Privacy Policy
Last Updated: September 2026
Data Ownership & Local-First Philosophy
Onextap is built on the principle of Data Sovereignty. By default, all personal information, resume data, and application history are stored locally on your device within the browser's storage.
Stored locally is not the same as never transmitted. When you use an AI feature, the relevant text is sent out to be processed — sections 2 and 4 set out exactly what is sent, to whom, and what is kept.
Data Collection and Usage
Personal Information: We do not sell, rent, or trade your personal data. Your profile data is used to power Onextap's core features — autofill, answer generation, and job matching — as described below.
AI Processing — Answer Studio & resumes: When you generate or improve an answer, we send Groq your question, your draft answer, the job description from the page you have open, a brief summary of your profile (current role, top skills, and recent experience), and any of your saved Answer Vault answers that are relevant to the question. When you upload a resume, the file itself is sent to Google (Gemini) to extract structured profile data. We do not use this data to train our own models; what Groq and Google do with data submitted through their APIs is governed by their own terms of service, not ours.
AI Processing — Job Matches: When you use Job Matches, a summary of your profile — skills, job titles, seniority level, and years of experience, not your full resume text — is sent to whichever model is ranking that batch. By default that's Google (Gemini); Groq is used automatically as a fallback if Gemini is unavailable. If you select "Explain my fit" on a specific job, fuller resume text (your summary and experience) is sent to Groq for that one job's tailored analysis. Section 4 covers what's recorded about these requests, and for how long.
Account & Billing Data: If you create an account, your email address, display name, credit balance, subscription status, and — if you subscribe — the customer and subscription identifiers Dodo Payments uses to manage your billing are stored in our database (Supabase), transmitted via SSL/TLS encryption. Your profile data — personal details, saved answers, and cover letters — is not uploaded and remains on your device.
Feedback: If you submit our feedback form, your message — and a reply-to email address, if you choose to include one — is emailed to our team via Resend. It is not stored in any database.
Third-Party Services
Onextap interacts with the following services:
- Supabase: For encrypted authentication and billing records (credits and subscription status).
- Groq: For generating and improving application answers, for the deeper "Explain my fit" analysis on a specific job, and as the automatic fallback for job ranking if our primary ranking model is unavailable.
- Google (Gemini): For parsing uploaded resumes into structured profile data, and as our primary model for ranking job listings against your resume.
- Google Fonts: For the typefaces used across this site. Loading a font, like any request to a third-party server, can expose your IP address to Google, under Google's own policies.
- Google Sign-In: If you sign in with Google, your browser is sent to Google's own sign-in page; we receive back only your email and name through Supabase's authentication integration.
- Opik (Comet): For recording operational metadata about AI requests — things like counts, search filters, job IDs, and whether a request succeeded — so we can diagnose and improve reliability. As of this writing, these records do not include your resume, profile, or answer text — see section 4.
- Dodo Payments: For secure payment processing (we never see or store your credit card details).
- Resend: For delivering feedback-form submissions to our team, including a reply-to email address if you choose to provide one.
- Job-board sources (Adzuna, Greenhouse, Lever, Ashby, Arbeitnow, Jobicy, Himalayas, Remotive, RemoteOK): We pull public job postings from these sources to build the listings you search and match against. This is a one-way, read-only feed — none of your personal data is sent to them.
Job Matching & AI Observability
What is sent when you match jobs: Job Matches ranks listings against your resume. To do that, a summary of your profile — your skills, job titles, seniority level, and years of experience, not your full resume text — is sent together with the job listings being considered to whichever model is doing the ranking (Gemini by default, Groq as an automatic fallback), so it can score each one and write the short explanation you see next to it. This happens only when you use the feature. We do not store your resume text in our database.
Explain my fit: Selecting "Explain my fit" on a specific job sends fuller resume text — your summary and experience — together with that job's description to Groq, so it can generate a more detailed, job-specific analysis. This is a separate action from bulk ranking, and it also happens only when you choose it.
What is recorded, and for how long: To debug ranking quality and catch failures, requests to the ranking and "Explain my fit" endpoints are recorded with Opik, an AI observability service operated by Comet. As of this writing, these records contain only operational metadata — job counts, search filters, job IDs, and success/failure — never the resume, profile, or answer text those requests carry. They are accessible to the Onextap team. We use them only to diagnose and improve how the product works. We do not sell them, do not use them for advertising, and do not use them to build a profile of you. If we ever start including resume or profile text in these records, we will say so here first.
When nothing is sent: Resume and profile text leaves your device only when you use an AI feature — uploading a resume for parsing, generating or improving an answer, personalizing a cover letter, or matching or explaining jobs. Autofill itself is entirely local: filling a form uses only the copy of your profile stored in your browser.
Your choices: You can use Onextap's autofill and local profile features without ever invoking an AI feature. If you would like any of the records described above deleted, contact us at the address below and we will remove them.
What the Extension Can Access
Onextap's browser extension asks for a small, specific set of permissions:
- storage: to keep your profile on your device.
- activeTab & scripting: to read a job posting or fill a form — but only on the tab you're looking at, and only after you click something in the extension. There's no standing access to your other tabs, and no script runs automatically when you open a page; the extension only acts when you tell it to.
- identity: to open Google's own sign-in window when you choose "Sign in with Google."
The extension does not request access to every website you visit, and it doesn't run in the background on pages you haven't asked it to act on.
When you do ask Onextap to read a job posting — to fill an application, generate an answer, or run Job Matches — it reads the company name and description text visible on that page (capped at 8,000 characters) and nothing else: not your cookies, not your other open tabs, not your browsing history.
Cookies & Local Storage
Onextap's website and extension don't use tracking cookies, and as of this writing we don't run any analytics or advertising scripts. Your signed-in session is kept in your browser's local storage — not a cookie — the same place your profile and saved answers live.
This site also loads Google Fonts (see section 3), which is a request to Google's servers for a stylesheet, not a tracking script. If we ever add analytics, the notice on this site will tell you and let you opt out, and we'll add it to the "Third-Party Services" list above first.
Security
We use HTTPS/TLS encryption for everything transmitted to our servers and to Supabase. Locally stored data — your profile, resume, and saved answers — is protected by your device's own browser and operating system; we don't add a separate layer of encryption on top of it, and we do not have "backdoor" access to it. Your "Master Profile" is yours alone.
Data Retention & Your Rights
We keep your account data (email, display name, credit balance, and subscription status) for as long as your account exists. Your profile, resumes, and saved answers exist only on your own device, so deleting them is as simple as clearing them in Onextap or uninstalling the extension. To request deletion of your account, or a copy of your account data or the AI-observability metadata described in section 4, contact us at the address below and we'll take care of it.