Legal
Privacy policy
Fillaid keeps your details on your own device and sends the least it can, only when you ask it to fill something. This page says exactly what that means.
- Effective date:
- 21 September 2026
- Questions:
- abuzar0013@gmail.com
On this page
- 01The short version
- 02Who we are
- 03What is stored on your device
- 04What leaves your device, and when
- 05What the extension learns as you type
- 06Passwords and other secrets
- 07Paying for a subscription
- 08How we may and may not use this data
- 09Who else handles the data
- 10The permissions Chrome asks for
- 11Sensitive details
- 12Deleting your data
- 13Your rights
- 14Children
- 15Changes to this policy
- 16Contact us
The short version
- Your profile lives on your own device, in Chrome's extension storage. The extension creates no account and asks for no sign-up.
- Nothing is written into a page and nothing leaves your browser until you click the fill prompt on a field.
- When you click it and you have a paid subscription, the form's field descriptions and the profile values that could answer them go to us, and on to the model that works out the match, for that one fill. We do not store them and we do not log them.
- Passwords are never saved and never filled.
- The released extension collects no browsing history, no analytics and no usage telemetry.
- We do not sell your data, we do not use it for advertising, and we do not train any model on it.
Who we are
Fillaid is a Chrome extension built and published by one independent developer, not by a company. This policy covers the extension and this website.
That same person is the data controller for UK and EU data protection law and the business for the California Consumer Privacy Act. Write to abuzar0013@gmail.com about anything on this page.
What is stored on your device
Everything below is held in Chrome's extension storage on the computer you installed the extension on. It is not synced to any account, because the extension has none, and we cannot read it.
- Your profiles. Names, addresses, phone numbers, email addresses, dates, card details, and any other fact you typed in yourself. You can keep more than one profile and choose which one is in use.
- Your settings. For example whether filling waits for your click or runs when a page opens.
- Your licence key, if you subscribe, and the short-lived token it is exchanged for.
- A short diagnostic record. The last 25 form submissions it saw, any corrections you made to a value it filled, and the last request it sent for a match. This is kept so a problem can be looked into on your own machine; the released extension sends it nowhere.
What leaves your device, and when
On a page with a form, the extension reads the fields to work out whether it has anything worth offering. That reading happens entirely inside your browser and is never sent anywhere. If it has something to offer, it shows a prompt when you hover a field.
Nothing is filled and nothing is sent until you click that prompt. When you do, and your subscription is active, the extension sends over an encrypted connection to our backend, which runs on Netlify:
- a description of each field on the page: its label, name, placeholder, type, the heading of the section it sits in, any format hint, its maximum length, whether it is required, the value currently in it, and the choices offered by a dropdown or a multiple-choice question;
- the title and address of the page, which the model uses as context for the match;
- the profile values that could answer those fields.
Our backend passes that on to a model that decides which value belongs in which field, receives that answer back, returns it to your browser and keeps nothing. The model is a decision model from TypeSafe AI, reached through OpenRouter; it chooses among the values you saved and never writes text of its own. We keep a model we fine-tuned ourselves, hosted at Baseten, as the alternative we can switch to; when it is in use it receives the same request instead. Fill requests are not stored and not written to logs. The only database we run holds licences, and a fill never touches it. The model we fine-tuned is not trained, retrained or improved on your data. What OpenRouter and TypeSafe AI keep of a request they pass through is governed by their own terms and by the settings on our account with them, not by us.
Without an active subscription the extension fills from rules that run on your device, and nothing is sent at all.
The page address goes with that single request as context and is not kept. We do not build any record of the pages you visit, and pages you never ask to be filled are never described to us.
What the extension learns as you type
Values you type into ordinary form fields are saved into your local profile once you are finished with a field: when you move off it, change a dropdown, submit the form or leave the page, and never while you are still typing. This runs on plain rules inside the extension, on your device. No model is involved, nothing is sent, and it works whether or not you pay.
These are never saved:
- passwords, and anything else shaped like a secret: tokens, API keys, passphrases, security answers, card or login PINs, licence keys;
- site search boxes and “ask anything” prompt boxes;
- anything you write rather than state about yourself: message, reply, comment and chat boxes, subject lines, issue and task titles, description boxes;
- a value that cannot be complete for the kind of field it is in.
Details that belong to somebody else on a form — a guarantor, an emergency contact, a nominee — are kept under that person's own label, such as “Guarantor phone”, and never merged into your own details.
Everything the extension has learned is listed on its profiles page, where you can edit any value, delete any value, or delete the whole profile.
Passwords and other secrets
Passwords are never saved, never filled and never sent. Keep using your password manager for those.
A box whose words say password, passcode, token, API key, secret, credential, security answer or card PIN is treated as a secret whatever type it claims to be, so a “show password” toggle cannot slip one through.
Card details are not secrets in this sense. If you save a card in a profile, it is stored on your device and can be sent for a paid fill like any other value. See sensitive details.
Paying for a subscription
Subscriptions are processed by Dodo Payments, which is the merchant of record. Your card details go to Dodo, not to us: we never see or handle your card number. What Dodo collects is governed by its own privacy policy at dodopayments.com/privacy-policy.
Dodo also issues your licence key and emails it to the address you paid with. We do not send that email and we do not store the key itself.
Our database (Postgres, hosted by Neon) holds one table, for licences. A row contains: a SHA-256 hash of the licence key — never the key itself — and its first few characters, the email address Dodo reports for the checkout, the plan, the subscription status and the date the paid period ends, the Dodo licence, customer and subscription identifiers, when the row was created, when the key was first activated, and how many times it has been activated. Nothing about your forms or your profile is in it.
Activating a licence sends the key to our backend once, and our backend asks Dodo whether that key is still valid — so the key reaches Dodo, which issued it, and nobody else. It replies with a token that is valid for 24 hours, which the extension attaches to each fill and renews on its own. The fill path checks the token, not the database.
How we may and may not use this data
Our use of information received from Fillaid complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. In plain terms:
- the data is used only to provide the filling feature you asked for, at the moment you asked for it;
- it is not sold, and not transferred to anyone except the service providers listed below who process it on our behalf, or where the law requires it;
- it is never used for advertising, ad targeting, ad measurement, credit scoring or lending;
- no human reads it. The hand-off to the model is automatic and nobody at Fillaid reads your profile or your form data, except where you send it to us yourself for support, where the law requires it, or where it is strictly necessary to investigate abuse or a security incident;
- no model is trained or improved on it.
If we ever want to use this data for a purpose this policy does not describe, we will ask for your explicit consent first, and it will apply only from the moment you give it.
Who else handles the data
The service providers we rely on, each doing one job, none of them free to use the data for their own purposes:
- Netlify — hosts our backend, which receives a fill request and passes it on. It does not store fill requests.
- OpenRouter and TypeSafe AI — OpenRouter routes the fill request to TypeSafe AI, whose decision model matches fields to values. For a paid fill they receive the field descriptions, the page title and address, and the profile values for that fill.
- Baseten — hosts the model we fine-tuned ourselves, the alternative we can switch to. When it is in use it receives the same request in place of the above.
- Dodo Payments — takes the payment as merchant of record, and issues and emails the licence key.
- Neon — hosts the Postgres database holding the licence table.
These are companies we buy a service from, and a paid fill is processed on their systems rather than ours, which for someone in the UK or EU can mean it is processed outside it. Without a subscription nothing is sent to any of them at all.
The permissions Chrome asks for
Chrome shows these when you install. This is what each one is for:
- Access to all websites. A form can be on any site, so the extension has to be allowed to work on any site. On a page it reads the fields to see what it could offer; it writes only when you click the prompt.
- Scripting. To place the filling script into the tab you are on, at the moment it is needed, rather than running on every page all the time.
- Storage. To keep your profiles and settings on your device.
- Tabs. To know which tab is in front, so a fill goes to the page you are looking at.
The extension asks for no access to your browsing history, bookmarks or downloads, and uses no permission for any purpose other than the one given here.
Sensitive details
You decide what goes into a profile. Anything in it can be offered to a form and, on a paid fill, sent for matching, so we suggest not keeping health information, government identity numbers or financial details there unless you actually need them filled.
Anything you change your mind about can be deleted on the profiles page, and deleting it there deletes it for good.
Deleting your data
- On your device. Delete a single value or a whole profile on the extension's profiles page. Uninstalling the extension removes everything it stored, including your profiles and your licence key.
- Your licence record. Ask us at abuzar0013@gmail.com and we will delete the row. Otherwise a licence row is kept for as long as the key can still be used, so that an active subscription can be checked.
- Your payment record. Dodo holds the payment record, and has to keep parts of it for tax and accounting for as long as its own policy and the law require. Ask Dodo to delete it and it will tell you what it can remove.
There is nothing to delete from a fill, because no fill request is kept in the first place.
Your rights
Most of your data is on your own computer, so seeing it, correcting it and deleting it is immediate, on the profiles page, without asking us.
For what we do hold — the licence record — you can ask for a copy, a correction, its deletion, a portable export, or that we stop processing it, and you may complain to your data protection authority. Under the California Consumer Privacy Act you may ask what we have collected, ask us to delete it, and opt out of the sale or sharing of personal information; we do not sell or share personal information, so there is nothing to opt out of. We will not treat you differently for exercising any of these rights.
Write to abuzar0013@gmail.com. We may ask you to send the request from the email address the licence was bought with, so we know the record is yours, and we will reply within 30 days.
Children
Fillaid is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, write to abuzar0013@gmail.com and we will delete it.
Changes to this policy
Changes are posted on this page with a new effective date. If a change widens how your data may be used beyond what this policy describes, we will ask for your explicit consent before it applies to you, rather than treating continued use as agreement.
Contact us
Email abuzar0013@gmail.com for anything about this policy, a data request, or a security concern. Email is the only way to reach us.
Our terms of service cover the rest of the relationship.