Privacy
Your application records stay yours.
This page describes the Interndex web app and the Interndex Capture browser extension, including what the extension reads, stores, and sends when installed from the Chrome Web Store or loaded locally as an unpacked developer build.
Effective date / last updated: September 11, 2026.
Who operates Interndex
Interndex is built and operated by an individual developer, not a registered company, based in Ontario, Canada. If Interndex ever incorporates, changes ownership, or moves, this page will say so and name the new operator.
For anything about your privacy — a question, a correction, a deletion request, or a concern about how your data is handled — the person accountable is the same person who builds Interndex, reachable at support@interndex.dev. There is no separate privacy team; every request goes to that inbox and gets a reply from a person.
What Interndex collects, and why
Each category below exists for one stated reason. Interndex does not collect anything beyond what that reason needs.
- Account data. Your name, email address, and password (handled entirely by Supabase, Interndex's authentication provider — see “Where your data is stored” below). Used to create your account, sign you in, and secure it.
- Application data. The job records you save or edit yourself, that a connected AI assistant saves or edits on your instruction, or that the Interndex Capture extension saves after you confirm a capture — company, title, status, dates, notes, and the other tracker fields described in the app. Used to run the tracker, pipeline, dashboard, and analytics you see.
- Browser-capture data. What the Interndex Capture extension reads from a job posting page, described fully below. Used only to fill in the application record you confirm saving.
- Technical data. Session cookies and tokens that keep you signed in, and the ordinary connection information (like IP address) that any website or its hosting provider logs to keep the service running and secure. Interndex does not run any analytics, advertising, or tracking script of its own — see “Cookies and local storage” below for the full picture.
Consent
Creating an account is how you consent to account and application data being collected as described here. Installing the Interndex Capture extension and granting its permissions is separate consent for browser-capture data, and connecting an AI assistant in Settings is separate consent for that assistant to read and write your application records.
You can withdraw any of these independently: disconnect an AI assistant or the extension's access in Settings without closing your account, uninstall the extension without affecting your account, or permanently delete your account yourself from Settings after confirming your password. If you would rather have help with any of this, email support@interndex.dev. Withdrawing consent for a feature stops that feature; it does not retroactively delete records already saved unless you also delete those records, or your account.
The web app today
Interndex stores the account information needed to sign you in and the application records you choose to save. A connected AI assistant can work with those records only after you authorize its connection to your account. You can review and revoke connected clients in Settings.
Your records are used to provide Interndex's tracker, pipeline, dashboard, analytics, and connected-assistant features. Interndex does not sell your application records or use them for personalized advertising. You can edit, archive, and delete tracked records through Interndex.
How a connected AI assistant fits in
Interndex itself does not run any AI. It has no chatbot and no model of its own, and it never sends your application data to an AI provider on its own initiative. The Interndex Capture extension does include a deterministic, rule-based parser — no AI or machine learning involved — that reads structured posting data from the page you open it on to fill in fields like title, company, and location; see “The Interndex Capture browser extension” below for exactly what it reads and sends. When you connect an assistant like Claude or a ChatGPT connector, that assistant is your own tool, signed in as you, reading a job posting or a spreadsheet you gave it directly — Interndex never sees that posting or that file. The assistant only reaches Interndex when it calls one of a fixed set of documented actions (saving, listing, reading, or updating your own applications), authenticated as your account and limited to records that account can already reach.
What that assistant does with a posting or a spreadsheet before it talks to Interndex — and whatever it stores or sends elsewhere — is between you and that assistant's own provider and their own privacy policy, not Interndex. Interndex only stores what the assistant sends it, the same way it stores what you type into the web app yourself.
The Interndex Capture browser extension
Interndex Capture is a manual capture tool, not an AI, discovery, or background-monitoring product. It does what its one button says: it saves the posting you are looking at into your own tracker.
- Page data is read only after you open the extension on a page. It registers no content script and holds no permission for job sites, so it has no way to read a page you have not opened it on.
- What it reads is the posting's own published job details and standard page metadata. The page's full contents are never transmitted.
- Extracted posting information is sent to your own Interndex account, and only after you confirm it and choose to save.
- Interndex does not continuously monitor browsing. Nothing runs in the background between captures, and the extension keeps no record of pages you visited.
- Sign-in information is used only to connect your own Interndex account. Credentials are held by the extension and are never given to the job page.
- Captured data is used only to provide Interndex functionality, not sold or used for personalized advertising.
- You can edit or delete captured records through Interndex, just like records saved another way, and you can remove the extension's access at any time in Settings.
- The extension provides no AI of its own. It does not classify jobs, match or tailor a resume, write applications, fill forms, or apply on your behalf.
Deliberate limits
Interndex does not need to infer personal facts, continuously scrape job sites, detect submissions, or inspect unrelated browsing to store a posting. Unknown information remains unknown: when a posting does not state something, the extension leaves the field empty rather than guessing at it.
All communication between the extension and Interndex, and between the extension and Supabase, happens over HTTPS. The extension does not sell captured data or use it for advertising, and it does not share it with any other third party.
If an application has a company website saved, the web app asks Logo.dev to show that employer's logo. Your browser requests that image directly from Logo.dev using the company's domain. Along with that domain, Logo.dev receives the ordinary request metadata any website sees when your browser contacts it — such as your IP address and browser user agent — but never your name, email, or any other Interndex data. Leave the company website field empty and Interndex shows a plain lettermark instead, with no request to Logo.dev at all.
Cookies and local storage
The web app sets one kind of cookie: a session cookie from Supabase that keeps you signed in. It is strictly necessary — without it, Interndex could not tell it was still you on the next page — and it is not used to track you across other sites or to serve ads. Interndex runs no analytics, advertising, or third-party tracking script, so there is nothing else to opt out of.
The Interndex Capture extension stores your sign-in tokens in Chrome's own extension storage rather than a cookie: the short-lived access token in memory (cleared when Chrome closes), and the longer-lived refresh token on disk so you are not asked to reconnect every session. Both are readable only by the extension itself, never by the pages you visit.
Where your data is stored
Interndex runs on two hosting providers: Vercel for the website and Supabase for the database and authentication. Both are configured to run in the Canada (Central) region, so your data is processed and stored in Canada. Optional company logos are requested directly from Logo.dev, described above.
How long we keep your data
Interndex keeps your application records for as long as your account exists, with no automatic expiry — a job search runs for months and the whole point of the tracker is a record that lasts as long as you need it to. You can archive an application at any time, and permanently delete an archived one yourself, right in the app, whenever you choose.
Deleting your account is self-service: open Settings, choose Delete my account, and confirm your password. Your profile, application records, and status history are deleted with it — the database is built so that removing your account automatically removes everything tied to it, rather than leaving orphaned rows behind. Before you do, Settings also lets you download your profile, every application you have tracked, and its status history as one Excel workbook. If you need help with either step, email support@interndex.dev.
Security
Every connection to Interndex — the web app, the extension, and a connected AI assistant — happens over HTTPS. Interndex itself never sees or stores your password; Supabase handles that. Every table that holds your data enforces row-level security in the database itself, so a request for another student's applications is rejected before it ever reaches application code, not just hidden by the interface. Every ordinary request — from the web app, the extension, or a connected assistant — runs as your own account and is held to that protection.
The one exception is a server-only privileged credential that Interndex uses solely to carry out an account deletion you started yourself. It never runs in your browser, is never sent to any user, extension, or assistant, and is not used for anything else.
Your privacy rights
You can see everything Interndex holds about you by signing in and looking at your applications, your profile, and your Settings page — there is no hidden data — and you can download your profile, applications, and status history as one Excel workbook from Settings. You can correct almost anything yourself by editing a record or your account details. For anything you cannot fix in the app — correcting account information, asking what data Interndex holds about you, or challenging how a request was handled — email support@interndex.dev. Expect a reply within a few days.
Children and eligibility
Interndex is built for students old enough to be applying to internships and co-ops, and is not directed at young children. Signing up today does not ask for or verify your age. If you believe a child has created an Interndex account, email support@interndex.dev and it will be removed.
Changes to this policy
If this policy changes in a way that matters — a new category of data, a new third party, or a different retention rule — the “last updated” date above will change and Interndex will tell you directly (an email or an in-app notice) rather than only updating this page silently. A minor wording or formatting fix may update the date without a separate notice.
Managing your data
You can review, edit, archive, and delete your application records at any time by signing in to Interndex. Settings is where Supabase, not the extension itself, is the source of truth about who still has access: revoking the Interndex Capture extension's connection there — or a connected AI assistant's — is independent of whatever the browser extension still has stored locally, and disconnecting from inside the extension does not by itself revoke that server-side access.
This page works alongside Interndex's Terms, which cover the agreement for using the service rather than how your data is handled. Questions that aren't about privacy can also go through Support.
This page is provided as-is and isn't a substitute for legal advice.

