This policy explains how NeoDrive AI Form Autofill (the “extension”) handles information when you use NeoDrive records to fill forms on websites you select. It covers the extension and the NeoDrive services supporting its form assistant. The handling of your broader NeoDrive business account and third-party websites may also be covered by their respective policies and agreements.
For privacy questions or requests, contact privacy@neodrive.org.
Information the extension handles
NeoDrive account and record information. When you start the assistant from a NeoDrive record, the extension receives your username, the record identifier and type, its field values, and available source-file identifiers and metadata. The backend reloads the record and checks the agent’s access before processing it. AI requests can include permitted record fields and schema, source-file metadata, your business agent’s context instructions, and saved instructions for the selected site.
Selected website and form information. The extension processes the destination URL, including its path, query parameters, and fragment, and information about form controls. This includes field identifiers, labels, nearby headings, input types, placeholders, available options, and existing field values. Browser-agent requests also include visible page text, the page title, interactive element descriptions and positions, and viewport/scroll information. Form values and page content can contain personal, financial, business, or authentication information depending on the selected page. Password-type controls are not automatically excluded; the extension does not determine sensitivity from an input’s appearance or type alone. Hidden backing inputs are excluded from field extraction, but this is not a comprehensive exclusion of sensitive data.
Requested screenshots and browser actions. When structured page information is insufficient, the assistant can request a screenshot of the active target tab's visible viewport. The extension hides its own chat overlay during capture. Screenshots can contain any visible target-page content, including information unrelated to the form. The screenshot is sent through NeoDrive to OpenAI for that task. The assistant can also request scrolling, control clicks, and field filling in the bound target tab; updated page context and verified results are returned after actions. The extension does not capture other tabs or record desktop video.
Open tabs and saved destinations. The destination picker reads the titles, URLs, and available favicon URLs of open tabs so you can choose a destination. It saves destination addresses you select for future use. The open-tab list is used for selection, rather than sent as a list to the AI provider. The selected destination URL is sent with form requests.
Feedback and mappings. The extension processes your chat feedback, recent conversation context, proposed field mappings, assigned values, explanations, and details of fill failures. These help the assistant answer questions and correct the form.
Authentication. The background worker reads your existing neodrive_session cookie for the NeoDrive account you used to launch the task and sends it to NeoDrive to authenticate the connection. The session cookie is not sent to the destination website or AI provider, and the extension does not save a separate copy in extension storage.
Preferences and activity. The extension stores language, theme, autofill and highlight preferences, saved destinations, the most recent transferred record, task information, and recent activity metadata in Chrome’s local extension storage. Activity metadata can include record identifiers or summaries, destination URLs, timestamps, mapped-field counts, model names, and processing durations. NeoDrive records AI token usage and associated account/session metadata for budget accounting. Diagnostic console output can contain URLs, transferred records, mappings, feedback, and errors.
How information is used and shared
Information is used to authenticate your NeoDrive account, retrieve authorized records, map and fill selected forms, process corrections, remember site instructions, reuse saved mappings, manage preferences, and account for AI usage.
The extension sends form information, requested screenshots, browser-action results, and feedback to the NeoDrive backend. When AI processing is needed, NeoDrive sends relevant record, page, form, image, instruction, and conversation information to its AI service provider, currently OpenAI. Hosting and database services used by NeoDrive, including AWS, process information needed to provide the service. Provider processing and retention are governed by the applicable service configuration and agreements. Reusing a valid saved mapping does not require a new AI request or screenshot.
Under NeoDrive’s participation in OpenAI’s data-sharing incentive program, shared AI inputs (including record data, page content, and screenshots) and outputs may be used to improve and train OpenAI models.
Filled values are placed into the website you select. That website’s scripts may access those values before you submit the form. The extension does not automatically submit forms, and the destination website’s handling of information is governed by its own policies.
Extension data use: The extension does not use this information for advertising or transfer it to advertising platforms or data brokers. Information is transferred to provide the form assistant, under the AI-provider terms described above, or to meet applicable legal obligations. The Chrome Web Store User Data Policy sets requirements for extension data handling, including Limited Use restrictions.
Storage and retention
Local preferences, saved destinations, the most recent record, and other stored task data remain until replaced, removed, or cleared through Chrome. Closing a target tab removes its associated task entry, but does not necessarily remove the most recent record or other stored data. Local activity history is limited to the latest 50 entries. Chat messages are held in the target page’s memory while the assistant is open; portions may be transmitted during feedback processing.
Requested screenshots and browser observations are held in memory for the running task. The extension and NeoDrive do not save screenshot files or page observations to extension storage, the database, or the file library. OpenAI retention follows its applicable terms and account settings; store: false does not guarantee zero retention.
NeoDrive stores reusable mappings by page and record type and saved instructions by site origin. Mappings store recipes, selectors, and explanations rather than the current record’s resolved field values; recipes, explanations, user-specified constants, and saved instructions may still contain personal or business information. These settings do not have a fixed automatic expiry. Source records remain in your NeoDrive business account. AI accounting records are retained for account and budget administration. Uninstalling the extension does not delete information already stored by NeoDrive or its service providers.
Your controls and requests
You choose when to launch the assistant and which website receives the form values. You can change extension preferences, remove saved destinations, ask the assistant to forget saved site instructions, clear local extension data through Chrome, revoke extension access, or uninstall it.
For access, correction, deletion, or other privacy requests concerning information held by NeoDrive, email privacy@neodrive.org. We may need to verify your identity and authority for the business account. Legal obligations and applicable business-account agreements may affect what information can be deleted or disclosed.
Security and policy updates
Connections to hosted NeoDrive services use encrypted HTTPS/WSS transport, and the backend checks authentication and record access. Local development connections may use unencrypted localhost HTTP/WS. These measures do not make every destination website or local device secure.
We may update this policy when the extension’s data practices change. The updated policy will show its revision date, and material changes will be communicated as required by applicable rules.