Privacy Policy
Last updated: March 7, 2026
Overview
PrepPilot is an AI-powered interview preparation tool available as a desktop application and a Chrome browser extension. We are committed to protecting your privacy. This policy explains what data PrepPilot collects, how it is stored, and how it is used.
The short version: PrepPilot stores your data locally on your device by default. If you sign in, your job and application data, profile, and resume text sync to your PrepPilot account so they're available across the desktop app and extension. Your API keys never leave your device except to authenticate directly with the AI providers you choose to use — they are never stored on PrepPilot servers.
Data We Collect
PrepPilot itself does not collect any data. All information you provide is stored locally on your device:
Desktop Application
- API Keys — Your Anthropic, OpenAI, and Google Gemini API keys are stored in a local configuration file on your computer. They never leave your device and are never synced or sent to PrepPilot servers.
- Resume Text — If you upload a resume, the extracted text is stored locally for use in generating personalized responses.
- Chat History — Conversations with the AI assistant are stored in local application memory during your session.
- Settings & Preferences — Your chosen AI model, hotkey configurations, and other preferences are saved locally.
Chrome Extension
- API Keys — Stored via Chrome's built-in
chrome.storage.localAPI on this device only — keys are never synced across browsers or to PrepPilot servers. Keys are only used for direct API calls to your chosen AI provider. - Job Data — When you save a job from a supported job board, the job title, company, location, description, and URL are extracted from the page DOM and stored locally via
chrome.storage.local. - Application Tracking — Job application statuses, notes, and history are stored locally on your device.
- User Profile — Your name, email, phone, LinkedIn URL, and resume text (used for autofill and match analysis) are stored locally.
- Generated Content — Cover letters, outreach messages, and match analyses are stored locally.
How Your Data Is Used
- AI API Calls — When you request AI assistance (chat, match analysis, cover letter generation, etc.), your prompt and relevant context (resume text, job description) are sent directly to the AI provider (Anthropic, OpenAI, or Google) using your own API key. PrepPilot acts as a client; it does not proxy or intercept these requests.
- Job Extraction — The Chrome extension reads job posting content from supported job board pages (LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, Workday) using DOM parsing. No data is sent to external scraping services.
- Form Autofill — If enabled, the extension can fill in application forms using your locally stored profile data. This never submits forms automatically; you always retain control.
Data Storage & Security
- Local-First Storage — Your data is stored on your device. The desktop app uses the local filesystem; the Chrome extension uses Chrome's Storage API.
- Account Sync (Optional) — If you sign in, your job and application data, profile, and resume text are stored in your PrepPilot account (hosted on Supabase) to enable sync between devices. API keys are never stored server-side. You can delete your synced data at any time.
- No Analytics or Tracking — PrepPilot does not use any analytics services, cookies, or tracking pixels. We do not track usage patterns or collect telemetry.
- No Third-Party Data Sharing — Your data is never sold, shared, or transferred to any third party. The only external communication is the direct API calls to AI providers that you initiate.
Third-Party AI Services
When you use AI features, your prompts are sent directly to the AI provider you select. Each provider has its own privacy policy governing how they handle API requests:
- Anthropic (Claude) — anthropic.com/privacy
- OpenAI (GPT) — openai.com/policies/privacy-policy
- Google (Gemini) — ai.google.dev/terms
API requests made through PrepPilot use your personal API keys. Most AI providers do not use API data for model training. Please review each provider's data usage policies for details.
Chrome Extension Permissions
The PrepPilot Chrome extension requests the following permissions:
- storage — To save your settings, tracked jobs, and generated content locally.
- sidePanel — To open the PrepPilot side panel for match analysis, cover letters, and application tracking.
- contextMenus — To add a right-click "Ask PrepPilot" option for selected text.
- alarms — To send application reminder notifications you configure.
- notifications — To display reminder alerts for tracked job applications.
- activeTab — To access the current tab's content when you click the extension or use the context menu.
- Host permissions (job boards) — To detect and extract job postings from LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, and Workday pages.
- Host permissions (AI APIs) — To send requests directly to Anthropic, OpenAI, and Google AI endpoints using your API keys.
Your Rights & Control
- Full Data Control — Since all data is stored locally, you have complete control. You can view, modify, or delete any data at any time.
- Desktop App — Uninstalling the application removes all stored data.
- Chrome Extension — You can clear all extension data from Chrome's settings (Extensions → PrepPilot → Details → Clear data), or simply uninstall the extension.
- API Keys — You can remove or rotate your API keys at any time through the Settings page.
- Autofill — Form autofill can be disabled entirely in extension settings. When enabled, it never submits forms without your action.
Children's Privacy
PrepPilot is not directed at children under 13. We do not knowingly collect information from children under 13. Since all data is stored locally on the user's device and we do not collect any data, this is inherently enforced.
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. Since PrepPilot does not collect email addresses or personal contact information, we cannot notify users directly of changes. We encourage you to review this page periodically.
Contact
If you have questions about this privacy policy or how PrepPilot handles your data, please reach out: