Privacy Policy
Last updated: March 2026
1. What FillKit Is
FillKit is a developer tool designed exclusively for software development, QA testing, and demo environments. It generates realistic but entirely synthetic (fake) data to autofill forms. FillKit is not intended for filling real forms with real personal information, and should never be used for identity fraud, impersonation, or any unlawful purpose.
2. Information We Collect
The only personal information we collect is: (a) your email address if you join our waitlist or sign up for FillKit Cloud; (b) basic usage analytics on the fillkit.dev website (page views, browser type, approximate location) through standard web analytics tools; (c) account information (name, email, company) if you register for a FillKit Cloud plan.
3. SDK and Browser Extensions — Open Source, Local Processing
The FillKit SDK and browser extensions are open source (github.com/fillkit) — you can inspect, audit, and verify exactly what runs on your device. They operate entirely on your device by default. All form detection, field classification, and fake data generation happen locally using the built-in data engine (Faker.js). No form data, field values, or page content is transmitted to our servers. The browser extensions request broad host permissions (all URLs) solely to detect and autofill forms on any page you visit during development or testing — no data leaves your browser. Only the FillKit Cloud dashboard and API are closed source.
4. Browser Extension Data
The FillKit browser extensions store only your preferences (locale, fill mode, widget position, keyboard shortcuts) in your browser's built-in sync storage. When you uninstall the extension, all stored preferences are automatically deleted by your browser — no data persists after removal. The extensions do not: (a) read, collect, or transmit any data you type into forms; (b) set or read cookies on websites you visit; (c) track your browsing history; (d) send analytics or telemetry from the extension.
5. FillKit Cloud (Optional, Opt-In)
FillKit Cloud is an optional paid service that provides curated datasets and team features. Cloud mode is never enabled by default — you must explicitly create an account, obtain an API token, and configure the SDK or extension to use it. When Cloud mode is active, form structure metadata (field labels, input types, HTML attributes) may be sent to our servers for enhanced field detection. Form values — what users type into fields — are never collected or transmitted. You may use FillKit in local-only mode indefinitely at no cost.
6. Future Cloud Features — Forward Disclosure
A future version of the browser extensions will support connecting to FillKit Cloud. When this feature ships, opting in will allow the extension to send form structure metadata (field names, labels, input types, HTML attributes) to fillkit.dev for improved field detection and dataset matching. This will require explicit opt-in: you must enter an API token and enable Cloud mode in the extension settings. No form values or personal data you enter into forms will ever be collected. We are disclosing this now so you are informed before the feature is available. This policy will be updated with full details when the feature launches.
7. How We Use Your Information
We use collected information to: (a) notify waitlist subscribers about FillKit Cloud launch updates; (b) understand how visitors use the fillkit.dev website so we can improve it; (c) provide and improve FillKit Cloud services for opted-in users; (d) respond to support requests; (e) comply with legal obligations. We do not use your data for advertising or profiling.
8. Data Sharing
We do not sell, rent, or trade your personal data. We may share information with: (a) hosting and infrastructure providers necessary to operate the Service; (b) analytics tools to understand website usage; (c) law enforcement when required by applicable law. All third-party providers are bound by data processing agreements.
9. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and secure coding practices. API tokens use the format fk_live_* (production) and fk_test_* (testing) and should be kept confidential. No system is completely secure, and we cannot guarantee absolute security.
10. Cookies and Tracking
The fillkit.dev website uses essential cookies for session management and may use analytics cookies to understand usage patterns. You can control cookie preferences through your browser settings. The FillKit browser extensions do not set or read cookies on the websites you visit.
11. Data Retention
Waitlist email addresses are retained until you unsubscribe or request deletion. Website analytics data is retained in aggregate form. FillKit Cloud account data is retained while your account is active and deleted upon request. You may request deletion of your data at any time by contacting us.
12. Your Rights
Depending on your jurisdiction, you may have rights to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion; (d) export your data; (e) object to processing. Contact us to exercise these rights.
13. International Transfers
Your data may be transferred to and processed in the United States or other countries. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
14. Children's Privacy
FillKit is a developer tool not intended for users under 13 years of age. We do not knowingly collect personal data from children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date on this page. Significant changes to data collection practices (such as enabling Cloud features in the browser extensions) will be clearly communicated before they take effect.
16. Contact
For privacy-related questions or to exercise your data rights, contact us at hi@claviscore.com.