Privacy Policy

Last updated: September 16, 2026

ClickRoles is a job application tracker. This page describes what we collect, why, and what the browser extension can and cannot see. The short version: your data exists so that you can track your job search. We don't sell it, we don't show ads, and the extension doesn't track your browsing.

What we collect, and why

Account data. Your email address and authentication credentials, used to sign you in and to send account-related email. Authentication and data storage are provided by Supabase.

Jobs you save. When you click Save on a job listing — from the extension or in the app — we store what was extracted from that listing: job title, employer name, location, salary when shown, the job description, and the listing URL. This is the product: it exists so you can see and manage your applications.

Notes, statuses, and documents you add. Anything you attach to an application (status changes, notes, resume text you paste for scoring) is stored in your account.

Payment data. Payments are processed by Stripe. We never see or store your card number; we store your subscription status and Stripe's reference IDs.

What the browser extension does

The extension loads by itself on eleven job boards and on clickroles.com. The boards are LinkedIn, Indeed, Greenhouse, Lever, Ashby, Workday, SmartRecruiters, Wellfound, Dice, Glassdoor and ZipRecruiter. Those are the only sites it loads itself into, and Chrome holds it to that list. It also holds standing access to one address that is not a site you visit: ClickRoles' own API host at Supabase (the project's *.supabase.co origin), which is where it saves a job and reads your profile. That is the app's own backend, the same one clickroles.com uses. Anything the extension reads off a page goes there, or to clickroles.com itself in the three narrow forms set out below. It goes nowhere else and to no one but us.

On a supported board it reads the job listing on the page in order to show the Save button and, when you click it, sends that one listing's details to your ClickRoles account. Before the button can tell you whether a job is already on your board, it asks your account about that one listing, by the board's own job ID or the listing URL. That question goes to your account and nowhere else, and the listing is stored only when you click Save.

On a LinkedIn profile page the extension reads the top card of the profile, without being asked, so it can offer a Save contact button beside the person's name. What it reads is what the top card shows you: the name, the headline under it, the current employer, and the page's own tab title, which it uses to check that the name it found really belongs to the profile you are on. It re-reads them as the page changes, several times a second while LinkedIn is still rendering. It reads nothing further down the profile — not the experience, education, activity or contact-info sections. Before the button appears it asks your account two questions: whether your plan includes contacts, and whether that profile is already one of yours. The person's name, headline, employer and profile link are stored only when you click Save contact.

On any other site, nothing runs until you click. The extension's popup has two buttons that act on the tab you are looking at. Scan this page reads a job posting off a company careers page that the eleven boards don't cover, so you can save it the same way. Autofill this form types your saved contact details into an application form. Chrome grants the extension that one tab because you clicked its toolbar icon, and the grant ends when the tab navigates. Until you press one of those buttons, the extension has read nothing on the page.

What autofill writes. It fills your full name, preferred name, email, phone, city, region, country, and your website, LinkedIn, GitHub and portfolio links. All of it comes from the profile you filled in yourself at clickroles.com, and it goes into the form's own fields, in your browser. A profile field you left blank is never filled with something else: the popup tells you it is not in your profile, and the box stays empty. The one thing it changes is a link you typed without a scheme ("linkedin.com/in/you"), which gets "https://" in front of it as it goes into a form, because a form's URL box rejects it otherwise; your profile keeps it the way you typed it. Nothing about an autofill is sent to us or to anyone else, and we keep no record that one happened. Your work history and education are never read: the extension does not request those columns at all.

Autofill refuses password, payment and government-ID fields, leaves salary questions and other people's details alone, and never submits a form. The popup lists every field it filled and every field it left alone, and an Undo button puts back what was there before. The Undo stays offered each time you reopen the popup on that tab, until you use it or leave the page.

The extension does not follow you around the web. It builds no history of where you go, sells nothing to anyone, and sends no page content anywhere except the single listing you choose to save. Off the listed sites it does nothing at all until you open the popup and press a button, and then only on that one tab.

There is one place that general statement needs to be narrowed, and it is better said than implied. Two of the requests described below mention a page you had open: the record that a save happened, which carries the listing's address, and the match score the Saved badge fetches, which names the application it is about. Both concern a job that is already in your own board, both are sent as you and land against your own account, and neither happens on a page you have not saved. That is the whole of what we can infer about where you have been, and it is a good deal less than the phrase "we don't track you" usually covers, which is why it is written out here.

A record that a save happened. When a save succeeds, the extension sends one event to clickroles.com: the time, the word "extension", and the listing's address with the query string stripped off. It is how we can tell saves made from the extension from jobs added by hand in the app. The address is the one thing in it that comes from the page — there is no title, no employer and no description — and it is sent as you, so it lands against your own account rather than in anyone else's hands.

The match score on a saved listing. When you open a listing you have already saved, the badge says Saved and then asks clickroles.com for that application's resume match score, so the score can be shown on the pill without you opening the app. The request names the application and is sent as you. It is a read: it can never spend one of your AI actions, and it happens only on a listing that is already in your board. What it tells us is that you had that saved job's page open, which is the narrowing described above.

Anonymous breakage reports. Job boards redesign their pages, which breaks extraction. So the extension may report that a field failed to extract. That report contains only: the board's name (e.g. "dice"), which fields came back empty (e.g. "salary"), and the extension version. It contains no URL, no page content, no job details, and no user identifier — it tells us "salary extraction is failing on Dice," never "this person looked at this job." It goes to clickroles.com with no credentials attached, so it is not linked to you even by accident.

The extension also periodically fetches its extraction configuration (a list of CSS selectors) from clickroles.com. That request is made without cookies and carries no personal data.

AI features

If you use resume scoring or other AI features, the text needed for that feature — the job description and the resume text you provide — is sent to our AI providers (Anthropic and/or OpenAI) to generate the result. AI features run only when you invoke them.

Content you submit to AI features may be used for training. By using an AI feature, you agree that the content you submit to it (for example, resume text and the job description being scored) may be used to train and improve AI models and the ClickRoles product. Don't submit content to AI features that you aren't comfortable being used this way. Jobs you save without invoking an AI feature are not used for training.

What we don't do

We don't sell your data. We don't share it with advertisers or data brokers. We don't show ads. We don't use your saved jobs or documents for anything other than operating ClickRoles for you.

Where your data lives, and for how long

Your data is stored in our Supabase-hosted database and is retained while your account exists. Delete an application and it is removed from your account; delete your account and your data is deleted. Aggregated, anonymous extraction-breakage counts (which contain no personal data) are kept for up to 180 days for reliability monitoring.

Your choices

You can edit or delete any saved application at any time. You can uninstall the extension at any time without losing your saved data — the extension is a way in, not the store of record.

You may delete your account and its data from the Settings page of clickroles.com. The same page lets you export your data first. If you can't sign in to do it, contact us at the address below and we'll handle it.

Contact

Questions about this policy or your data: support@clickroles.com. General help lives at clickroles.com/support.

If this policy changes in a way that matters, the date at the top changes with it and material changes will be announced in the app.