Privacy Policy
Last updated: July 17, 2026
Litos is a Chrome extension and web dashboard. When you open a job posting, it builds a resume tailored to that posting, fills out the application form, and drafts an outreach email to a real person at the company. This policy says exactly what that requires us to read and store, in plain language. It will grow as the product does, and the date above changes every time it does.
What the extension reads
Only the page you are actively viewing, and only when it is a job posting on a supported platform (Greenhouse, Lever, Ashby, Workday, LinkedIn) or a LinkedIn profile you opened. There is no bulk collection and no background scraping. If you are not on a posting, it reads nothing.
What we store
Your account email. The profile we parse out of the resume you upload, including your experience bank. We read that upload once to build the profile and do not keep the file itself. Your application details, which reach us two ways: values you enter in Settings, and values the extension learns while it watches you fill your first application during onboarding (the next section says exactly how that works and what it will never learn). The contacts we resolved, the drafts we wrote, and the tailored resumes we generated, so your dashboard can show them back to you.
Application details that are sensitive (phone, location, citizenship, date of birth, availability, salary) are encrypted at rest. Your work authorization and sponsorship answers are stored as plain yes/no values, not encrypted.
Learning your profile from your first application
Starting with extension version 0.4.0, onboarding works by watching, not asking. The first job application you fill in by hand, on the employer's own form, teaches Litos your answers: while onboarding is open and you are on a recognized application page, the extension reads what you type into that form and saves it to your profile, so you never type it again. Versions before 0.4.0 do not do this; they only store what you enter in Settings.
This learning is passive. It never fills, clicks, or submits anything by itself, and it only records what you yourself typed: values the extension wrote, or a script wrote, are ignored. It can learn at most these seventeen fields: phone, city, state, zip, country, LinkedIn URL, GitHub URL, portfolio URL, citizenship, date of birth, availability date, availability term, desired salary, GPA, GPA scale, major, and how you heard about the role. Anything that is not one of those fields, including anything that looks like an essay, is not recorded.
Three promises about it. First, it never learns your work authorization, sponsorship, or self-identification answers. Those questions are refused in the extension, refused again by the server, and there is no place in the learned profile they could even be stored. Second, it never overwrites: a value you entered in Settings always wins over one we watched you type. Third, it ends. Learning stops for good the moment your onboarding completes, and it does not restart.
Contacts and outreach
Contact emails are found and verified against public professional sources, and every contact is labeled with how confident we are. If we cannot verify an address, we say so and never guess one. We never resell contact data.
Outreach emails are sent by you, from your own Gmail account. Drafts wait in your drafts folder and never send themselves.
Applications submit only when you click Submit, unless you turn on auto-submit. With auto-submit on, a 15-second countdown runs before the application goes out, and one click cancels it.
EEO and demographic questions
Voluntary self-identification questions default to decline-to-answer everywhere. They are only ever filled with a value if you explicitly opt in inside the extension.
Billing
Payments are processed by Stripe. We never see or store your card number. Canceling takes the same clicks as signing up, from the billing portal linked in your receipt email.
How long we keep it
Generated resume PDFs are deleted 30 days after we make them. The record of what we tailored for which job stays in your dashboard, but the file itself is gone and any link to it stops working.
Links to a resume file expire about an hour after they are issued, so a link that ends up somewhere it should not be does not stay a working key to your resume.
The resume you upload is read once to build your profile and is not kept as a file. Everything else described above is kept for as long as your account is open.
Export and deletion
Email mehekman@usc.edu from your account address to export or delete everything Litos stores about you.
Deletion removes your account, the profile parsed from your resume, your experience bank, your application details, both the ones you saved and the ones learned during onboarding, your drafts, your autofill history, and every resume we generated for you, including the files. It cannot be undone.
Contacts are the one exception, and not because we keep them for you. A contact record is a real person at a company. We store it once per company and everyone who looks up that company sees the same record, so it is not yours to delete and removing your account does not remove it. Which contacts you were shown, and what you drafted to them, is yours and does get deleted.
We also keep anonymous outcome rows, meaning which kind of intro tends to get a reply, with the link to your account removed so they cannot be traced back to you.
Questions
Same address: mehekman@usc.edu. You will get an answer from a person.