This policy applies to the Careerify Fit browser extension (the "Extension"). It is written to be read alongside, not instead of, the Careerify Privacy Policy, which governs the Careerify service as a whole.
1. What the Extension Is
The Extension is an internal tool for Careerify recruiters. A Careerify recruiter installs it, signs in with their Careerify staff account, and it does one thing: on an employer's job application page, it fills the application form with the details of the job seeker the recruiter is working for, and it captures a screenshot of the employer's confirmation page as proof that the application was filed.
The Extension is not a consumer product and is not distributed publicly. It is not intended for, and is not made available to, job seekers.
The Extension also carries a demonstration job seeker— seeded, fictional data bundled inside the Extension, not a real person — so that it can be tried without a Careerify account. While the demonstration seeker is loaded, nothing is sent to Careerify: no sign-in, no record of what was filled, and no screenshot. The Extension says so on screen the whole time.
2. What It Reads
The Extension is active only on the employer application domains listed in its manifest — Workday, Greenhouse, Lever, Ashby, iCIMS, ADP, Oracle Cloud Recruiting, and Paylocity Recruiting. On any other website it does not run at all.
On those domains, when a recruiter opens it, the Extension reads:
- The page's job posting details — the URL, the job title, the employer name, and the location — so it can identify which posting in the recruiter's queue this page is.
- The application form's structure — the labels, question text, field types, and available options of the form on the page. This is the form's own wording, not anything you typed.
The Extension also retrieves, from Careerify's own API, the list of job seekers assigned to the signed-in recruiter, and the profile of the job seeker the recruiter selected: name, contact details, location, work authorization status, work history, education, skills, and the resume file to attach. That information originates with the job seeker, who provided it to Careerify to be used for exactly this purpose. A recruiter can only retrieve the seekers Careerify has assigned to them.
3. What It Sends, and Where
The Extension communicates with one server and one server only: Careerify's own API at backend.careerify.io. It sends:
- The recruiter's sign-in — their Careerify email address and password, and the one-time code Careerify emails them — used only to sign in. The password is never stored by the Extension.
- The job posting URL, so Careerify can identify which posting in the seeker's queue this page is.
- For an open-ended question the recruiter asks the Extension to draft, that question's wording, so Careerify can draft an answer from the seeker's profile and resume.
- A record of which fields were filled and which were skipped, which becomes the application's audit trail in the seeker's dashboard.
- Screenshots, as described in the next section.
The Extension does not send data to any advertising network, analytics vendor, data broker, or any other third party, and Careerify does not sell or rent this data to anyone.
4. Screenshots
The Extension can capture an image of the visible area of the current browser tab. It does this in two situations, both of them initiated by a recruiter:
- After the recruiter submits an application, to capture the employer's confirmation page as evidence of delivery.
- When the recruiter explicitly presses "Capture proof now", for the roughly half of employer sites the Extension cannot fill automatically and the recruiter completed by hand.
A screenshot is never taken silently or on a schedule. It captures what is on screen at that moment, in that tab, and it is uploaded to Careerify and attached to that seeker's record for that job posting, so the job seeker can see proof that their application was filed.
5. What It Stores in Your Browser
The Extension keeps these values in Chrome's extension storage on the recruiter's own machine:
- Sign-in session tokens for the recruiter's Careerify account, together with the recruiter's own name, email address and staff role, so they are not asked for a one-time code on every page. They are removed when the recruiter signs out.
- A short-lived copy (a few minutes) of the selected job seeker's profile and matched postings, kept in Chrome's session storage so the popup opens without re-fetching. It is cleared when Chrome closes.
- Which job seeker the recruiter last had selected.
- The time the recruiter accepted the Extension's in-product disclosure.
- A short-lived per-tab marker noting that a submission is expected on that tab, so the screenshot step can run after the Extension's popup has closed.
- Per-posting status notes: whether a confirmation screenshot was filed for that posting, and whether a fill record failed to save, so the popup can tell the recruiter.
No resume file is written to storage, and no job seeker profile data is written to long-term local storage. If a confirmation screenshot cannot be uploaded right away, the Extension may hold that one image in extension storage until the recruiter sends it, and removes it once it is filed. Signing out removes the session token; removing the Extension removes all of these values.
6. What It Never Does
- It never submits a job application.
- It never runs on, reads, or records activity on any website outside the employer application domains listed in section 2.
- It never collects browsing history, keystrokes, or form data you typed on unrelated sites.
- It never reads or fills an employer site's password or credential fields, and it never stores the recruiter's own password.
- It never creates an account on an employer's site on anyone's behalf.
- It never sells or transfers data to a data broker.
- It never uses the data it handles for advertising, ad targeting, or credit assessment.
- It never determines a person's creditworthiness or eligibility for lending.
7. Why Each Permission Exists
- Host access to employer application domains — the Extension has to be able to read and fill the application form on the page it is looking at. These are the only sites it runs on.
- Host access to
backend.careerify.io— Careerify's own API, the one server the Extension talks to, so the sign-in, the seeker profile, the fill record and the screenshot can travel between the Extension and Careerify. - activeTab — lets the Extension act on the tab the recruiter has open at the moment they click it, and is what permits the screenshot of that tab.
- scripting — used to place the form-filling logic into the page the recruiter is on.
- storage — holds the values in section 5.
8. Limited Use Commitment
In plain terms: the data the Extension handles is used only to file job applications on behalf of the job seeker it belongs to, and to prove to that job seeker that the application was filed. It is not used for any other purpose, it is not transferred to anyone except as described in section 9, and it is not sold.
9. Third Parties
The Extension itself talks only to Careerify. Careerify's server, in turn, relies on a small number of processors to operate the service:
- Anthropic — an open-ended application question and the relevant facts from the seeker's profile and resume are sent to Anthropic's Claude API to draft an answer, which the recruiter reviews before it is submitted. Anthropic does not use this data to train its models.
- Amazon Web Services — hosting for Careerify's API and storage for the resume files it renders and the screenshots it holds. The resume the Extension attaches is rendered by Careerify and fetched by the Extension from Careerify's storage.
- Vercel — hosting for Careerify's web applications, where recruiters and job seekers view the records the Extension creates.
Beyond these processors, the only parties who receive an applicant's information are the employers the job seeker asked Careerify to apply to. Once an application is submitted to an employer, that information is subject to the employer's own privacy practices.
10. Retention and Deletion
Application records and their proof screenshots are retained for as long as the job seeker's account is active, and are deleted in line with the retention schedule in the Careerify Privacy Policy. Deleting a job seeker's account deletes their profile, applications, and screenshots.
11. Your Rights
Job seekers may request access to, correction of, or deletion of the information Careerify holds about them, including anything filed through the Extension, by writing to privacy@careerify.io. Recruiters may sign out of the Extension at any time, which removes the session token from their browser, and may have their access revoked by Careerify; uninstalling the Extension removes every locally stored value.
12. Changes to This Policy
We may update this policy as the Extension changes. The "Last updated" date above reflects the most recent revision. Material changes to what the Extension collects or where it sends data will be reflected here before the change ships.
13. Contact Us
Questions about the Extension's data handling go to privacy@careerify.io. Our website is www.careerify.io.