offergenie_white

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how xGenie LLC ("we", "us", "our") collects, uses, shares, and protects user ("you", "your") information when you visit and interact with our website, services, and software (collectively, "Services"). Please read this Privacy Policy carefully. By using our Services, you agree to the processing of your information in accordance with this Privacy Policy.

1. Information We Collect

We collect the following categories of information to provide and improve our Services:

  • Account Information: Email address, name, phone number, and password when you create an account.
  • Resume and Career Data: Uploaded resumes, cover letters, work history, education, skills, career preferences, and job descriptions.
  • Interview Data: Interview recordings, transcriptions, responses to interview questions, performance metrics, and AI-generated feedback.
  • User-Generated Content: Custom interview questions, notes, feedback, saved responses, and any content you create using our Services.
  • Payment Information: Payment details are securely processed by Stripe. We do not store credit card numbers or banking information.
  • Technical Data: IP address, browser type, device information, operating system, usage logs, and performance data.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide, personalize, maintain, and improve our Services
  • Process your transactions and manage your account
  • Generate AI-powered interview questions and feedback tailored to your experience
  • Analyze your resume and provide optimization suggestions
  • Respond to your comments, questions, and customer support requests
  • Send you technical notices, updates, security alerts, and administrative messages
  • Monitor and analyze usage patterns to improve user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our Terms of Service

3. OfferGenie Copilot

OfferGenie Copilot is available as a Chrome extension that a signed-in user starts from Job Apply. You review and approve application details there before opening the matching supported employer form. Copilot can add routine details that you already approved automatically. Sensitive or unverified details, items that require a fresh choice each time, resumes, and manual steps remain for you to decide or complete. You remain responsible for reviewing and submitting the form.

Information Copilot handles

  • Short-lived credentials used only to connect the extension securely to your OfferGenie account and the application you selected
  • Application details you approved for that application, such as your name, email address, telephone number, mailing address, work-eligibility answers, optional equal-opportunity answers, and a label showing where each saved detail came from
  • Limited information about the selected employer form, including its web address and frame, field labels, field types and options, whether fields are required or disabled, and signals used to confirm that the form has not changed
  • Workflow details such as prior approvals, fresh choices for held-back items, whether each field was added or already matched, timestamps, your submit action, and limited confirmation signals used for your application history
  • If the optional AI answer-draft feature is enabled for your paid plan, the AI request can include the job title and employer, a bounded job description, facts you already confirmed, an eligible employer question's field key, label, input kind and bounded answer choices, and a bounded plain-text projection of the professional content in the resume selected for that application. Structured resumes omit phone number, email address, location and website fields. A legacy or plain-text resume uses a bounded fallback that removes labeled contact lines and recognizable email, phone, URL and government-ID tokens. Raw file bytes, unbounded or unredacted extracted text, page HTML, selectors, credentials and extension browsing history are excluded. The OpenAI Responses request sets store: false, so the generated response is not stored for later retrieval through the Responses API. This setting is not a Zero Data Retention claim; OpenAI's applicable account data controls and abuse-monitoring retention still apply.
  • Anonymous mechanical-failure details when a fill fails: only an error code, the supported application system and host, and the extension version. This diagnostic contains no account, session, workflow, proposal, field, applicant, employer-path, or page-content information.
  • If you mark a filled answer Not right, Copilot uses the claimed short-lived session and sends only the contract version, current application handoff ID, existing proposal ID, retry-event ID, and extension version. It does not send the employer field key, canonical key, label, answer value, tenant, or page content. OfferGenie verifies that the proposal belongs to the current approved packet and was filled, then records an account- and application-linked durable answer-quality audit record. The audit keeps identifiers for the existing approved packet and proposal, the proposal's source category, the application system and extension version, and information needed to prevent duplicate records. It does not store the field key, label, or answer value. Authorized personnel may follow its packet/proposal reference to investigate the existing approved answer after you send the report.

A routine detail is added automatically only when it was already approved in Job Apply, is fillable and verified, is not sensitive, and does not require a fresh choice each time. Optional equal-opportunity details, including ethnicity, gender, veteran status, or disability status, remain unselected until you choose them for that application. An AI-assisted draft is always labeled unverified and requiring a fresh choice, so Copilot never adds it automatically. Copilot may compare a current form value locally to show whether it matches a saved detail, but it does not send applicant-entered current values while discovering the form. It also does not send confirmation-page text or HTML.

Optional site access is requested from the extension panel rather than at installation. For each request, Chrome is asked only for the supported host pattern that matches the current application system. Across the extension, the six possible patterns cover boards.greenhouse.io, job-boards.greenhouse.io, jobs.lever.co, jobs.eu.lever.co, jobs.ashbyhq.com, and Breezy employer subdomains under breezy.hr. If you grant one, a packaged extension component may load in top-level documents and frames whose own URLs match that pattern, but Copilot does not inspect or fill a form unless the tab and frame match the exact application you started from Job Apply. When a Greenhouse direct-board form is embedded, the outer employer page only hosts the exact signed target iframe; Copilot does not inspect or fill the outer page or an arbitrary employer iframe. For Breezy, validation accepts only the one-level employer subdomain and application path in the active workflow. You can deny or revoke this access in Chrome. Without it, a toolbar click provides temporary access to the single active application.

Copilot receives a credential-free selector configuration from OfferGenie. It contains bounded form-root, field-identity, label, choice, honeypot, and submit selectors plus bounded application-system host and path metadata. The installed extension contains the parser and adapter logic that validates and interprets this configuration, and uses bundled rules if it is unavailable or invalid. The configuration is not JavaScript, WebAssembly, or an executable string, grants no site permission, and cannot bypass the signed application target. The 0.2.4 release scope is limited to Greenhouse, Lever, Ashby, and Breezy; a selector entry by itself does not make another site available.

Copilot does not collect cookies, passwords, unrelated file contents, complete page HTML, screenshots, device location, or browsing activity outside the user-started workflow. Resume contents are used only when you explicitly choose that resume for the current application. The bounded professional-text projection described above may be used server-side for an eligible AI answer draft, but resume contents are not included in extension form discovery or reliability reports.

How this information is used

We use this information only to open the application you selected, add routine details already approved in Job Apply, offer an unverified AI draft when that optional feature is enabled, show the review panel for items that still need your decision, preserve progress safely, diagnose fill failures, investigate answer quality when you request it, and record limited confirmation evidence in your application history. We do not sell this information or use it for advertising, unrelated profiling, or creditworthiness decisions.

Our personnel do not read extension user data unless you affirmatively consent for support or answer-quality review, access is necessary to investigate security or abuse, disclosure is required by law, or the information has been aggregated and de-identified for internal operations. Our use of information received through Copilot complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

Storage, deletion, and sharing

Temporary extension state, including approved application details, field selections, secure session credentials, and results waiting to be delivered, stays in browser-session storage, is available only to trusted extension components, and clears when that browser session ends. The one-time credential used to start a workflow is never saved and is removed immediately after use.

Local extension storage contains only the last validated selector configuration and the time it was fetched so the packaged extension can keep working if the network is unavailable. This non-user configuration may remain between browser sessions. No credential, application answer, resume, workflow record, user identifier, or browsing history is stored there. Server-side account and workflow records, including the account- and application-linked Not right audit item, follow the retention and deletion rules in this Privacy Policy.

The extension communicates only with OfferGenie and the selected employer form. When AI-assisted drafts are enabled, OfferGenie sends the limited draft input described above to OpenAI as our AI service provider using a Responses request with store: false. This means the generated response is not stored for later retrieval through the Responses API; it does not mean Zero Data Retention, and OpenAI's applicable account data controls and abuse-monitoring retention still apply. Copilot writes only routine details already approved in Job Apply or items you freshly choose into the exact selected employer form. The employer handles a completed form under its own privacy terms. OfferGenie service providers, legal disclosures, security disclosures, and business transfers remain governed by the other sections of this Privacy Policy. You may request access, correction, or deletion by contacting us as described below.

4. AI and Machine Learning

We use artificial intelligence to enhance our Services. Here's how:

  • Interview responses and transcriptions are processed by AI to provide real-time feedback and personalized coaching suggestions
  • We use OpenAI's API to generate interview questions, analyze responses, and provide improvement recommendations. Your data is processed according to OpenAI's data usage policies
  • Resume data is analyzed by AI to provide optimization suggestions and match job requirements
  • When Copilot answer drafts are enabled for an eligible paid plan, OpenAI receives only the bounded job, confirmed profile facts, professional resume projection, and employer-question details described in the Copilot section. Each draft remains unverified and requires your explicit choice before it can be added to a form. The Responses request sets store: false; this prevents later retrieval of the generated response through the Responses API, but is not a Zero Data Retention claim and remains subject to OpenAI's applicable data controls and abuse-monitoring retention.
  • We do NOT use your personal interview data to train our own machine learning models without your explicit consent
  • Audio recordings are processed through Azure Speech Services for transcription. These recordings are deleted immediately after transcription unless you choose to save them
  • AI-generated content is tailored to your specific profile and is not shared with other users

5. How We Share Information

We share your information only in the following circumstances:

  • We NEVER sell, rent, or trade your personal information
  • Service Providers: We share data with trusted third-party services that help us operate our platform (see 'Third-Party Services' section)
  • Legal Requirements: We may disclose information if required by law, court order, or government request
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred with appropriate notice
  • With Your Consent: We share information when you explicitly authorize us to do so
  • Aggregated Data: We may share anonymized, aggregated data that cannot identify you personally

6. Third-Party Service Providers

We work with trusted third-party services to provide our Services:

  • OpenAI: For AI-powered interview coaching, content generation, and optional Copilot answer drafts under the limits described above
  • Azure Speech Services: For speech-to-text transcription of interview recordings
  • AWS S3: For secure cloud storage of resumes and user-uploaded files
  • Stripe: For secure payment processing (we never see or store your credit card details)
  • Google Analytics: To understand usage patterns and improve our Services
  • Email Service Providers: For transactional emails and communications

8. Data Retention and Deletion

We retain your data only as long as necessary to provide our Services:

  • Active Account Data: Retained while your account is active and for 30 days after account closure
  • Interview Audio and Video: Not written to our servers. Audio is transcribed in real time and the raw audio and video are discarded
  • Voice Samples: Stored only if you record one yourself, and retained until you remove it
  • Transcriptions: The text of the session, together with the questions and the AI's answers, is saved to your account so your report and feedback can be generated from it, and retained while the account is active
  • Resume Data: Retained while your account is active. You can delete individual resumes at any time
  • Payment Records: Retained as required by financial regulations (typically 7 years)
  • Usage Logs: Retained for 12 months for security and analytics purposes
  • Account Deletion: You can request deletion of your account and personal data at any time by contacting [email protected]
  • Upon deletion request, we will remove your personal data within 30 days, except where retention is required by law

9. How We Protect Your Information

We take the security of your data seriously:

  • Encryption: All data transmissions are encrypted using SSL/TLS protocols
  • Secure Storage: Your data is stored in encrypted databases with restricted access
  • Access Controls: Only authorized personnel with a legitimate need can access personal data
  • Regular Security Audits: We conduct regular security assessments and updates
  • Password Protection: User passwords are hashed and salted using industry-standard methods
  • Third-Party Security: We require our service providers to maintain appropriate security measures
  • Incident Response: We have procedures in place to detect, investigate, and respond to data breaches

10. Your Privacy Rights

You have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal requirements)
  • Portability: Request your data in a structured, machine-readable format
  • Restriction: Request we limit processing of your personal information
  • Objection: Object to certain uses of your personal information
  • Withdraw Consent: Withdraw consent for processing where we rely on your consent
  • To exercise any of these rights, please contact us at [email protected]
  • We will respond to your request within 30 days in accordance with applicable laws

11. Region-Specific Rights

Additional rights based on your location:

  • California Residents (CCPA): You have the right to know what personal information we collect, request deletion, opt-out of sale (we don't sell data), and non-discrimination for exercising your rights
  • European Residents (GDPR): You have enhanced rights including data portability, right to erasure, and the right to lodge a complaint with supervisory authorities
  • Nevada Residents: You may opt-out of the sale of personal information (we don't sell data)
  • Other Jurisdictions: We comply with applicable data protection laws in all regions where we operate

12. Children's Privacy

Protecting children's privacy is important to us:

  • Our Services are not intended for children under the age of 16
  • We do not knowingly collect personal information from children under 16
  • If you are under 16, please do not use our Services or provide any personal information
  • If we learn we have collected information from a child under 16, we will promptly delete it
  • Parents who believe we have collected information from their child should contact us immediately at [email protected]

13. International Data Transfers

Your information may be transferred internationally:

  • Our Services are operated from the United States
  • Your information may be stored and processed in any country where we or our service providers maintain facilities
  • By using our Services, you consent to the transfer of information to countries outside your country of residence
  • We ensure appropriate safeguards are in place for international transfers as required by law

14. Changes to This Privacy Policy

  • We may change this Privacy Policy from time to time.
  • If we make changes, we will notify you by revising the date at the top of the policy.
  • In some cases, we may provide you with additional notice (such as adding a statement to our homepage or sending you a notification).

15. Contact Us

If you have any questions about this Privacy Policy, please contact us at: [email protected]
We will make every effort to respond to your inquiries in a timely manner.

By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.