BananaJobz Autofill — privacy

Last updated 20 September 2026

The extension fills job application forms using the profile you already keep in BananaJobz. This page describes exactly what it reads, what it stores, and what it sends. It reflects what the code does; if the two ever disagree, that is a bug and we want to hear about it.

What it reads

  • The content of pages on the job sites built into the extension, and on any other site you have explicitly turned it on for. On an application form it reads field names and labels so it knows what each field is asking for. On a job posting it reads the title, company, location and description.
  • On any other site, one thing and only one: when you open the extension’s popup, it looks at the page you are on to tell you whether there is an application form there and roughly how many fields it could fill. It counts what it finds and keeps nothing — that count is shown to you, is not stored, and is not sent anywhere. It happens when you open the popup and at no other time, and not at all once you have turned the site on, because then the page can answer for itself.
  • Turning it on for a site is a deliberate act: the popup asks for that one site by name, Chrome shows its own permission prompt, and you can turn it back off from the same place.
  • Your BananaJobz profile — name, contact details, work history, education, skills, and your resume — fetched from your account after you connect it.

What it stores

  • A connection token, in your browser’s local extension storage. It identifies your account to BananaJobz and nothing else.
  • A cached copy of your profile, so the panel can open without waiting on the network.

Both stay on your device. Disconnecting the extension, from its popup or from Settings in BananaJobz, deletes the token and the cached copy.

What it sends, and where

The extension talks to the BananaJobz API and to nothing else — there are no analytics and no trackers. BananaJobz then passes some of it to one third party: Anthropic, whose models work out what an unfamiliar form field is asking for, draft an answer when you ask for one, tailor a resume to a posting, and score a match. Anthropic processes that content on our behalf and does not use it to train its models. Saving a job to your tracker makes no such call. It sends:

  • The job title, company, location and description of a posting — when you ask for a match score, when you save the job to your tracker, or when you ask for a resume tailored to it.
  • The names and labels of form fields it could not identify on its own, so the server can work out what they are asking for. These are the form’s own words, never your answers. The result is remembered so the same form is never sent twice, and because it describes the form rather than you, it is not tied to your account.
  • The text of a free-text question, when you press “Draft an answer” on it.
  • Nothing else about the page. Not the rest of its content, not other tabs, not your browsing history, and not what you type into a form.

What it will not do

  • It never submits an application. It fills fields and shows you what it filled; sending the form is always your click.
  • It never infers an equal-opportunity, veteran or disability answer. It leaves those blank unless you have both written an answer in Settings and switched that section on; with the switch off, your answers are not even sent to the browser.
  • It fills a work-authorization, sponsorship, salary, notice-period or start-date question only from an answer you wrote yourself in Settings. Where you have not answered, it leaves the field blank and tells you so. It never invents one.
  • It never writes drafted text into a form on its own. A draft is shown to you in the panel first, and inserted only if you press Insert after reading it.
  • When it tailors your resume it may reorder and rephrase what is already there. It cannot add a skill, an employer, a qualification or an achievement you do not have — that is enforced in code, not left to the wording of a prompt.
  • It does not appear on sign-in or account-creation pages, and it does not handle passwords.

Your control

Every connected browser is listed under Settings → Account in BananaJobz, with a Disconnect button. Disconnecting takes effect immediately and cannot be undone from the extension — it has to be reconnected deliberately. Removing the extension from your browser also deletes everything it stored.

Each site you have turned the extension on for can be turned off again from the extension’s popup, or revoked from Chrome’s own extension settings. Either way it stops running there straight away.

Questions

Write to us and we will answer. If something on this page does not match what you observe the extension doing, say so — that is the report we most want.