Folioflight · a project by Prashant Jacob
Folioflight Privacy Policy
Last updated: 2026-09-30
- Your profile, resumes, answers and application history stay in your browser.
- Matching runs on your computer. No cloud AI.
- The only downloads: the matching model (once, from Hugging Face) and public job-posting data.
- It never submits, never sends email, never invents answers.
- Nothing runs on LinkedIn unless you turn quiet mode off.
Who we are and what this covers
Folioflight is a Chrome extension that fills job application forms from a profile you keep, records which resume version you sent, and keeps a board of your applications up to date from your email. This policy describes exactly what data it reads, where that data is kept, and every network connection it makes.
There is no Folioflight server, account or sign-in. The developer does not receive any of your data.
Where your data is kept
Everything you enter or the extension records is stored on your computer, in this browser profile’s extension storage (chrome.storage.local and IndexedDB):
- your profile (contact details, address, work history, education, screening answers, optional self-identification answers, references, photo if you add one);
- your resume and cover-letter files and the text read from them;
- saved answers, “fix this field” rules, and answers learned from what you type into forms;
- your applications (company, role, status, dates, notes, saved job postings, contacts, interviews);
- email suggestions waiting for your confirmation (sender, subject, preview text, detected status);
- job pages you opened on job sites (address, company, title, date) — used for “reposted” and “already applied” warnings;
- which job sites you created accounts on and the email address you used (never passwords);
- diagnostics about filling (per site: counts of fields found, filled and failed, the question text of fields that failed — never your values);
- fields you report with “Report a miss”: the field’s markup and question, with your values and profile text removed. They leave your computer only if you export the file and send it yourself.
Uninstalling the extension deletes all of it. Settings → Danger zone deletes it without uninstalling.
Every network connection the extension makes
- The matching model: the first time local AI matching is used, the model files (Xenova/all-MiniLM-L6-v2, about 23 MB) are downloaded once from huggingface.co and cached in the browser. Only the files are requested; none of your data is sent. You can turn local AI off in Settings.
- Public job-posting data: when you open a job on Greenhouse, Lever or Ashby, the extension asks that site’s public API (boards-api.greenhouse.io, api.lever.co, api.ashbyhq.com) for the posting’s text and publication date, and on Workday it asks the same Workday site for the posting’s public JSON. The request contains only the job’s identifier from the page address.
Nothing else. There are no analytics, no crash reporting, no advertising, and no remote code: all program code is inside the extension package.
Separately, Chrome may download its own built-in model (Gemini Nano) if you ask it to in Settings → Local AI; that download is handled by Chrome, and the model runs on your device.
What it reads on web pages, and why
- Job application pages on the job-site platforms listed in the store listing (and, only if you allow it, other career sites): the form’s fields and their labels, to fill them; the job posting, to save it with your application; the button you click (Submit / Next), to mark the job applied and to check that filled values were kept; the email address you type when you create an account on a job site, so you know which email you used there. Password fields are never read.
- Gmail and Outlook on the web, only after you allow it: the sender, subject and preview text of messages in the list you are looking at, and the text of the email you open, to detect updates about your applications (received, interview, rejection, offer…). This happens on your computer. Only messages that look job-related are kept, as suggestions, until you confirm or dismiss them. “Scan my inbox” (which you start) opens a Gmail search for application emails and reads the result list the same way. The extension never sends, deletes, moves or marks email.
- LinkedIn: nothing. Quiet mode is on by default; if you turn it off, LinkedIn pages are treated like other job sites.
Learning from what you type
When you type an answer into an application form yourself, the extension can remember it on your computer so the next form fills it (for example a profile field that was empty, or a custom question). You can undo each one, review them in the dashboard, or turn this off in Settings. It never learns from password, ID-number, bank, card, date-of-birth or signature fields.
What it never does
- It never submits an application, clicks “Next”, sends an email, or posts anything for you.
- It never writes answers, cover letters or messages: the AI only chooses among information you already entered.
- It never sells, rents or shares your data, and never uses it for advertising, credit, lending or any purpose unrelated to the features described here.
Permissions and why each is needed
- Access to job-site platforms (Workday, Greenhouse, Lever, iCIMS and the others listed): to read and fill application forms there.
- Access to boards-api.greenhouse.io, api.lever.co, api.ashbyhq.com: to save public posting text and dates (see above).
- storage, unlimitedStorage: to keep your profile, resume files and history on your computer.
- scripting, activeTab: to fill a form in the tab you are using when you press the toolbar button or keyboard shortcut.
- contextMenus: for “Folioflight: fix this field…” on right-click.
- alarms: for follow-up reminders, interview reminders and weekly backups.
- offscreen: to write the weekly backup file into the folder you picked.
- Optional, only when you turn the feature on: Gmail / Outlook (email tracking), other websites (company career sites), LinkedIn (if you turn quiet mode off), notifications (reminders), downloads (backups to your Downloads folder).
Backups
Backups are files written to a folder you choose, or to your Downloads folder. They stay on your computer (or wherever you move them). They contain everything listed under “Where your data is kept”, including resume files.
Chrome Web Store User Data Policy
Folioflight’s use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide the features described in this policy and shown in the extension, is not transferred to anyone, and is not used or read by the developer.
Children
Folioflight is a job-search tool and is not directed at children under 13.
Changes and contact
This policy was last updated on 2026-09-30. Changes are published with the extension (Dashboard → Privacy) and at the privacy policy address on its Chrome Web Store page.
Questions: use the support contact on the extension’s Chrome Web Store page.