Legal & PoliciesFillo Browser Extension Privacy Policy
Privacy

Fillo Browser Extension Privacy Policy

How the Fillo browser extension handles your data. Fillo runs entirely on your own device, makes no network requests, and sends nothing to Kira or to anyone else.

Effective June 1, 2026Last updated June 2026

1. What this policy covers

This policy applies specifically to Fillo, the Kira browser extension for filling web forms. It is separate from, and additional to, the Kira Privacy Policy that covers the kiraai.ai platform and web application.

The short version

Fillo makes no network requests of any kind. It has no server, no analytics, no telemetry and no tracking. Everything you enter stays in your own browser, and neither Kira nor anyone else can see it.

2. What Fillo stores

Fillo stores only what you type into it yourself. Nothing is gathered in the background and nothing is inferred about you.

DataWhere it is storedWhat it is for
Autofill profiles — name, email address, phone number, postal address, company, website, and any custom fields you createchrome.storage.sync, in your own browserSupplying the values Fillo writes into form fields
Password vault entries (optional feature)chrome.storage.sync, encrypted on your device before being writtenFilling password fields on sites you have chosen to save
Fill history — site domain, page title, profile used, and field countschrome.storage.local, on that device onlyLetting you see where a profile has recently been used

Fill history never records the values that were filled, and never records the full URL of a page — only its domain.

3. Where that data goes

Nowhere. The extension contains no code that makes network requests. There is no Fillo server, and the extension does not communicate with the Kira platform, with kiraai.ai, or with any third party. Kira has no access to your Fillo data and no mechanism by which it could obtain it.

Data saved in chrome.storage.sync is synchronised by Google Chrome itself between browsers where you are signed in to your own Google account, in exactly the way Chrome syncs your bookmarks. That synchronisation is performed by Chrome, is governed by Google’s own privacy policy, and is not accessible to Kira. You can prevent it entirely by turning off Chrome sync.

4. How Fillo accesses web pages

Fillo requests no host permissions. It uses the activeTab permission, which means it can only read a page after you click the Fillo icon on that specific tab. It has no standing access to any website, cannot run in the background, and cannot see pages you have not opened it on.

When you click Analyze, Fillo reads the labels, names, ids, placeholders and input types of the form fields on that page in order to match them against your selected profile. Page content is used in memory to perform the fill and is then discarded. It is never stored and never transmitted.

Fillo never submits a form on your behalf. You review what was filled and submit it yourself.

5. The password vault

The password vault is optional and off until you create it. When you do, Fillo derives an encryption key from your master passphrase using PBKDF2-SHA-256 with 250,000 iterations, and encrypts each stored password with AES-GCM-256. Only the resulting ciphertext is written to storage.

Your passphrase cannot be recovered

Your master passphrase is never stored anywhere and never leaves your device. That is what makes the vault safe, and it also means that if you forget the passphrase, nobody — including Kira — can recover your saved passwords.

6. What Fillo never does

  • Never sells or transfers your data to third parties.
  • Never uses your data for any purpose other than filling forms at your request.
  • Never uses your data to determine creditworthiness or for lending purposes.
  • Never loads or executes remote code — all code ships inside the extension package.
  • Never submits a form without you doing it yourself.

7. Deleting your data

You can delete individual profiles, saved passwords, and fill history from the Fillo options page at any time. Removing the extension from your browser deletes everything it has stored.

Because none of this data ever reaches Kira, there is nothing for us to delete on our side and no deletion request to make. If you also use the Kira platform, the separate Data Deletion policy covers your platform account.

8. Children

Fillo is not directed at children under 13 and collects no data from anyone.

9. Changes to this policy

If Fillo’s data practices change — in particular if a future version communicates with the Kira platform — this policy will be updated before that version ships, and the change will be described here with a revised date.

10. Contact

For any question about privacy in the Fillo extension, contact support@kiraai.ai.

Frequently asked questions

Quick answers to common questions.

No. The extension makes no network requests at all. It has no connection to the Kira platform and no server of its own.

No. Fillo works entirely on its own, with no sign-in and no account.

No. Passwords are encrypted on your device with a key derived from a passphrase that is never stored and never leaves your browser. Kira never receives them in any form.

To find the form fields and match them to your profile. It can only do this on a tab where you have clicked the Fillo icon, and the page content is discarded straight after the fill.