Skip to content

Autofill Extension Privacy Policy

Version 2.2 · Last updated: September 26, 2026

This policy covers the GoRefer Autofill browser extension. The public Chrome Web Store release is 1.3.0, checked on September 25, 2026. Its data handling is described first. The numbered sections that follow describe the newer version 2.1.0, which is not yet on the Chrome Web Store, separately; they do not imply that its controls are available in the public release. The GoRefer web application and client intake form are covered by the GoRefer Privacy Policy.

Published release 1.3.0

These disclosures describe the packaged release available from the Chrome Web Store, last updated there on September 10, 2026. This release requires Chrome 114 or later. It is an authenticated tool for tax professionals working with their firm's existing GoRefer client records.

Account and client data

Sign-in sends your GoRefer email and password, and a two-factor code when required, to GoRefer's API. The extension holds your account profile and session tokens. It retrieves client identity and contact details, intake progress, assignments and tax-year information. Opening a client requests decrypted intake data, which can include Social Security Numbers, dates of birth, bank details and tax figures. That decrypted intake remains in runtime memory; it is not written to the extension's browser storage. Values you fill are then present in the tax-software page you opened and subject to that software's handling.

When you use the related controls, the extension exchanges client notes, assistant messages, document references, due-diligence reports, referral and practice records with GoRefer's API. Generating or emailing a due-diligence report uses that API; the extension does not send mail directly. It sends client presence information so firm colleagues can see who is viewing a record. Fill activity records sent to the API identify the client, software, tax year, sections, field counts and outcome, rather than the filled values.

Storage and removal

Access and refresh tokens use Chrome session storage. Local storage can retain the client list cache, notes, assistant conversations, fill history, settings, pinned client ids, intake completion metadata and filing status, presence, synchronization state, onboarding state and field maps. Client-list cache entries expire after 24 hours and cached notes after 30 minutes. Decrypted intake data is not written to browser storage. Due-diligence API reports are held in the panel; assistant messages generated alongside a report can be retained in the local conversation history.

Signing out clears authentication, cached clients, notes, assistant conversations, fill history, presence and intake metadata. Preferences, pinned client ids, onboarding state and field maps can remain. Remove the extension to clear its local storage completely. Removing it does not delete your firm's records from GoRefer; use the account-data process in the GoRefer Privacy Policy for those records.

Browser access and page handling

Version 1.3.0 requests storage, alarms, sidePanel, scripting and tabs. These support local state, background refresh, the side panel, registered content scripts and detecting the active tax-software tab. Its manifest grants access to api.gorefer.io and declares content scripts on oltpro.com, *.oltpro.com, taxslayer.com, *.taxslayer.com, cloudtaxoffice.com and *.cloudtaxoffice.com. This permission disclosure is not a claim that every site or form on those domains is supported.

Optional access to https://*/* allows you to grant an individual white-labelled tax-software site through Chrome's permission prompt. It is not standing access to all sites. The content script reads the supported page to identify fields, writes intake values only after you start a fill and reads them back to check entry. In the public release, the extension's description of each OLT Pro page has not been verified against the live product, so review the values, save and move between pages yourself. Reading a value back does not establish that the tax software saved the page.

Transport and version-specific controls

API requests go to https://api.gorefer.io over HTTPS with bearer authentication, cookies omitted, redirects rejected and no referrer. Chrome's extension policy limits API connections to GoRefer. Showing or copying sensitive fields has a password-confirmation control. This release does not request Chrome's privacy permission and does not provide version 2.1.0's client-scoped step-up grants, preparer acknowledgement or saved checklist outcomes. Do not rely on those newer controls when using version 1.3.0.

Platform retention, service providers and account-data requests follow the GoRefer Privacy Policy. The rights, children's privacy and contact information in sections 8–11 below apply to both versions.

Version 2.1.0 (pre-release)

The numbered technical sections below describe version 2.1.0 (Manifest V3), which is not yet published on the Chrome Web Store. They are not the feature or permission list of the public 1.3.0 release. Refer to the published-release section above for that version.

1. Who the Extension Is For

GoRefer Autofill is a tool for tax professionals. The person who installs it and signs in is a preparer or firm administrator with an existing GoRefer account. The personal information the extension handles belongs to that firm's clients, not to the installing user, and it is information the firm already holds in its GoRefer account.

The extension does not create new client records, and it obtains client data from no source other than the firm's own GoRefer account. It does not operate at all without a successful sign-in.

2. What the Extension Handles

2.1 Sign-In Credentials

Your GoRefer email address and password are sent to GoRefer's API to obtain a session. If your account has two-factor authentication enabled, the one-time code you enter is sent to the same API. Your password is never stored by the extension — it is held in the sign-in form's memory for the duration of the request and is not written to any storage area.

2.2 Your Account Profile

After sign-in the extension holds your user id, email address, display name, role, firm id, firm name and profile-picture URL, together with the access and refresh tokens for the session.

2.3 Client Records

For the firm you are signed in to, the extension retrieves and caches the client list: client id, first and last name, email address, phone number, firm id, tax year, status, created and updated timestamps, intake completion percentage and status, and the assigned preparer's id and name.

2.4 Tax Intake Data, Including Sensitive Personal Information

When you open a client and start an autofill, the extension requests that client's tax intake in decrypted form from GoRefer's API. Depending on what the client submitted, that record can contain:

  • Social Security Numbers — taxpayer, spouse and each dependent
  • Dates of birth — taxpayer, spouse and each dependent
  • Bank routing numbers and account numbers, account type and bank name
  • Employer Identification Numbers and other business-identity fields
  • Names, home address, phone number, email address, occupation
  • Filing status, dependents and their relationships
  • Income, deduction, credit, healthcare, education, rental, investment and prior-year figures

This is the most sensitive category of data the extension touches, and it is the reason this policy exists. Decrypted intake data is never written to browser storage. It is held in memory only for as long as the panel has that client open.

2.5 Autofill Activity Records

For each autofill run the extension records the client id, client name, tax software, tax year, the names of the intake sections that were filled, the number of fields, the duration and the outcome.

No field values are recorded. Social Security Numbers, bank numbers and dates of birth do not appear in the local fill history or in the activity record sent to GoRefer's server — only section names and a field count. The activity record also carries a one-way fingerprint of the tax software's own return token, so a record can be matched to the return it was made for; the token itself is never sent.

Learning signals. So that GoRefer can learn which box each intake field belongs in, the extension also sends its API three kinds of record, each carrying the client id, the run id, the tax software, the tax year and the extension version:

  • Corrections — when you change a box after a fill, the form and field identifiers, the intake field the extension used, and the intake field your new entry matches. The match is made inside your browser against salted one-way hashes of the client's intake; what you typed is never sent.
  • Your rating of a run (good or bad) and the run's grade — how many fields were verified, fillable and saved, a percentage and a band.
  • Pop-ups the extension did not recognise — the pop-up's title and button labels, after every fragment of this client's details and anything shaped like an identifier has been removed. A pop-up whose text still looks sensitive after that is not sent at all.

2.6 Client Notes, Assistant Messages and Presence

  • Notes you read or add for a client, including their text and author, are exchanged with GoRefer's API and cached locally.
  • Assistant messages. If you use the in-panel assistant, your typed message, the client id you have open and the recent conversation history are sent to GoRefer's API. What happens to that message on the server, including any AI model provider GoRefer uses to generate a reply, is governed by the GoRefer Privacy Policy.
  • Presence. While a client is open, the extension periodically sends that client id to GoRefer's API so colleagues in the same firm can see who is viewing the record, and reads back the list of other viewers.

2.7 Client Documents and Due-Diligence Memos

The panel can list the documents your client uploaded to their GoRefer file — name, type, size and upload date — and you can send one to the in-panel assistant so it can be read and summarised. The document itself is never handled by the extension: it names the file to GoRefer's API, and the server does the reading.

You can also generate a due-diligence memo for a client. GoRefer's API builds it from that client's uploaded documents, your preparer notes and their intake, and returns it to the panel for you to read. From the panel you can then e-mail it to the client or send them a secure link to sign it. Doing so transmits the memo and the client's e-mail address to GoRefer's API, which sends the message — the extension never sends mail itself and never contacts your client directly. A memo can contain the same sensitive figures the intake does, so it is held in the panel's memory and is not written to browser storage.

2.8 Commissions, Referrals and Practice Records

So the panel can show a client's full picture without sending you back to the web app, it also reads that client's commission figures, appointments, recent workflow runs, and your own unread notifications. You can create a referral for a client from the panel, which writes a referral record to your firm's GoRefer account.

All of it is your firm's own data, read from and written to your firm's own GoRefer account over the same single API host. None of it is stored anywhere else.

2.9 Which Page You Are On

The extension reads the hostname of your active tab in order to tell whether you are on a supported tax-software site and which one. That is the hostname alone, on whatever tab you have in front of you — not the page, not the address, not your other tabs. Nothing about your browsing is stored or transmitted.

On a supported site, and only there, the extension reads more than the hostname once you start a fill. Section 6 sets out exactly what and why. None of it leaves your browser.

2.10 What the Extension Does Not Collect

  • No browsing history. The extension never enumerates tabs or history. It queries only the active tab, and holds host permissions for GoRefer's API plus the tax-software domains listed in section 6, plus any single white-labelled site you grant it yourself (section 5) — never standing access to the web at large.
  • No page content leaves your browser. The content script does read the tax-software page it is running on — it has to, to know which step of the wizard you are on and whether a value it wrote was accepted (section 6 sets out exactly what it reads). Every bit of that reading is used and discarded inside the tab. No page text, field value, heading or URL from your tax software is ever transmitted to GoRefer or to anyone else, with one exception: the redacted title and button labels of a pop-up the extension did not recognise (section 2.5). None of it is written to browser storage. What is reported back to the panel, and later to GoRefer's API, is the names of the intake sections that were filled, per-field identifiers and outcomes, counts, and the learning signals in section 2.5 — never a value.
  • No keystroke, mouse or screen recording.
  • No device fingerprinting, advertising identifiers or cross-site tracking.
  • No cookies. Every API request is sent with credentials omitted; authentication is by bearer token only.

3. Where Data Is Sent

The extension transmits data to exactly one host: https://api.gorefer.io.

Every network call is built from a single API base URL, and the extension's Content Security Policy restricts outbound connections to that one origin. Chrome enforces that policy, so a request to any other host would be blocked by the browser itself.

There are no analytics SDKs, no telemetry services, no crash reporters, no advertising networks, no tag managers and no third-party scripts of any kind in this extension. No web fonts or other assets are fetched from any external host. The extension has an analytics screen; it displays your own firm's autofill statistics returned by GoRefer's API and involves no third party.

Requests are additionally hardened: non-HTTPS API URLs are refused, redirects are rejected rather than followed so a bearer token cannot be forwarded to another host, no referrer is sent, and every request times out.

What GoRefer's servers do with data once it arrives, including any onward disclosure to service providers, is described by the GoRefer Privacy Policy.

4. How Long Data Is Kept

Nothing below is a summary. This is every category the extension writes to your browser.

Ends when you close Chrome (Chrome's session storage area):

  • Session tokens — your access and refresh tokens, and the time you signed in. Closing Chrome ends your session; you sign in again next time.
  • Your acceptance of the preparer terms, deliberately kept here so the next sign-in asks again rather than assuming.
  • Correction windows — for up to four hours after a fill on a tab, the salted one-way hashes of that client's intake and the salt, so a box you correct can be matched to an intake field without the plaintext (section 2.5). No value is stored.
  • The redacted pop-ups already reported today, so each one is sent once a day rather than on every page.

Never written down at all:

  • Decrypted intake data — SSNs, dates of birth, bank numbers. Held in memory only, for as long as the panel has that client open.
  • Due-diligence memos — same reasoning, same treatment.
  • Step-up grants. When you re-enter your password to reveal a client's sensitive fields or to run autofill for them, the short-lived grants that one entry issues for that client are held in the background worker's memory and nowhere else — not on disk, not in session storage, not in the panel. If the worker restarts you are asked for your password again, which is the intended outcome.

Kept on your device until you sign out or remove the extension, unless a shorter life is given:

  • The client list cache — expires 24 hours after it is written.
  • Cached client notes — expire 30 minutes after they are fetched.
  • Fill history and per-client fill records — which sections and forms ran, field counts and outcomes. Never values.
  • Fill-audit records awaiting delivery — the same PII-free paper trail, held until GoRefer's API confirms receipt, then retried on a later fill rather than dropped.
  • Learning signals awaiting delivery — the corrections, ratings, grades and redacted pop-ups in section 2.5, held until GoRefer's API accepts them, and sent only under the account that produced them.
  • Reviewed field-map corrections — the corrections GoRefer has approved to which box an intake field goes into, cached so an outage keeps the last good set. They contain no client data.
  • The preparer terms — the current wording and version, as served by GoRefer's API.
  • Which account last used this browser — its user and firm id, so the next account to sign in starts without the last one's client data.
  • Your assistant conversation history with the in-panel assistant.
  • Convenience state — your settings, pinned clients and when and why each was pinned, the client you last opened, whether you have finished onboarding, the day you last dismissed a reminder, the current list of colleagues viewing a client, and the last status answer from GoRefer's API.
  • Two figures derived from an intake — how many documents a client uploaded and whether their return carries a heavy schedule, cached per client so the list can show how large a job is before you open it. These are counts and a flag, never intake values, but they are derived from the intake and so are named here rather than left to the sentence above.
  • White-labelled sites you have confirmed (section 5), so the extension recognises them on later visits.

Signing out or uninstalling clears all of it from your device. Records held server-side by GoRefer are governed by the GoRefer Privacy Policy.

5. Browser Permissions and Why Each Is Required

  • storage — keeps you signed in between openings of the panel, caches the client list, and stores your settings and fill history.
  • alarms — schedules three background jobs a Manifest V3 service worker cannot hold timers for: refreshing your access token before it expires, re-syncing the client list, and refreshing the unread-notification count.
  • sidePanel — the extension's entire interface is a Chrome side panel, so your client's data stays visible beside the return while the fill runs and while you verify it.
  • scripting — used only for the optional per-site grant described in the last bullet, never to inject into an arbitrary page. Once you grant access to a site, the page reader is injected into that one tab to work out which tax product it is, and once you confirm the site the content script is registered for that origin so it loads on later visits. Removing the site unregisters it in the same action.
  • tabs — reads the active tab's hostname to identify the tax software, sends the fill instruction to that tab, and opens GoRefer billing links. It does not enumerate your tabs, read history, or access tab contents.
  • privacy — while a fill is running, and only then, the extension turns off three of Chrome's own settings: save-addresses, save-payment-methods and offer-to-save-passwords. It puts all three back exactly as it found them when the fill ends. This is done for your client's privacy, not at its expense: without it Chrome offers to file the name, home address and bank details being typed into the return into your browser profile, where they would outlive the return, follow you to every other site and sync to your other devices. These three settings are profile-wide, which is the reason the extension restores them and the reason it touches no others. If your employer's policy or another extension controls one of them, our change is refused and the panel says so rather than letting you believe it worked.
  • Host access to api.gorefer.io — the only host the extension communicates with.
  • Host access to tax-software domains — the sites listed in section 6, so the fill can write into their forms.
  • Optional host access to https://*/* — declared as an optional permission and not granted when you install the extension. Many firms reach the same tax products through a service bureau's own white-labelled domain, and those domains cannot be enumerated in advance, so no fixed list can cover them. When you open one and press “Check this site” in the panel, Chrome — not the extension — asks whether to grant access to that one origin. A grant covers that origin and nothing else, and you can revoke it at any time by removing the site in Options, or in Chrome's own extension settings.

6. What Happens Inside Your Tax Software

The content script is injected automatically, with no further permission needed, into pages on these domains: oltpro.com, *.oltpro.com, proapp.taxslayer.com, cloudtaxoffice.com and *.cloudtaxoffice.com — that is, OLT Pro and both of TaxSlayer's web products (Pro Online, which the extension matches on the proapp host only and never on the consumer taxslayer.com filing site, and Pro Web, which is served from cloudtaxoffice.com).

Beyond those, you can grant the extension one further origin at a time — your firm's or service bureau's white-labelled instance of one of those same products. You open that site and press “Check this site” in the panel; Chrome, not the extension, then asks whether to grant access to that one origin. Nothing is read or written there until you grant it, the grant covers that origin alone, and removing the site under Options → “Your tax software sites” revokes the grant and unregisters the content script for it in the same action.

On those pages the script:

  1. Checks the hostname first. If the frame is not on a recognised tax-software host, it does nothing at all.
  2. Waits for your explicit instruction. Nothing is written until you choose a client and start a fill from the panel.
  3. Works out which page of the wizard you are on. To do that it reads the page's address, its headings, which known field names are present, and up to roughly 20,000 characters of its visible text. Tax software renders every step from the same handful of controls, so the text is the only thing that distinguishes one screen from another, and filling the wrong screen is the failure worth the most effort to avoid. If it cannot tell, it stops and asks you.
  4. Locates form fields by CSS selector and writes your client's intake values into them, highlighting each field as it fills.
  5. Reads each value back to confirm the software accepted what was written, and reads any validation message the software raises so the panel can show you what it objected to in the vendor's own words.
  6. Hands the page back to you. It moves to the next screen by itself only where that page's layout has been verified against the running product; anywhere else it stops, and you navigate. It never submits or files anything.
  7. Reports back a count. The panel receives how many fields were filled and skipped, per section — not their values.
  8. Notices your corrections. On a recognised form it keeps, in memory, the value of the box you are in, so that when you change a box after a fill it can hash your entry inside the tab and find which intake field it matches (section 2.5). Only that match leaves the tab — never the entry. It ignores the extension's own writes, and does nothing with an edit unless a fill ran on that tab in the last four hours.

So the script does read the page it is filling — steps 3 and 5 are reading, and the fill would be guesswork without them. What it does not do is take any of it anywhere: nothing it reads from your tax software is transmitted to GoRefer or to anyone else, and nothing it reads is written to browser storage, except what section 2.5 names: the matches from step 8, a one-way fingerprint of the return token, and the redacted title and buttons of a pop-up it did not recognise. The rest is read inside the tab, used for the fill in progress, and discarded with the page. It does not record keystrokes, and beyond step 8 it reads nothing until you start a fill.

Fills are best-effort: vendors change their forms without notice, so some fields will be skipped. Review the return before you file it.

GoRefer is not affiliated with, endorsed by, or partnered with any of the tax software vendors named above. Their names appear only to identify where the extension operates.

7. Security

  • All communication with GoRefer's API is over HTTPS; plaintext URLs are refused.
  • Authentication is by bearer token with no cookies, and redirects are rejected so a token cannot be forwarded to another host.
  • A Content Security Policy limits scripts to the extension's own package and outbound connections to GoRefer's API. All code is packaged in the extension; none is loaded remotely.
  • Refresh tokens are held in session storage, so closing the browser ends the session.
  • Decrypted client intake data is never written to disk.
  • Revealing a client's Social Security Number, date of birth or bank details requires you to re-enter your password. The permission that results is scoped to that one client and that one purpose, expires in minutes, and is held only in the background worker's memory — so a password confirmed for one client never unlocks another.
  • Chrome's own save-address, save-payment-method and save-password prompts are suppressed for the duration of a fill and restored afterwards, so a client's details are not filed into your browser profile as a side effect of preparing their return (section 5).

GoRefer's platform-level security commitments are described in the GoRefer Privacy Policy.

8. Your Rights, and Your Clients' Data

The extension is a window onto data your firm already holds in its GoRefer account. It is not a separate system of record, and deleting the extension does not delete anything from your GoRefer account.

You can clear the extension's local data at any time by signing out or removing the extension. For access, correction, export or deletion of the underlying client records — including requests made by a client under laws such as the CCPA/CPRA or the GDPR — use the process in the GoRefer Privacy Policy or contact us at the address below.

As a tax professional you have your own obligations for taxpayer data, including IRS Publication 4557 and the FTC Safeguards Rule. This extension is a tool you operate; it does not discharge those obligations for you.

9. Children's Privacy

The extension is a professional tool and is not directed to children. It does handle dependents' information, including minors' names, dates of birth and Social Security Numbers, but only because a tax return requires it and only as supplied by the firm's adult client. The extension collects nothing from a child directly.

10. Changes to This Policy

Material changes will be reflected here with an updated version and date, and noted in the release notes for the affected extension version. Your continued use of the extension after a change constitutes acceptance of the updated policy.

11. Contact

Questions about this policy, or a request concerning data handled by the extension:

GoRefer Inc.
Email: privacy@gorefer.io
Support: support@gorefer.io
Website: https://gorefer.io