Legal
Privacy Policy
No servers, no database, no analytics. Everything you type stays on your device except the request you send to your own AI provider.
Last updated: 29 June 2026
This Privacy Policy explains how the ScissorCV browser extension (“the Extension”, “we”, “us”) handles your information. The Extension is provided by Rohan Malodia.
The short version. The Extension runs entirely in your browser. We operate no servers and never receive, store or see your data. Your resume, job descriptions, profile details, screening answers, API keys and application history are stored locally on your own device. The only time your content leaves your browser is when it is sent directly to the AI provider you choose and configure, using your own API key. We do not sell your data, show ads, or run analytics or tracking of any kind.
What the Extension stores, and where
All of the following is saved using your browser's local extension storage (chrome.storage.local) on your device only. None of it is transmitted to us:
- Your resume text and any extra skills or keywords you add.
- Job descriptions you paste or grab from a page.
- Profile and autofill details you enter: name, email, phone, links, location, education and work experience.
- Screening answers such as work authorisation, notice period, salary expectations, and optional voluntary EEO fields.
- AI provider settings, including the API key you supply and any saved API profiles.
- Application history, including each tailored resume, cover letter, ATS report and token-usage count.
What we collect
Nothing. The developer has no backend, no database and no analytics. We never receive your resume, job descriptions, personal details, API keys or usage data.
When your data leaves your browser
The Extension contacts a third party only in these cases, and only with data you initiated:
- Generating a tailored resume, cover letter or ATS report. Your resume text and the target job description are sent directly from your browser to the AI provider you have configured, authenticated with your own API key. We are not an intermediary and the data does not pass through any server we control.
- Optional Humanize, Boost or Dream CV features. These send the relevant resume or cover letter text to the same provider you configured.
Your use of a given AI provider is governed by that provider's privacy policy and terms, not ours. Please review them:
- Groq — groq.com/privacy-policy
- NVIDIA NIM — nvidia.com privacy policy
- OpenRouter — openrouter.ai/privacy
- OpenAI — openai.com/policies/privacy-policy
- Anthropic (Claude) — anthropic.com/legal/privacy
- Google (Gemini) — policies.google.com/privacy
- Microsoft Azure OpenAI — Azure OpenAI data privacy
- If you use a local model such as Ollama or LM Studio, the data stays on your own machine and no third party is involved.
Payments and licensing
If you buy a licence, your licence key and a device label are sent to our payment processor, Dodo Payments, only to activate and validate your purchase. We never receive or store your card details — payment is handled entirely by Dodo Payments under their own terms and privacy policy.
Your API key
Your API key is stored locally on your device and is sent only to the provider it belongs to, solely to authenticate your own requests. We never transmit, log or have access to it.
The autofill helper
The autofill helper is injected into a web page only when you click “Autofill this application” in the side panel. When you run it, it reads the form fields on that page and fills blank ones using details you saved locally. It does not send any page content or your details to us or to any third party. Highlighting of filled and required fields happens entirely on that page.
Permissions and why we request them
| Permission | Why it is needed |
|---|---|
storage / unlimitedStorage | To save your resume, settings and application history locally on your device. Unlimited storage prevents the Extension from breaking once history grows. |
activeTab + scripting | To inject the autofill helper into the current tab, and to read the visible job description when you click Grab from page — only on your click. |
sidePanel | To show the Extension's side panel interface. |
| Host permissions | Limited to AI provider API endpoints and localhost for local models, so the Extension can send your requests to the provider you chose. Broader site access is optional and requested only if you configure a custom endpoint. |
Data retention and deletion
Because all data is local, you are in full control:
- Use the Reset button to clear your resume and job description.
- Delete individual applications from the Dashboard.
- Uninstalling the Extension removes all locally stored data from your browser.
We hold no copies because we never receive your data in the first place.
Children
The Extension is intended for job seekers and is not directed at children under 16. We do not knowingly collect information from children.
Changes to this policy
If the Extension's data practices change — for example, if a managed or hosted AI option is added in future — we will update this policy and revise the “Last updated” date. Material changes will be noted in the Extension's store listing.
Contact
Questions about this policy? Contact us at rohanmalodia@gmail.com.