Skip to main content

Security

Last reviewed: 4 October 2026

Permissions we ask for

  • • Sign-in: your Apply Bee account. Signing in with Google is separate from connecting Gmail.
  • • Gmail (optional): the gmail.compose scope from a dedicated OAuth project. Google documents it as permitting managing drafts and sending email. Apply Bee only creates drafts you approved — our code has no send path, and the HTTP layer rejects send endpoints even by mistake.
  • • Nothing else: no mailbox reads, no contacts reads, no drive access.

Storage and files

Resumes live in private storage with quarantine → scan → immutable clean storage. Downloads use short-lived authorized links. Directory emails are protected at rest with envelope encryption and never appear in list responses, exports, or logs — only revealed to the account that unlocked them.

AI data handling

Generation sends only your confirmed profile facts, approved company evidence, and any job description you paste, to the model provider under commercial processing terms. Draft bodies, resumes, and tokens are never logged. Model output is validated against your fact snapshot before you ever see it.

Money and credits

Payments run through Razorpay with server-side signature verification. Credits live in a transactional ledger with per-lot allocation: concurrent actions cannot double-charge, and a captured payment grants exactly once no matter how many confirmations arrive.

Responsible disclosure

Found something? Email security reports via the contact page with the “security” category. We triage quickly and credit coordinated disclosures where appropriate.

Current status

Pre-launch: compliance certifications not yet heldDraft-only Gmail enforcement in code and testsTransactional credit ledger with automated consistency checks