Effective date: September 24, 2026 · Last updated: September 24, 2026
This policy explains how the “RoleStack — Job Application Autofill” Chrome extension (the “Extension”) collects, uses (handles), stores, and shares user data. The Extension is operated by Mantrix LLC (“we”, “us”). This policy covers only the Extension. For the RoleStack web platform, see the RoleStack Privacy Policy.
The Extension fills in job-application forms on supported applicant-tracking systems (Greenhouse, Lever, Ashby, Workable, BambooHR, Amazon, SuccessFactors, and Workday) using the signed-in user’s saved RoleStack profile.
Employers often embed these application forms inside their own career pages (for example, a Greenhouse or Workday form inside company.com/careers). To support that, a small script from the Extension loads on web pages you visit. Its only job is to check whether the page contains a form from a supported applicant-tracking system. If it doesn’t find one, the script stays hidden and does nothing: it does not read, store, or send the page’s content, its URL, or your browsing activity, and nothing leaves your device. The Extension only reads page content when (a) a supported application form is found, or (b) you click “Import this job” in the Extension to read the job posting on the current page once.
Most of the data the Extension uses (your name, contact details, résumé and work history) is information you already saved in your RoleStack account. The Extension retrieves it from our backend to fill forms; it does not gather that information from other sources. The Extension also directly collects a small amount of new data: the sign-in email you enter on supported employer sites, any changes you make to your employment or profile details while filling a form (which are saved back to your RoleStack profile), the final values you submit on an application, and the content of the application form and job description.
The table below lists every category of data the Extension collects, accesses, or uses:
| Category | What exactly | When |
|---|---|---|
| Authentication information | A RoleStack session token, received after you sign in on rolestack.ai. The Extension never asks for or collects your RoleStack password. | On sign-in |
| Personally identifiable information | Name, email, phone number, postal address, and the email you use to sign in on Workday and Amazon application sites. | When filling forms |
| Employment information | Résumé, work history, education history, work-authorization / visa-sponsorship status, and your answers to common application questions, including optional voluntary self-identification answers (e.g., gender, race/ethnicity, veteran status, disability status) only if you choose to save them; these are never inferred. Most of this is already in your RoleStack account. The Extension retrieves it from our backend to fill the application you’re working on. If you add or update employment details while filling a form, the Extension sends those changes to our backend and saves them to your RoleStack profile, so they’re ready for your next application. | Retrieved when filling forms; sent to our backend when you add or change details |
| Website content | On pages that contain a supported application form: the form’s field labels and options, and the job title and description. On any page where you click “Import this job”: that job posting. | When you use the Extension |
| Web history (limited) | The URL of the supported application page you are on, so the Extension can detect the site and record which job you applied to. No URLs are collected on other sites. | On supported sites only |
| Application records | A snapshot of the final field values you submitted, plus the job and company, so your application can be marked “Applied” in RoleStack. | On submission |
| Account status | Remaining résumé-tailoring credits, your account role, and whether you have connected a mailbox for reply tracking. The Extension does not read your mailbox. | While signed in |
We use the data above only to provide and improve the Extension’s single purpose — filling job applications:
We do not:
On your device (Chrome’s local extension storage):
| Data | Leaves your device? | How long it’s kept |
|---|---|---|
| Session token | Sent to our backend only to authenticate requests | Until you log out or it expires |
| Extension settings and preferences | No | Until you change them or uninstall |
| Temporary form/page data | No (other than as described in Section 5) | Discarded after the fill completes |
Uninstalling the Extension deletes everything stored locally.
On our servers: Your profile, résumé, saved sign-in emails, and application records are stored in a MongoDB database hosted in the United States.
Security: All data between the Extension and our backend is encrypted in transit using HTTPS/TLS. Data on our servers is encrypted at rest. Only authorized personnel can access production systems, and only as needed to operate the service.
Retention: Server-side data is kept while your account is active. Deleted within 30 days of an account-deletion request, apart from what we must keep to meet legal obligations.
We share user data only with the following parties, and only for the purposes stated:
| Recipient | What is shared | Why |
|---|---|---|
| MongoDB (database hosting, United States) | Profile and application data | To store your data. Acts as our service provider and does not use your data for its own purposes. |
| Google (Gemini API) | The relevant application question(s), the job description, and the parts of your profile needed to answer them | To generate answers to application questions. We use Google’s paid Gemini API, under which Google does not use this data to train or improve its models. |
| The employer / application site you apply on | The information you choose to submit through the filled form | To submit your application. This happens only when you submit, and that site’s own privacy policy applies. |
| Authorities | Only what is legally required | To comply with law, legal process, or to protect rights and safety |
If we are involved in a merger or acquisition, user data may be transferred under the same protections described here, and we will notify you.
We send our AI provider only what is needed to answer the question at hand. We do not send your voluntary self-identification answers (gender, race/ethnicity, veteran status, disability status) to the AI provider.
All of the parties above store and process your data in the United States.
We do not share, sell, rent, or transfer your personal data to any other third party, including data brokers or advertisers.
The Extension is not directed to anyone under 16, and we do not knowingly collect data from children.
If we change this policy, we will update the “Last updated” date above. Material changes will also be announced in the Extension or by email before they take effect.