Legal
Privacy Policy
Last updated 8 September 2026
The short version
- Wynda writes your resume, ranks jobs, and fills in application forms for you. Everything we hold is there to do one of those three things.
- When you ask Wynda to apply to a job, the text and screenshots of the application pages it is working on are sent to our server and from there to Google Gemini, so the model can decide which field to fill next. That is the only reason they are sent, and they are not stored afterwards.
- The extension only reads a page you pointed it at, or a page it opened for a task you started. It never runs in the background on sites you browse yourself.
- We do not sell your data, we do not use it for advertising, and we do not use it to build profiles of you for anyone else.
- Delete your account and everything above goes with it. Email privacy@wynda.io if you would rather we did it for you.
Who this covers
This policy covers the Wynda web app at wynda.io and the Wynda browser extension for Chrome. The two are one product: the extension has no account of its own and no data of its own — it signs in with the same session your browser already holds for the web app, and everything it learns is stored against that account.
Wynda is operated by ConvergeX AI. If you are in a jurisdiction with data-protection law that gives you rights over this data — the UK and EU GDPR, the CCPA, India’s DPDP Act — we act as the controller for it, and the rights section below tells you how to use them.
What we collect
Your account
You sign in with Google, and nothing else. From that sign-in we receive your name, email address, profile picture and a Google account identifier. We request only the openid, email and profile scopes — we cannot read your Gmail, your Drive, your Calendar or your contacts, and we never ask for a password.
The profile you give us
Everything an application form asks for, because a form that asks for it will otherwise stop and wait for you: work history, education, projects, skills, certifications, languages, phone number, postal address, links to LinkedIn/GitHub/portfolio, salary expectations, notice period, citizenship and work authorisation.
Some forms also ask voluntary equal-opportunity questions — gender, ethnicity, veteran status, disability status. These are optional everywhere, including here. If you leave them blank, Wynda answers “prefer not to say” on the form rather than guessing.
Resumes and applications
The resumes Wynda generates for you, the jobs you save, and a record of each application attempt: which job, when, what the outcome was, and a step-by-step log of what the assistant did.
Pages the assistant works on
This is the part worth reading closely, and it is described in full in the next section.
What the browser extension can see
The extension does not run on pages you browse. It has no content scripts — nothing of ours is injected into a page automatically. It reads a page in exactly two situations, both of which you start:
- 1
You click the Wynda icon on a job posting
Wynda reads the visible text of that one tab so it can tell you whether it is a job posting and save it to your account.
- 2
You ask Wynda to apply to a job
Wynda opens the employer’s application form in a background tab and works through it. On each step it reads the page’s interactive elements and visible text, and sometimes takes a screenshot of that tab, so that the model can decide what to click or type next.
That page text and those screenshots are sent to Wynda’s server over HTTPS, and from there to Google Gemini, which returns the next action to take. This is the whole mechanism: the model runs on our server and never inside your browser, which is also why the extension contains no downloaded or remotely-executed code of any kind.
What is kept, and what is not
The page text and screenshots are not written to our database. What we keep for each step is the URL, the page title, the list of actions taken, and how large the page was — enough for you to see what happened on your Applications page, and not the contents of the page itself.
The extension also refuses, in the browser and before any page is read, to open or read: webmail, password managers, sign-in pages at identity providers such as Google or Microsoft, search engines, and the Chrome Web Store itself. If an application form redirects to a sign-in page, Wynda stops and asks you to complete it yourself rather than reading it.
Wynda never types your password anywhere, and never has it to type. When a form needs you — a login, a verification code, a “prove you are human” check — it pauses and asks.
The permissions, and why each one exists
Access to job sites (<all_urls>)
Optional, and never requested when you install. An application form can be on any company’s careers page and routinely redirects across two or three hosts, so no fixed list of sites would work. The extension asks for this from its popup, next to an explanation, the first time you run a task — and you can revoke it at any time in Chrome’s extension settings.
Screenshots of the working tab (debugger)
A run happens in a background tab so it does not interrupt you. Chrome’s ordinary screenshot API can only photograph the tab you are looking at, so using it would mean yanking your screen away every time the assistant wanted to check its own work. Chrome shows a “Wynda started debugging this browser” bar while this is in use; Wynda attaches for a single screenshot and detaches immediately, so it appears for a fraction of a second and only during a run you started.
The tab you are on (activeTab)
Lets the popup read the page you are looking at when you click the Wynda icon — which is how it can tell you whether a posting is real, and how it can ask for access to job sites in context rather than at install.
Tab groups (tabGroups)
Puts the working tab in its own labelled, coloured group, so a run happening in the background is visible in your tab strip without opening anything. It carries a status: waiting, finished, failed, or needs you.
Reading and filling the form (scripting)
How the extension actually reads a form and types into it. Every read and every click on the application page goes through this, and only on the tab a run has opened. Nothing of Wynda’s runs on pages you browse yourself: the extension ships no content scripts, so there is no code of ours sitting on any other site.
Remembering a run in progress (storage)
Session storage only — the task, the tab it is using, and which step it reached. It is held in memory and cleared when you close the browser, so a run can survive Chrome pausing the extension mid-application instead of stranding a half-filled form. Nothing about a run outlives the browser session.
A place to run (offscreen)
A hidden page that hosts the loop driving a run. Chrome shuts down an extension’s background worker after short fixed limits, and a single application regularly takes longer than those allow; this is the supported way to outlast them. It displays nothing and has no access of its own.
Talking to Wynda (host access to wynda.io)
The one access requested at install, and the only site the extension can reach on its own: it is where your session lives, so signing in and fetching your own tasks and resume happen against Wynda and nowhere else.
Notifications
Optional and off unless you turn it on. Only ever fired when a task finishes or needs you — never for progress.
How we use it
- To write and tailor your resume for a specific job.
- To rank job postings by how well they fit your profile.
- To fill in and, when you ask for it, submit an application on the employer's own form.
- To find and draft messages to the people who make hiring decisions for a role, when you use that feature.
- To show you your own history: what was applied to, when, and what happened.
- To keep the service working — diagnosing failures, preventing abuse, and enforcing the daily limits that stop a runaway loop.
We do not use your data to train models. The providers we send it to are engaged under terms that do the same; see below.
Who we share it with
Only the providers that make the product work, each for a single named purpose, and none of them receive it for their own use:
| Provider | What it receives | Why |
|---|---|---|
| Google (Gemini) | Page text and screenshots of the application form; your profile fields and resume content | Deciding the next action on a form, and writing resume prose |
| Google (Sign in with Google) | Your name, email and profile picture | Authentication |
| Google Cloud | Everything, at rest and in transit | Hosting and the database |
| Exa | Your name and email during onboarding; role and company names when you use outreach | Finding your public professional profile, and finding who to contact at a company |
| JSearch (RapidAPI) | Job search terms — no personal data | Ingesting job postings |
| Google Analytics | Pages visited, approximate location from IP, device and browser | Knowing which pages people arrive on, and from where |
| PostHog | Pages visited, device and browser, and your account id once you are signed in — not your name, email or resume | Understanding which parts of the product people actually get through |
Beyond that, we share data only where the law requires it, and if Wynda is ever acquired we will tell you before your data moves.
Cookies and analytics
Two kinds of storage. The first keeps you signed in and remembers your theme; the product does not work without it and there is nothing to opt out of.
The second is analytics — Google Analytics and PostHog, as listed above. These tell us which pages people land on and which parts of the product they get through. They are not advertising cookies, we do not run ads, and nothing here is sold or shared with data brokers.
Analytics is disabled entirely for anyone whose browser sends a Do Not Track signal. We do not record your screen: session replay is switched off in our code rather than in a dashboard setting, so no recording of your resume, profile or messages is ever captured.
What we never do
- We do not sell your personal data, and never have.
- We do not transfer it to third parties for advertising, brokerage, or any purpose unrelated to running Wynda.
- We do not use it to determine creditworthiness or for lending.
- We do not read pages you browse on your own, and the extension does nothing at all until you ask it to.
How long we keep it
Your account, profile, resumes and application history are kept until you delete them or delete your account — this is your job-search record, and it is only useful if it persists.
The contents of pages the assistant worked on are not kept at all; they exist for the length of one request. Screenshots are held in memory for the same request and are never written to disk. The step-by-step log of what the assistant did — URLs, actions, outcomes — is kept with the application it belongs to and is deleted with it.
Your choices
- Revoke the extension's access to job sites at any time from chrome://extensions, without uninstalling it.
- Uninstall the extension. Nothing about it survives on your machine — its working state lives only in browser memory and is cleared when Chrome closes.
- Delete any resume, saved job or application from the dashboard.
- Delete your account, which removes your profile, resumes, applications and every step log with it.
- Ask us for a copy of your data, or for it to be corrected or erased, by writing to the address below. We will respond within 30 days.
- Revoke Wynda's access to your Google account at myaccount.google.com/permissions.
Security
Everything travels over HTTPS. The database is on a private network with no public address and is reachable only by the application itself. Access to production is limited to the people who operate it. No system is perfect, and we will tell you promptly if something happens that affects your data.
Children
Wynda is for people looking for work and is not directed at anyone under 16. We do not knowingly collect data from children; if you believe we have, write to us and we will delete it.
Changes to this policy
If we change how any of the above works, we will update this page and move the date at the top. A change that materially widens what we collect or who we send it to will be announced in the app before it takes effect, not after.
Contact
Questions, requests, or anything on this page that does not match what you have seen the product do: privacy@wynda.io.