Legal

Privacy Policy

Last Updated: September 2026

1

Data Ownership & Local-First Philosophy

Onextap is built on the principle of Data Sovereignty. By default, all personal information, resume data, and application history are stored locally on your device within the browser's storage.

Stored locally is not the same as never transmitted. When you use an AI feature, the relevant text is sent out to be processed — sections 2 and 4 set out exactly what is sent, to whom, and what is kept.

2

Data Collection and Usage

Personal Information: We do not sell, rent, or trade your personal data. Your profile data is used to power Onextap's core features — autofill, answer generation, and job matching — as described below.

AI Processing — Answer Studio & resumes: When you generate or improve an answer, we send Groq your question, your draft answer, the job description from the page you have open, a brief summary of your profile (current role, top skills, and recent experience), and any of your saved Answer Vault answers that are relevant to the question. When you upload a resume, the file itself is sent to Google (Gemini) to extract structured profile data. We do not use this data to train our own models; what Groq and Google do with data submitted through their APIs is governed by their own terms of service, not ours.

AI Processing — Job Matches: When you use Job Matches, a summary of your profile — skills, job titles, seniority level, and years of experience, not your full resume text — is sent to whichever model is ranking that batch. By default that's Google (Gemini); Groq is used automatically as a fallback if Gemini is unavailable. If you select "Explain my fit" on a specific job, fuller resume text (your summary and experience) is sent to Groq for that one job's tailored analysis. Section 4 covers what's recorded about these requests, and for how long.

Account & Billing Data: If you create an account, your email address, display name, credit balance, subscription status, and — if you subscribe — the customer and subscription identifiers Dodo Payments uses to manage your billing are stored in our database (Supabase), transmitted via SSL/TLS encryption. Your profile data — personal details, saved answers, and cover letters — is not uploaded and remains on your device.

Feedback: If you submit our feedback form, your message — and a reply-to email address, if you choose to include one — is emailed to our team via Resend. It is not stored in any database.

3

Third-Party Services

Onextap interacts with the following services:

4

Job Matching & AI Observability

What is sent when you match jobs: Job Matches ranks listings against your resume. To do that, a summary of your profile — your skills, job titles, seniority level, and years of experience, not your full resume text — is sent together with the job listings being considered to whichever model is doing the ranking (Gemini by default, Groq as an automatic fallback), so it can score each one and write the short explanation you see next to it. This happens only when you use the feature. We do not store your resume text in our database.

Explain my fit: Selecting "Explain my fit" on a specific job sends fuller resume text — your summary and experience — together with that job's description to Groq, so it can generate a more detailed, job-specific analysis. This is a separate action from bulk ranking, and it also happens only when you choose it.

What is recorded, and for how long: To debug ranking quality and catch failures, requests to the ranking and "Explain my fit" endpoints are recorded with Opik, an AI observability service operated by Comet. As of this writing, these records contain only operational metadata — job counts, search filters, job IDs, and success/failure — never the resume, profile, or answer text those requests carry. They are accessible to the Onextap team. We use them only to diagnose and improve how the product works. We do not sell them, do not use them for advertising, and do not use them to build a profile of you. If we ever start including resume or profile text in these records, we will say so here first.

When nothing is sent: Resume and profile text leaves your device only when you use an AI feature — uploading a resume for parsing, generating or improving an answer, personalizing a cover letter, or matching or explaining jobs. Autofill itself is entirely local: filling a form uses only the copy of your profile stored in your browser.

Your choices: You can use Onextap's autofill and local profile features without ever invoking an AI feature. If you would like any of the records described above deleted, contact us at the address below and we will remove them.

5

What the Extension Can Access

Onextap's browser extension asks for a small, specific set of permissions:

The extension does not request access to every website you visit, and it doesn't run in the background on pages you haven't asked it to act on.

When you do ask Onextap to read a job posting — to fill an application, generate an answer, or run Job Matches — it reads the company name and description text visible on that page (capped at 8,000 characters) and nothing else: not your cookies, not your other open tabs, not your browsing history.

6

Cookies & Local Storage

Onextap's website and extension don't use tracking cookies, and as of this writing we don't run any analytics or advertising scripts. Your signed-in session is kept in your browser's local storage — not a cookie — the same place your profile and saved answers live.

This site also loads Google Fonts (see section 3), which is a request to Google's servers for a stylesheet, not a tracking script. If we ever add analytics, the notice on this site will tell you and let you opt out, and we'll add it to the "Third-Party Services" list above first.

7

Security

We use HTTPS/TLS encryption for everything transmitted to our servers and to Supabase. Locally stored data — your profile, resume, and saved answers — is protected by your device's own browser and operating system; we don't add a separate layer of encryption on top of it, and we do not have "backdoor" access to it. Your "Master Profile" is yours alone.

8

Data Retention & Your Rights

We keep your account data (email, display name, credit balance, and subscription status) for as long as your account exists. Your profile, resumes, and saved answers exist only on your own device, so deleting them is as simple as clearing them in Onextap or uninstalling the extension. To request deletion of your account, or a copy of your account data or the AI-observability metadata described in section 4, contact us at the address below and we'll take care of it.

Questions?

If you have any concerns about your privacy, we're happy to help.

Contact Us