Retention and deletion
How long we keep things, and what deletes it.
Each period below is applied by a scheduled job that runs every hour and records what it removed. It is a schedule, not an intention.
ApplySafer stores no CV or uploaded file of any kind. There is no upload feature to store one with. It stores no IP address, no location history, and no card details — card payments are handled entirely on Stripe's own pages.
- Account details
- Your email address, an optional display name, and whether the address is verified. Cleared when you ask us to delete your account.
- Sign-in sessions
- Expired sessions are deleted automatically, and every session is revoked immediately when an account is erased.
- Reviews and replies
- If you ask us to erase your account, your words are replaced with a removal notice and the review stops being shown. The moderation record and the employer's own reply survive, because a complaint about a published statement has to be answerable and the employer's words are not yours to remove.
- Salary and interview submissions
- Deleted outright when you ask us to erase your account.
- Application profile snapshot and screening answers
- The copy of your profile that you consented to send is removed on that clock whether or not anyone asks. The fact that you applied, and the outcome, stay: both sides need that record. Recruiter notes about your application are deleted at the same time.
- Messages with an employer
- Message bodies are replaced with a removal notice after a year. Contact details are never stored at all - they are stripped before the message is saved.
- Email send log
- We record that we tried to email you, the subject, and whether it sent, so we can answer 'did the reset email go out?'. The address is stored masked and the message body is never stored.
- Usage counts
- Counts of searches, job views and applications, used to tell an employer how a listing performed. These records do not identify who did any of it - no user reference is stored on them.
- Abuse counters
- Short-lived counters that stop somebody flooding the site with submissions.
- Team invitations
- Then the address and the invitation link are deleted.
- Moderation audit records
- Who made a moderation decision, when, and the reason code. This is the record that makes moderation accountable and lets a decision be challenged; it holds references and reasons rather than content.
While the account exists
Until the session expires
While published
While published
180 days after the application closes; 365 days at the outside
365 days from the message
90 days
90 days
7 days
30 days after the invitation expires
Kept
Asking us to delete
You can ask us to delete your account or just your contributions. When we do, we clear your name, address and credentials, revoke every session, delete the records that exist only to describe you, and replace anything you wrote with a removal notice. A small amount is kept where the law requires it or where a complaint about something already published still has to be answerable — that is described in full in our privacy notice.
The complete record of what is held and why, table by table, is maintained alongside the code in docs/data-inventory.md.