Legal
Privacy Policy
Last updated 18 August 2026
The short version
- Wynda writes your resume, ranks jobs, and fills in application forms for you. Everything we hold is there to do one of those three things.
- When you ask Wynda to apply to a job, the text and screenshots of the application pages it is working on are sent to our server and from there to Google Gemini, so the model can decide which field to fill next. That is the only reason they are sent, and they are not stored afterwards.
- The extension only reads a page you pointed it at, or a page it opened for a task you started. It never runs in the background on sites you browse yourself.
- We do not sell your data, we do not use it for advertising, and we do not use it to build profiles of you for anyone else.
- Delete your account and everything above goes with it. Email privacy@wynda.io if you would rather we did it for you.
Who this covers
This policy covers the Wynda web app at wynda.io and the Wynda browser extension for Chrome. The two are one product: the extension has no account of its own and no data of its own — it signs in with the same session your browser already holds for the web app, and everything it learns is stored against that account.
Wynda is operated by ConvergeX AI. If you are in a jurisdiction with data-protection law that gives you rights over this data — the UK and EU GDPR, the CCPA, India’s DPDP Act — we act as the controller for it, and the rights section below tells you how to use them.
What we collect
Your account
You sign in with Google, and nothing else. From that sign-in we receive your name, email address, profile picture and a Google account identifier. We request only the openid, email and profile scopes — we cannot read your Gmail, your Drive, your Calendar or your contacts, and we never ask for a password.
The profile you give us
Everything an application form asks for, because a form that asks for it will otherwise stop and wait for you: work history, education, projects, skills, certifications, languages, phone number, postal address, links to LinkedIn/GitHub/portfolio, salary expectations, notice period, citizenship and work authorisation.
Some forms also ask voluntary equal-opportunity questions — gender, ethnicity, veteran status, disability status. These are optional everywhere, including here. If you leave them blank, Wynda answers “prefer not to say” on the form rather than guessing.
Resumes and applications
The resumes Wynda generates for you, the jobs you save, and a record of each application attempt: which job, when, what the outcome was, and a step-by-step log of what the assistant did.
Pages the assistant works on
This is the part worth reading closely, and it is described in full in the next section.
What the browser extension can see
The extension does not run on pages you browse. It has no content scripts — nothing of ours is injected into a page automatically. It reads a page in exactly two situations, both of which you start:
- 1
You click the Wynda icon on a job posting
Wynda reads the visible text of that one tab so it can tell you whether it is a job posting and save it to your account.
- 2
You ask Wynda to apply to a job
Wynda opens the employer’s application form in a background tab and works through it. On each step it reads the page’s interactive elements and visible text, and sometimes takes a screenshot of that tab, so that the model can decide what to click or type next.
That page text and those screenshots are sent to Wynda’s server over HTTPS, and from there to Google Gemini, which returns the next action to take. This is the whole mechanism: the model runs on our server and never inside your browser, which is also why the extension contains no downloaded or remotely-executed code of any kind.
What is kept, and what is not
The page text and screenshots are not written to our database. What we keep for each step is the URL, the page title, the list of actions taken, and how large the page was — enough for you to see what happened on your Applications page, and not the contents of the page itself.
The extension also refuses, in the browser and before any page is read, to open or read: webmail, password managers, sign-in pages at identity providers such as Google or Microsoft, search engines, and the Chrome Web Store itself. If an application form redirects to a sign-in page, Wynda stops and asks you to complete it yourself rather than reading it.
Wynda never types your password anywhere, and never has it to type. When a form needs you — a login, a verification code, a “prove you are human” check — it pauses and asks.
The permissions, and why each one exists
Access to job sites (<all_urls>)
Optional, and never requested when you install. An application form can be on any company’s careers page and routinely redirects across two or three hosts, so no fixed list of sites would work. The extension asks for this from its popup, next to an explanation, the first time you run a task — and you can revoke it at any time in Chrome’s extension settings.
Screenshots of the working tab (debugger)
A run happens in a background tab so it does not interrupt you. Chrome’s ordinary screenshot API can only photograph the tab you are looking at, so using it would mean yanking your screen away every time the assistant wanted to check its own work. Chrome shows a “Wynda started debugging this browser” bar while this is in use; Wynda attaches for a single screenshot and detaches immediately, so it appears for a fraction of a second and only during a run you started.
Notifications
Optional and off unless you turn it on. Only ever fired when a task finishes or needs you — never for progress.
How we use it
- To write and tailor your resume for a specific job.
- To rank job postings by how well they fit your profile.
- To fill in and, when you ask for it, submit an application on the employer's own form.
- To find and draft messages to the people who make hiring decisions for a role, when you use that feature.
- To show you your own history: what was applied to, when, and what happened.
- To keep the service working — diagnosing failures, preventing abuse, and enforcing the daily limits that stop a runaway loop.
We do not use your data to train models. The providers we send it to are engaged under terms that do the same; see below.
Who we share it with
Only the providers that make the product work, each for a single named purpose, and none of them receive it for their own use:
| Provider | What it receives | Why |
|---|---|---|
| Google (Gemini) | Page text and screenshots of the application form; your profile fields and resume content | Deciding the next action on a form, and writing resume prose |
| Google (Sign in with Google) | Your name, email and profile picture | Authentication |
| Google Cloud | Everything, at rest and in transit | Hosting and the database |
| Exa | Your name and email during onboarding; role and company names when you use outreach | Finding your public professional profile, and finding who to contact at a company |
| JSearch (RapidAPI) | Job search terms — no personal data | Ingesting job postings |
Beyond that, we share data only where the law requires it, and if Wynda is ever acquired we will tell you before your data moves.
What we never do
- We do not sell your personal data, and never have.
- We do not transfer it to third parties for advertising, brokerage, or any purpose unrelated to running Wynda.
- We do not use it to determine creditworthiness or for lending.
- We do not read pages you browse on your own, and the extension does nothing at all until you ask it to.
How long we keep it
Your account, profile, resumes and application history are kept until you delete them or delete your account — this is your job-search record, and it is only useful if it persists.
The contents of pages the assistant worked on are not kept at all; they exist for the length of one request. Screenshots are held in memory for the same request and are never written to disk. The step-by-step log of what the assistant did — URLs, actions, outcomes — is kept with the application it belongs to and is deleted with it.
Your choices
- Revoke the extension's access to job sites at any time from chrome://extensions, without uninstalling it.
- Uninstall the extension. Nothing about it survives on your machine — its working state lives only in browser memory and is cleared when Chrome closes.
- Delete any resume, saved job or application from the dashboard.
- Delete your account, which removes your profile, resumes, applications and every step log with it.
- Ask us for a copy of your data, or for it to be corrected or erased, by writing to the address below. We will respond within 30 days.
- Revoke Wynda's access to your Google account at myaccount.google.com/permissions.
Security
Everything travels over HTTPS. The database is on a private network with no public address and is reachable only by the application itself. Access to production is limited to the people who operate it. No system is perfect, and we will tell you promptly if something happens that affects your data.
Children
Wynda is for people looking for work and is not directed at anyone under 16. We do not knowingly collect data from children; if you believe we have, write to us and we will delete it.
Changes to this policy
If we change how any of the above works, we will update this page and move the date at the top. A change that materially widens what we collect or who we send it to will be announced in the app before it takes effect, not after.
Contact
Questions, requests, or anything on this page that does not match what you have seen the product do: privacy@wynda.io.