Refolk

Legal

Privacy Policy

Last updated September 13, 2026

Who we are

Refolk operates anysearch, a tool for discovering people, repositories, and organizations from public data sources. For privacy questions, contact hello@refolk.ai.

Data we collect

  • Account data. Email, name, and avatar provided by your sign-in provider (Google or GitHub). If you connect GitHub, we store an OAuth token used only to query GitHub on your behalf.
  • Usage data. Search queries, conversations, credit ledger entries, and basic request metadata (timestamps, IP, user agent) needed to operate, secure, and bill the service.
  • Payment data. Stripe handles all card data. We store only the Stripe customer/charge identifiers needed to reconcile credit top-ups.
  • Search results. Public data about third parties returned by GitHub, third-party people/company data providers, GH Archive, and Anthropic web search. We cache results transiently to make follow-up questions fast.

How we use it

  • To run searches you request and return results in your conversations.
  • To operate accounts, credits, billing, and customer support.
  • To prevent abuse, fraud, and to protect the service and its users.
  • To improve product quality (aggregated, de-identified usage analysis).

We do not sell personal data. We do not use your conversations to train third-party models.

The browser extension

Refolk AutoApplyis an optional Chrome extension that fills a job application form in from what your Refolk account already holds. It is what makes an application possible on boards that only accept a submission made in your own browser. It never presses submit: it fills the form in, scrolls the employer’s own submit button into view, and stops.

  • Where it runs. Only on four job board domains and on refolk.ai. It cannot read any other site, and on those four it acts only when you click it.
  • What leaves your browser. The address of the job page you clicked it on, the access key described below, and anything you type into the note box yourself. Nothing else. The contents of the page are read in the tab and are not sent anywhere.
  • What comes back. Your own answers, your resume, and the cover letter written for that one application. This is fetched per application, used to fill the form in, and gone when the tab closes. The extension stores none of it.
  • What it stores.One access key, in the browser’s own extension storage. That key is issued when you press connect on your account page, it is not your sign-in, and only its hash is kept server-side. Revoking it from that page stops the extension working and leaves you signed in everywhere else.
  • Telling Refolk something. The extension has a note box, in its toolbar popup and under the message left after a form is filled in. What is sent is what you typed, the address of the board page you were on, the line the extension had just shown you, and its version - and only when you press send. It arrives as an email to the support address with your own address as the reply-to, so a reply comes back to you. Nothing is read off the page to fill it in.
  • Verification codes. Some boards email a one-time code before they will accept a form. If you have connected your mailbox, the extension asks for that code so it can be typed in for you. The code is used once and never stored.

What the extension does not collect, stated because the permissions it asks for would allow some of it and it does not do it:

  • No browsing history. The address of the one job page you clicked it on is sent, so the right application can be identified. No list of pages you have visited is collected, and it can see no page outside the four job board domains and this site.
  • No other tabs, and no activity. No keystrokes, clicks, mouse position, or scrolling are recorded anywhere.
  • No credentials of yours. The only credential involved is the key this account issued to the extension. Your password and your sign-in are never read, and no password you type into a form is collected.
  • No mailbox access from the extension. Where a board holds an application until an emailed code is typed back in, that code is looked up server-side under the read grant you gave separately, and the extension receives the code and nothing else. It cannot read your email.
  • No location, health, or financial data. A city or country you have put on your own answer sheet is filled into forms that ask for it, which is your answer being reused rather than your position being measured.

Nothing the extension collects is sold, used for advertising, used to build a profile for any purpose other than filling in your applications, or passed to a third party. There is no analytics or tracking code in it.

Subprocessors

We share the minimum data required with these processors:

  • Supabase / Neon (Postgres hosting)
  • Vercel (application hosting)
  • Anthropic (LLM and web-search)
  • Stripe (payments)
  • Resend (transactional email)
  • Google & GitHub (sign-in)
  • Third-party people/company data providers, GitHub API, Google BigQuery (data sources)
  • PostHog (product analytics and error tracking)
  • Microsoft Clarity (session replay and heatmaps)

Third-party data and your rights

anysearch surfaces public information about third parties from sources like GitHub. If you are a data subject and want your information removed from results we return to our users, email hello@refolk.ai and we will action requests within 30 days where the law requires.

Under GDPR/CCPA you may request access, correction, deletion, or export of your account data. Account holders can request deletion at any time by emailing the address above; we will purge your account, conversations, and credit ledger within 30 days, subject to billing/audit retention required by law.

Retention

We retain account and conversation data for as long as your account is active. Credit ledger entries are retained for at least 7 years to satisfy financial recordkeeping. Logs and telemetry are retained for up to 90 days.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to authorized personnel using SSO and least-privilege controls.

Children

The service is not intended for users under 16.

Changes

We will post material changes here and update the “Last updated” date. Continued use of the service after a change means you accept the updated policy.