Who we are
AiESphere is operated by TECHPRAPT PRIVATE LIMITED (CIN U62099KA2026PTC221135, GSTIN 29AANCT1635Q1ZI), registered at DLF Newtown, Akshayanagar, Bengaluru 560068, Karnataka, India ("AiESphere", "we", "us", or "our"). We operate the website at aiesphere.com and related applications (the "Service") — an AI-assisted career, learning, mentorship, and professional networking platform.
For the purposes of the Digital Personal Data Protection Act, 2023 and its Rules, we are the Data Fiduciary for the personal data described in this policy. Where the UK/EU GDPR applies to you, we act as the controller.
This Privacy Policy applies to everyone who creates an account or otherwise uses the Service. By using AiESphere, you agree to the collection and use of information in line with this policy.
If you have questions about this policy or your data, contact us at [email protected].
Information we collect
Account information: your name, email address, and either a securely hashed password (for email sign-up) or basic profile details (name, email, profile picture) received from Google or LinkedIn when you choose to sign in with them.
Profile and career data: information you add or upload, including your resume, work history, education, skills, certifications, aspirations, and current role. Resume files you upload are stored and processed to help populate your profile.
Application profile: details you save so applications can be completed for you, which may include your postal address, phone number, date of birth, work-authorisation and visa status, notice period, and current and expected compensation.
Screening answers: the questions employers ask on application forms and the answers given, saved so they can be reused on later applications. These are stored as free text, so whatever a given form asks for is what gets stored.
Content you create: posts, blogs, courses, comments, reactions, direct messages, community (sphere) chat messages, and any files or media you attach to them.
Mentorship data: details related to mentorship sessions you book or host, including scheduling and session lifecycle information.
Assessment data: your answers and results on assessments and skill verifications, and where an assessment is proctored, the integrity signals and logs described in section 8.
Payment data: your billing records, invoices, plan and credit history. Card and UPI details are collected and held by our payment partner, not by us.
Usage and device data: IP address, approximate location derived from it, device and browser type, activity logs, and usage events. We use these for security, fraud prevention, abuse detection, regional access controls, and service reliability.
Cookies and analytics data: see section 9.
Sensitive personal data
Some parts of the Service handle categories of data that receive extra protection under Indian law and count as special category data under the UK/EU GDPR. We collect these only where a feature you use requires them.
Government identifiers: employer application forms and onboarding flows sometimes require a PAN or an equivalent tax or identity number. Where you provide one, it is stored with your application profile or, if it was entered into an application form, with your saved screening answers.
Demographic and self-identification data: many applications include voluntary questions on gender, race or ethnicity, veteran status, and disability status. Where you answer them, the answers are saved alongside your other screening answers.
Health-adjacent data: institutional and campus profiles may include a blood group where the institution collects it as part of student records.
Financial data: your current and expected compensation, where you provide them.
We use these only to complete and track the applications and records you ask us to. We do not use them for profiling, advertising, or any automated decision about you, and we do not sell or share them.
You can decline any of these on any form, ask us to delete what we hold, and switch off automatic capture of screening answers in your settings.
How we use your information
To create and operate your account, sign you in, and secure access.
To provide core features: profile creation, resume parsing, role and skill matching, recommendations, learning content, assessments, mentorship, community feeds, and messaging.
To find and rank job openings against your profile, tailor your resume for a specific posting, complete and submit applications on your instruction, and track what happens to them.
To send service communications such as verification codes, password resets, security alerts, and notifications, delivered through our email providers.
To take payment, issue invoices, and meet the tax and accounting obligations that come with them.
To protect the platform: detect and prevent fraud, abuse, and unauthorized access, including IP-based security and regional access controls.
To measure how the Service is used, in aggregate, so we can improve it, diagnose problems, and develop new features.
AI and automated processing
Many features use automated systems and third-party AI providers to process content you submit — for example, parsing your resume into structured fields, scoring role matches, finding skill gaps, tailoring a resume to a posting, drafting cover letters, and drafting answers to application questions.
When such features run, relevant content (such as resume text, profile details, or the text of a job description) is sent to an AI provider solely to produce that output for you. The providers we use for this are listed in section 11. We do not authorise them to use your content to train their own models.
AI outputs are assistive only. They can be incomplete or inaccurate, and you are responsible for reviewing them before saving, publishing, submitting, or relying on them for any decision.
You can withdraw consent for AI processing of your profile at any time in your settings. Doing so stops role matching, skill-gap analysis, resume tailoring, and cover letters from working, rather than letting them run without your consent.
Automated job applications
If you turn on automated applications, the Service acts on your behalf to complete and submit job applications to employers and their applicant-tracking systems. This runs on our systems, not only in your browser, and it can continue while you are offline.
To do this we operate an automated browser that opens the employer’s application page, fills the form using your profile and saved answers, uploads the resume you selected, and submits it. We record a screenshot or page capture of what was submitted so you have a record and so we can diagnose failures.
Employer accounts: many applicant-tracking systems require an account before an application can be submitted. Where that is the case, we create an account on that system for you and store the credentials so future applications can reuse it. Stored passwords are encrypted at rest using AES-256-GCM. Creating that account means your details are also held by that employer’s system under its own privacy policy.
Verification codes: some of those systems email a one-time code to complete sign-in or submission. Where the application used an address we manage for you, we read that code from the inbox automatically and enter it, solely to complete the step you asked for.
You remain responsible for the content of every application submitted for you. You can turn automated applications off at any time, and you can ask us to delete stored employer-account credentials.
The managed apply inbox and connected email
So that employer replies can be collected and tracked, we can put an address we manage for you (at inbox.aiesphere.com) on the applications we submit. Mail sent to that address is delivered to us, not to your personal mailbox.
What we store: for messages received at that address we store the sender and recipients, subject, date, the full message body, any attachments, and the original raw message file. We process them to thread replies against the right application, work out what a reply means (for example an interview invitation or a rejection), and surface it to you.
Connected personal mailbox: you can optionally connect your own Google mailbox instead. If you do, we request read-only access through our integration provider and read only the messages needed to match employer replies to your applications. We never send mail from your personal mailbox. You can disconnect it at any time from your account or from your Google security settings, which revokes our access immediately.
Automated verification codes received at the managed address are used as described in section 6.
You can withdraw consent for the managed inbox at any time. Employer replies then stop being collected, and automated applications can no longer complete any step that needs an emailed code.
Assessments and proctoring
Where an assessment is marked as proctored, we record integrity signals while you take it. These can include when the assessment window loses focus, navigation away from the page, timing data, and other events that suggest the attempt was not completed under the stated conditions.
These signals are used to decide whether an attempt passes integrity checks and to review disputes. They are attached to that attempt and retained with it.
Where an assessment is run by an employer or an institution through the Service, the result and its integrity outcome are shared with that employer or institution.
Institutional and campus accounts
Where your college, university, or employer provides the Service to you, that institution may create your account and supply the records it holds about you — for example your name, contact details, enrolment and programme details, date of birth, and other student or employee record fields.
In that arrangement the institution decides what to share with us and why, and we process it on its instructions to run the features it has enabled. Your relationship with the institution, and its own privacy notice, govern that sharing.
Administrators at your institution can see the data it supplied, your progress on institution-assigned activity, and results of assessments it runs. They cannot see private messages, or applications and career activity you carry out on your own account.
If you want data your institution supplied corrected or removed, raise it with the institution first, since it controls that record. You can also contact us and we will pass the request on and act on it where we are able to.
Data storage and international transfers
Your data is primarily stored and processed on infrastructure located in India (Oracle Cloud, Hyderabad region).
Several sub-processors named above operate outside India and will process limited data in other countries, including the United States and the European Union. Where this happens, we rely on those providers’ contractual and technical safeguards, including standard contractual clauses where they apply.
Data retention
We retain your account and profile data for as long as your account is active and as needed to provide the Service.
When you request deletion, your account is deactivated immediately and scheduled for permanent deletion 30 days later. You can cancel during that window; after it passes, your personal data is erased.
Records we must keep: invoices, payments, and the tax records attached to them are retained for the period required by tax and company law. Where the account they belonged to has been deleted, those records are anonymised so they no longer identify you.
We may also retain limited information for longer where required for legal, audit, security, or fraud-prevention purposes. When data is no longer needed, we delete or anonymise it using reasonable measures.
Security
We apply reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, AES-256-GCM encryption for stored third-party credentials, access controls, signed time-limited links for private files, and encrypted backups.
If a personal data breach occurs, we will notify the Data Protection Board of India, and affected users, as required by applicable law.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. Keep your login credentials confidential and notify us promptly of any suspected unauthorised access.
Your rights and choices
You can access and update most of your profile information directly within the platform at any time.
Subject to applicable law, you have the right to: obtain a summary of the personal data we process about you and who we have shared it with; have inaccurate or incomplete data corrected or updated; have your data erased; and receive a copy of the data you provided.
Nomination: you may nominate another person to exercise these rights on your behalf in the event of your death or incapacity. Contact us to record a nomination.
Where the UK/EU GDPR applies to you, you additionally have the right to object to or restrict certain processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority.
To exercise any of these, contact us using the details in section 19. We may need to verify your identity, and some data may be retained where required for legal, security, or audit reasons. We will respond within the period required by applicable law.
You can request account deletion at any time from your account settings.
Consent and withdrawing it
Where we rely on your consent, you can withdraw it at any time from the privacy controls in your account. Withdrawing consent does not affect processing carried out before you withdrew it.
The consents you control separately are: AI analysis of your profile; the managed apply inbox; and automatic capture of screening answers from the browser extension. Each one names, before you confirm, exactly which features stop working if you withdraw it.
Withdrawing a consent disables the feature that depends on it rather than allowing it to continue without your consent.
Grievance Officer
If you have a complaint about how your personal data has been handled, or about content on the Service, you can raise it with our Grievance Officer:
Name: [full name of the appointed Grievance Officer]
Email: [email protected]
Address: TECHPRAPT PRIVATE LIMITED, DLF Newtown, Akshayanagar, Bengaluru 560068, Karnataka, India
Please include your registered email address, a description of the complaint, and any information that helps us locate the account or content in question.
We acknowledge every complaint within 24 hours of receipt and work to resolve it within 15 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
If you are not satisfied with the outcome, you may escalate your data-protection complaint to the Data Protection Board of India.
Children and young users
Accounts created directly on aiesphere.com are intended for users who are 18 or older. We do not knowingly allow anyone under 18 to create an account on their own.
Where a school, college, or university provides the Service to its students, that institution may enrol students who are under 18 and supply their records to us, as described in section 10. In that case the institution is responsible for obtaining any consent required from a parent or lawful guardian before sharing that data with us, and we process it on the institution’s instructions.
We do not use a young user’s data for advertising, and we do not carry out behavioural tracking or profiling directed at them.
If you believe a minor has provided us data outside an institutional arrangement, contact us and we will take appropriate steps to remove it.
Third-party links
The Service may contain links to third-party sites or content (for example, news articles, courses, or company pages). We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.
Auto-Apply browser extension
AiESphere offers an optional companion browser extension ("Auto-Apply") that helps you complete job applications faster. The extension is installed separately, is not required to use the Service, and can be removed at any time from your browser.
Where it runs: the extension activates only on the supported applicant-tracking-system (ATS) domains it is built for (for example Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, and similar career/application pages). It does not read, monitor, or collect your general browsing on other websites.
Data it accesses on your behalf: to sign you in, the extension stores an authentication token locally in your browser’s extension storage. Using that token, it retrieves your AiESphere profile and resume data so it can populate application fields for you.
Data it writes: on the supported ATS pages you visit, the extension fills application form fields (such as your name, contact details, work history, and resume) with your profile data. It writes this information into the third-party application form only when you use it.
AI-drafted answers: for free-text screening questions we cannot answer from your saved answers, the extension can generate a draft using your profile and write it into the field for you. Drafts are generated by our AI provider from the question text and your profile. You can review, edit or replace any drafted answer before submitting, and you can switch this behaviour off in the extension's settings. You are responsible for the content of anything you submit.
Screening answers: the extension saves the screening questions you are asked and the answers given, so they can be reused on future applications. Answers are saved shortly after a field is completed — this includes answers you type yourself, and it happens whether or not you go on to submit that application. You can switch this capture off in your privacy settings, and you can ask us to delete your saved answers at any time using the contact details in this policy.
Equal-opportunity and demographic questions (sensitive information): many applications include voluntary self-identification questions covering gender, race or ethnicity, veteran status, and disability status. Where you answer these, the extension records the answer along with the other screening answers, and where a "decline to self-identify" option exists it may select that option by default. These answers are sensitive personal information (and special category data under the UK/EU GDPR). We process them only to complete and track your applications, we do not use them for profiling, advertising or any automated decision about you, and we do not sell or share them. You can switch off the extension's handling of these fields in its settings, decline to answer them on any form, and ask us to delete any we hold.
Application and page information: when you use the extension on an application, it records the application page address (URL), the employer and role as shown on the page, the applicant-tracking system in use, and the text of the job description from that page. On job listing and search pages of supported ATS sites, the extension also sends us the job links visible on the page so it can show you which of those roles you have already applied to. This is limited to links on supported ATS pages; the extension does not collect your general browsing history, and it does not run on other websites.
Fonts: the extension's in-page panel loads a web font from Google Fonts, which means your IP address is visible to Google when the panel is shown. We are working to serve this font from our own systems.
Third-party sites: the ATS websites where the extension operates are controlled by their own operators and governed by their own privacy policies. We are not responsible for their practices, and you should review their policies. Note that while the extension is filling a form, the data it writes is, by necessity, present in that page — which the site operator and any scripts they run may be able to observe.
Retention and deletion: extension-collected data is retained with your AiESphere account and deleted when you delete your account, or sooner on request. Removing the extension from your browser stops all further collection immediately and deletes the authentication token stored in your browser.
The extension does not sell your data, does not inject or run remote code, and requests only the browser permissions needed for the functions described above.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you. Where a change requires your consent, we will ask for it before relying on it. Continued use of the Service after changes take effect means you accept the updated policy.
Contact us
For any privacy question or data request, contact us at [email protected].
For a formal complaint, contact our Grievance Officer at [email protected] (see section 17).
TECHPRAPT PRIVATE LIMITED, DLF Newtown, Akshayanagar, Bengaluru 560068, Karnataka, India. Telephone +91-80-48533161. CIN U62099KA2026PTC221135.
Questions about this document? Email [email protected].

