← Back to home

Privacy Policy

Last updated 2026-09-04

Lynder, a general partnership operated from California, USA ("Lynder," "we," "us," or "our")

  • Effective date: 2026-09-04
  • Last updated: 2026-09-04

This Privacy Policy explains what personal information Lynder collects, why we collect it, how we use, store, share, and protect it, and the rights and choices you have. It applies to the Lynder website, application, and related services (together, the "Service").

Lynder is an auto-apply agent. You tell it what you want to apply to; it finds real application forms, opens each one, reads the questions it asks, answers them from what you have told us and nothing else, submits the application on your behalf, and records what happened. Résumé and cover-letter tailoring is part of it.

Two things Lynder does not do, so there is no ambiguity about them:

  • Lynder does not have access to your email. It never requests a Gmail permission of any kind — not read, not send. Signing in with Google grants identity only.
  • Lynder does not send messages to anyone on your behalf. It fills and submits application forms. It does not email hiring managers, recruiters, or anyone else for you.

If you have any questions, contact us at info@lynder.ai.

1. Who we are

Lynder is a general partnership operated from California, USA. The party responsible for your personal information is:

Lynder (a general partnership)
California, USA
Email: info@lynder.ai

2. Summary (the short version)

  • We collect your account details, the profile and onboarding answers you enter, the résumé and cover letter you upload, the materials the agent generates from them, and a record of the applications it opened and submitted. We also keep basic request logs.
  • We use it to run the auto-apply agent for you: to find application forms, read what each one asks, answer those questions from what you have given us, and submit.
  • We put your answers on third parties' application forms. That is the Service. When an application is submitted, the employer or organisation running that form receives the information their form asked for. See Section 6.
  • We never sell your personal information, we do not use it for advertising, and we do not use it to train generalized AI/ML models.
  • We share it only with the service providers named in Section 7.
  • You control it. You can export everything we hold as one file, and delete your account and data, from inside the product — see Section 8.

This summary is for convenience only; the full Policy below governs.

3. Information we collect

3.1 Information you provide

3.2 Payment information

If you subscribe to Pro, payment is processed by Stripe. Stripe collects your card and billing details directly under Stripe's Privacy Policy; Lynder never receives or stores your card number. We store the Stripe customer and subscription identifiers and your subscription status so we know what plan you are on.

3.3 Logs, cookies, and analytics

We are specific here rather than generic, because most of the usual list does not apply to us.

  • One cookie. lynder_session — a signed, HttpOnly, SameSite=Lax session cookie with a rolling 30-day lifetime, set when you sign in. It is what keeps you signed in. There are no advertising cookies, no third-party tracking cookies, and no cross-site trackers on this site.
  • IP address, for rate limiting. Public forms (sign-up, waitlist, password reset) and the metered product routes count requests against a short-lived per-address counter so one script cannot exhaust the Service. That counter row expires on its own.
  • Request and error logs kept by our hosting providers, containing the usual technical fields (IP, user agent, path, status, timing).
  • Vercel Web Analytics is enabled site-wide and records aggregate page views and referrers.

3.4 Sensitive information

Some of what you give us — the contents of your résumé, and answers to application questions about work authorisation, veteran status, disability status, race or gender where a form asks them — is sensitive personal information. We store it for one reason: to answer that question, on that form, the way you answered it. We do not use it to infer anything about you, we do not sell it, and we do not use it for advertising. See Section 11 for the California "right to limit."

4. Sign-in and connected accounts

4.1 Google sign-in — identity only

If you sign in with Google, Lynder requests exactly three OAuth scopes:

That is the complete list. Specifically:

  • No Gmail scope is requested — not gmail.send, not gmail.readonly, not any other. Lynder holds no permission to read, search, list, or send mail in your account, and holds no ability to acquire one without putting you through a new, separate Google consent screen.
  • No offline access, no refresh token. The sign-in request sets Google's offline flag off, so Google never issues Lynder a durable grant on your Google account. The authorization we receive is used once, at sign-in, to read your identity.
  • We do not receive, and cannot receive, any of your email content.

4.2 GitHub

You may optionally connect GitHub. This is a GitHub App connection: its permissions come from the App's configuration, which GitHub shows you on the authorization screen before you approve it, and you can revoke it at any time from your GitHub settings. It is never required.

4.3 If we ever change this

If Lynder ever requests a different permission from Google or GitHub, that is a new consent screen you would have to approve, and we will update this Policy before asking.

5. How we use information

We use personal information to:

  1. Find application forms that match what you said you were looking for, by walking public job boards and public federal listing sources directly.
  2. Read each form — open it and record the questions it asks.
  3. Answer those questions from your stored answers, résumé, and generated materials, and from nothing else. The engine that fills forms makes no model call and has no default values: a required field with no answer of yours behind it stops that application and tells you which question is missing. It is never guessed, never defaulted, and never improvised.
  4. Generate materials — tailored résumés and cover letters. This step sends your profile, résumé text, and the target's own posting text to our model provider (see Section 7) to produce that output for you, and for nothing else.
  5. Submit applications and record the outcome, including the confirmation text read back off the organisation's own page.
  6. Run the in-product chat agent, which can read your agent state and change your settings when you ask it to. Your messages to it, and the context needed to answer them, go to the same model provider.
  7. Process payments and manage your subscription through Stripe.
  8. Send you account email you asked for — today that is exactly one thing: a password-reset link, sent through Resend when you request one.
  9. Secure and maintain the Service — rate limiting, abuse prevention, debugging, and enforcing our Terms.
  10. Comply with law and enforce our legal rights.

We do not use your personal information for advertising, we do not sell it, and we do not use it to train generalized or standalone AI/ML models.

6. Applications we submit for you

This is the part of the Service that moves your information off our systems on purpose, so it gets its own section.

  • We submit applications on your behalf. When an application is submitted, the organisation running that form — the employer, and whichever application platform they use — receives whatever their form asked for: your name, your contact details, your résumé and cover-letter files, and your answers to their questions. Their handling of that information is governed by their privacy policy, not this one.
  • Only your own answers are ever submitted. Every value written into a form field comes from your stored profile, your answers, your résumé, or materials generated from them. Nothing is invented to fill a gap.
  • Review before submit is a setting you can turn on. By default the agent submits without stopping for you — that is what the product is. You can turn on a review step during onboarding, in Settings → What you want, or by asking the in-product agent, and then nothing goes out until you say so. It is off unless you turn it on.
  • You can also tell it to let you choose the targets rather than choosing for you. Same places, same effect: it still finds and reads every form, but waits for you.
  • Creating accounts on application sites is opt-in and off by default. Some application systems (Workday is the common one) will not show you the application at all without a candidate account on that employer's site. If — and only if — you turn this on, Lynder may register such an account for you using your email address and a password derived on the spot from a server secret. That password is not stored anywhere, by us or in your account. With the setting off, those targets stay on your board marked as needing an account, and Lynder does not register anything.
  • Stop means stop. Turning the agent off, and deleting your account, both write a durable stop flag that the worker checks before every pass, so work already in flight halts rather than finishing.

7. How we share information — sub-processors

We do not sell or rent your personal information. We share it only with the providers below, who help us operate the Service:

Separately, and by design, the employers and application platforms you apply to receive your application — see Section 6.

We may also disclose information: (a) to comply with law or valid legal process; (b) to protect the rights, safety, and security of Lynder, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case any successor will be bound by this Policy or a policy at least as protective.

8. Data retention, deletion, and export

Exporting your data. Settings → Your data → Export everything returns everything we hold about your account as one JSON file, immediately, in one authenticated request. No ticket, no queue, no waiting period. The file names what it deliberately leaves out: session ids, your password hash, OAuth tokens, and Stripe identifiers — machine credentials, not facts about you.

Deleting your account. Settings → Your data → Delete this account, where you confirm by typing your own email address. What happens, in this order: the agent is stopped with a durable flag the worker reads before every pass; live Google and GitHub authorizations are revoked with those providers; and then your sessions, sign-in record, résumé and cover-letter files, connected-account records, your decision history, and your user row — which carries your profile, your answers, and every target and application — are deleted. The response tells you what was actually removed, verified by re-reading the record rather than assumed.

One thing deletion does not do, stated plainly because you should know it before you click: it does not cancel a live Stripe subscription. If you are on Pro, cancel billing first — Settings → Billing → Manage subscription opens the Stripe portal — or email info@lynder.ai and we will cancel and refund it. The product warns you about this before the delete, not after.

Applications already submitted cannot be recalled. They are with the organisations you sent them to, and their copies are governed by their policies.

If you would rather not use the in-product controls, email info@lynder.ai from the address on your account and we will do both by hand. Some information may be retained where required by law, to resolve disputes, prevent abuse, or enforce our agreements, and residual copies may persist briefly in our providers' backups.

9. Your rights and choices

Wherever you live, you can:

  • Access and update your profile, your answers, and every agent setting in the product.
  • Export everything we hold — Section 8.
  • Delete your account and data — Section 8.
  • Disconnect a linked Google or GitHub account at any time.
  • Turn off the agent, turn on review-before-submit, or withdraw the account-creation opt-in, at any time.

To exercise any right we have not built a button for, email info@lynder.ai from the address on your account. We will verify your request and respond within the time required by applicable law, and we will not discriminate against you for exercising your rights.

10. Where the Service is available (United States only)

The Service is intended only for users located in the United States. We do not target, market to, or knowingly provide the Service to residents of the European Economic Area, the United Kingdom, or Switzerland, and we therefore do not provide GDPR-specific data-subject rights, an EU/UK representative, a Data Protection Officer, or international-transfer mechanisms such as Standard Contractual Clauses. If you are located outside the United States, please do not use the Service.

11. Your California rights (CCPA/CPRA)

This section applies to California residents under the California Consumer Privacy Act, as amended by the CPRA.

Notice at collection — categories of personal information we collect:

We collect this from you, from your connected accounts with your permission, and automatically from your use of the Service.

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months.

We do not use or disclose sensitive personal information for any purpose other than those permitted under the CCPA/CPRA — namely, providing the Service you asked for. Because our use is already limited to those purposes, the "right to limit" requires no further action, but you may still contact us.

Your California rights: to know and access, to delete, to correct, to opt out of sale or sharing (not applicable — we do neither), to limit the use of sensitive personal information, and to non-discrimination. Email info@lynder.ai to exercise them; we verify identity by confirming control of the account email, accept an authorized agent with proper authorization, and respond within the CCPA's timeframes (generally 45 days, extendable once).

"Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.

12. Data security

Measures in place today:

  • HTTPS everywhere, including to every provider named in Section 7. The endpoints for our model, mail, and OAuth providers are hard-coded rather than configurable, so no single setting can redirect your data to another host.
  • Passwords are stored only as bcrypt hashes (cost 12), never in plain text or in a reversible form.
  • Session cookies are HttpOnly, SameSite=Lax, Secure in production, and HMAC-signed, so a cookie cannot be forged without our server secret, and your session id is rotated at sign-in.
  • Secrets are isolated. Connected-account tokens and billing identifiers live in one table and are never returned by an API response; the data-export path refuses outright — it does not quietly redact — if a secret ever reaches it.
  • Row-level security is enabled on every table that holds your data, so the database's public API role can read none of it.
  • Fetches built from a URL you supply are guarded against internal-network access, re-checked on every redirect hop.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and any regulators as required by law.

13. Children's privacy

The Service is intended for adults and is not directed to children. You must be at least 18 years old (or the age of majority where you live) to use Lynder — see our Terms of Service. We do not knowingly collect personal information from anyone under 16, and in no case from children under 13 in a manner requiring parental consent under the U.S. Children's Online Privacy Protection Act (COPPA). If we learn that we have, we will delete it. If you believe a child has provided us personal information, contact info@lynder.ai.

The Service connects to and submits applications on third-party sites. Your relationship with those sites — the employers you apply to, the application platforms they use, and providers such as Google, GitHub, and Stripe — is governed by their terms and privacy policies, not this one. We are not responsible for their privacy practices.

15. Changes to this Policy

We may update this Policy as the Service changes or as law requires. When we make a material change we will update the "Last updated" date above and, where appropriate, notify you and, where required, obtain your consent. Your continued use after an update takes effect means you accept the revised Policy.

16. Contact us

Questions, requests, or complaints about this Policy or your personal information:

Lynder (a general partnership, California, USA)
Email: info@lynder.ai

We will do our best to resolve your concern.