What the extension permissions are for
Every permission the extension asks for, what it is used for, and how to take a site back. It ships with access to no job board at all.
The extension asks for very little at install time and asks for the rest one site at a time, in the click that needs it.
Granted at install
| Permission | What it is used for |
|---|---|
| Storage | Holds the resume snapshot and the answers you have typed before, on your machine |
| Downloads | Saves the tailored file so the form's upload dialog opens on the right one |
| Active tab and scripting | Injects the form filler into the one tab you pressed the button on |
| Tabs | Opens and follows the tabs in a queued run |
| involveresume.com | Reads the resume the site already parsed and the sign-in you already have |
| The Supabase project host | Reads your own profile row, under row-level security, to answer what your plan allows |
Asked for later, one site at a time
| Permission | When it is asked for |
|---|---|
| Any job board, per site | At the moment you press a button that needs that site, granted for that host only |
| JobTeaser | Named separately so the browser dialog says the portal rather than all sites |
Out of the box there is no registered content script on any site except Involve's own. Not an allowlist, not a wildcard: nothing. The extension is inert on every page you visit until you grant a site.
Reading and filling are two different grants
Letting the extension fill a form on a site does not start it reading every page you open there. The sites the score reader runs on are their own list, written only by the switch in the popup. Turning that switch off, or revoking the site permission in the browser, both stop it.
What it will not do with any permission
- It never submits a form from the toolbar button.
- It never overwrites a field you have already filled in.
- It never ticks a consent checkbox or radio. Those are yours.
- It never answers a work authorisation, visa, citizenship, clearance, criminal record, disability, veteran, ethnicity, gender or date of birth question. Where you have answered one before, it is replayed with a red outline and a note telling you to check it.
- It leaves a required field it has no answer for blank and marks it, because a silently wrong answer is worse than a visible gap.
Taking access back
- Open the browser's extensions page.
- Open the extension's details, then its site access settings.
- Remove the host, or set it to "on click".
Nothing about your account changes. To clear what the extension holds on the machine instead, use Forget everything at the foot of the popup, which drops the resume snapshot and the saved answers.
What the website holds is a separate question, answered in your data, and how to delete it.
Questions about this
Why does it ask again on every new site?
Because it ships with permission for no job board. Chrome grants a host permission only inside a click, for the one site you are on, and you can take it back at any time.
Does letting it fill a form let it read every page on that site?
No. Filling and reading are separate lists. The score reader runs only on sites you turned it on for with that switch in the popup.
How do I revoke a site?
From the browser's own extensions page, under the extension's site access settings. The extension stops running there immediately.
Why does it need downloads?
It saves the tailored document to your machine so the form's upload dialog opens on the right file.
Grant one site, not all sites
There is a wildcard option in the browser dialog and there is no reason to use it. One board at a time is the intended shape.
Open Involve Resume