For compliance and risk teams · Updated 26 August 2026
We never see your clients' details. The extension reads a form inside your staff member's browser. Then it types the details into the MyCRM tab they already have open. Nothing is sent to us.
Most security checks assume the software company holds your data. We don't hold any. That's why a lot of the answers below are short.
From the form into MyCRM, on your own computer. That's the whole trip.
The PDF is read inside your browser. The details sit in your computer's memory for a few minutes. Then they get typed into MyCRM. Nothing is uploaded to us.
Here is every place the extension can connect to. This is the full list, not an example.
| Where | What it sends |
|---|---|
| mycrm.finance | Your CRM, in the tab your staff member is already logged into. |
| mycrmautofill.com | Checks the licence is still active. Also sends a short note about whether a fill worked. No words from your file. See Q4. |
| places.googleapis.com | Only if your firm sets up its own Google account and switches on the employer lookup. It runs on your Google key, under your control, not ours. See Q12. |
| stripe.com | Only if someone clicks Subscribe. Opens a payment page. Never used during a fill. |
Chrome decides where an extension may connect. It reads that list from a public file that Google checks. So this isn't a promise from us. It's the browser blocking everything else.
On a standard install we are not a recipient of any personal information, so this does not add a party to your data flow. It sits where the keyboard sits: a tool used on data already in your possession.
Whether you need to change your privacy notice is your privacy officer's call, not ours. We'll put the facts in writing so they can decide.
| What | Where it sits | How it goes |
|---|---|---|
| Client details None. They never reach us. |
Your computer's memory, while your staff work | Gone when Chrome closes. Never saved to your hard drive. |
| Licence record Work email, a random ID, licence status |
Our licence database | Email us and we delete it. |
| Fill reports Whether it worked, which part, an error code, how many items, how long, version |
Same database | Deleted with the licence record. |
That's the whole list. Licence records are stored with Supabase. Our licence server runs on Netlify. We can confirm where they're hosted in writing.
There's no path for them to leak. Here is how that works.
mycrm.finance. To change that we'd need a new version and a fresh Google review.No. That rule (APP 8) applies when you send someone's details to a company outside Australia. Our extension doesn't send details anywhere. So there's nothing going overseas.
Where your team sits comes from your staffing, not from our tool. If someone overseas has a MyCRM login today, that's already the case. Adding this doesn't move data anywhere new.
| Rule | Where we stand |
|---|---|
| APP 1 Being open | A privacy policy and this FAQ. You can read what the extension may reach before you install it. |
| APP 3 Collecting | Nothing about your clients. From your staff, a work email and a random ID. |
| APP 5 Telling people | We collect nothing about your clients, so there's nothing for us to tell them. |
| APP 6 Using and sharing | Licence admin only. Never sold. Never shared. |
| APP 8 Sending overseas | See Q5. |
| APP 11 Keeping it safe | The safest way to hold client data is to never hold it. Licence records are locked in storage and while they travel. Licence replies are signed so they can't be faked. |
| APP 12, 13 Seeing and fixing | Email us. We hold no client records to show you or correct. |
Here is everything we hold:
If someone broke into our systems, they'd get a list of work email addresses and who is paying. They would not get one client's financial details. That information has never been in our systems.
We follow Australia's rules for reporting data breaches. We check within 30 days of suspecting one. If it's serious, we tell the people affected and the privacy regulator (the OAIC) as soon as we can.
No. It works inside the login your staff member already has. It sees what they see. It can do what they can do. It never gets their MyCRM username or password, and it has no login of its own.
It does read the file that's open, so it doesn't create a duplicate. That's the same information already on their screen, and it isn't sent anywhere.
None. No AI, no chatbot, no outside service reading your file. It follows fixed rules we wrote in advance. Nothing about a client is sent to an AI company, because nothing is sent anywhere.
There is an optional employer lookup, and it uses Google. A firm can set up its own Google account and switch it on. Then, when a form has no employer phone or address, it asks Google for the employer's contact details. It runs on your own Google key. We never supply one and never see it. It's off by default and never on for a trial.
We do get reports about your fills. Not what's in them. Just which parts ran, whether they worked, and what went wrong. It's how we fix faults before they spread.
The ID follows a Chrome profile, not a computer. It's random and says nothing about the person or their machine. Chrome syncs it, so a licence survives a reinstall.
Client details are on your staff member's computer while they work. In that computer's memory, gone when Chrome closes. That's the same as having the CRM open in a tab. Protecting that computer is your job, not ours.
Anything not answered here: help@mycrmautofill.com. If your firm has its own list of security questions, send it and we'll answer it in writing.
Privacy policy · Back to mycrmautofill.com
This isn't legal advice. It explains how the software works, so your own checks are based on facts.
MyCRM AutoFill is independent software built by working Australian mortgage brokers. It is not affiliated with, endorsed by, or supported by LMG (Loan Market Group). MyCRM is a product of LMG.