How the JobAssist AI Chrome Extension collects, uses, and protects your data.
Effective date: June 9, 2026Last updated: June 21, 2026Applies to: JobAssist AI (Chrome Extension, Manifest V3)
JobAssist AI ("the Extension", "we", "us") is a Chrome browser extension that helps you
scrape job postings, auto-fill job application forms, and generate tailored resumes. This
Privacy Policy explains exactly what data the Extension handles, why, where it goes, and the
control you have over it. We have designed the Extension to be local-first:
your personal data is stored on your own device and is only transmitted to a third-party
service when a feature you actively trigger requires it.
1. Summary
We do not sell, rent, or share your personal data with data brokers or advertisers.
We do not use your data for advertising, profiling unrelated to job applications, or any purpose other than providing the Extension's features.
Your profile, resume, saved answers, scraped jobs, and API keys are stored locally in your browser (chrome.storage.local).
Data leaves your device only to the specific service required for a feature you trigger (resume tailoring, Google Sheets logging, or an AI provider you configure).
The Extension does not access your Gmail, Google Drive, files on your computer, or any local server.
2. Data We Collect and Store
All of the following is stored locally on your device unless explicitly transmitted (see Section 3). You enter or import this data yourself.
Category
Examples
Where stored
Profile / application data
Full name, first/last/preferred name, email, phone, date of birth, postal address, city, state, postal code, LinkedIn / GitHub / portfolio links, current job title, years of experience, education, university, graduation year, desired salary.
Local (chrome.storage.local)
Voluntary / sensitive self-identification
Gender, ethnicity, veteran status, disability status, LGBTQ self-identification, work authorization (US/Canada/UK), visa sponsorship needs, security clearance. These are optional and used only to answer equivalent application questions when you choose to provide them.
Local (chrome.storage.local)
Resume content
Resume text and/or an uploaded resume (PDF or DOCX) used for tailoring and autofill. Uploaded files are parsed locally in your browser.
Local (chrome.storage.local)
Saved answers (Knowledge Base)
Question/answer pairs you save or harvest from application forms so they can be reused.
Local (chrome.storage.local)
Scraped jobs
Job titles, companies, locations, descriptions, and links collected from job pages you visit (e.g., Jobright) and application status.
Local (chrome.storage.local)
Settings & credentials you provide
Your own AI provider API keys (Groq, OpenAI, OpenRouter, Google Gemini), optional local AI URL, Google Spreadsheet ID and tab name, and feature toggles.
Local (chrome.storage.local)
Account / identity
Your Google account email address (read via the Chrome identity API) and a cached approval status for the Resume Tailoring service.
Local (chrome.storage.local); email also sent to the Tailoring service (see Section 3)
The Extension does not collect browsing history, keystrokes on unrelated sites,
passwords, payment information, or content from pages outside the job/application sites it is
explicitly configured to run on.
3. How We Use Data & Third-Party Services
Data is transmitted off your device only when you trigger a feature that needs it.
The destinations are limited to the hosts declared in the Extension's manifest. The relevant
third-party services are:
3.1 Smart Resume Tailor API (resume tailoring & question answering)
What is sent: your resume text (or uploaded resume), the target job description, application questions (for AI-generated answers), and your Google account email address (used to verify that your account is approved to use the service).
Purpose: to generate a tailored resume and first-person answers to open-ended application questions, and to enforce a per-user approval allowlist.
Processing: the service uses Google's Gemini model server-side to generate output and returns it to your browser.
3.2 Google Sheets API (optional application tracking)
What is sent: a row containing the application date, company name, role, a link to your tailored resume, and the job link — appended only to a spreadsheet whose ID you provide.
Purpose: to maintain a job-application tracking sheet that you own and control. This feature is optional; if you do not configure a spreadsheet, no data is sent to Google Sheets.
We access only the spreadsheet you specify. We do not list, read, or modify other files in your Google account, and we do not access Google Drive or Gmail.
3.3 AI providers you configure (optional)
Endpoints (only if you enable and supply a key): Groq (api.groq.com), OpenAI (api.openai.com), OpenRouter (openrouter.ai), Google Gemini (generativelanguage.googleapis.com), or a local model URL you specify (e.g., Ollama).
What is sent: job descriptions, application questions, and relevant resume/profile snippets needed to generate answers.
Purpose: to generate application answers using the provider you choose. These calls use your API key and are governed by that provider's own privacy policy and terms.
If you do not configure any AI provider, these calls are not made.
3.4 Job sites you visit (e.g., Jobright, ATS portals)
The Extension reads job and form content from job sites and Applicant Tracking System (ATS) pages you open (Workday, Greenhouse, Lever, Ashby, iCIMS, SmartRecruiters, Taleo, Breezy, Jobvite, Workable, BambooHR, ApplyToJob, and similar).
It uses your existing logged-in session in those sites to read and fill forms. It does not collect or transmit your credentials for those sites.
Removed integrations. Earlier development versions referenced Gmail OTP reading,
Google Drive upload, and a local file-writer server (localhost).
These have been removed. The current Extension does not request Gmail or Google
Drive access, does not communicate with any localhost server as part of its core
features, and does not upload your files to Google Drive. Resume files you upload (PDF or DOCX)
are parsed locally in your browser and are never sent to Google Drive.
4. Legal Bases & Purpose Limitation
We process your data solely to provide the features you request: tailoring resumes, answering
application questions, auto-filling forms, and (optionally) logging applications to your own
spreadsheet. We do not use your data for advertising, resale, credit scoring, or any
purpose unrelated to helping you apply for jobs.
5. Data Retention
Local data (profile, resume, saved answers, scraped jobs, settings, API keys, cached approval status) persists in your browser until you delete it, clear the Extension's storage, or uninstall the Extension.
Resume Tailoring service: requests are processed to generate output and return it to you. Your approval record (email address and status) is retained by the service to enforce the allowlist; you may request its deletion (see Section 6).
Google Sheets: rows written to your spreadsheet remain in your Google account and are controlled by you.
Third-party AI providers: retention is governed by each provider's own policy.
6. Your Rights & How to Delete Your Data
View / edit: open the Extension and review or change any profile field, resume, or saved answer at any time.
Delete local data: use the Extension's "Clear" controls, remove individual saved answers, or remove the Extension from chrome://extensions. Uninstalling permanently deletes all locally stored data.
Delete tailoring-service records: contact us (Section 11) to request deletion of your approval record (email address and status) from the Resume Tailoring service.
Spreadsheet rows: delete any rows directly in your own Google Sheet.
Depending on your jurisdiction (e.g., GDPR/CCPA), you may have additional rights to access, correct, port, or erase your data. Contact us to exercise them.
7. Security Practices
All network requests are made over HTTPS.
Personal data is stored locally in your browser's extension storage rather than on our servers.
The Extension requests the minimum permissions needed and limits host access to specific job/ATS domains and the named API endpoints in its manifest.
Access to the Resume Tailoring service is gated by a per-user approval allowlist.
No security system is perfect; we cannot guarantee absolute security, and transmission of data is at your own risk. Keep any API keys you enter confidential.
8. Children's Privacy
JobAssist AI is intended for job seekers who are 16 years of age or older and is
not directed to children. We do not knowingly collect personal information from children under 13
(or the minimum age in your jurisdiction). If you believe a child has provided us with personal
data, contact us and we will delete it.
9. Chrome Web Store Limited Use Disclosure
JobAssist AI's use and transfer of information received from Google APIs adheres to the
Chrome Web Store User Data Policy,
including the Limited Use requirements. Specifically:
We only request access to data that is necessary to provide the Extension's features.
We use Google user data only to provide and improve the user-facing features described in this policy.
We do not transfer Google user data to third parties except as needed to provide or improve those features, to comply with applicable law, or as part of a merger/acquisition with prior consent where required.
We do not use Google user data for advertising, and we do not sell Google user data.
We do not allow humans to read Google user data unless we have your consent for specific data, it is necessary for security/legal compliance, or the data has been aggregated and anonymized.
Where applicable, the Extension's use of information received from Google APIs also complies with the
Google API Services User Data Policy,
including its Limited Use requirements.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Extension or legal requirements.
Material changes will be indicated by updating the "Last updated" date above and, where
appropriate, through the Extension. Continued use after an update constitutes acceptance of the
revised policy.
11. Contact
For privacy questions, data-deletion requests, or any other concerns about this policy, contact: