Privacy & security

Powerful magic. No black box.

Trust is the whole product. Your data stays yours, nothing is submitted without your say-so, and — if you want maximum control — you can run the AI on your own provider key. Here's exactly how it works, in plain language.

Your data stays yours

Resumes, history, and answers are yours to export or delete. We never sell it, and it never becomes anyone's training data.

You approve every send

The pause-for-review step means no application is ever submitted on your behalf without your explicit, final approval.

Bring your own key optional

Want the AI to run on your own OpenAI, Anthropic, or Gemini account? Add your key on any plan so requests never touch a shared pool. Included on Ultimate.

Bring your own AI key · optional add-on

Why BYO-key changes the privacy math

By default, ApplyMagik's built-in AI does the work — covered by your plan's monthly token allowance, and never trained on your data. But if you want your most sensitive document, your career, to run entirely on infrastructure you control, add your own key. It's $4.99/mo on any plan and included on Ultimate.

1
You add your key once.

Stored encrypted at rest, used only to make calls you initiate.

2
Calls run through your provider.

Your OpenAI/Anthropic/Gemini account governs retention and data-use — under their enterprise no-train terms if you have them.

3
You can revoke instantly.

Pull the key on your provider's side and ApplyMagik loses access immediately.

applymagik — trace data-flow
$ applymagik trace --request "tailor resume"
your résumé & profile
│ encrypted at rest (AES-256)
applymagik · orchestration only, no model
│ signed with your key →
your AI provider account
no shared pool · no training · revocable
$
applymagik — submit confirmation
# all fields filled for Staff Engineer @ Northwind
résumé: jordan-lee-northwind.pdf
cover letter attached
all answers reviewed by you
AWAITING CONFIRMATION
Confirm & submit

Nothing leaves until you press this.

Pause-for-review

The safety step that's actually a feature

Automation without oversight is a liability — especially when your name is on the application. ApplyMagik pauses on every judgment call and ends every session with an explicit submit confirmation.

  • Subjective questions queue with a draft for your edit
  • Demographic / EEO fields never auto-guess
  • Captchas and verification codes hand control back to you
  • A final confirmation gate before any real submit
Under the hood

Security practices

Encryption at rest

AI keys and sensitive profile fields are encrypted in storage, not kept in plaintext.

Encrypted in transit

Everything moves over TLS. Auth uses signed, HTTP-only session tokens.

Scoped access

Developer API tokens carry granular scopes and can be revoked or expired individually.

One-click export

Download a full copy of your data whenever you want, in a portable format.

Real deletion

A delete that means delete — your data is removed, not merely hidden.

No data resale

We don't sell your data and we don't feed it into model training. Ever.

Magic you can audit, control you can feel

Start free, keep your data yours, and keep your hand on the wheel from the very first application.