SEOmade Autofill browser extension · Last updated July 22, 2026
The short version
Everything you put into this extension stays in your own browser. It is not uploaded to SEOmade,
not shared with anyone, not sold, and not used for advertising or analytics.
The extension makes no network requests on its own — only the three below, and only when you click something.
What the extension stores
All of it lives in Chrome’s local extension storage, on the device you installed it on. None of it is sent anywhere.
Your product profile
Name, tagline, short and long descriptions, website URL, category, tags, pricing, launch date, target audience and features — whatever you type into the editor.
Images
The logo and screenshots you add, resized and kept as data URLs.
Contact details
The name, email, job title, phone number, company details and social handles you choose to store, so submission forms can be filled with them.
Settings
Whether the helper button is shown, whether terms checkboxes may be ticked, and any sites where you dismissed the helper.
A local activity log
The hostnames where you used the extension and when, so the popup can show recent submissions. Capped at 200 entries.
What it never collects
No passwords. The extension has no password field and will never type into a password input on any page.
No browsing history. It does not record, transmit or analyse the pages you visit. The local activity log exists only to show you recent submissions, and never leaves your device.
No page content. Form labels are read in memory while filling and are discarded immediately.
No analytics, telemetry, tracking pixels, cookies or advertising identifiers. There is no analytics code in the extension at all.
No accounts. The extension works fully signed out. A SEOmade account is optional and only enables the sync described below.
Every network request it can make
There are three, all triggered by you:
When you click “Fetch” in the editor
The extension requests the website address you typed and reads its title, description and icon tags. The request goes to that website, from your browser. Nothing is sent to SEOmade.
When you click “Import from seomade.app”
The extension opens or reuses a seomade.app tab and lets that page make the request using the session you are already signed in with. The extension never reads, copies or stores your session cookie or any token.
When you submit a form on a directory linked to a SEOmade project
If — and only if — you have linked a project, the same seomade.app tab records that directory as “submitted” on your dashboard. Turn this off by not linking a project.
Beyond these, the extension makes no outbound connections. It loads no remote code, no fonts, no icons
and no scripts from any server — everything it runs is inside the package you installed.
Why it asks for each permission
Active tab
When you click the toolbar button, use the keyboard shortcut or pick the right-click item, Chrome hands the extension that one tab for that one moment. That is how filling works. It is not standing access, and it ends when you navigate away.
Storage
Keeps your product profile on your device between sessions.
Unlimited storage
Logos and screenshots are larger than Chrome’s default extension quota.
Scripting
Runs the fill routine in the tab you just pointed it at.
Context menus
Adds the right-click “Fill this form” entry.
seomade.app
Scoped to our own domain, and only used for the optional dashboard sync described above.
Access you can grant, and take back
Neither of these is requested when you install. Both are yours to switch off.
Access to all sites — off unless you turn it on
Ticking “Spot forms automatically” in the popup asks Chrome for access to every site, so the extension can notice a submission form and offer to fill it before you click anything. Unticking the box gives the access back immediately and stops the detection script from running at all. Nothing about the extension requires it — filling works fine without it.
One site, for one read
When you type your website address and press “Fetch”, the extension asks for access to that single address, reads its title, description and social image, and then removes that permission again as soon as it is done.
Your data, your call
Export it — “Export backup” in the editor writes a JSON file you own.
Delete it — deleting a project removes it and its images immediately. Uninstalling the extension erases everything Chrome stored for it.
Revoke access — untick “Spot forms automatically” in the popup, or use Chrome’s own site-access controls on the extension.
Nothing to request from us — since we never receive your data, there is no copy on our side to hand over or delete.
If this policy changes
Any change that affects what is stored or sent will be published here with a new date, and — if it widens what the
extension collects — called out in the release notes on the Chrome Web Store before the version ships.
Contact
Questions about this policy, or about anything the extension does: @mdanassaif on X.