and configuration described in the notice shown before use.

Anthropic states that it stores API data in the United States and may process it in the United States, Europe, Asia or Australia, and that it deletes API inputs and outputs within 30 days of receipt or generation, except where it must keep them longer by law or to investigate a violation of its usage policies.

Our Anthropic account is not enrolled in any feedback, development-partner or model-improvement program. Content flagged by Anthropic’s automated safety systems may be reviewed by authorized Anthropic staff.

AI output can reproduce or infer personal information and may be inaccurate or biased. Avoid submitting information that is not reasonably necessary, including government identification numbers, financial account information, medical records, or another person’s confidential information.

6. Service providers and disclosures

We disclose personal information to service providers only as reasonably necessary for them to perform services for us. We remain accountable for information transferred for processing and use contractual or other measures designed to require comparable protection.

We may also disclose personal information:

We do not sell personal information. We do not disclose resume or career content to third parties for their independent advertising purposes.

Apple, Google, and Stripe may also process information as independent organizations under their own privacy notices when they administer an account, app-store purchase, or payment. Their independent processing is not performed on our instructions, although information they return to us is handled under this Policy.

7. Processing outside Canada

Application Engine is based in Ontario, but some service providers and their subprocessors may process personal information in the United States or other countries. While information is in another jurisdiction, it may be subject to that jurisdiction’s laws and may be accessible to courts, law-enforcement, or national-security authorities under lawful process.

We remain accountable under PIPEDA for personal information transferred to a service provider for processing. We assess providers and use contractual or other measures intended to provide a level of protection comparable to the protection required of us. Contact the Privacy Officer for information about our use of providers outside Canada.

8. Retention and deletion

We retain personal information only as long as reasonably necessary for the identified purposes, to meet legal obligations, or to establish or defend legal claims. We use retention rules based on the type and sensitivity of information, the reason it was collected, account status, legal requirements, and the availability of secure deletion.

Retention schedule

When information is no longer required, we delete, erase, or anonymize it using measures appropriate to its sensitivity. Anonymized information that cannot reasonably be linked to an identifiable individual is not personal information.

If we create de-identified or aggregated information, we use reasonable technical and contractual controls intended to prevent re-identification and do not attempt to re-identify it except to test safeguards or as permitted by law.

9. Safeguards

We use administrative, technical, and physical safeguards appropriate to the sensitivity, amount, format, distribution, and storage of personal information. Depending on the system and information, safeguards may include encryption in transit and at rest, access controls, least-privilege permissions, authentication controls, logging and monitoring, secure development practices, backups, vendor review, staff confidentiality obligations, and secure deletion.

No safeguard can eliminate every risk. We maintain incident-response procedures and review safeguards as threats, systems, and legal requirements change.

10. Privacy incidents

If a breach of security safeguards occurs, we will investigate and take reasonable steps to contain and mitigate it. Where PIPEDA requires, we will report a breach to the Office of the Privacy Commissioner of Canada, notify affected individuals, and notify another organization that may be able to reduce the risk of harm as soon as feasible. We maintain a record of every breach of security safeguards for at least 24 months after the day we determine the breach occurred.

11. Your privacy rights

Subject to limited legal exceptions, you may ask whether we hold personal information about you and request access to it. You may also request an account of how it has been used and the third parties to which it has been disclosed, and challenge its accuracy or completeness.

To make a request, contact the Privacy Officer. We may ask for information reasonably necessary to verify your identity and locate the relevant records. We will use verification information only for that purpose. We ordinarily respond within 30 days, unless PIPEDA permits an extension and we notify you within the initial period. Access is provided at minimal or no cost unless the law permits otherwise and we tell you in advance.

If we refuse access in whole or in part, we will explain the applicable reason unless prohibited by law. If you show that information is inaccurate or incomplete, we will amend it as appropriate and, where appropriate, notify a third party that received it. If a disagreement remains unresolved, we will record the substance of the challenge where required.

You may also request account deletion. We will delete or anonymize information that is no longer required, subject to legal, security, backup, fraud-prevention, and recordkeeping needs. PIPEDA does not create an unconditional right to erase every record.

Where required by an app store, account deletion can be initiated in the application. We will explain what is deleted, what must be retained and why, the expected completion period, and how an active app-store subscription is managed. Deleting an account does not itself cancel an Apple or Google subscription.

If you live in Quebec, you may also ask us to give you personal information we collected from you in a structured, commonly used technological format, or to transfer it to a person or organization you authorize. You may also contact the Commission d’accès à l’information du Québec.

12. Complaints

You may raise a privacy concern with the Privacy Officer using the contact information in Section 1. We will acknowledge and investigate the complaint, communicate the outcome, and take appropriate corrective steps if the complaint is justified.

If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada through www.priv.gc.ca. This does not limit any other right or remedy available to you.

If another provincial privacy law applies to the Service or your information, you may also have a right to contact the applicable provincial privacy regulator.

13. Cookies and local storage

We use cookies or similar local-storage technologies that are necessary to maintain sessions, remember preferences, protect accounts, and operate the Service. We may also use limited analytics or diagnostic technologies if identified in the notice presented to you.

The technologies we use are: sign-in session storage in the app (necessary for authentication), and, on our website, browser storage of your chosen currency (a preference you can clear at any time). We do not use analytics, advertising or attribution tools.

Browser or device controls may allow you to block or remove some technologies. Blocking a technology that is necessary for authentication or security may prevent part of the Service from working.

14. Commercial electronic messages

We send transactional messages needed to operate the Service, such as account, security, password-reset, purchase, and material service notices. If we send marketing messages, we will do so with consent or another basis permitted by Canada’s anti-spam legislation, include required sender information and an unsubscribe mechanism, and process unsubscribe requests within the legally required period. Unsubscribing from marketing does not stop necessary service messages.

15. Children

The Service is intended for people 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that we collected such information, we will take reasonable steps to delete it, subject to legal requirements. Contact the Privacy Officer if you believe a minor has provided personal information.

16. Changes to this Policy

We may update this Policy to reflect changes to the Service, our practices, or legal requirements. We will post the revised Policy with a new effective date and provide advance notice of a material change where appropriate. If a change introduces a new purpose that requires consent, we will seek that consent before using information for the new purpose.

17. Contact

Questions, access or correction requests, withdrawal-of-consent requests, deletion requests, and privacy complaints may be sent to:

Privacy Officer, Application Engine Inc.
3050 Erin Centre Boulevard, Unit 146, Mississauga, Ontario L5M 0P5, Canada
Telephone: (647) 402-4633
Email: welcome@applicationengine.ca