Scope and publisher
Effective 8 October 2026. WD DIGI publishes JobApply Studio. Contact support@wddigi.com about this policy. The extension and this supporting website have different data flows, described below.
Local private vault
The extension handles your contact details, experience, saved job descriptions, notes, requirement links, CV snapshots and application tracker to provide the features you use. These are encrypted in IndexedDB in your current browser profile using a passphrase-derived key. The passphrase and unlocked key stay in the open page’s memory; WD DIGI does not receive them.
Optional provider API keys stay in memory unless you explicitly save them in the encrypted credential record. They are excluded from encrypted domain backups. Chrome storage holds non-sensitive preferences such as language, theme and idle-lock choice; CVs and keys are not placed in Chrome sync storage.
Private data stays until you delete the vault or browser data removes it. There is no publisher copy, automatic account sync or password recovery. Local encryption does not protect against malware or someone using an already unlocked browser session.
Public feeds and links
Jobicy and Himalayas are optional official public feed sources. Each fetch needs permission for its own host. Up to 200 public listings are cached separately from the private vault; old cache entries expire after seven days. Refresh attempts are limited to once per 24 hours per source, and provider rate limits may require longer waits.
Role/location filters are applied on your device and are not attached to feed requests. Feed providers still receive ordinary connection information, such as your IP address and request metadata. Their own terms apply. Opening JobStreet, Glints, Cake, Remotive or a source posting uses that external site’s privacy rules; those portal links are not connected feeds.
Opening the visible Google search sends its displayed role/location query to Google. This is your explicit navigation, not a background CV upload.
Optional Chrome AI
If you select Chrome AI, the selected English input you approve is processed by Chrome’s on-device model. No cloud API key or WD DIGI AI server is used. Model availability and initial downloads are managed by Chrome. After download, inference can work offline; the model file is outside the extension vault and is not erased by deleting that vault.
Local output can be inaccurate. Every suggested change needs your factual review before it is applied. The extension destroys its model sessions on completion or cancellation and does not save a conversation history.
Optional cloud AI
If you choose OpenRouter, Gemini, OpenAI or Groq, model-list requests send your key directly to the selected provider in an authentication header. Generation sends only the selected facts and optional job description displayed for your approval, plus rewriting instructions. Name, email, phone, full profile, entire vault and document files are not included automatically. Selected prose may itself contain personal information; inspect it before approving.
The provider receives approved input, key/account identifiers and connection metadata and handles them under its own terms. WD DIGI does not proxy these requests. Output returns to the extension for validation and human review.
OpenRouter requests require structured output, ZDR routing, denied data collection and no fallback. ZDR is not a claim that data stays on your device or that account/network logging disappears. Gemini, OpenAI and Groq apply their own tier/account retention and training terms; there is no blanket zero-retention claim.
No automatic retry, paid model switch or local-to-cloud fallback occurs. Cancellation may not stop upstream processing or charges. Disconnect deletes local saved keys and cancels proposals, but does not revoke the key at its provider; use the provider’s account controls.
Exports, backups and deletion
PDF, DOCX, text and optional plaintext data exports create files you control; they are no longer protected by the vault’s encryption. Encrypted backups include private domain data but exclude API keys. Downloaded files remain after deleting the vault. A lost passphrase cannot be reset by WD DIGI.
Delete all local data removes the extension vault, saved keys, preferences and public cache in this browser. Other browser profiles, downloaded files and provider-side records need their own deletion. Restore replaces the vault only after a preview and confirmation. No CV is uploaded to this website for export or restore.
Website and support email
This website serves static information. It has no CV upload, login, AI proxy, payment form, advertising SDK or analytics script. Its hosting provider can process IP addresses and normal request/security metadata to deliver the site. Such hosting records are controlled by that provider’s configuration and retention, not by the encrypted extension vault.
If you email support, WD DIGI and its email service receive your address, message and any attachments you choose to send. Use a minimal example without passphrases, API keys or a full CV. We use support messages to answer your request and handle follow-up. You can request deletion; necessary unresolved support or legal records may need to be retained. We do not promise that email providers delete all operational backups immediately.
Limited Use and control
JobApply Studio uses handled data only to provide the described user-facing features. WD DIGI does not sell personal data, use it for advertising or transfer it for unrelated purposes. Human access is limited to content you intentionally send for support, with your consent, or where required by applicable law. The use of data follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Review permissions in Chrome, revoke individual optional hosts, disconnect provider keys, lock or delete your vault, export a backup, and stop using a source at any time. Material changes to these data flows will be described here and in the extension before any newly required consent.