ForwardApplyBack to site

Legal

Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how GradientSparrow (“GSparrow”, “we”, “us”) collects, uses, stores, and shares information when you use the ForwardApply CoPilot browser extension (the “Extension”) together with the ForwardApply dashboard and API (the “Service”). It covers the data the Extension reads from your browser and the data you provide to the Service.

1. Who we are

GSparrow provides an AI-assisted job-search tool that helps you find jobs and complete and submit job applications. The Extension is a companion to your GSparrow account and works inside your own logged-in browser session. The data controller for the purposes of this policy is GradientSparrow. You can reach us at hr@gradientsparrow.com.

2. Information we collect

We collect only what the Extension and Service need to provide their features:

Account and authentication data

When you sign in (or pair the Extension with an open dashboard tab), we process your email address and the authentication tokens issued by our identity provider. These tokens are stored locally in your browser (chrome.storage.local) and sent as a bearer credential on calls to our API so we can authenticate you.

Profile and resume data

To help you complete applications, the Extension uses details from your GSparrow profile (such as your name, contact details, and work history) and, when you choose to upload one, your resume file.

Job and application page content

When you use the Extension on a supported job or application page, it reads the job-posting details and the application form on that page so it can provide its features. It only reads pages you use it on; it does not monitor your general browsing.

Application inputs

When you use the apply or autofill features, we process the information involved in your application (for example, answers to application questions) so the Extension can help you complete and submit it. Our cross-user form telemetry stores field metadata and autofill outcomes, not the answer text. Application data can still appear in your own profile, application workspace, evidence, and provider processing where needed for the feature you request.

Application authorization

Before Auto-Apply can start, we ask you to authorize ForwardApply from Profile → Consent. If you approve, we keep a dated record of that choice and may use your saved profile answers, complete required application acknowledgements, and enter your saved name where an electronic signature is required. We do not use this permission for optional marketing choices or to invent missing facts. You can revoke it at any time from Profile → Consent, which pauses automated applications.

Diagnostic data

We process limited technical information, such as the Extension version, page origin, field type, outcome, timestamps, and pseudonymous account identifiers, to operate, secure, and troubleshoot the Service. Query strings and fragments are removed from telemetry URLs.

Optional integrations and application evidence

If you choose to connect LinkedIn, we store the session material you provide in encrypted form for no more than 80 days, and you can disconnect it from your profile. If you use application evidence or support features, we may store screenshots, attachments, or recruiter-email content that you submit or receive through the Service.

Information stored on your device

Settings, cached profile fields, drafts, and your authentication tokens are stored locally in your browser via the extension storage API. This account data is removed when you sign out; uninstalling the Extension also removes its storage. Your theme may remain after sign-out. Application authorization is stored with your ForwardApply profile, not as a separate Extension approval.

3. How we use your information

  • Provide and operate the Service.
  • Help you complete and submit job applications from your own browser session, at your direction.
  • Provide the optional AI-assisted features you choose to use.
  • Authenticate you and keep your account and the Service secure.
  • Maintain, troubleshoot, and protect the Service.

We do not sell your personal information, and we do not use it for advertising or for any purpose unrelated to providing the Service. We do not use your data to determine creditworthiness or for lending purposes. Consistent with the Chrome Web Store User Data Policy, including its Limited Use requirements, our collection and use of data obtained through the Extension is limited to the practices disclosed in this policy.

4. How we share information

We do not sell your data. We disclose it to service providers that help us operate the feature you request, including providers for:

  • Cloud hosting, storage, and data processing.
  • Authentication and identity.
  • AI processing that powers optional matching, résumé, and form-answer features. Prompts may contain profile, résumé, job, and application information. Sensitive use cases are restricted to an approved provider list and provider-side context caching is disabled by default.

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the Service. If GSparrow is involved in a merger or acquisition, we will continue to protect your information and notify you of any change in control.

5. Browser permissions

The Extension requests the minimum permissions needed for its features:

  • storage, alarms — save your settings and tokens, and run periodic background checks.
  • scripting, tabs, activeTab — read and help complete the job and application pages you use the Extension on.
  • webNavigation — detect supported application-page navigation so the side panel can refresh its page context.
  • notifications — alert you to relevant jobs.
  • sidePanel— open the Extension’s side panel.
  • Host access to supported job sites and approved ForwardApply API endpoints. Access to any other site is requested per-site, only when you choose to use the Extension there, via Chrome’s standard permission prompt.

The Extension never reads or intercepts your cookies and never proxies your network traffic.

6. Data retention

Retention depends on the data: self-service access exports expire after 7 days; raw recruiter email after 30 days; recruiter-email metadata, value-free form telemetry, and application-flow telemetry after 180 days; new support attachments after 180 days; and new retention-tagged application proofs and tailored PDFs after 365 days. LinkedIn session material expires within 80 days unless you disconnect earlier. Security and deletion audit evidence, financial records, legal holds, and historical untagged artifacts can be kept longer where required or while their approved migration is pending.

7. Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:

  • Manage your profile, create a seven-day access export, disconnect LinkedIn, and queue an erasure request in the dashboard.
  • Sign out or uninstall the Extension to stop collection and clear locally stored data.
  • Email hr@gradientsparrow.com for requests that cannot be completed in the dashboard.

We verify completion across each system owner before reporting an erasure as complete. Required financial, fraud-prevention, security, legal-hold, and deletion-audit records may be preserved or pseudonymized instead of deleted.

8. Security

We protect your data with industry-standard measures: encryption in transit (HTTPS/TLS), access-controlled and origin-locked storage, and scoped, short-lived access tokens. No method of transmission or storage is completely secure, but we work to protect your information and review our practices regularly.

9. International data transfers

We process and store data in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.

10. Children’s privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.

12. Contact us

Questions about this policy or your data? Email us at hr@gradientsparrow.com.

ForwardApply© 2026 GradientSparrow. All rights reserved.
PrivacyTermsHome