Effective September 14, 2026 · Version 2026-09-14.1

Privacy Policy

Email verification and account security

Before a new member account is created, we send a random six-digit code to the supplied email address. The code is stored only as a one-way hash, expires after five minutes, works once, and is subject to retry and resend limits. We keep the verification time and limited security records to prevent unauthorized account creation. Verification codes are never sent to advertising or analytics providers.

Alomar Marketing LLC, a New Jersey limited liability company doing business as Alomar Apply (“Alomar Apply,” “we,” “us,” or “our”), provides the Alomar Apply website, membership service, and desktop Chrome extension (together, the “Service”). This Policy explains what personal information we process, why we process it, when it is disclosed, how long it may be retained, and the choices available to you. This Policy does not replace the privacy policies of job platforms, employers, login providers, payment processors, or AI providers.

Information we collect

Depending on the features you use, we may collect: (a) account and contact information, such as name, email, preferences, plan, consent records, and support messages; (b) applicant information you choose to save, such as contact details, resume-related data, qualifications, experience, work authorization, answer rules, and application preferences; (c) application activity, such as job URLs, employers, titles, locations, descriptions, form steps, answers, status, timestamps, and confirmation evidence; (d) device and extension data, such as an installation identifier, extension version, browser-profile connection, feature mode, usage counts, logs, and supported-page state; and (e) transaction information, such as Stripe customer, checkout, subscription, plan, payment-status, and billing-contact identifiers. Do not provide information you do not have the right to use.

Sources of information

We receive information directly from you, from the extension as it performs actions you request, from login providers you select, from Stripe and other service providers, and from supported job pages visible in your browser. Employers and job platforms independently collect information submitted to them. We do not receive your ChatGPT, Google, job-platform, or payment-account password.

Local extension storage

The extension may store settings, answer memory, job history, logs, account connection tokens, and limited application data in your Chrome profile. This local information may remain until you clear it, remove the Chrome profile, or uninstall the extension. The extension requests access only to the website categories declared in its Chrome manifest; it does not request permission to read your general browser history.

How and why we use information

We use personal information to provide the Service; create and authenticate accounts; record consent; connect the website and extension; carry out user-selected application steps; remember answers; prevent duplicate submissions; issue and enforce licenses and limits; process and reconcile payments; provide support; send requested or essential service messages; maintain security; detect misuse; debug and improve reliability and accessibility; comply with law; and establish, exercise, or defend legal claims. We do not use job-application data to make hiring decisions.

Signup notifications

At account creation, a notification containing the submitted name, email, login method, consent version, and signup time may be queued for an authorized secure support channel and sent through a configured transactional-email provider. It does not contain passwords, resumes, saved answers, or authentication tokens.

Lead and customer records

When you submit an email form or create an account, we store the name, email address, selected login method, form source, and available campaign parameters in our first-party database. If you type a first name on the homepage before signup, we may store it in your browser and pass it into the signup draft so the next page can feel personalized. We may send those fields server-to-server to GoHighLevel (LeadConnector) to maintain a customer and support record. API credentials remain server-side. Creating an account does not by itself authorize promotional email; marketing messages are sent only when permitted by law and include required choices.

Job platforms and employers

When you direct the Service to interact with Indeed, LinkedIn Easy Apply, Google Careers, an applicant-tracking system, or an employer, the information needed for the selected action may be transmitted to that third party. Selecting an auto-submit mode authorizes the extension to submit supported applications that match your settings until you pause it or change modes. Those parties control their own systems and process submitted information under their own notices. Intermediate controls may save data before a final submission. We do not control an employer’s handling of an application.

AI services

AI features are optional. When activated, the minimum information reasonably needed to fulfill your request—such as instructions, job text, resume content, or applicant answers—may be sent to the AI provider you select. AI output can be inaccurate and should be reviewed. If you supply an API key, the extension is designed to retain it in extension storage and transmit it only to the selected provider, but you remain responsible for protecting and rotating it. We do not use information obtained through Google APIs to train generalized AI or machine-learning models.

Payments

Stripe processes payment-card details, billing information, transaction data, and fraud signals under its own privacy notice. Alomar Apply receives limited identifiers and status information needed to start checkout, activate access after a verified payment, manage renewals and cancellations, address disputes, and keep accounting records. We do not store complete payment-card numbers or Stripe secret keys in public website or extension files.

Analytics, advertising measurement, and diagnostics

With your optional analytics consent, the website uses Google Analytics 4 to measure page views and signup, installation, checkout, and support journeys. With your separate advertising-measurement consent, the website uses the Meta Pixel to measure visits and campaign results. These providers may receive online identifiers, device and browser information, approximate location derived from IP address, page and referral information, and campaign parameters under their own policies. Depending on applicable law, advertising measurement may be considered targeted advertising, a sale, or sharing even when no money is exchanged. We do not activate Google Analytics or Meta Pixel until the corresponding choice is allowed. You may choose Essential only or Analytics only.

First-party service records may include account creation, successful login, ZIP download, Chrome-profile connection, access-key activation, supported-platform run, confirmed application, timestamps, plan, extension version, and coarse campaign source. The extension does not load Google or Meta scripts on Indeed, LinkedIn, Google Careers, or Chrome-extension pages. Analytics events must not contain passwords, email verification codes, full access keys, payment-card data, resumes, job-application answers, or AI provider keys. Operational application logs are handled separately from advertising analytics.

Hourly operational reports may summarize extension snapshots, application logs, run events, analytics events, Supabase mirroring status, detected errors, active-use timing, likely fixes, and product recommendations. We may store changelog and ops-report summaries in owner-controlled Google Drive or Google Sheets for service operations and support. These reports must not include passwords, verification codes, authentication tokens, full raw access keys, resumes, full application answers, payment-card data, or AI provider secrets.

Cookies and local storage

We use secure session cookies for website login and browser storage for preferences, consent evidence, connection state, welcome-guide progress, and extension memory. Welcome-guide answer drafts require a signed-in account, are separated by member in tab session storage, and are no longer restored after 30 minutes. Changing accounts clears the previous account's temporary draft. Disability choices are not included in these drafts. Final profile answers must be reviewed and saved separately in profile setup. Essential storage supports security and core operation. Removing it may sign you out, clear draft answers, or disconnect the extension.

Optional notifications, location, and career-fair reminders

The website or extension may ask for browser notification permission so you can receive setup reminders, daily apply reminders, run-complete notices, profile-completion reminders, career-fair reminders, account alerts, and human-action-required alerts when a supported application step needs your review, a verification check, or manual input. Optional reminder emails are off until you enable them in your account, include a preference-management link, and can be disabled again at any time. Browser notifications are also optional and can be disabled in your browser, extension, or account preferences. The website may ask for optional browser location permission to personalize local, remote, or nearby job-search examples and event context in your browser. You can decline location sharing and still use Alomar Apply. Do not share precise location if you do not want it used for those optional features.

When information is disclosed

We disclose personal information only as reasonably needed to service providers that support authentication, hosting, databases, customer relationship management, email, analytics, payments, AI, security, and customer support; to job platforms and employers at your direction; to professional advisers; to authorities or other parties when reasonably necessary to comply with law or protect rights and safety; and in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable safeguards. We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising or use it for surveillance pricing.

Role-based support access

Authorized support and operations personnel may access limited member, plan, diagnostic, and service records only as needed for support, billing, security, fraud prevention, troubleshooting, legal compliance, and service operation. Access is role-based, logged where practical, and designed to avoid unnecessary exposure of passwords, verification codes, resumes, full application answers, payment-card numbers, raw access keys, authentication tokens, or provider secrets.

Retention

We retain information for the shortest period reasonably necessary for the purposes described here. Account and profile data generally remain while your account is active. Application history and answer memory remain until you delete them or close the account, subject to operational recovery periods. Consent, billing, fraud-prevention, security, and legal records may be retained longer when reasonably necessary to document transactions, comply with law, resolve disputes, or enforce agreements. Backup copies may persist for a limited period before deletion or de-identification. Local extension data remains under your Chrome profile until cleared or uninstalled.

Security

We use access controls, secure transport, server-side authorization, hashed tokens, scoped permissions, and secret separation. The master role is server-controlled. No security method is perfect. Protect your device, use separate Chrome profiles where appropriate, update software, and report suspected misuse.

Your choices and privacy rights

You can pause automation, change submission mode, review answers, disable optional notifications, disconnect Chrome, clear local data, and export available records. Subject to applicable law, you may request confirmation of processing, access, correction, deletion, or a portable copy of personal information, and may opt out of a sale, targeted advertising, or qualifying profiling. We do not discriminate against you for exercising a privacy right. We may need to verify your identity and may deny or limit a request where permitted by law, such as when retaining information is required for security, legal compliance, or another person’s rights.

Appeals and authorized agents

If we deny a qualifying privacy request, you may appeal through the secure support channel listed in your account or official Alomar Apply support materials. Explain the decision you are appealing. Where required, we will respond within the legally applicable period and explain any further complaint option. An authorized agent may submit a request where permitted by law, but we may require proof of authority and identity verification.

Sensitive information and voluntary demographic data

Some job applications ask for sensitive or voluntary self-identification information. Provide it only when you choose and when legally permitted. The extension should follow your saved choice or pause for review; it must not infer protected characteristics. We do not use sensitive information to advertise, determine prices, or make employment decisions.

Children and international processing

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from a child. Service providers may process information in the United States or other countries; where required, legally recognized safeguards apply.

Policy changes

We may update this Policy and will post a new effective date. Material changes may require renewed consent. Archived consent versions may be retained to document acceptance.

Contact

Alomar Marketing LLC is the operator responsible for this Policy. For privacy, access, correction, deletion, appeal, account, or security requests, use the secure support channel available from your account or official Alomar Apply support materials. Include the email connected to your account and the type of request, but do not send passwords, API keys, one-time codes, complete payment-card details, or private job-platform credentials. We may verify the requesting account before acting.