My Info Autofill — privacy policy

Effective September 21, 2026. Applies to version 1.0.22 and later until this policy is updated.

Information used

My Info Autofill uses the information you choose to enter in profiles: names, contact information, gender, mailing addresses, employment details, travel or identity-document details, and custom fields. These fields are optional. Avoid adding secrets, passwords, or payment details to custom fields.

To match and fill forms, the extension examines relevant form controls, labels, accessible names, placeholders, autocomplete attributes, and existing values. It checks the current page’s address to determine whether filling is supported and whether the hostname is paused. Field-edit events are used to avoid overwriting your changes. It does not record a browsing-history log, capture keystroke sequences, or build a behavioral profile.

The extension also stores your default-profile choice, the automatic-filling and filled-field-summary settings, and the hostnames you explicitly pause.

Use and sharing

Profile information is used to fill supported forms. The extension does not send profiles or page data to the developer, an analytics service, an AI service, or an advertising service. There is no developer-operated server, account system, cloud backup, or synchronization.

Filling a field makes its contents available to that website immediately, before you submit the form. Automatic filling includes any saved passport and driver’s license details. This transfer to the website is the purpose of the extension. The website’s own collection and handling of the information is governed by its policies. Review websites and forms before using them.

The extension does not sell information, use it for advertising, or transfer it for unrelated purposes. Its use of user information is limited to the form-filling features described here. The developer cannot access stored profiles through this extension.

Storage and security

Profiles and settings are encrypted locally with AES-256-GCM. A key is derived from your vault password using PBKDF2-SHA-256 with 600,000 iterations and a random salt. Your password is not saved. While unlocked, profiles and a decryption key are held in Chrome’s memory-only session storage, restricted to trusted extension contexts. Content scripts receive the chosen profile for filling. Locking or restarting the browser requires unlocking again. Encryption cannot protect information from malicious software running on an already-unlocked device.

Before saving profiles, you choose a vault password and affirmatively agree to the in-product data-use disclosure. Existing unencrypted profiles from earlier local versions are migrated only after setup; autofill stays off until then. Keep your password safe: the developer cannot recover it.

The store package is restricted to HTTPS websites. The local development build also supports localhost for fictional-data tests. The extension skips recognized login, password, verification-code, payment, and hidden fields. Matching is heuristic and cannot guarantee that every website is recognized correctly.

The optional on-page summary lists filled field names, not their values. It is temporary page UI, not a saved history of websites or form submissions.

My Info Autofill’s use of information complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Information is used only for the disclosed profile and form-filling features, never for advertising, creditworthiness, or lending decisions.

Choices and retention

You can edit or delete a profile from the extension, choose another default, pause a hostname, turn automatic filling off, or uninstall the extension. Profiles remain locally until you delete them or remove the extension. Other copies made by your operating system or backup software are controlled by that software.

Undo restores eligible fields on the current page, but cannot withdraw information a website has already read. Deleting a profile or uninstalling the extension does not delete information already sent to websites.

Contact and changes

For questions, report an issue at GitHub support issues and include “My Info Autofill” in the title. Do not include profile data, passwords, identity documents, or backup files in public issues. This policy will be updated when information handling changes.

Exported backups

You can export profiles and settings to an encrypted JSON backup and import it into another browser using the password used at export time. Backups contain encrypted copies of all saved details. Legacy unencrypted backups can still be imported; they are encrypted on save. Previously exported unencrypted files remain unencrypted and should be protected or removed by you. The extension does not upload these files. You control where you store or share them. Deleting profiles or uninstalling the extension does not delete exported backup files. Imports replace local profiles and settings only after validation and your confirmation.