Privacy Policy
Last updated: August 6, 2026
The short version: Workmostat runs entirely inside your browser. There is no Workmostat server. Your resume, your scores, and your settings are stored only on your device and are never transmitted anywhere. There's one narrow, clearly-labeled exception described below, and it only ever runs when you click it.
What Workmostat stores, and where
Workmostat uses the browser's own chrome.storage.local, which keeps data only on your device. Not on any server we operate, since we don't operate one. This includes:
- Your resume text and any additional resume profiles you create
- Your saved "hot match" history (postings that scored 65%+ while you browsed)
- Aggregate stats on which skills keep showing up as missing
- Your extension settings (preferences, active profile, and similar)
None of this is uploaded, synced to an account, or visible to us in any way. We don't have accounts, sign-in, or a backend that could see it.
What Workmostat does not do
- No remote servers, so there's nothing to send your data to
- No analytics or tracking scripts of any kind
- No sale or sharing of data with third parties, since there's nothing collected to share
- No advertising
The one exception: "Copy Prompt"
The results view has a "Copy Prompt" button, and Workmostat only does any of this if you click it. Clicking it copies a prompt containing the job description and your resume text to your clipboard, and, unless you've selected "Just copy the prompt" in settings, opens your chosen AI provider's website (ChatGPT, Claude, or Gemini) in a new tab. Workmostat itself does not transmit anything to that provider. The content is only on your clipboard, and it's up to you whether to paste it once you get there. This is the only action in the entire extension that involves data leaving your browser, and it never happens automatically.
Why Workmostat asks for the permissions it does
Each permission in the extension's manifest maps to a specific, narrow purpose:
storage: saving your resume, profiles, and settings locallyactiveTab/scripting/tabs: reading the text of the job posting you're currently viewing, so it can be scoredwebNavigation: detecting when a new job-posting page has finished loading, so auto-analyze knows when to run- A fixed list of job board domains (LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, and similar sites). Workmostat's page-reading logic only runs on these sites, and it does not run on, or have access to, any other website you visit.
Your control over your data
Since everything lives in your browser, you're already in full control of it. The extension's settings include an Export data button to download a complete backup as a JSON file, and a Delete all data button that permanently erases every profile, saved match, and setting from your browser. Uninstalling the extension also removes all of its stored data, per standard browser behavior.
Changes to this policy
If this policy changes, the "Last updated" date at the top of this page will change with it.