← mycrmautofill.com

Security & Privacy FAQ

For compliance and risk teams · Updated 26 August 2026

We never see your clients' details. The extension reads a form inside your staff member's browser. Then it types the details into the MyCRM tab they already have open. Nothing is sent to us.

Most security checks assume the software company holds your data. We don't hold any. That's why a lot of the answers below are short.

Open all before printing

THE DATA

01Where does client data go?

From the form into MyCRM, on your own computer. That's the whole trip.

The PDF is read inside your browser. The details sit in your computer's memory for a few minutes. Then they get typed into MyCRM. Nothing is uploaded to us.

Here is every place the extension can connect to. This is the full list, not an example.

WhereWhat it sends
mycrm.financeYour CRM, in the tab your staff member is already logged into.
mycrmautofill.comChecks the licence is still active. Also sends a short note about whether a fill worked. No words from your file. See Q4.
places.googleapis.comOnly if your firm sets up its own Google account and switches on the employer lookup. It runs on your Google key, under your control, not ours. See Q12.
stripe.comOnly if someone clicks Subscribe. Opens a payment page. Never used during a fill.

Chrome decides where an extension may connect. It reads that list from a public file that Google checks. So this isn't a promise from us. It's the browser blocking everything else.

02Do we have to tell our clients about this?

On a standard install we are not a recipient of any personal information, so this does not add a party to your data flow. It sits where the keyboard sits: a tool used on data already in your possession.

Whether you need to change your privacy notice is your privacy officer's call, not ours. We'll put the facts in writing so they can decide.

03What do you collect, and how long do you keep it?
WhatWhere it sitsHow it goes
Client details
None. They never reach us.
Your computer's memory, while your staff work Gone when Chrome closes. Never saved to your hard drive.
Licence record
Work email, a random ID, licence status
Our licence database Email us and we delete it.
Fill reports
Whether it worked, which part, an error code, how many items, how long, version
Same database Deleted with the licence record.

That's the whole list. Licence records are stored with Supabase. Our licence server runs on Netlify. We can confirm where they're hosted in writing.

04How do you stop income, addresses and bank details leaking?

There's no path for them to leak. Here is how that works.

  • Chrome blocks other websites. The extension is allowed one: mycrm.finance. To change that we'd need a new version and a fresh Google review.
  • Nothing from a client is saved to your hard drive. Details and notes sit in your own computer's memory. They're gone when Chrome closes.
  • Error reports can only use words from a set list. When something goes wrong, the error message is swapped for a short code inside your own browser. The real message is thrown away there, on your machine. So a client's address can never travel with it. We check that list three times: in the page, in the extension, and on our server.
  • Forms are treated as unsafe. Text from a client form is cleaned before it's shown on screen. A booby-trapped form can't make the extension do anything.
  • One outside library, built in. No tracking, no analytics, nothing loaded from another website while it runs.

THE RULES

05Our team works overseas. Is that a problem?

No. That rule (APP 8) applies when you send someone's details to a company outside Australia. Our extension doesn't send details anywhere. So there's nothing going overseas.

Where your team sits comes from your staffing, not from our tool. If someone overseas has a MyCRM login today, that's already the case. Adding this doesn't move data anywhere new.

06How does this fit Australia's privacy rules?
RuleWhere we stand
APP 1 Being openA privacy policy and this FAQ. You can read what the extension may reach before you install it.
APP 3 CollectingNothing about your clients. From your staff, a work email and a random ID.
APP 5 Telling peopleWe collect nothing about your clients, so there's nothing for us to tell them.
APP 6 Using and sharingLicence admin only. Never sold. Never shared.
APP 8 Sending overseasSee Q5.
APP 11 Keeping it safeThe safest way to hold client data is to never hold it. Licence records are locked in storage and while they travel. Licence replies are signed so they can't be faked.
APP 12, 13 Seeing and fixingEmail us. We hold no client records to show you or correct.

THE RISKS

07What if you get hacked?

Here is everything we hold:

  • Licence records: work email, random ID, status, end date
  • Licence history: when trials started, when licences were checked
  • Fill reports: whether it worked, which part, error code, counts, how long, version
  • Firm settings: firm name, adviser and assistant names

If someone broke into our systems, they'd get a list of work email addresses and who is paying. They would not get one client's financial details. That information has never been in our systems.

We follow Australia's rules for reporting data breaches. We check within 30 days of suspecting one. If it's serious, we tell the people affected and the privacy regulator (the OAIC) as soon as we can.

08Can the extension change after we approve it?
  • No hidden updates. Chrome bans extensions from downloading new code. What's on your computer is what Google checked.
  • Every version is checked again. If what it can reach changes, your staff see it.
  • Nothing is downloaded while it runs.
  • Over 200 automatic tests run before we build a release. Some of them exist only to protect the promises on this page.
  • Licence replies are signed, so a fake server can't unlock anything.
09Can it do more in MyCRM than our staff can?

No. It works inside the login your staff member already has. It sees what they see. It can do what they can do. It never gets their MyCRM username or password, and it has no login of its own.

It does read the file that's open, so it doesn't create a duplicate. That's the same information already on their screen, and it isn't sent anywhere.

10Is there any AI in it?

None. No AI, no chatbot, no outside service reading your file. It follows fixed rules we wrote in advance. Nothing about a client is sent to an AI company, because nothing is sent anywhere.

CHECK IT YOURSELF

11Can we check all this ourselves?
  • Before you install. The Chrome Web Store page lists what the extension can reach. You'll see one website.
  • While it runs. Right-click the MyCRM page, choose Inspect, open Network, then run a fill. Watch every request it makes. Two minutes.
  • Read the permission file. Extensions unpack onto your hard drive. It's plain text.
12What we don't claim

There is an optional employer lookup, and it uses Google. A firm can set up its own Google account and switch it on. Then, when a form has no employer phone or address, it asks Google for the employer's contact details. It runs on your own Google key. We never supply one and never see it. It's off by default and never on for a trial.

We do get reports about your fills. Not what's in them. Just which parts ran, whether they worked, and what went wrong. It's how we fix faults before they spread.

The ID follows a Chrome profile, not a computer. It's random and says nothing about the person or their machine. Chrome syncs it, so a licence survives a reinstall.

Client details are on your staff member's computer while they work. In that computer's memory, gone when Chrome closes. That's the same as having the CRM open in a tab. Protecting that computer is your job, not ours.

Anything not answered here: help@mycrmautofill.com. If your firm has its own list of security questions, send it and we'll answer it in writing.

Privacy policy · Back to mycrmautofill.com

This isn't legal advice. It explains how the software works, so your own checks are based on facts.

MyCRM AutoFill is independent software built by working Australian mortgage brokers. It is not affiliated with, endorsed by, or supported by LMG (Loan Market Group). MyCRM is a product of LMG.