Privacy
Dossier privacy policy
This policy covers the Dossier web app and the private-alpha Chrome autofill extension.
Last updated July 21, 2026
What Dossier handles
If you request private-alpha access, Dossier stores your email address, the review status, and a keyed source fingerprint used to limit automated submissions. Dossier does not store the raw source IP for this purpose.
Dossier stores the factual profile you review, including your name, application email, phone, location, links, work history, education, and recurring application facts. The Chrome extension reads that profile after you connect it to your Dossier account.
The extension also stores its connection token, a profile cache, extension preferences, and one PDF resume in your current Chrome profile. The PDF is limited to 5 MB. Dossier does not upload that PDF to its servers as part of the base-resume attachment feature.
If the founder-only LinkedIn Easy Apply runner is enabled, Dossier stores the sensitive application defaults you explicitly save as an encrypted account record. Decrypted values are used only in memory for the active run and are not written to Chrome storage, AI prompts, answer history, diagnostics, audit records, or logs.
How autofill works
On supported job application pages, Dossier reads field labels, control types, and existing values so it can fill empty factual fields. It does not overwrite values already on the page, complete EEO or verification questions, or submit an application.
For an unfamiliar factual field, Dossier may send a sanitized label and limited field structure to its server for classification. Profile values, current answers, files, cookies, screenshots, and full page snapshots are not included in that classification request.
Site access and diagnostics
The beta has standing access only to Dossier and its supported job application systems: Greenhouse, Lever, Workday, Ashby, and SmartRecruiters. On another HTTPS site, Dossier asks for access only after you choose to activate it there.
Automatic diagnostics contain bounded technical facts such as the site scope, an opaque field fingerprint, the control type, the reason autofill could not finish, and the extension build. If you choose Report missed fields, Dossier also sends the field label, control metadata, and the page origin and path. Reports never include your answers, control values, files, cookies, screenshots, page HTML, or URL query strings.
How data is used and shared
Dossier uses this data to review private-alpha access, notify the operator about a new request, connect the extension, provide factual autofill, attach your saved PDF, keep your profile current when you explicitly save a correction, improve supported field patterns, prevent abuse, and diagnose failures.
In the founder-only unpacked development build, the Easy Apply runner may read the current LinkedIn job and open modal, fill empty controls, send up to eight written questions with the relevant job and career evidence for answer generation, and activate Next or Review. It leaves a selected LinkedIn resume untouched and never activates Submit. This capability is not present in the public MVP or Chrome Store manifest.
Dossier does not sell personal data or use extension data for advertising. Service providers may process data only to operate Dossier, such as hosting, error monitoring, email delivery, and the bounded field-classification service described above.
Your choices
You can disconnect the extension from Dossier at any time. You can remove the saved PDF from the companion hub, clear extension data by removing the extension from Chrome, and correct factual profile data in Dossier. During the private alpha, account export and deletion requests are handled through the publisher contact shown on the Chrome Web Store listing or in your tester invitation.
Retention and security
Private-alpha request records are kept while Dossier operates the alpha and as needed to administer access, prevent repeated abuse, and document account admission. A claimed request remains linked to the account it admitted; declined or pending requests can be removed through the publisher contact.
The extension connection expires after 90 days unless you reconnect it. Local extension data remains in the Chrome profile until you remove it, clear it through Dossier where that control is available, or uninstall the extension. Server data is kept while your alpha account is active and as needed for security, legal obligations, and reliable operation.
Dossier uses encrypted HTTPS connections and stores extension tokens in hashed form on the server. No method of storage or transmission is completely secure, so the private alpha should not be used for information beyond what employers normally request in a job application.