Security
Last reviewed: 4 October 2026
Permissions we ask for
- • Sign-in: your Apply Bee account. Signing in with Google is separate from connecting Gmail.
- • Gmail (optional): the gmail.compose scope from a dedicated OAuth project. Google documents it as permitting managing drafts and sending email. Apply Bee only creates drafts you approved — our code has no send path, and the HTTP layer rejects send endpoints even by mistake.
- • Nothing else: no mailbox reads, no contacts reads, no drive access.
Storage and files
Resumes live in private storage with quarantine → scan → immutable clean storage. Downloads use short-lived authorized links. Directory emails are protected at rest with envelope encryption and never appear in list responses, exports, or logs — only revealed to the account that unlocked them.
AI data handling
Generation sends only your confirmed profile facts, approved company evidence, and any job description you paste, to the model provider under commercial processing terms. Draft bodies, resumes, and tokens are never logged. Model output is validated against your fact snapshot before you ever see it.
Money and credits
Payments run through Razorpay with server-side signature verification. Credits live in a transactional ledger with per-lot allocation: concurrent actions cannot double-charge, and a captured payment grants exactly once no matter how many confirmations arrive.
Responsible disclosure
Found something? Email security reports via the contact page with the “security” category. We triage quickly and credit coordinated disclosures where appropriate.