Privacy Policy
Nyanza Autofill helps you fill out job applications using the profile you built at nyanza.ai. The extension keeps a local autofill copy, while your synced source profile and kits live in your Nyanza account. The extension fills supported fields and you review and submit the application. It never clicks a page-owned Next, Continue, or final Submit control.
nyanza.ai account. When you ask
Nyanza to generate a kit or answer, relevant job and career content may be processed by Nyanza's
server and its managed AI provider or the provider you configured. Values placed into an
employer-controlled page may be processed by that page before you submit. An optional,
default-off vault can securely store and fill a host-bound employer-site login on narrowly
reviewed account steps.
What the extension does
Its single purpose is to help you apply to jobs with your own Nyanza materials. It can read and save a posting you choose, show fit and sponsorship history, request a prepared kit or draft, fill matching application fields, attach your tailored résumé, and record the outcome. You review everything and submit directly on the application page.
If you separately enable the login vault, the extension can generate or retrieve an employer-site credential, store it encrypted in your Nyanza account, and fill it only on a reviewed account-creation or sign-in surface for the same host. Account consent, verification challenges, and the Create Account or Sign In action remain yours.
For Save + build kit, the extension reads only this browser's Local/Cloud engine choice from nyanza.ai. In known Local mode it saves the posting but does not request cloud kit generation. If it cannot verify the choice, it explains that the build uses Nyanza's server and an AI provider and requires a second confirmation before starting it. The relayed preference contains no API key, model name, prompt, résumé, or profile content.
Background preparation (opt-in, off by default)
Nyanza has an optional background-preparation mode you turn on yourself in your nyanza.ai settings. It is off unless you enable it. It acts only on applications whose grounded kit cleared Nyanza's strictest gates and only after you grant the relevant board permission and start a capped run. It can fill supported fields on the current application surface and attach the planned résumé, then hands the page back to you. It never clicks a page-owned Next, Continue, or final Submit control and never sends an application. It stops for anything it is not sure about, including a visible CAPTCHA, missing required answer, stale high-risk data, or an ambiguous control. At a reviewed account wall, the separately enabled vault may fill the host-bound login and then stop for your action; all other account walls remain manual. You can turn preparation off at any time, and every run is logged for you to see.
Information the extension handles
- Your application details - the profile you use to apply: name, email address, phone number, home or mailing address, current location, professional links, current role and employer, years of experience, education, target or preferred job location, work preferences, and any compensation or salary preference you chose to save.
- Your saved ordinary answers - reusable answers you explicitly ask Nyanza to remember are stored in your signed-in Nyanza account. Self-identification, legal/history, salary, CAPTCHA, consent, and work-authorization or sponsorship answers are excluded.
- Your separately authorized Application disclosures - exact pronoun, gender, race or ethnicity, veteran-status, and disability-status choices you save outside your Persona and ordinary answer bank. A supported choice can fill only from a fresh record, with separate authorization, applicable job context, an exact page option, and successful read-back. Legal attestations, signatures, marketing choices, and account consent remain manual. A separate default-off setting may check only a narrowly matched required privacy or terms acknowledgement; ambiguous or bundled notices remain manual.
- Messages in your Nyanza account - the extension may display inbound recruiter messages or a fresh verification code delivered to your Nyanza reply alias so you can copy it manually. These messages are not supplied to autofill, and the extension does not read or fill a verification-code or CAPTCHA control.
- Optional employer-site login credentials - only if you enable the vault, the extension can generate or retrieve an email and password for a narrowly reviewed employer account step. The credential is encrypted at rest in your Nyanza account, bound to your authenticated owner and the exact employer host, and can be revealed, copied, or deleted by you. Password values are excluded from field plans, audit events, compatibility reports, diagnostics, and AI requests.
- Your authenticated Nyanza session - account requests use the existing nyanza.ai sign-in session in your browser. The extension does not request Chrome's cookies permission, read or store the raw session cookie, or expose it to an employer page.
- The selected page URL and content - on a page where you invoke Nyanza, it may handle the URL; public job title, company, description, and job location; and the application field labels, questions, available options, and current field state needed to detect the application, avoid overwriting your work, plan a fill, and verify the result. A signed-out posting capture is stored locally; when you save the job, build a kit, or request an answer while signed in, the relevant selected-page content is sent to your Nyanza account. Starting a fill may also send bounded question and option context to Nyanza for grounded answer resolution. It is not included in value-free compatibility reports.
- Your actions in the extension and fields it filled - the extension handles clicks on its own controls, such as Autofill, Sync, Copy, Save, share, and revoke. After an explicit fill, it locally observes trusted input or change events only on fields it filled so it can remove its highlight and offer a manual correction. It does not record a keystroke sequence, mouse path, or unrelated page interaction. A correction's field label and current value are sent to Saved Answers only if you explicitly choose to save that correction; otherwise they remain ephemeral in the application tab.
- Local field/page failure metadata - after an explicit Autofill action, the extension can record a closed failure category, coarse widget or page-access type, pseudonymous site/form/field fingerprints, booleans, and bucketed counts or timing. Page receipts cover cases such as no usable form inventory, an inaccessible embedded surface, a page change, or zero committed fields. Structural reporting never includes a field label or question, answer/input value or selected option text, selector or element ID/class, URL or path, page text or HTML, résumé content or filename, validation prose, screenshot, credential/token/cookie, or free-form error.
The extension does not use Chrome's History API or build or store a browsing history. Guided autofill handles the current page URL and content only when you invoke it. If you separately enable the in-page prompt, it can inspect pages covered by the site access you grant to detect an application form. Background preparation processes only approved jobs during a capped run you start.
How your information is used
- To fill job-application forms you open, and to attach your résumé file when you ask.
- If you enable the vault, to generate or retrieve an exact-host login, encrypt it in your Nyanza account, and fill it on a reviewed account surface.
- To sync your profile, list your prepared kits, and render your tailored résumé from your own Nyanza account.
- To save a selected posting and, when you request it, generate a kit or draft answer using Nyanza's managed AI provider or the provider configured in your account.
- To mark a job "applied" in your Nyanza Job Agent when you tell it to.
- To notice when you manually change a field Nyanza just filled, clear the field highlight, and offer the exact correction for you to review and optionally save.
- To sync value-free audit events such as field category, source, freshness, review, and submission status. Field labels and values are excluded from those events.
- To explain why a field or page could not be completed, verify a manual correction, and - only when you explicitly share one event - aggregate value-free compatibility evidence without mixing it with your private saved answers.
- If you separately enable reliability sharing, to aggregate only attempted, browser-read-back-verified, and deferred field counts after a fill. This setting is off by default and does not send field values, questions, URLs, selectors, identifiers, page text, or document details.
Your information is used only for these purposes. It is never used for advertising, creditworthiness, or lending.
Where your information is stored and sent
- In your browser. The extension stores its autofill copy and preferences in
chrome.storage.local. Filling a field does not upload that field's value, although an exact correction is sent to Saved Answers if you explicitly save it, and the value-free audit events described above may sync to your account. Field-edit observation and unsaved correction text remain ephemeral in the application tab. Self-healing field receipts use a separate capped local ledger (up to 300 records), page-failure receipts use another (up to 100), and the delivery outbox is capped at 150. Receipts stay local by default. Only your explicit share action for one rendered event can put its reduced, value-free report in the retry outbox; sharing one event does not create standing consent. If you enable the separate reliability setting, three aggregate counts may be sent after a fill while the full lifecycle ledger remains on this device. - In your Nyanza account. The extension contacts
https://nyanza.aiover your signed-in session to fetch your synced profile, kits, résumé PDF, and Tracker messages; save selected postings; request generation; and update application status and audit history. If you enable the credential vault, employer-site logins are encrypted at rest with AES-256-GCM and bound to the authenticated owner and exact host; the plaintext password is returned only for your requested reveal or matching fill. A structural report you explicitly share is sent to a dedicated authenticated Nyanza report store that normal Persona sync cannot read or overwrite and that is separate from Saved Answers, application audit, generic telemetry, and submission state. The résumé PDF is fetched by the extension's popup, so your Nyanza session cookie is not exposed to the application website. Opted-in aggregate reliability counts enter bounded anonymous day, ATS-family, extension-version, and outcome buckets; they do not retain an account, run, page, or field identifier. - At an AI provider, when you request generation. Relevant job description, question, resume, and profile content may be sent through Nyanza's server to its managed AI provider or the provider configured in your account. That provider's terms apply.
- At the employer or ATS page when Nyanza fills it. Values written into an employer-controlled page may be processed by that page before submission. Final submission always follows your explicit action directly on the page. Optional background preparation may fill supported fields, but it never clicks a page-owned Next, Continue, or final Submit control.
Nyanza does not send extension data to advertising analytics or use it for unrelated purposes. The AI-provider and employer/ATS disclosures above are the feature-related destinations.
Autofill compatibility reports
The extension's Autofill history remains available after the original application tab closes. It explains field and page failures and shows whether an eligible report is not shared, queued, uploaded, waiting to retry, or revoked. You can share one event, retry or cancel a queued report, revoke an uploaded report, delete a local receipt, or clear device history. These controls do not edit or delete your private Saved Answers.
Local field receipts, page receipts, queued report payloads, and payload-free delivery records are physically deleted after at most 90 days. The local ledgers are also size capped, and surviving rows are rebuilt through allowlist schemas on worker startup.
Shared report content is retained by Nyanza for at most 90 days and is capped per account. Revoking deletes the structural content; Nyanza may keep only the random event ID and revocation time for up to 180 days so a delayed offline retry cannot restore it. Deleting the Nyanza account removes its dedicated structural-report store. Clearing device history by itself does not delete reports already sent to Nyanza, and the extension warns you when remote reports remain.
Nyanza clusters only closed structural fields such as ATS family, page type, adapter version, normalized field intent, widget type, failure code, pseudonymous fingerprint, and verified resolution outcome. Extension version is retained as an aggregate breakdown rather than used to split the same component pattern into separate clusters. A cluster is shown as candidate evidence only after at least 3 distinct users across 2 distinct sites. Aggregates contain counts, not user identities or site hashes. A single correction never creates a global rule. Learned recipes are not distributed to or executed by the extension.
Disabled future "Report this form" diagnostic
This richer diagnostic is a design only and is not enabled. The extension does not currently capture or upload form HTML, labels, option text, or screenshots for self-healing. Any future version would require a separate preview and consent flow, clone only the relevant form area, and aggressively remove values, checked/selected states, filenames, hidden inputs, tokens, scripts, styles, unrelated content, and sensitive/legal/ self-identification fields. It would also require short encrypted retention, restricted operator access, and deletion controls. Whether labels, options, reduced markup, or screenshots should ever be allowed; how redaction is verified; retention and operator access; third-party content; and backup/derived-data deletion remain open privacy decisions. The feature will stay disabled until those decisions and safety thresholds are resolved.
What the extension does not do
- It does not navigate or submit applications for you. It fills supported fields and attaches your résumé; you advance the page, review the application, and click submit.
- Your Persona, AI, and ordinary Saved Answers do not infer self-identification answers. A fresh, separately authorized Application disclosure can fill an exact supported pronoun, gender, race or ethnicity, veteran-status, or disability-status choice when its policy and job-context checks pass. A separately enabled notice setting may check a narrowly matched required privacy or terms acknowledgement. Legal attestations, signatures, account consent, marketing choices, and ambiguous notices remain manual.
- Ordinary autofill does not read or write employer-site password, verification-code, or CAPTCHA controls. The default-off vault is the only password exception: after exact-surface and exact-host checks, it can generate or retrieve and fill a credential you control. The extension may separately display an inbound message or verification code from your Nyanza account for manual copy; it never passes that content to autofill.
- It does not sell your data or transfer it for advertising or unrelated purposes, and it does not load or execute any remote code.
- It does not turn a field correction into executable code or automatically distribute a learned autofill rule.
Permissions and why they're needed
storage- to save your autofill profile and preferences locally so you don't re-enter them each time, including the last observed Local/Cloud engine choice used to keep Local mode from starting a cloud kit build, plus the capped, value-free field/page receipt ledgers, the default-off vault preference, and the explicit-consent structural-report retry outbox described above. Vault passwords are not stored in Chrome local storage.activeTabandscripting- to run autofill on the tab where you click the button, injected on demand at that moment.- Access to
https://nyanza.ai- to read your own profile, kits, résumé, Tracker messages, and device Local/Cloud choice; to save selected jobs, request generation when permitted, manage an optional encrypted credential vault, and update your application status and audit history; and, only after explicit per-event consent, to upload or revoke a value-free structural compatibility report in the separate authenticated store. If you enable reliability sharing, this access also sends the three aggregate counts described above after a fill. - Optional site access - in-page detection and background preparation require additional host access that Chrome asks you to grant. The extension uses it only for the application pages covered by that permission; you can revoke it in Chrome's extension settings.
Your choices
You can view and edit the extension's local autofill copy from its "Edit details" screen. You can turn aggregate reliability sharing on or off at any time in Fill settings; it is off by default. Autofill history lets you revoke shared reports and delete individual local receipts; you can also clear device history or remove the extension. Clearing local storage does not revoke a report already received by Nyanza, so use Revoke first when you also want the server content deleted. Individual receipts and reports are bounded by the caps and retention periods above. Private Saved Answers remain separate and are not changed by these controls. Vault logins can be revealed, copied, or deleted from the extension when the vault is available. Your synced source profile, kits, and activity remain in your Nyanza account until you edit or delete them there. To stop the extension from accessing the account, sign out of nyanza.ai; to remove optional site access, revoke it in Chrome's extension settings.
Changes to this policy
If this policy changes, we'll update the date at the top of this page.
Contact
Questions about this policy or your data? Email privacy@nyanza.ai.