PrismCV Chrome Extension Privacy Disclosure
Last updated: September 2, 2026
This page explains how the PrismCV Chrome extension handles data while helping you score, fill, tailor, and track job applications. The extension runs only on the sites declared in its Chrome Web Store permissions.
What the extension does
PrismCV reads supported job pages to provide resume match scores and save job details. On Greenhouse, Lever, and Ashby, it can fill application fields from your PrismCV profile bank, attach a selected resume, and record a tracked application after submission.
Autofill is review-first. An optional auto-submit mode is off by default and available only when enabled for your account. It requires your explicit opt-in for the run, a review with no unanswered required fields, one unambiguous submit control, and a cancelable five-second countdown. Otherwise, you submit the application yourself.
Data handling
The extension handles the following data to provide those features:
- Authentication token: You create a scoped PrismCV API token in the web app and paste it into the extension. It is stored in
chrome.storage.local, attached as a bearer credential only to authenticated HTTPS requests to the configured PrismCV API endpoint, and not sent to job sites. - Job-page content and URLs: The extension can read a job's URL, title, company, description, location, and salary. It sends this content to PrismCV when you save or score a job, pause on a LinkedIn result long enough to request a score, tailor a resume, or complete a tracked application.
- Resume content: If you upload a resume during extension setup, the file is sent to PrismCV for parsing and profile-bank seeding. The request bytes are processed for that operation and are not retained as an uploaded document by this endpoint. The extracted profile entries are retained in your PrismCV account.
- Profile-bank and form data: Contact details, links, employment history, education, skills, saved screening answers, and optional EEO answers are retrieved from PrismCV to power autofill. The local snapshot is used as a cache for up to 30 minutes before refresh and may remain stored until it is replaced, you disconnect, or you uninstall the extension. Values read from an employer's application form are processed locally for review and completeness checks; they are not sent back to PrismCV.
- Application metadata: After a supported ATS shows a submission confirmation, PrismCV may record the tracked application ID, job title, company, URL, ATS provider, submission time, and the resume version used. It does not send the employer form's field values.
- Operational telemetry: Account-associated lifecycle events, ATS name, fields detected and filled, duration, and success or failure state are sent to monitor feature reliability. Telemetry excludes resume text, job descriptions, and application field values.
Data the extension does not collect
- Browsing activity outside the domains declared in the release manifest.
- Passwords, job-site authentication cookies, or session tokens from other sites.
- Keystrokes, mouse movements, screen recordings, or device contacts.
- EEO answers that you have not explicitly saved in PrismCV and approved for the current autofill review.
Service providers and Limited Use
AI-assisted resume parsing, matching, or tailoring may send resume and job content through PrismCV's contracted AI processing provider, as described in the main PrismCV Privacy Policy. The extension does not load third-party scripts, advertising networks, or social pixels into job sites.
PrismCV's use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Chrome Web Store Limited Use requirements. Extension data is used only to provide or improve the user-facing features described above, for security, to comply with law, or for aggregated internal operations. It is not sold, used for advertising, or made available for unrelated human review.
Retention and deletion
Local extension settings and caches remain in Chrome until replaced, cleared, or removed with the extension. Pending operational events are removed after successful delivery. Profile-bank entries, saved jobs, application records, and generated documents remain in PrismCV until you delete them or close your account, subject to the retention and legal obligations in the main Privacy Policy.
Your choices
- Leave optional auto-submit disabled and submit applications yourself.
- Revoke the extension's API token at any time in PrismCV settings.
- Disable or uninstall the extension through Chrome's extensions page.
- Export or delete your PrismCV data through the web app.
Contact
Questions or requests: privacy@prismcv.com.