Legal
Privacy policy
Fillaid keeps your details on your own device and sends the least it can, only when you ask it to fill something. This page says exactly what that means.
- Effective date:
- [PLACEHOLDER: effective date]
- Questions:
- [PLACEHOLDER: contact email]
On this page
- 01The short version
- 02Who we are
- 03What is stored on your device
- 04What leaves your device, and when
- 05What the extension learns as you type
- 06Passwords and other secrets
- 07Paying for a subscription
- 08How we may and may not use this data
- 09Who else handles the data
- 10The permissions Chrome asks for
- 11Sensitive details
- 12Deleting your data
- 13Your rights
- 14Children
- 15Changes to this policy
- 16Contact us
The short version
- Your profile lives on your own device, in Chrome's extension storage. The extension creates no account and asks for no sign-up.
- Nothing is written into a page and nothing leaves your browser until you click the fill prompt on a field.
- When you click it and you have a paid subscription, the form's field descriptions and the profile values that could answer them go to us, and on to the model that works out the match, for that one fill. We do not store them and we do not log them.
- Passwords are never saved and never filled.
- The released extension collects no browsing history, no analytics and no usage telemetry.
- We do not sell your data, we do not use it for advertising, and we do not train any model on it.
Who we are
Fillaid is a Chrome extension published by [PLACEHOLDER: legal entity — confirm], [PLACEHOLDER: registered address]. This policy covers the extension and this website.
The data controller for UK and EU data protection law, and the business for the California Consumer Privacy Act, is [PLACEHOLDER: controlling entity — confirm with counsel]. Write to us at [PLACEHOLDER: contact email] about anything on this page.
What is stored on your device
Everything below is held in Chrome's extension storage on the computer you installed the extension on. It is not synced to any account, because the extension has none, and we cannot read it.
- Your profiles. Names, addresses, phone numbers, email addresses, dates, card details, and any other fact you typed in yourself. You can keep more than one profile and choose which one is in use.
- Your settings. For example whether filling waits for your click or runs when a page opens.
- Your licence key, if you subscribe, and the short-lived token it is exchanged for.
- A short diagnostic record. The last 25 form submissions it saw, any corrections you made to a value it filled, and the last request it sent for a match. This is kept so a problem can be looked into on your own machine; the released extension sends it nowhere.
What leaves your device, and when
On a page with a form, the extension reads the fields to work out whether it has anything worth offering. That reading happens entirely inside your browser and is never sent anywhere. If it has something to offer, it shows a prompt when you hover a field.
Nothing is filled and nothing is sent until you click that prompt. When you do, and your subscription is active, the extension sends over an encrypted connection to our backend, which runs on Netlify:
- a description of each field on the page: its label, name, placeholder, type, the heading of the section it sits in, any format hint, its maximum length, whether it is required, the value currently in it, and the choices offered by a dropdown or a multiple-choice question;
- the title and address of the page, which the model uses as context for the match;
- the profile values that could answer those fields.
Our backend passes that on to a language model we fine-tuned before release and host at Baseten, receives back which value belongs in which field, returns it to your browser and keeps nothing. Fill requests are not stored and not written to logs. The only database we run holds licences, and a fill never touches it. The model is not trained, retrained or improved on your data.
Without an active subscription the extension fills from rules that run on your device, and nothing is sent at all.
The page address goes with that single request as context and is not kept. We do not build any record of the pages you visit, and pages you never ask to be filled are never described to us.
What the extension learns as you type
Values you type into ordinary form fields are saved into your local profile once you are finished with a field: when you move off it, change a dropdown, submit the form or leave the page, and never while you are still typing. This runs on plain rules inside the extension, on your device. No model is involved, nothing is sent, and it works whether or not you pay.
These are never saved:
- passwords, and anything else shaped like a secret: tokens, API keys, passphrases, security answers, card or login PINs, licence keys;
- site search boxes and “ask anything” prompt boxes;
- anything you write rather than state about yourself: message, reply, comment and chat boxes, subject lines, issue and task titles, description boxes;
- a value that cannot be complete for the kind of field it is in.
Details that belong to somebody else on a form — a guarantor, an emergency contact, a nominee — are kept under that person's own label, such as “Guarantor phone”, and never merged into your own details.
Everything the extension has learned is listed on its profiles page, where you can edit any value, delete any value, or delete the whole profile.
Passwords and other secrets
Passwords are never saved, never filled and never sent. Keep using your password manager for those.
A box whose words say password, passcode, token, API key, secret, credential, security answer or card PIN is treated as a secret whatever type it claims to be, so a “show password” toggle cannot slip one through.
Card details are not secrets in this sense. If you save a card in a profile, it is stored on your device and can be sent for a paid fill like any other value. See sensitive details.
Paying for a subscription
Subscriptions are processed by Dodo Payments, which is the merchant of record. Your card details go to Dodo, not to us: we never see or handle your card number. What Dodo collects is governed by its own privacy policy at dodopayments.com/privacy-policy.
Dodo also issues your licence key and emails it to the address you paid with. We do not send that email and we do not store the key itself.
Our database (Postgres, hosted by Neon) holds one table, for licences. A row contains: a SHA-256 hash of the licence key — never the key itself — and its first few characters, the email address Dodo reports for the checkout, the plan, the subscription status and the date the paid period ends, the Dodo licence, customer and subscription identifiers, when the row was created, when the key was first activated, and how many times it has been activated. Nothing about your forms or your profile is in it.
Activating a licence sends the key to our backend once, and our backend asks Dodo whether that key is still valid — so the key reaches Dodo, which issued it, and nobody else. It replies with a token that is valid for 24 hours, which the extension attaches to each fill and renews on its own. The fill path checks the token, not the database.
How we may and may not use this data
Our use of information received from Fillaid complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain terms:
- the data is used only to provide the filling feature you asked for, at the moment you asked for it;
- it is not sold, and not transferred to anyone except the service providers listed below who process it on our behalf, or where the law requires it;
- it is never used for advertising, ad targeting, ad measurement, credit scoring or lending;
- no human reads it. The hand-off to the model is automatic and nobody at Fillaid reads your profile or your form data, except where you send it to us yourself for support, where the law requires it, or where it is strictly necessary to investigate abuse or a security incident;
- no model is trained or improved on it.
If we ever want to use this data for a purpose this policy does not describe, we will ask for your explicit consent first, and it will apply only from the moment you give it.
Who else handles the data
Four service providers, each doing one job, none of them free to use the data for their own purposes:
- Netlify — hosts our backend, which receives a fill request and passes it on. It does not store fill requests.
- Baseten — runs the fine-tuned model that matches fields to values. For a paid fill it receives the field descriptions, the page title and address, and the profile values for that fill.
- Dodo Payments — takes the payment as merchant of record, and issues and emails the licence key.
- Neon — hosts the Postgres database holding the licence table.
[PLACEHOLDER: where each provider processes the data, and the transfer mechanism relied on for UK and EU users — confirm with counsel]
The permissions Chrome asks for
Chrome shows these when you install. This is what each one is for:
- Access to all websites. A form can be on any site, so the extension has to be allowed to work on any site. On a page it reads the fields to see what it could offer; it writes only when you click the prompt.
- Scripting. To place the filling script into the tab you are on, at the moment it is needed, rather than running on every page all the time.
- Storage. To keep your profiles and settings on your device.
- Tabs. To know which tab is in front, so a fill goes to the page you are looking at.
The extension asks for no access to your browsing history, bookmarks or downloads, and uses no permission for any purpose other than the one given here.
Sensitive details
You decide what goes into a profile. Anything in it can be offered to a form and, on a paid fill, sent for matching, so we suggest not keeping health information, government identity numbers or financial details there unless you actually need them filled.
Anything you change your mind about can be deleted on the profiles page, and deleting it there deletes it for good.
[PLACEHOLDER: adjust once the category-consent design is settled — per-category choice at setup for card and identity details]
Deleting your data
- On your device. Delete a single value or a whole profile on the extension's profiles page. Uninstalling the extension removes everything it stored, including your profiles and your licence key.
- Your licence record. Ask us at [PLACEHOLDER: contact email] and we will delete the row. Otherwise licence rows are kept for [PLACEHOLDER: retention period for licence rows after a subscription ends].
- Your payment record. Dodo holds the payment record, and some of it has to be kept for tax and accounting: [PLACEHOLDER: statutory retention period].
There is nothing to delete from a fill, because no fill request is kept in the first place.
Your rights
Most of your data is on your own computer, so seeing it, correcting it and deleting it is immediate, on the profiles page, without asking us.
For what we do hold — the licence record — you can ask for a copy, a correction, its deletion, a portable export, or that we stop processing it, and you may complain to your data protection authority. Under the California Consumer Privacy Act you may ask what we have collected, ask us to delete it, and opt out of the sale or sharing of personal information; we do not sell or share personal information, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
Write to [PLACEHOLDER: contact email]. [PLACEHOLDER: identity verification steps and the response deadline we commit to]
Children
Fillaid is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, write to [PLACEHOLDER: contact email] and we will delete it. [PLACEHOLDER: age threshold per jurisdiction, per counsel]
Changes to this policy
Changes are posted on this page with a new effective date. If a change widens how your data may be used beyond what this policy describes, we will ask for your explicit consent before it applies to you, rather than treating continued use as agreement.
Contact us
Email [PLACEHOLDER: contact email] for anything about this policy, a data request, or a security concern. By post: [PLACEHOLDER: postal address].
Our terms of service cover the rest of the relationship.