Red Team Privacy Policy.
Showcify Red Team is a Chrome side-panel extension that runs one adversarial review of your resume against the job posting you are viewing. This policy describes exactly what the extension reads, where it sends data, and what it stores. It is written to match the extension’s actual behaviour.
In one line: everything stays on your device except the two requests you explicitly trigger — reading your own resume from your Showcify account, and sending your resume plus the job text to OpenAI for the review you asked for.
This policy covers the browser extension only. Your Showcify account itself is governed by the Showcify Privacy Policy.
1. Who this policy is for
Anyone who installs and uses the Showcify Red Team browser extension.
2. What the extension accesses
- The job posting you are viewing — only after you click the toolbar icon and ask it to detect the posting. The extension reads the page once, on that explicit action, using Chrome’s
activeTabpermission. There are no persistent content scripts, and the extension never writes to or submits the job page. - Your Showcify resume — only if you connect your existing
app.showcify.comaccount. The extension reads your account and resume data using the session cookie already in your browser. It never asks for your Showcify password. - Your OpenAI API key— you paste your own key (BYOK, “bring your own key”). It is used only to run the review you request.
The extension does not read passwords, payment information, or identity-document fields. When the optional application-answers feature scans a form, it reads field labels and types only — never the values you typed, and password, payment, and identity fields are excluded entirely.
Questions about protected characteristics — for example gender, race, veteran status, or disability — are detected and fenced: they are never sent to the model and never auto-filled. The extension reads only their labels, in order to recognize them and leave them alone.
3. Where data is sent
Network requests go to exactly two destinations, and nowhere else:
| Destination | What is sent | When |
|---|---|---|
https://app.showcify.com | Read-only account/resume requests, authorized by your existing browser cookie | When you connect your account and load a resume |
https://api.openai.com | Your resume text and the job-posting text, plus your API key as an authorization header | Only when you click Run Red Team review |
There are no other network destinations. The extension contains no analytics, no telemetry, no tracking, no remote code, and no third-party CDN requests. Nothing is sent automatically or in the background.
Your resume and the job text are sent to OpenAI solely to generate the review. OpenAI processes that request under OpenAI’s own privacy and API data-usage terms; your use of your own API key is governed by your agreement with OpenAI.
4. What is stored, and where
Everything the extension stores is kept locally in your browser (chrome.storage.local). Nothing is synced to any Showcify or third-party server, and nothing is stored outside your browser.
- Your OpenAI API key — stored locally, sent only to OpenAI as an authorization header, and never logged, exported, or transmitted anywhere else.
- Your Showcify session — read fresh from the browser cookie for each request and never copied into extension storage. (A one-way SHA-256 fingerprint of the session is stored only so cached results expire when you switch accounts; the session token itself is never stored.)
- Reviews — up to the 10 most recent completed reviews are cached locally so you can reopen them without paying for a new model request.
- Pasted resumes — if you paste a resume instead of connecting an account, it stays local to the extension.
- Saved application answers (optional feature) — explicit-save only, gated by a one-time consent screen, stored only in this browser, and never synced or transmitted.
The extension never logs your resume text, job text, credentials, cookies, or full API request contents.
5. Your controls
- Delete a single review from the Review history.
- Clear all local datafrom the extension’s settings — this removes cached reviews, your stored API key, pasted resumes, and any saved answers from this browser.
- Turn off the answers feature with the kill switch in settings; it stops form reads, copy, and save.
- Uninstall the extension to remove its local storage from your browser.
Because all data is local, clearing it or uninstalling fully removes what the extension retained. Data already sent to OpenAI under your own key is subject to OpenAI’s retention policies, not ours.
6. Limited Use disclosure (Chrome Web Store)
Our use and transfer of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Concretely:
- User data is used onlyto provide the extension’s single, user-facing purpose: reviewing your resume against a job posting and helping you complete that application with answers you saved.
- User data is transferred only (a) to OpenAI, at your explicit action and under your own API key, to generate the review you requested, and (b) to your own Showcify account to read your own resume. There are no other transfers.
- User data is never sold, and never used or transferred for advertising, ad targeting or personalization, retargeting, or interest-based profiling, nor to determine creditworthiness or for lending purposes.
- No humans at Showcify read the data this extension handles. The extension never uploads anything to Showcify: its only Showcify requests are read-only fetches of the resume already stored in your own account (that account data is governed by the Showcify Privacy Policy). Reviews, pasted resumes, saved answers, and job-page text stay in your browser and are sent to no analytics, telemetry, or advertising service — so human access to them is impossible except data you choose to send us yourself (e.g. attaching an exported file to a support email), where required by law, or for security review with your explicit consent.
7. Children
This extension is a professional job-application tool and is not directed to children under 13.
8. Changes to this policy
Material changes will be reflected here with an updated “Updated” date at the top of this page.
9. Contact
Questions or privacy concerns: legal@showcify.com.
To report a security vulnerability, write to the same address with “Security” in the subject line. Please give us a reasonable window to remediate before public disclosure.