Privacy Policy
Last updated 2 August 2026
The short version. Applytrac detects job application form fields, fills them from a profile you control, and tracks the applications you submit. It requires an account and does nothing at all until you sign in. Your profile is stored in your own browser; your Resumes and the applications you submit are saved to your own account so you can track them. We do not sell, rent or trade your personal information or job application data to anyone, and we do not use it to train AI models. Anything optional is off until you switch it on, and you can delete everything at any time.
1. Single purpose
Applytrac has one purpose: to detect job application fields and help you auto-fill and track job applications. We do not use the extension for advertising, analytics resale, price comparison, content injection, or any purpose unrelated to that.
2. What we collect, and where it lives
Your saved profile — contact details, work history, education, the answers you reuse and the per-site corrections Applytrac learns — stays on your machine. The extension stores it in chrome.storage.local, which is sandboxed to the extension and unreadable by the websites you visit. It is not encrypted at rest, so anyone with access to your computer and your Chrome profile can read it. Two things are deliberately not local, because being local would break them: your Resumes, and the applications you actually submit. The table below is the complete list.
Resumes are the exception, and deliberately so: they are stored in your account, so the web app and every browser you sign in from use the same set instead of a per-browser copy that drifts. Deleting a Resume in the web app removes it everywhere, including the file.
| Data | Where it lives | Why |
|---|---|---|
| Contact details, work history, education, answers you reuse, learned per-site corrections | Your browser only (chrome.storage.local). Never uploaded. | Filling forms without sending your details to a server. |
| Your Resume files and their text | Our database and private file storage, in your account. Requires being signed in. | One Resume Vault behind both the web app and the extension: you upload once and can fill, score and attach with it from anywhere, and your history shows which Resume went to which company. |
| Account email, name, password | Our authentication provider (Supabase, hosted in the United States). | Signing you in and linking your pipeline to you. |
| Applications you submit: company, role, job URL, job description, the questions and the answers you submitted, which Resume you used, status and your notes | Our database, in your account. | This is the tracker itself — the application list and reminders you came for. |
| Usage counters (number of autofills and AI drafts per month) | Our database, in your account. | Enforcing free-plan limits and billing. |
| Payment details | Stripe. We never see or store your card number. | Subscriptions. |
| Optional: redacted field-structure reports and field mappings | Our servers, in a table with no user column — not linked to your identity. | Improving field detection for everyone. Off unless you switch it on (see §6). |
3. We do not sell your personal information
Applytrac does not sell, rent, or trade your personal information or job application data to third parties. We do not share it for cross-context behavioural advertising, and we have no advertising business. We use a small number of processors strictly to run the product — Supabase (database and authentication), Stripe (payments), and Anthropic (AI drafting, see §5) — and they may only process data on our instructions.
4. Site access, stated plainly
The extension asks Chrome for access to all websites, and Chrome shows you that at install. It needs the breadth because job applications are not submitted in one place: they are on the big boards, on the applicant tracking systems behind them (Greenhouse, Lever, Workday, Ashby, iCIMS and others), on every company’s own careers domain, and inside the third-party frames those forms embed. That list cannot be written down in advance, and asking for permission mid-application is not something we are willing to put in your way.
What we do with that access is narrower than the permission itself:
- Nothing happens until you sign in. A signed-out install reads no page, fills nothing and sends nothing. Sign out and it stops on pages already open.
- Nothing happens in a frame that has no form. The extension checks for form fields first and does not load your profile into frames that have none.
- Filling is a click, not a default. Auto-fill on page load is off until you turn it on, and even then only on a recognised application form.
- We never inject content into pages and never read pages that are not job applications.
You can narrow the access yourself at any time: in chrome://extensions set Applytrac’s site access to On click or to specific sites. If you do, use “Enable Applytrac on this site” in the popup to grant a site when you need it.
5. How AI requests are handled
Field detection itself uses no AI and no network: it runs on rules shipped inside the extension, plus a shared mapping cache described in §6. Nothing about the form leaves your browser in order to fill it.
Two features send personal content. Draft with AI runs only when you click the button next to a screening question, and sends that question along with your Resume text and the answers you have saved before, so an answer can be written for you to edit. Drafted text is surfaced for you to review and is never submitted for you.
The match score sends your Resume text and the job description shown on the page, and returns the percentage, the skills you cover and the ones the posting asks for that you do not. It runs when you open Applytrac on a job posting. If you would rather it did not run, close the popup on job pages, or sign out — signed out, the extension makes no requests at all.
These requests are processed transiently through our API endpoints to Anthropic’s API and are not used to train AI models. We keep the drafted answer only where you can see it — in your answer bank or the application record.
6. The shared field-mapping cache, and the one opt-in switch
Application forms repeat. When Applytrac works out that a particular field on a particular applicant tracking system is “phone number”, that knowledge helps the next person who meets the same form. Two things follow from that, and they are deliberately separate:
- Reading the shared cache is on by default. When Applytrac meets a field it cannot place, it asks our server whether other users have already resolved the same one. The request carries the applicant tracking system’s name and a hashed fingerprint of the field layout — never your answers, never your Resume, never the page’s contents.
- Contributing back is off until you switch it on. Under Settings → Your data, “Help improve field detection” is off by default. When you turn it on, Applytrac shares the field mappings it worked out (a signature hash and the field type it turned out to be) and reports the redacted shape of fields it failed to recognise — tag names, labels and nearby text, with email addresses, URLs, Social Security / national ID numbers, payment card numbers, phone numbers, dates and street addresses stripped out, plus any exact value we know is in your stored profile. Turning it off again discards anything still queued locally, unsent.
Neither of these is stored against your account. The reports table has no user column at all — a valid session is required to send one, so the endpoint cannot be used as an open firehose, but the identity is discarded before anything is written. There are no screenshots and no session recording: the extension does not bundle rrweb and has no code path that captures a replay of a page.
7. Your rights and how to exercise them
If you are a California resident, the CCPA/CPRA gives you the right to know what we collect, to delete it, to correct it, and not to be discriminated against for asking. You do not need to be in California to use any of the controls below.
- Delete everything on your device: extension → Settings → Account → Delete my data → “Wipe this browser”.
- Delete your account and all cloud data: web app → Settings → Delete account. This permanently removes your pipeline, Resumes, answers, notes, usage history and your login. It cannot be undone.
- Export: any application can be downloaded as a Markdown profile from its detail panel.
- Correct or ask a question: email privacy@applytrac.com.
8. Retention
Pipeline data is kept until you delete it or close your account. Anonymous field-structure reports are retained in aggregate and are not tied to you. Local browser data lives until you wipe it or remove the extension.
9. Children
Applytrac is not directed to children under 13 and we do not knowingly collect their data.
10. Changes
If we change how data is used, we will update this page and the date above, and any new data sharing will remain off until you opt in.
Questions? privacy@applytrac.com