Smart Autofill Hub — Privacy Policy Chrome Extension
Last updated: August 4, 2026
This privacy policy applies to the Smart Autofill Hub Chrome extension (the "Extension") and describes how it handles information when you use it to fill web forms with profile data shared from the Smart Autofill Hub Android app (the "Android app").
1. Overview
The Extension's single purpose is to fill web forms in your browser using profile information (name, contact details, address, date of birth, government ID numbers, education and employment details) that a sender has chosen to share with you from the Android app via a secure share link. The Extension does not collect browsing history, clicks, keystrokes, or any other user activity.
2. Information the Extension Processes
2.1 Shared Profile Data
When you open a share link from the Android app, the sender provides you with:
- Share token — a short, unguessable session identifier embedded in the share link.
- 6-digit OTP — a one-time code provided by the sender.
You enter these into the Extension. The Extension sends the token and OTP to the Smart Autofill Hub backend over HTTPS to retrieve the encrypted share payload. The payload is decrypted entirely within your browser using a cryptographic key derived from your OTP and token (PBKDF2 with 120,000 iterations and AES-256-GCM). The decrypted profile fields (e.g., name, email, phone, address, date of birth, government IDs, education and employment records) are shown to you in the Extension's side panel or popup and are used solely to fill form fields on the page you are viewing when you click "Fill Form on This Page".
2.2 Documents
If the sender has included documents with the shared data and has permitted downloads, you may open or download those documents through the Extension. Documents are retrieved from the backend over HTTPS only when you request them.
2.3 Per-Domain Fill Overrides (stored locally on your device)
When you manually correct a field after the Extension has filled it, the Extension stores a mapping in your browser's local storage so the same form can be filled correctly on your future visits. This mapping contains only a CSS selector and a field category — it never contains your profile values, shared data, or page content. You can clear it by clearing your browser data or uninstalling the Extension.
3. How Information Is Used
All processed data is used exclusively to:
- Authenticate your access to a share session (token + OTP verification).
- Decrypt and display the shared profile fields and documents.
- Fill matching form fields on the active page when you explicitly click "Fill Form on This Page".
Form field detection happens locally in your browser. No web page content is collected, stored, or transmitted by the Extension.
4. Data Storage & Retention
- In-memory only: Shared profile data is held in memory only for the duration of the active share session and is never written to disk by the Extension.
- Automatic clearing: Data is automatically flushed from memory when the share session expires, is revoked by the sender, is viewed beyond its maximum view limit, or when you click "Switch Person / Clear Session".
- Local overrides: The only data the Extension persists is the per-domain CSS-selector override mapping described in section 2.3.
5. Data Transfers to Third Parties
- The Extension communicates only with the Smart Autofill Hub backend (
api.smartformautofill.hopxai.in) over HTTPS to fetch the encrypted share payload and documents.
- No personal data is sold, rented, or transferred to any third party.
- No data is used for advertising, tracking, or profiling.
- No data is used to determine creditworthiness or for lending purposes.
6. Permissions & Justification
- storage — stores the local per-domain CSS-selector override mapping described in section 2.3.
- activeTab — lets the Extension read and fill form fields on the currently active page only after you explicitly click "Fill Form on This Page".
- sidePanel — displays the Extension's user interface (token/OTP entry, shared data review, and the Fill button) in Chrome's side panel.
- Host access () — web forms can appear on any website; this broad permission is required so the Extension can fill forms on whichever page you are actively viewing. The content script only acts when you explicitly trigger a fill.
7. Remote Code
The Extension does not execute any remote code. All JavaScript is bundled inside the Extension package. The only network requests are HTTPS calls to the Smart Autofill Hub backend to fetch and decrypt the encrypted share payload.
8. Your Controls
- Clear Session — click "Switch Person / Clear Session" in the Extension to remove the current shared data from memory immediately.
- Do not load data — you can simply close the Extension side panel or popup without entering a token or OTP; no data is fetched until you do.
- Uninstall — uninstalling the Extension removes the locally stored CSS-selector override mappings from your device.
- Sender controls — the sender of the shared data can revoke a session at any time, set an expiry, limit the number of views, and choose whether copying, downloading, and autofill are permitted.
9. Safety for Sensitive Information
- Password, OTP, CVV, PIN, and passcode fields are never filled by the Extension.
- Sensitive ID fields such as Aadhaar and PAN are masked by default in the Android app and displayed masked where applicable.
- Private fields are only revealed when you explicitly expand them in the Extension.
- All communication between the Extension and the backend is encrypted with HTTPS; shared payloads are end-to-end encrypted with AES-256-GCM and can only be decrypted with your OTP and token.
10. Children's Privacy
The Extension is not directed to children under 13 and does not knowingly collect information from children.
11. Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. Your continued use of the Extension after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this privacy policy or the Extension's data handling, contact us at the developer email listed on the Chrome Web Store listing.
Smart Autofill Hub · Chrome Extension · Last updated August 4, 2026