Last updated 3 October 2026 · This policy applies to foriforeign.com, the ForiForeign app and the forimail.com mailboxes we operate for applicants.
What this means for you
Your CV and documents are stored encrypted, used only for the applications you choose, and deleted when you ask: a deletion request is completed within 30 days.
Nothing is sent in your name until you have seen it and pressed Send yourself.
We do not sell your data, and no advertising ever appears inside the signed-in app or beside your documents.
You can download everything, correct it or close your account from your Profile at any time.
Questions and requests go to admin@foriforeign.com. The data controller is ForiForeign.com, named in section 1.
1. Who we are
ForiForeign.com (the registered business named on the Legal page: FBR NTN 3740563858417, PSEB Z-25-22541/26) operates ForiForeign and is the data controller for applicants who use the platform directly. Write to admin@foriforeign.com, or by post to ForiForeign.com, 3rd Floor, Block 17-D, Bella Road, G-10 Markaz, Islamabad, Pakistan, for anything in this policy.
When a consultancy, university or employer uses the platform for its own clients, that organisation is the controller and ForiForeign is its processor, as set out in the data processing terms.
2. What we collect
Account details: name, email address, phone number, country, language and the profile you complete.
Documents you upload: CV, certificates, transcripts, language test results and, only if you switch it on, confidential items such as bank statements or visa papers.
Correspondence: mail sent to the ForiForeign mailbox we create for you, and messages you send from the app.
Applications: the positions you choose, the documents prepared for them and the replies received.
Payments: what you bought, when, for how much, and the transaction reference the payment provider returns. Your card details go to the payment provider (Safepay); ForiForeign never sees or stores a full card number and never asks for a bank password.
Technical data: the session token, your language choice and basic server logs (IP address, browser, time) kept for security.
3. Why we use it
To find and verify study places and remote jobs that match your profile, and to prepare the applications you decide to make.
To read and organise your correspondence so the app can show you the next step.
To take payment for the package you chose and to keep the records tax law requires.
To keep the platform secure, detect fraud and answer your questions.
To improve the platform, using aggregate figures that identify no one.
The legal bases are the contract with you, our legitimate interest in running a secure service, your consent where we ask for it (for example a connected portal or a confidential document), and legal obligations such as tax records.
4. Automated reading and writing
Your documents and mail are read by automated systems, including AI models from Anthropic, Google and OpenAI, to extract facts, check consistency and draft documents for your review. Under their API terms these providers do not train on your data. Every document prepared for you is shown to you before anything is sent, and it is sent from your own address in your name.
The assistant (“Let’s talk”). It gives general information. It is not legal, immigration or financial advice, and it cannot promise any outcome.
Messages you type are processed by an AI model to write a reply.
A voice message or a live voice conversation is sent to our AI provider (Google) to be turned into text and answered. We do not store the audio.
A file you attach in the chat is read once for a first impression of your CV. It is not stored and is not added to your account.
To improve answers we keep, for 180 days, the topic, the language and the question with email addresses, phone numbers, long numbers and links masked. We do not keep audio, attachments or the replies.
The conversation you see is kept only in your own browser until you clear it.
The Apply Assistant (browser extension). If you install it, it works only in a browser tab you open from your ForiForeign case, and only on a portal website you allowed. What it does:
It types the details from your case into that portal's form and attaches documents from your case when you press the button to attach them. It never presses Submit, Send or Pay.
It reads what the portal shows about your application (for example the application number, status, deadlines, fees, requested documents, appointments and decisions) and saves it on your case. A letter or receipt on that site is saved to your case only when you press "Save to my case".
On a portal's sign-up page, and only when you press the button, it can create a strong password for that portal, type it into the new-account form and keep it encrypted in your ForiForeign account. It never types the password you use to sign in, one-time codes, CAPTCHA answers or payment details.
When you ask, it places an application email ForiForeign prepared into your own Gmail, Outlook or Yahoo compose window. It never reads your mailbox and never sends.
It keeps your case details only in the browser's session memory, which is cleared when you close the browser. It sends nothing to anyone other than ForiForeign, and nothing is used for advertising.
When a consultancy works your case for you, what it saves is marked as done by your consultancy.
You can remove it at any time from your browser's extensions page.
5. Who receives your data
Only the services that run the platform, each receiving what its function needs: Supabase (database, storage, sign-in), Railway (hosting), Anthropic, Google and OpenAI (document reading and writing), Resend and Cloudflare (email on forimail.com), Safepay (the card payments you make), Meta (WhatsApp notifications when you enable them) and Google (page translation when you pick a language). Universities and employers receive only the application you chose to send.
We do not sell personal data, and we do not share it with data brokers.
6. Where it is stored
Data is stored on infrastructure in the region set in the platform (currently Singapore) and processed by the providers above in their own regions, under standard contractual clauses or equivalent safeguards where the law requires them.
7. How long we keep it
Active accounts: for as long as the account exists.
Closed, rejected or withdrawn cases: prepared documents and mail bodies deleted 180 days after closure; an audit line stays.
Inactive accounts: documents and personal fields purged after 18 months of inactivity, with notice by email.
Payments and invoices: for the period tax law requires (six years in Pakistan).
Consents: for the life of the account plus the statutory limitation period.
Assistant analytics (masked questions and counts): 180 days.
Deletion requests: completed within 30 days unless a legal retention applies, and confirmed to you.
8. Your rights
You can download all your data or request deletion from your Profile, or by writing to admin@foriforeign.com (or to the postal address in section 1). We answer within 30 days. You may ask us to correct data, to restrict or object to processing, and to withdraw a consent at any time. You may also complain to the data-protection authority of the country you live in. Nothing here limits the rights you have under that country's law.
This policy is governed by the laws of Pakistan, as the Terms of Service state. Our liability for personal data is as set out in the Terms, section 9: limited to the extent the law allows, and never for what the law does not allow to be limited.
9. Cookies and local storage
The platform sets only what the service needs: the session token, your language choice, a dashboard snapshot for speed, and the translation preference when you pick a language. These are strictly necessary and are not used for tracking. The full list, and how to change your choice, is in the Cookie Policy.
10. Advertising
Public pages of foriforeign.com may in future carry advertising served by Google AdSense. If they do, Google and its partners, as third-party vendors, use cookies to serve ads based on your prior visits to this and other websites, including the DoubleClick cookie. Advertising cookies are set only after you allow them in our consent banner, which is shown before any advertising loads.
You can opt out of personalised advertising at Google Ads Settings and at aboutads.info. Advertising never appears inside the signed-in app, and never on pages that show an applicant's documents or correspondence.
11. Security
Documents are encrypted at rest. A portal password is stored only if you choose to connect a portal, only in encrypted form (the platform refuses to store it when encryption is not available), and it is deleted when you disconnect. Access is by role and is logged; staff cannot read an organisation's client list. If a breach affects your personal data we will tell you and the authority without undue delay.
12. Age
ForiForeign is for people aged 18 or over. A person under 18 may use it only with a parent or guardian who accepts the terms on their behalf and manages the account.
13. Changes
When this policy changes, the date above changes and the app shows the new version at the next consent point. Earlier versions are available on request.