Privacy policy

FormFolio Privacy Policy

FormFolio is a local-first Chrome extension for filling job application forms from answers provided by the user. This policy describes the 0.16.0 release. The Chrome Web Store listing shows the version available for installation; this policy does not indicate publication or Google approval.

What FormFolio sends

Answers and resumes are not included in reports. Optional reports exclude saved profile values, answers, documents, full URLs, and page HTML. Updated one-time setup approval permits automatic reports with screened question/options and diagnostic details. Text may still identify people despite screening. Start without sharing leaves automatic reports off. Existing category-only consent is not broadened automatically.

Data handled by the extension

The extension can handle data that the user chooses to save:

Local storage

Saved data is stored in Chrome extension local storage for the browser profile where the extension is installed, and survives package updates. Canonical application scope removes tracking/session parameters from identity. Known ATS tenant routes can establish employer scope; unknown forms use conservative application scope. Scope may identify an employer or application. Scope, journal, private repair IDs, and Undo data stay private and are included in private backups, not reports.

The milestone counter stores no website or employer information. It keeps only successful-use timestamps, removes entries older than 30 days, and is used to show the optional-reporting invitation at 10 uses and the optional support message at 20 uses. Reporting reminders defer for 30 days; support reminders defer for 90 days or 180 days after opening the support link. Reporting invitations are hidden while setup is offered and whenever reporting is enabled. Setup does not reset history or cooldowns.

Resume extraction

PDF, DOCX, and TXT resume text is processed locally to create grounded contact and professional profile facts. Resume text is not transmitted to the developer or a remote extraction service.

Page access

Before Start FormFolio or Use recommended setup, the disclosure explains required-field filling, local memory including eligible sensitive answers, supported required acknowledgment and application terms/privacy acceptance, on-device AI when available, and screened question/options with answer-free diagnostics. Acceptance on your behalf may have legal effect; review linked terms yourself. Start without sharing enables the same local features without automatic reports. Setup requests website access. It inspects pages locally and activates when a job-application detector passes. Use FormFolio here can instead confirm the current top-level application page without changing consent. Confirmation stays in that document, not unrelated routes or embedded frames. Login, password, payment, account, and submitted pages remain blocked.

Automatic document attachment requires strong application context and an upload identified as required. A resume can be stored without being attached. Optional fields and uploads, and fields not identified as required, are never filled, including with manual Fill. Heuristic-only matches leave documents for manual review. Enabled filling and attachment place information on the employer page, separately from FormFolio's reporting service.

Setup is never enabled automatically on installation or update. Individual controls are in Advanced. Ordinary Stop/Start keeps sensitive, acknowledgment, AI, and reporting choices; Apply recommended setup explicitly reapplies the disclosed bundle. Imports preserve consent. When learning is enabled, committed entries and corrections are saved on text blur/change, native selection changes, and supported custom-choice clicks. There are no idle-timer saves or keystroke logs. Clearing a required answer rejects the prior answer until a replacement is supplied, not the question forever. Optional clears create no persistent blank preference. Inferred keep-blank records migrate to rejection; explicit custom rules remain. Stop disables automatic filling and learning.

Both setup choices enable eligible sensitive learning and filling. Each can be disabled independently in Advanced, including manual Learn. Without setup or explicit enablement they remain off. Protected password, government-identifier, birth-date, signature, factual-attestation, and employee-ID values are never filled or retained in learning. Answer-free private metadata can retain a manual-only policy. Sensitive-off episodes exclude before/after values. Extension-generated fill events are ignored.

Required acknowledgments and application terms

A separate disclosed choice can enable acceptance of supported required single-choice informational acknowledgments and application terms/privacy agreements on your behalf. This may have legal effect; review linked terms yourself. The choice is independent of sensitive filling and diagnostic sharing. Individual opt-out is in Advanced. Disabling acceptance does not withdraw selections already on the form.

Existing users keep acceptance off until explicit approval of the disclosure that includes it, or the individual control. The acknowledgment approval is separate from diagnostic setup approval; earlier setup messages and ordinary Stop/Start do not enable it. Optional, multiple, ambiguous, signature, factual-certification, background/criminal/credit-check, marketing, and other excluded authorization controls remain manual.

Agreement values are not learned as applicant facts, and AI does not decide acceptance. With local memory enabled, unchecking an automatic acceptance can save an answer-free manual-only rule for that question and scope. Undo changes the stored rule, not the live application.

Eligible commits are observed independently of successful mapping or answer learning. The missed-field picker can select an unrecognized control for diagnostic evidence. Typed repairs distinguish contact fact synonyms, option equivalence, rejected categories, employer responses, and rejected prior answers. Similar wording alone does not authorize copying an answer into a different context.

A committed blur save is handed to the background before awaiting completion, but instantly killing a tab or browser can interrupt it. Navigation is not an absolute save guarantee. Undo last save affects stored memory only, never the live application, and invalidates inference from the undone episode. Background inference, AI, and collector failures never discard a committed local repair.

On-device AI

When enabled and supported by Chrome, the built-in on-device model can classify bounded question, section, option, control, and attempted-category context. An eligible local answer is included only where learning consent permits retention. Answer-free negative, cleared, and scoped tasks are permitted. This processing occurs on the device. No prompts, profile values, or form contents are sent to a remote model service.

Deterministic matching handles known questions before the model. Automatic analysis uses Chrome's Gemini Nano in the extension background worker, not the employer page's content script. Diagnostic analysis receives question context and answer-free decision evidence, not applicant answer values. Validated model proposals become local facts and matching rules; FormFolio does not train or fine-tune model weights. Numeric facts preserve exact values, bounds, units, and context; ranges do not become invented exact values.

Unfamiliar completed questions can remain temporarily in a local processing queue so classification survives page navigation. The queue stays in Chrome extension storage and is never shared between users. The exact repair is saved before optional generalization. Model output is untrusted and checked for category, scope, sensitivity, source episode, and contradictions. Invalid or unavailable inference leaves the exact repair intact. Chrome device, storage, and model requirements apply. Setup does not download a model or guarantee availability. Prepare on-device AI is an optional Advanced action when supported. Unavailable AI does not block setup, deterministic filling, or local memory; no remote or paid AI fallback is used.

Community question intelligence

FormFolio includes versioned patterns for common public application questions. These patterns identify question meaning only. They do not contain applicant answers and are bundled with extension releases.

Optional sanitized contribution mappings remain local until the user explicitly exports them. Exported mappings exclude saved answers, resumes, URLs, and profile values. Sanitization can miss company names or other identifying wording, so users should review exports before sharing.

Export creates a local file only. FormFolio does not upload or send that file. A user can separately choose to share an exported, answer-free mapping with the maintainers for review and possible inclusion in a later extension release.

Optional mapping improvement reports

Ongoing reporting stays off until recommended setup after the disclosure, or explicit Advanced opt-in. Start without sharing leaves it off. Reporting can be disabled independently of local learning; ordinary Stop/Start does not re-enable it. Automatic report failures do not discard local corrections.

Report issue includes a missed-field picker. With automatic diagnostic consent, selecting a problem queues screened evidence without another approval. Otherwise, optional one-off review uses a trusted extension page and explicit Send. The employer page cannot grant consent. Manual review sessions are ephemeral and bounded, and a one-off send does not enable ongoing sharing.

Automatic examples are limited to ten attempts in a rolling day and accepted duplicates are suppressed for thirty days. Local hashes and timestamps enforce this policy and are not sent. Unsafe examples stay local. Clear all and opt-out invalidate queued examples; a request already sent cannot be recalled. Failed reports never discard local repairs. After a suspected mapping problem, an opted-out customer may see a nonblocking invitation at most once per thirty days, with Not now and Don't ask again. Accepting in the protected sharing page changes reporting only, not local AI or sensitive-answer choices.

Fixed-category correction feedback

The mapping_feedback signal does not need AI. It contains only action, control kind, field type, built-in previous/corrected semantic categories, question category, and a first/repeat bucket. The envelope adds report and software versions and ATS family, with public rule/version provenance for the attempted decision. It has no question or option text, answers, custom IDs, hostnames, URLs, hashes, timestamps, or user counts.

Question and control examples

Under updated setup approval, automatic examples use the distinct diagnostic_example type. Individually reviewed examples use reviewed_example. A minimal example can contain question and section wording, public options, allowlisted control relationships, required status, and attempted-decision provenance, together with software versions and ATS family.

Diagnostic details can include issue category, answer-transformation category, write status, option-list completeness, answer-shape and comparison categories, and candidate semantic categories with source categories, bounded matching scores, and decision outcomes/reasons. A candidate outcome describes a matching rule, not the applicant's selected option. Protected-question diagnostics omit answer shape and comparison. Private fact values, answer snippets, and selected option indices or flags are excluded.

Evidence excludes entered or selected answers, selected flags, saved answers, resumes, files, full page URLs, page HTML, arbitrary DOM attributes, profile values, private scopes and repair IDs, and user identifiers. Allowlisted structure is extracted instead of uploading a complete page. Questions and options, including sensitive wording, can identify people. Automatic preparation rejects known unsafe text; manual review permits editing or cancellation. Sanitization alone does not guarantee anonymity.

Identifier questions omit options. Sensitive questions strip free-text choices; a narrow exception permits only fixed public gender vocabulary spanning at least two categories. Every label must pass the allowlist. Examples use the complete public choice list, never a selected answer or before/after pair. This does not make arbitrary sensitive text safe to share.

The collector retains legacy sanitized question/control schemas for older clients. Earlier category-only consent does not authorize automatic question examples without updated approval.

Optional reports target the maintainer's Cloudflare Worker, using signals only to improve reviewed FormFolio rules. Cloudflare processes the network request under its own privacy and security terms. Disabling the setting stops automatic reports and removes the service-specific Chrome permission. A later one-off report requires its own confirmation and permission.

Maintainer tools require explicit review of automatic evidence. Report frequency is neither distinct customers nor ground truth. Candidates and synthetic fixtures are validated against different fictional profiles and negative cases, never customer answers. Explicit review binds content and validation before packaging. There is no server AI retraining, remote runtime code, or automatic publication. No paid AI or always-running model is required. Quota/network failure affects reporting only, without upgrading billing or rolling back local saves.

Data sharing and monetization

The extension does not sell, rent, share, or use application data for advertising, credit decisions, or unrelated purposes. Optional learning signals are used only to improve reviewed question, option, and control mappings in later FormFolio releases.

Safety restrictions

Deletion and export

Private learning shows recent question/action/category metadata, scope, and repair status, not raw before/after values. Enable/Disable generalization controls a derived repair without removing the exact saved answer. Enable/Disable saved override controls exact personal repairs without deleting stored answers. Protected fields remain manual regardless of these controls. Clear learning history (keep saved answers) clears episodes, Undo history, and episode-linked pending inference, preserving answers and repairs.

Users can edit answers in profile/custom mappings editors or by correcting an application, manage exact repairs with saved override controls, undo a local save without changing the form, export a private JSON backup, clear all extension data, or uninstall. Clearing extension data does not delete exported files or reports already sent.

Chrome Web Store Limited Use

Use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Contact

Privacy questions can be sent to . See the Support page for contact options.