The Hiring Record

The extension

It shows you what we have observed about the job posting you are looking at, on the boards we already crawl. It is a record of what we saw and when, not a rating, and not a judgement about the employer.

Version 1.1 · October 6, 2026

Where it runs without being asked

On nine applicant tracking system domains, and nowhere else. These are the boards this product already crawls, so the extension is showing you a record that exists rather than building one from your browsing.

  • boards.greenhouse.io
  • job-boards.greenhouse.io
  • jobs.lever.co
  • jobs.eu.lever.co
  • jobs.ashbyhq.com
  • *.myworkdayjobs.com
  • *.icims.com
  • apply.workable.com
  • *.recruitee.com
  • workforcenow.adp.com
  • www.themuse.com
  • www.usajobs.gov

It asks Chrome for four capabilities: local storage, a scheduled alarm, the ability to run its own script on those nine domains, and access to the current tab when you click the toolbar button. It does not ask for your browsing history, your bookmarks, or your identity.

Boards you add yourself

You can also point it at a board we do not crawl. When you do, Chrome asks you about that one site, by name, and you allow it or you do not. You can take it back at any time from Chrome’s own extension settings, and the extension stops running there when you do — it works out what it is allowed to do by asking Chrome, never from anything it recorded earlier.

Making that possible costs one line in the extension’s manifest that looks alarming out of context, so here it is: *://*/*, listed as an optional host pattern. Chrome will not let an extension ask for a site at runtime unless the manifest already declares a pattern covering it, and the list of every job board on the internet cannot be written in advance. So the wildcard is the declaration that makes a one-site-at-a-time request possible; it is not a grant, and it is not a hole.

  • It is optional, so Chrome grants none of it when you install the extension and shows no warning for it.
  • It is never requested as a whole. Every request the extension makes is built from one scheme and one host; there is no code path that asks Chrome for the wildcard.
  • Every grant that exists is a single site you chose, named in the prompt you answered. The extension refuses to run its script against a pattern rather than a host, so a wildcard grant — however it arrived — would still run nothing.

The alternative that avoids the wildcard is asking every person who installs this for access to all websites, up front, including the ones who only ever open the nine boards above. That is the larger request, not the smaller one. We would rather explain this line than have you find it in the manifest after reading a page that did not mention it.

What it reads on a page

The address of the posting you are on, and the fields the board itself prints: the title, the employer, the location, the posted line, the apply link, and the pay if the board states one. It reads what is on the screen, in the same way you are reading it.

The job description never enters our record of the posting. What we keep of a posting is a fingerprint that changes when the wording changes, which is enough to tell you a posting was edited without holding a word of it. There is no column for the text, in the record we publish or in the one we sell from.

There is one copy of a description this extension can make, and it is not ours: your own copy of the posting you applied to, taken when you mark the job as applied, if you asked for one. It goes to private storage under your account and nothing we publish or sell can read it. Without your agreement the text is not uploaded and not read — the page is never taken into the extension’s memory at all, which is a different thing from taking it and choosing not to send it. It is described in full below, under what it sends.

What it sends, endpoint by endpoint

Six addresses on this site, and — only when you are signed in and only for the things you do deliberately — your own account’s database and file storage. Every one is listed, including the ones that are easy to forget.

  • /v1/check — one posting URL, to ask what we have recorded about it.
  • /v1/scan/batch — the posting URLs on one board index page, in a single request, so a page of twenty results costs one round trip rather than twenty.
  • /v1/config — no payload. It asks what the current thresholds are.
  • /v1/sightings/marks — the listing ids on the screen, to ask which we have already seen. This request is deliberately anonymous: it names every listing in front of you, and attaching an account to it would turn our request log into your job search.
  • /v1/sightings — the opt-in contribution, described below. It is signed in, and it is the only contributed record where that is true: your account answers two questions at the door and nothing derived from it reaches the row.
  • /v1/board-candidates — a domain, and nothing else, when you tell us a board is worth watching. Signed in too, because it is you telling us something rather than us observing you; the row records that a board was named and never who named it.
  • Your account, when you are signed in and you save a job, mark one as applied, or agree to something — the application row itself (the employer, the role, the link, the date you gave it), and the record of the agreement. These go to our database provider under your own account, along with the sign-in refresh that keeps you signed in. They are your tracker, not the public record: nothing here is published, and none of it is what the panel shows other people.
  • Storage — your own private copy of the posting you applied to, if you asked for one and agreed to the separate wording that covers it. It is taken when you mark the job as applied, it is stored under your account where nobody else can read it, and nothing we publish, sell or count ever reads it. It is removed six months after that application is resolved, and when you delete your account. The privacy notice covers how long account data is kept and what deleting your account removes.

The install identifier. The extension mints a random 128-bit value when it is installed and sends it with three of those requests: /v1/check, /v1/scan/batch and /v1/sightings/marks. It exists so one install cannot use up everyone’s allowance. It is not derived from anything about you or your machine, it does not survive a reinstall, and the server treats it as untrusted — forging it or leaving it out moves you to a stricter limit rather than a looser one, so there is nothing to gain by lying about it.

Contributing what you see

Off by default. It covers boards we do not crawl, where the only way a listing enters the record is that a person saw it.

Turning it on takes two deliberate steps: you agree to specific wording, and Chrome separately asks whether to grant access to that site. Turning it off withdraws the agreement and drops the site access.

These are the words, in full — not a summary of them:

We keep the facts of each listing you see and the date, never what you searched for.

Stored as contribute_sightings v2. Agreed wording is never edited: if it changes it becomes a new version, and you are asked again rather than held to words you were not shown.

What a contributed listing carries:

  • Job title — the title as the board printed it
  • Employer name — as printed; null when the board does not show one
  • Location — the location line, unparsed
  • Posted — the board's own display text, never turned into a date
  • Employment type — read from a chip, from a closed vocabulary
  • Work arrangement — read from a chip, from a closed vocabulary
  • Apply link — the destination the board links out to
  • Compensation — the four fields the board states, or nothing
  • The board's own posting id — so two sightings of one listing are one row

The record says a listing was seen. It does not say who saw it. There is no person on the row — not an account, not an identifier, not a batch number that could be used to group one person’s reading together. Your account is checked at the door, for two questions only: have you agreed, and are you inside today’s limit. Nothing derived from it reaches the record.

Contributions are held and sent in groups, and the order within a group is shuffled before it leaves your browser, so the sequence you read a page in is not preserved.

What it never does

  • It does not run on sites outside the list above unless you grant them, one at a time. A grant is one site, never a pattern, and the manifest’s optional wildcard is what makes a single-site request possible rather than something we act on.
  • It does not put the text of a job description into our record, and the only copy it can make of one is the private copy you asked for, which is yours.
  • It does not send your browsing history, and it has no permission that would let it.
  • It does not attach your identity to the request that asks which listings we have seen.
  • It accepts messages from one website, this one, and no other.
  • It does not rate employers, and it does not tell you what a posting means. It tells you what we observed and when.

Reading the record it shows you

Everything the panel shows comes from the same observations behind the methodology and the same corrections process at corrections. If a figure looks wrong, it is worth telling us: we publish our own errors.

The extension — The Hiring Record