๐ Filtro AI โ Privacy Policy
Version: 1.0 (Draft) Last Updated: 2026-07-23 Effective Date: [Launch Date] Jurisdiction: United Kingdom (UK GDPR + Data Protection Act 2018)
1. Introduction
Filtro AI ("we", "us", "our") operates an AI-powered Chrome browser extension and associated cloud services (collectively, the "Service") designed to assist users with job searching, application management, and career development.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our Service. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
Data Controller: Filtro AI / [Legal Entity Name] Contact Email: contact@filtroai.com
2. Data We Collect
2.1 Account Data (Required)
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, authentication, communication | Contract performance |
| Password | Account security โ handled entirely by our authentication provider (Supabase Auth); we never see or store your password | Contract performance |
| Display name | Personalisation | Contract performance |
We offer email and password sign-in only. We do not use Google, Apple, or any other social sign-in, so we never receive an account identifier or profile from a third-party provider.
2.2 Candidate Profile Data (User-Provided)
| Data | Purpose | Legal Basis |
|---|---|---|
| Full name | Form autofill, document generation | Consent |
| Phone number | Form autofill | Consent |
| Town/city, region, and outward postcode (e.g. "M14") | Form autofill, job search filtering | Consent |
| Nationality & right-to-work status (a category such as "citizen" or "visa required") | Form autofill, compatibility analysis | Explicit consent |
| Professional registrations (NMC PIN, HCPC, GMC) | Form autofill, compatibility analysis | Consent |
| Work history | Form autofill, ATS scoring, compatibility | Consent |
| Education & qualifications | Form autofill, ATS scoring, compatibility | Consent |
| Skills & competencies | ATS scoring, compatibility, job matching | Consent |
| Salary expectations | Job search filtering | Consent |
| Diversity & equality monitoring answers | Form autofill | Explicit consent |
2.3 Data We Deliberately Do Not Yet Collect
We do not currently collect, transmit, or store any of the following:
- National Insurance number
- Date of birth
- Full postal address (we hold only town/city, region, and the outward part of your postcode)
- Referee names and contact details
- Right-to-work or immigration document details โ numbers, expiry dates, or share codes
We have chosen not to hold this information until we have added field-level encryption for it. Until then, when an NHS application form asks for these details, you type them in yourself and we never see them. Everything else on the form still fills automatically.
When we do introduce these fields, they will be encrypted before storage, this policy will be updated, and we will ask for your consent before collecting them.
2.4 Application & Activity Data (Auto-Collected)
| Data | Purpose | Legal Basis |
|---|---|---|
| Job applications tracked (title, company, URL, status) | Application dashboard | Contract performance |
| ATS scores & compatibility scores | Feature functionality | Contract performance |
| Generated documents (cover letters, statements) | Feature functionality, version history | Contract performance |
| Chat conversation history | Conversational AI continuity | Contract performance |
| Feature usage analytics (anonymised) | Product improvement | Legitimate interest |
2.5 Technical Data (Auto-Collected)
| Data | Purpose | Legal Basis |
|---|---|---|
| Browser type & version | Compatibility, debugging | Legitimate interest |
| Extension version | Compatibility, updates | Legitimate interest |
| Error logs (anonymised) | Bug fixing, reliability | Legitimate interest |
| IP address (server logs, not stored long-term) | Security, rate limiting | Legitimate interest |
2.6 Data We Do NOT Collect
- โ We do not track your general browsing history.
- โ We do not read or access pages you visit unless you explicitly invoke the extension.
- โ We do not sell, rent, or trade your personal data to third parties.
- โ We do not use your data for advertising purposes.
- โ Our staff do not browse your individual personal records โ admin dashboards use aggregated, pseudonymised data only.
- โ We do not collect biometric data.
3. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Service | Profile, applications, documents, chat | Contract performance |
| AI-Powered Features | Profile + job descriptions sent to AI providers | Contract performance + Consent |
| ATS & Compatibility Scoring | Profile + job descriptions | Contract performance |
| Form Autofill | Profile data injected into web forms | Consent (user-initiated) |
| Account Management | Email, auth tokens | Contract performance |
| Billing & Subscriptions | Email, Stripe customer ID | Contract performance |
| Product Improvement | Anonymised usage analytics | Legitimate interest |
| Product Analytics & Admin Insights | Aggregated & pseudonymised profile/activity data (e.g. NHS band, region, application counts, scores) โ never sensitive identifiers | Legitimate interest (you can opt out) |
| Security & Fraud Prevention | IP, auth logs | Legitimate interest |
| Customer Support | Email, chat logs, account data | Contract performance |
| Legal Compliance | All data as required | Legal obligation |
4. AI & Third-Party Data Processing
4.1 AI Providers
To power our AI features (chat, ATS scoring, document generation), we send relevant context data to third-party AI providers:
| Provider | Data Shared | Purpose |
|---|---|---|
| Google (Gemini API) | Job description text, anonymised profile excerpts, user prompts | Chat responses, ATS scoring, compatibility analysis, and document generation |
Google Gemini is our only AI provider. We do not send your data to any other LLM provider.
Important safeguards:
- We never send your phone number, address details, or other directly identifying personal data to AI providers. (The most sensitive identifiers โ see ยง2.3 โ we do not hold at all.)
- Data sent to AI providers is contextual (skills, experience summaries, job descriptions) โ not raw personal records.
- We use AI provider API agreements that prohibit training on customer data.
- All AI API calls are made server-side through our backend, not directly from the extension.
4.2 Other Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and application data (encrypted at rest) |
| Stripe | Payment processing | Email, subscription plan, payment method (handled by Stripe) |
| Sentry | Error monitoring | Anonymised error logs, stack traces |
| PostHog | Product analytics | Anonymised usage events (no PII) |
| Resend / Postmark | Transactional email | Email address, email content |
MarketingOS (go.wemmyneat.com, run by us) |
Counting signups and which of our links led to them (see ยง7.2) | Receives each new account's record when it is created. Keeps only the account ID, signup time, a one-way hash (SHA-256) of the email address, and the link reference if you allowed it; everything else, including the plain email address, is discarded |
All third-party processors have appropriate Data Processing Agreements (DPAs) in place.
5. Data Storage & Security
5.1 Storage Locations
| Data | Storage Location | Protection |
|---|---|---|
| Account data (email) | Supabase (EU region / UK) | AES-256 encryption at rest, TLS 1.3 in transit |
| Passwords | Supabase Auth | Hashed and managed by our authentication provider โ never stored or seen by us |
| Profile & activity data (name, phone, city/region, NHS band, role, specialty, skills, work history, applications, scores) | Supabase (EU region / UK) | AES-256 encryption at rest, TLS 1.3 in transit; access restricted per user by database Row-Level Security |
| Documents & attachments | Supabase Storage | Server-side encryption at rest |
| Cached profile data | Chrome extension local storage | Stored on your own device |
| Auth tokens | Chrome extension session storage | Cleared when you close your browser |
Website sign-in session (filtro-site-auth): a sign-in token, a token to renew it, and your account's email address and ID |
Your browser's local storage on filtroai.com | Stays on your device until you sign out or clear this site's data. Sent only to our sign-in service (Supabase) and our matching service (ApplicationOS) to prove it is you |
| Payment data | Stripe (PCI DSS Level 1) | Stripe handles all card data; we never receive it |
Being precise about encryption. Your data is encrypted at rest (the storage volumes our database and file storage sit on) and in transit (TLS 1.3). We do not currently apply an additional layer of application-level encryption to individual fields. That is exactly why we do not yet collect the identifiers listed in ยง2.3 โ rather than hold data we cannot protect to the standard it deserves, we do not hold it at all. Field-level encryption and those fields will be introduced together, and this policy will be updated when they are.
5.2 Security Measures
- All data transmitted over TLS 1.3 (HTTPS only).
- Encryption at rest on all databases and file storage (AES-256, provider-managed).
- Passwords are handled entirely by Supabase Auth; we never store, log, or transmit them.
- Row-Level Security (RLS) in Supabase โ enforced at the database level, so you can only ever access your own data, regardless of application code.
- Data minimisation: we do not collect the most sensitive identifiers at all (ยง2.3), and we store only the outward part of your postcode rather than a full address.
- Staff & admin access: our admin dashboards operate on aggregated and pseudonymised data only. No member of staff routinely views your individual personal records. Any individual-record access (e.g. to resolve a support ticket) is role-restricted, logged, and used only for that purpose.
- We conduct a Data Protection Impact Assessment (DPIA) for large-scale profiling and keep it under review.
- Regular security audits and dependency vulnerability scanning.
- API rate limiting to prevent abuse.
- No plaintext secrets in code โ all credentials in environment variables / secret managers.
5.3 Data Retention
| Data Type | Retention Period | Deletion |
|---|---|---|
| Active account data | Duration of account | Deleted on account deletion |
| Chat history | 12 months from last interaction | Auto-purged or on request |
| Generated documents | Duration of account | Deleted on account deletion |
| Application history | Duration of account | Deleted on account deletion |
| Server logs (anonymised) | 90 days | Auto-purged |
| Error logs | 30 days | Auto-purged |
| Stripe billing records | As required by law (7 years) | Retained per legal obligation |
6. Your Rights (UK GDPR)
Under the UK GDPR, you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of all your personal data | Settings โ Export Data, or email us |
| Rectification | Correct inaccurate personal data | Edit your profile directly, or email us |
| Erasure ("Right to be Forgotten") | Request deletion of your account and all data | Settings โ Delete Account, or email us |
| Data Portability | Receive your data in a machine-readable format (JSON) | Settings โ Export Data |
| Restriction of Processing | Restrict how we use your data | Email us |
| Objection | Object to processing based on legitimate interest | Email us |
| Withdraw Consent | Withdraw consent for optional data processing | Settings โ Privacy, or email us |
| Complaint | Lodge a complaint with the ICO | ico.org.uk |
Response time: We will respond to all rights requests within 30 days.
Contact: contact@filtroai.com
7. Cookies & Tracking
7.1 Chrome Extension
The Chrome extension does not use cookies. We use:
chrome.storage.localโ for caching profile data and preferences on your device.chrome.storage.sessionโ for authentication tokens (cleared on browser close).
7.2 Website
Draft for the owner to review before launch (not legal advice): the wording below, the banner text on filtroai.com, and the lawful basis stated here.
Our website, filtroai.com, sets no cookies and loads nothing from anyone else: no analytics scripts, no advertising tags, no third-party fonts. It uses your browser's local storage for three things only:
| What is stored | Why | When | How long |
|---|---|---|---|
Your answer to our privacy banner (filtro_consent) |
So we don't ask you again on every page | Always (strictly necessary) | Until you change it or clear this site's data |
A link reference (mos_tid) |
To learn which of our posts lead people to sign up | Only if you choose "Allow" | Up to 30 days, or until you create an account |
Your sign-in (filtro-site-auth) |
To keep you signed in, so you can see your matches without signing in each week | Only when you sign in (strictly necessary for the service you asked for) | Until you sign out or clear this site's data |
If you share a computer, sign out when you finish: anyone using the same browser profile could otherwise open your matches.
The link reference. Some of our posts and adverts link to filtroai.com through a tracked link
on go.wemmyneat.com, which belongs to MarketingOS, the marketing analytics service we run
ourselves. That link adds a reference to the web address: a random code that identifies one click
on one link, not you. Our website removes it from the address bar as soon as the page loads.
- If you choose "Allow", we keep the code on your device for up to 30 days. If you then create an account, we attach the code to it, and MarketingOS records that the click led to a signup. Once it has been sent, we delete it from your device.
- If you choose "No thanks", or don't answer, the code is discarded. It is never stored and never sent.
You can change your answer at any time from Privacy choices at the foot of every page. Choosing "No thanks" deletes a code we were keeping.
Lawful basis: your consent (PECR regulation 6 for storing the code on your device; UK GDPR Article 6(1)(a) for linking it to your account).
8. Children's Privacy
Filtro AI is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a user is under 16, we will promptly delete their account and data.
9. International Data Transfers
Our primary data processing occurs within the European Economic Area (EEA) and/or United Kingdom. Where data is transferred outside the UK/EEA (e.g., to AI API providers in the US), we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) with data processors.
- International Data Transfer Agreement (IDTA) as required by UK GDPR.
- Provider certification under relevant data protection frameworks.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Displaying a notice in the extension.
- Sending an email to your registered address.
- Updating the "Last Updated" date at the top.
Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
For any questions, concerns, or requests related to your privacy:
- Email: contact@filtroai.com
- Data Protection Officer: [DPO Name/Email โ to be appointed if required]
- ICO (UK supervisory authority): ico.org.uk | 0303 123 1113
12. Chrome Web Store Privacy Disclosures
Permissions Justification
| Permission | Justification |
|---|---|
activeTab |
Access current tab to detect job portals and extract job descriptions when user invokes the extension |
sidePanel |
Render the AI chat interface, job search, and application dashboard |
storage |
Cache user profile and preferences locally for offline access and performance |
notifications |
Job match alerts and application deadline reminders |
host_permissions: ["*://trac.jobs/*", "*://*.nhs.uk/*", ...] |
Inject content scripts for form autofill on supported job portals |
Data Use Disclosure (Chrome Web Store)
- Personally identifiable information: Collected (name, email, phone, town/city, work history, education). Used for form autofill and AI features. Not sold. National Insurance number, date of birth, full address, and referee contacts are not collected.
- Health information: Not collected.
- Financial information: Not collected (Stripe handles payment data).
- Authentication information: Collected (email address). Passwords are handled by our authentication provider and never stored by us. Email and password sign-in only โ no third-party sign-in.
- Location: Not collected (user-entered location preferences only).
- Web history: Not collected. Extension only reads pages when explicitly invoked by user action.
- User activity: Collected (feature usage, anonymised). Used for product improvement.