Effective: June 2026
Your name, contact details, optional cover letter text, an optional
CV PDF, and (if you connect an account) your Applai auth token — all
stored exclusively in your browser via chrome.storage.local.
This data never leaves your device unless you explicitly connect the
extension to your own Applai account.
chrome.storage.local
is stored in plain form on your device's disk, like most browser
extension data. Anyone with access to your operating-system user
account could read it. Only store a CV you're comfortable keeping
there, and use Clear stored data (below) on a shared
machine.
When you click an autofill button, the extension fills visible form fields on the page you are viewing and attaches your CV to the form's file input. It never submits forms, never runs in the background, and never fills anything without your click (except showing an inert button on known job-application sites).
If you connect an Applai account, the extension communicates only
with Applai's own hosted API (api.useapplai.com) or your
local dev server: to sign in, import your profile, and generate
cover letters from job descriptions you choose. The first request to
the hosted API asks the browser to grant access to that specific
host — the extension has no standing access to any other site.
Nothing. The extension has no analytics, no tracking, no remote logging, and no third-party services.
Click Clear stored data in the popup to wipe your profile, CV, cover letter, token, and API URL from this browser at any time. Removing the extension deletes everything too.
Questions about this policy: reach us via useapplai.com.