Privacy Policy

Version 0.1Drafted 9 July 2026Effective date: Pending publication

Draft — pending legal review

This text has not yet been reviewed by a lawyer, is not the final published version, and is not legally binding. It is shown here while we finalise our policies ahead of launch.

AppliHelm is a product of Mitudo Softwares Limited, No. 2, Jesuloba Street, Agura, Sabo, Sagamu, Ogun State, Nigeria. Mitudo Softwares Limited is the data controller for personal data processed through AppliHelm.

Privacy contact / Data Protection Officer: Timilehin Odulate, mitudosoftwares@gmail.com.

1.What we collect

Account data — name, email address, password (stored as a hash by our authentication provider), and account settings.

Career profile data — the information you add to your profile: education history, work experience, projects, skills, certifications, languages, interests, references (including referee names and contact details you provide), career summary, job preferences, and personal details such as your location. We treat all career profile data as sensitive personal data and apply the safeguards in Section 7, because in aggregate it reveals a detailed picture of your professional life and may reveal or imply protected characteristics.

Documents — CVs you upload (parsed and stored) and CVs, cover letters, and other documents generated in the app.

Job and application data — job postings you save or analyse, applications you track, and their statuses.

Payment data — handled by Paystack. We receive transaction references, plan, amount, and status — never your full card number.

Technical data — server logs (IP address, timestamps, request metadata) kept for security and debugging, and the aggregate, cookieless analytics described in Section 8.

AI usage data — counts of your AI feature usage (needed to enforce plan limits) and the inputs/outputs of AI requests as needed to provide the feature.

We collect this data directly from you. We do not buy data about you or track you across other sites.

2.Why we process it (purposes and lawful bases)

PurposeDataLawful basis (NDPA / GDPR)
Provide the service (profile, CVs, tracking)Account, career profile, documents, job dataContract
AI features you invoke (parsing, generation, analysis)Relevant career profile data and documents, sent to an AI providerContract; consent obtained at signup for the AI processing of career profile data
Billing and subscription managementAccount, payment dataContract; legal obligation (tax/records)
Enforcing plan limits, preventing abuseAI usage data, technical dataLegitimate interests
Security, debugging, incident responseTechnical dataLegitimate interests; legal obligation
Product analytics (aggregate, cookieless)Anonymous/aggregate usage eventsLegitimate interests
Service announcementsEmailContract
Marketing emails (if any)EmailSeparate opt-in consent, withdrawable at any time

For PIPEDA purposes, we rely on your knowledge and consent obtained at signup and at feature use, with purposes identified above; consent for non-essential purposes (marketing) is express and separate.

3.AI processing

When you use an AI-assisted feature, the relevant parts of your data are transmitted to one of our AI model providers — currently Google, OpenAI, and/or Anthropic — to generate the result, then returned to you. These providers act as processors/service providers for these requests; under their API terms, API data is not used to train their models.

We never sell your data to AI providers or anyone else, and AI outputs about you are visible only to you.

If you configure your own AI provider API key in settings, requests made with that key are governed by your own agreement with that provider; the key is stored in your browser, not on our servers.

No solely automated decisions with legal or similarly significant effects are made about you. AI features produce drafts and suggestions that you review and control.

4.Who we share data with (processors)

We share personal data only with the service providers needed to run AppliHelm:

  • Supabase — database, authentication, and file storage (primary data store)
  • Google / OpenAI / Anthropic — AI model processing (Section 3)
  • Paystack — payment processing (Paystack is an independent controller for its own compliance obligations)
  • Hosting provider (Vercel or equivalent) — application hosting; provider confirmed at production setup
  • Analytics provider (Plausible or PostHog in cookieless mode) — aggregate, cookieless product analytics; provider confirmed at production setup

Each processor is bound by a data-processing agreement or equivalent terms. We do not sell personal data, and we do not share it with advertisers. We may disclose data if required by law or to protect rights, safety, or the integrity of the service, and in a merger/acquisition context under confidentiality.

5.International transfers

Our providers store and process data outside Nigeria (primarily the United States and the European Union). Where personal data of Nigerian data subjects is transferred abroad, we rely on the transfer mechanisms permitted under the NDPA (including transfers to jurisdictions/instruments providing adequate protection and contractual safeguards). For EEA/UK data subjects, transfers rely on adequacy decisions or Standard Contractual Clauses as applicable. For Canadian users, data may be processed outside Canada and is subject to comparable contractual protection.

6.Retention

  • Account and career profile data: kept while your account is active.
  • On account deletion: personal data is deleted or irreversibly anonymised within 30 days, except records we must keep longer (e.g. payment/tax records, kept for the statutory period) and minimal logs kept for security.
  • Server logs: retained up to 90 days.
  • Backups: deleted data ages out of backups within the backup retention window of our hosting plan (confirmed at production setup).

7.Security

Data is encrypted in transit (TLS) and at rest. Database access is protected by row-level security so each user's records are accessible only to that user's authenticated session, enforced at the database layer in addition to application checks. Access to production systems is restricted. Platform API keys are held server-side only. In the event of a breach likely to result in risk to you, we will notify the Nigeria Data Protection Commission within 72 hours and affected users without undue delay, per the NDPA (and equivalent GDPR/PIPEDA duties).

8.Cookies and analytics

AppliHelm does not use advertising or cross-site tracking cookies.

  • Strictly necessary storage: we use your browser's local storage to keep you signed in (authentication session) and to save your in-app preferences (for example, AI settings). These are essential to the service and do not track you.
  • Analytics: we use a cookieless analytics tool that records aggregate usage (page views, feature usage) without cookies, without persistent identifiers, and without cross-site tracking.

Because we use no non-essential cookies or trackers, no cookie consent banner is required. If we ever introduce non-essential cookies, we will ask for your consent first and update this policy.

9.Your rights

Depending on where you live, you have rights under the NDPA (Nigeria), GDPR (EEA/UK), and PIPEDA (Canada), including to: access your data; correct it; delete it; receive a portable copy; restrict or object to certain processing; withdraw consent at any time (without affecting prior processing); and not be subject to solely automated significant decisions (we make none).

You can exercise most of these directly in the app (your profile is fully editable and exportable). For account deletion and anything else, contact the DPO above. We respond within 30 days.

You may also complain to a supervisory authority: the Nigeria Data Protection Commission (NDPC); your local EEA/UK authority; or the Office of the Privacy Commissioner of Canada (OPC). We'd appreciate the chance to resolve it directly first.

10.Children

AppliHelm is not directed at children and requires users to be at least 18. We do not knowingly process children's data; if you believe a child has created an account, contact us and we will delete it.

11.Changes

We will post any changes here with a new effective date and keep dated prior versions. Material changes will be notified in-app or by email before they take effect.