Passmatch
Back to home

Privacy policy — Chrome extension

Last updated: 26 July 2026

What the extension reads, and when

The extension reads a page only when you click its icon (Chrome's “activeTab” permission). It watches no browsing, reads no page in the background, and has access to no site other than the one in front of you at the moment you invoke it.

The only origin it reaches on its own initiative is passmatch.fr, to talk to your account.

Capturing the job ad

When you ask for an ad to be analysed, the extension captures the title, the URL and the text of the displayed page. That capture is held in the browser's session memory, consumed on first read, and gone when the browser closes.

The text reaches our servers only if you start the analysis yourself. The processing is then covered by our general privacy policy.

Connecting to your account (pairing)

If you connect the extension to your Passmatch account, it receives a reduced-scope access token stored in your browser (“storage.local”, never synchronised across your devices). That token lets it analyse an ad, start a generation, read your notifications, read your application kit, download a CV you generated, and record an application as sent after you confirm it.

Nothing else: it cannot edit your résumé, read your profile, reach your billing data, export your personal data, delete your account, or mint itself a new token. This limit is not a promise about how we use it: the server refuses any route that is not on an explicit allowlist.

You can revoke the token at any time from your settings, where its last use is shown.

Prefilling an application form

On your click, and only on the tab in front of you, the extension writes what it recognises from your application kit into the form's fields: identity, latest role, degree, availability, salary expectation, work authorisation, mobility. Those values are read from your account at the moment you click and are not kept by the extension.

It never replaces an answer you already typed, highlights the fields it filled, and never touches passwords, file inputs or dropdowns.

It never submits the form. No send click, no CAPTCHA, no action without a gesture from you: reviewing and sending are yours. The form's contents are transmitted to nobody.

Tracking your applications

On a tab where you engaged the extension (a generation started, or a form prefilled), it notices that you sent your application and asks you, in its popup: “Did you send your application for …?”.

It records the status only if you answer “yes”. A refusal, or no answer at all, writes nothing. This watching exists only on those tabs and only for the length of their session — never across the rest of your browsing — and no page content is transmitted.

Notifications

After you start a generation, the extension periodically asks our servers whether your CV is ready, to light up its icon badge. No page data is sent on that occasion.

What the extension does not collect

No analytics, no advertising identifier, no browsing history, and no cookie set by the extension. It runs only the code contained in its package: no script is loaded from a server.

Your rights, and contacting us

Your data is hosted in the European Union. Exporting and deleting your account are self-service from your settings, and also erase whatever the extension produced (pairing token, notifications).

Any question: contact@passmatch.fr.