Skip to main content

Privacy Policy

Last updated: September 8, 2026

FillMatic is built for private form testing. This policy explains what information the FillMatic Chrome extension and website handle, why they handle it, and your available choices. The extension does not require an account.

Table of Contents

Extension Data

Processed locally

When you activate a fill, the extension locally inspects supported form controls and related metadata such as labels, names, IDs, placeholders, autocomplete attributes, and widget state. It then generates dummy values and writes them into the page. This processing is required for autofill and is not sent to a FillMatic server.

Fills do not submit forms by default. File-input filling is currently unavailable while the feature is being prepared for release.

Saved in Chrome storage

The extension stores settings and configuration inchrome.storage.local on your device. This can include profiles, field rules, Actions, recipes, typing preferences, ignored fields, and any reusable password or PIN you configure. These values can be sensitive, so do not configure secrets you do not want stored in your browser.

AI-assisted Action builder

If you use the optional Action builder, it scans serializable field metadata and may use Chrome's on-device Prompt API when available. The model is not required to run a saved Action. Reviewed mappings are stored locally as ordinary Action field rules.

Website Data

Analytics

The FillMatic website uses PostHog, a third-party product analytics and error-reporting service. The site records usage events such as calls to action, demo interactions, and feedback-form submissions to help us understand and improve the website. PostHog also captures unhandled JavaScript errors and unhandled promise rejections so we can investigate website failures. This integration does not capture console errors, and the tracked events do not include feedback-form values, extension page contents, or generated form values.

On the deployed website, analytics requests use the same-origin /r route and are forwarded by our Cloudflare Pages Function to PostHog's EU service. The proxy does not store analytics payloads in our application. PostHog may process standard request and device information associated with these events, such as page URL, referrer, browser details, timestamps, and network information. Review PostHog's privacy policy for information about its processing.

Feedback and support requests

The feedback form on the FillMatic website collects the name, email address, and message you choose to submit. The form sends that data to Airform, a third-party form-processing service that forwards the submission to our support inbox.

Feedback is used to understand and respond to your request. It may be retained as reasonably necessary for support records. Do not submit passwords, payment details, private page contents, or other sensitive information. You can contact us directly at hello+fillmatic@abdulsamad.dev.

Extension Permissions

FillMatic requests these permissions for its user-triggered autofill features:

  • Website access on HTTP and HTTPS pages: The content script runs on ordinary websites so FillMatic can inspect supported form fields and fill them when you request it. Browser-internal pages such as chrome:// are not targeted.
  • activeTab: Lets a user-initiated popup, keyboard shortcut, or side-panel action interact with the current tab.
  • storage: Saves profiles, rules, Actions, recipes, preferences, and other configuration locally on your device.
  • webNavigation: Identifies frames in the active tab so autofill can reach forms embedded in iframes. Actions only run in child frames when their iframe option is enabled.
  • sidePanel (when the Action builder is included): Declared in builds that include the optional Action builder so Chrome can provide its side-panel API. The builder opens and scans fields only when you choose that action.

What we do not do

  • We do not collect or transmit general page contents, browsing history, form submissions, or file contents.
  • We do not send page contents, generated values, profiles, recipes, or mappings to a FillMatic server. Optional Action mapping runs on-device when supported by Chrome.
  • We do not sell extension data or share it with advertisers.

Sharing and Third Parties

The website shares usage and error-reporting data with PostHog as described above. The voluntary feedback form is processed by Airform before being forwarded to our support inbox. Review Airform's website before submitting feedback.

The website is hosted at https://fillmatic.pages.dev. The extension is distributed through the Chrome Web Store, whose own policies apply to that service.

Your Choices

  • Use normal autofill without opening the optional Action builder.
  • Remove saved extension data through the extension settings or Chrome's extension storage controls.
  • Uninstall the extension to stop its content script from operating on webpages.
  • Contact us at hello+fillmatic@abdulsamad.dev about a support submission or privacy question.

Changes to This Policy

If FillMatic introduces a feature that changes data collection, storage, or sharing, this policy will be updated accordingly.