Effective date: 2026-09-10. Applies to the FillMyForm browser extension.
FillMyForm is a browser extension that fills web forms with data you choose. This policy explains what data the extension handles and where it goes.
| Data | Where | Purpose |
|---|---|---|
| Profiles (name, email, phone, address and other values you type in) | chrome.storage.sync in your Google account | Filling forms |
| Default email / password, settings, theme | chrome.storage.sync | Your preferences |
| API keys you enter (OpenRouter, CapSolver, Supabase) | chrome.storage.sync | Calling the services you configured |
| Fill history (page URL, page title, counts, time) | chrome.storage.sync and a local mirror; optionally your own Supabase project | Showing your recent fills |
| Usage counters (forms filled, fields, captchas, AI tokens) | chrome.storage.local | The "Saved so far" panel |
The developer has no server and never receives any of this data.
| Feature | Sent to | What is sent | When |
|---|---|---|---|
| AI fallback | OpenRouter (openrouter.ai), with your own API key | Labels, names, placeholders and select options of fields the rules could not classify, the page title and URL, and your active profile values | Only when "AI fallback" is on and unmatched fields exist |
| Captcha solving | CapSolver (api.capsolver.com), with your own API key | The page URL, the captcha site key and captcha type | Only when "Solve captchas" is on and a captcha is present |
| Random persona | randomuser.me | A nationality code. No personal data is sent | Only when "Generate random data" and "Use randomuser.me API" are on |
| Account sync | Your own Supabase project | Fill history rows and your sign-in email / password (to Supabase Auth) | Only when you configured a project and signed in |
The extension does not send analytics, telemetry or crash reports.
The content script runs on web pages to read form fields and write values into them. It reads only form controls and their labels, and only when you trigger a fill from the popup or context menu. Nothing from the page is stored except the URL and title in your fill history.
All data lives in your browser profile, your Google account sync storage, or the Supabase project you own. Clear history from the popup, delete profiles in Advanced settings, or remove the extension to delete everything stored locally. Data in your Supabase project is under your control.
The extension is not directed at children under 13.
Updates to this policy will be published at this URL with a new effective date.
Publisher contact: see the support email on the Chrome Web Store listing.