1import{j as e}from"./animation-CddyXVCz.js";import{B as n,ae as i,ah as d}from"./index-DnWsV7cE.js";import"./react-vendor-CbN3pvl2.js";import"./supabase-iKSPld20.js";import"./docgen-Bp8WKBAE.js";import"./query-DPqpbKNH.js";const h={title:"Browser Extension Privacy Policy",lastUpdated:"September 25, 2026",sections:[{heading:"Scope",paragraphs:['This policy covers the CareerDiary browser extension: "CareerDiary Resume Tailor & Job Autofill" for Chrome, and "CareerDiary Assistant", the Safari extension inside the CareerDiary Mac app. It adds to the main CareerDiary Privacy Policy at https://careerdiary.io/privacy, which covers your CareerDiary account and the careerdiary.io web app.']},{heading:"What the Extension Does",paragraphs:["On supported job sites the extension reads the job posting and the application form you are viewing. It shows how well the job matches your CareerDiary profile, fills application fields from your profile, drafts answers to application questions from your career diary, attaches a resume you tailored in CareerDiary, saves jobs and tracks your applications in your CareerDiary account, and opens the CareerDiary tailor with the job already filled in. It never submits an application for you."]},{heading:"What It Reads on Job Sites",paragraphs:["The extension runs only on the job sites named in its permissions (for example LinkedIn, Indeed, Greenhouse, Lever, Workday and Ashby), and on another page only when you open the assistant there yourself with its keyboard shortcut. There it reads:"],bullets:["The job posting on the page: title, company, location and description.","Application form fields: their labels and types, to decide what to fill. Values you have typed are read only so they are not overwritten, and are never sent.","Job cards on LinkedIn, Indeed, Glassdoor and ZipRecruiter search results: title and company, to show match scores.",'Your own LinkedIn profile sections, only when you click "Sync from Diary", compared on your device.']},{heading:"What It Sends to CareerDiary, and When",paragraphs:["When you are signed in, the extension sends CareerDiary:"],bullets:["Automatically: requests for your profile and saved jobs, to keep them in sync (on start-up, at sign-in, and every few minutes while your browser is open).","Automatically: the titles and companies of job cards on search results, and of roles on a company careers page, to score them against your profile.","Automatically: up to 5,000 characters of the page text when a job posting cannot be read from the page structure, so our servers can pick out the job.",'Automatically: when you submit an application on a supported site, the job title, company and page address, saved to your application tracker as "applied" (you can undo it).',"When you use a feature: the job details that feature needs. Saving a job sends its title, company, description, location, notes and page address. Match scores, cover letters and keyword analysis send the job details. Drafting an answer sends the question and the job details."]},{heading:"When You Are Not Signed In",paragraphs:["Nothing from the page is sent, except when you try a draft: the question, the job details and the experience text you paste are sent to generate that draft, and are not saved to an account. The usage counts below still apply."]},{heading:"Usage Counts",paragraphs:[`The extension counts a few usage events so we can see which parts of it people use: that it was installed, that it was opened, that it detected a job posting, and that you started a tailor from it. Each carries a random install ID created by the extension, the extension version, and the job site's name (for example "greenhouse"). Nothing is counted until you answer the data notice the extension shows with "Got it": counts from before that answer are not kept or sent later, and the install is counted once, at that answer. When you are signed in, the counts are linked to your account. It also counts which features you use (for example that an autofill ran and how many fields it filled). No usage count ever carries page text, job titles, company names or web addresses.`,"You can turn usage counts off in the notice the extension shows, or at any time in its Settings under Privacy. When they are off, the extension sends no usage counts at all."]},{heading:"Where Your Data Goes",paragraphs:["The extension sends data to CareerDiary's servers at careerdiary.io, and to Supabase, the service that runs CareerDiary's sign-in and database, which it contacts directly to sign you in and read your profile. Signing in with Google or LinkedIn uses their sign-in pages. To score matches, draft answers and cover letters, and read job text, our servers send the text they need to Google's Gemini API, which returns the result."]},{heading:"Permissions and Why",paragraphs:["The extension asks for these permissions:"],bullets:["Access to the supported job sites and careerdiary.io: to read postings and forms on those sites and to reach your account.","Storage: to keep your sign-in session, a copy of your profile and settings on your device.","Identity: to open the CareerDiary, Google or LinkedIn sign-in window.","Active tab and scripting: to open the assistant on the page you are viewing.","Tabs: to show the job from the tab you are looking at, and to notice company careers pages.","Alarms: to sync your profile and check for follow-ups in the background.","Side panel: to show the assistant beside the page (Chrome).","Notifications: to remind you to follow up on applications (Chrome)."]},{heading:"Data Stored on Your Device",paragraphs:["The extension stores in your browser: your sign-in session; a copy of your profile, saved jobs, tailored resumes and cover letters; your settings; follow-up reminder state; match scores for pages you have viewed (keyed by page address); the random install ID; and usage counts waiting to be sent while you are offline. Signing out removes your session and the copy of your profile. Removing the extension deletes everything it stored."]},{heading:"Limited Use",paragraphs:["The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell your data, use it for advertising, or use it to decide creditworthiness or lending, and we share it only as described
1in this policy or when the law requires it."]},{heading:"Data Security",paragraphs:["Data is sent over encrypted (HTTPS) connections and protected by the measures described in the main CareerDiary Privacy Policy. No method of transmission or storage is 100% secure."]},{heading:"Your Rights",paragraphs:["You can access, correct, export or delete your CareerDiary data from your account at any time. Removing the extension stops everything it does."]},{heading:"Children's Privacy",paragraphs:["The extension is not intended for anyone under 18, and we do not knowingly collect personal information from children under 18."]},{heading:"Changes to This Policy",paragraphs:['We post changes on this page with a new "Last updated" date. When what the extension collects changes, the extension tells you in its panel as well, as it did when version 1.2.3 added usage counts.']},{heading:"Contact Us",paragraphs:["Questions about this policy? Contact us at"],email:"[email protected]"}]},g=({onBack:o})=>{const s=h;return e.jsxs("div",{className:"min-h-screen min-h-dvh bg-[var(--bg-primary)] transition-colors",children:[e.jsx("header",{className:"sticky top-0 z-50 border-b border-[var(--border-default)]/30 bg-[var(--bg-primary)]/90 backdrop-blur-xl",children:e.jsxs("div",{className:"mx-auto flex w-full max-w-6xl items-center justify-between px-4 py-4 md:px-8 safe-area-top",children:[e.jsxs(n,{onClick:o,variant:"ghost",size:"sm",className:"flex items-center gap-2 text-[var(--text-primary)] hover:text-[var(--color-accent)] transition-colors h-auto border-none p-0",children:[e.jsx("span",{className:"material-symbols-outlined",children:"arrow_back"}),e.jsx("span",{className:"font-semibold",children:"Back"})]}),e.jsx(i,{})]})}),e.jsx("main",{className:"mx-auto max-w-4xl px-4 py-12 md:px-8 md:py-16",children:e.jsxs("div",{className:"iconic-surface p-8 md:p-12 space-y-8",children:[e.jsxs("div",{className:"space-y-4",children:[e.jsx(d,{size:"md",className:"text-[var(--text-primary)]"}),e.jsx("h1",{className:"text-4xl font-bold text-[var(--text-primary)]",children:s.title}),e.jsxs("p",{className:"text-sm text-[var(--text-secondary)]/60",children:["Last updated: ",s.lastUpdated]})]}),e.jsx("div",{className:"space-y-6 text-[var(--text-secondary)]",children:s.sections.map((a,r)=>e.jsxs("section",{className:"space-y-3",children:[e.jsxs("h2",{className:"text-2xl font-bold text-[var(--text-primary)]",children:[r+1,". ",a.heading]}),a.paragraphs.map(t=>e.jsxs("p",{children:[t,a.email&&t===a.paragraphs[a.paragraphs.length-1]&&e.jsxs(e.Fragment,{children:[" ",e.jsx("a",{href:`mailto:${a.email}`,className:"text-[var(--color-accent)] hover:underline",children:a.email})]})]},t)),a.bullets&&e.jsx("ul",{className:"list-disc list-inside space-y-2 ml-4",children:a.bullets.map(t=>e.jsx("li",{children:t},t))})]},a.heading))})]})})]})};export{g as ExtensionPrivacyPage};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.