MyCRM AutoFill · Updated 26 August 2026
Doing a security review? The security and privacy FAQ answers the full set of questions: where data goes, what we keep, how this fits Australia's privacy rules, and what someone would get if we were hacked.
It reads the deal notes you type, and the client forms you load, inside your browser. Then it enters that information into MyCRM for you. All of the reading and typing happens on your own computer.
This is the one place a careless design would leak, because an error message can quote a client's address. So the error message is swapped for a short code from a set list inside your browser, and the real message is thrown away there. Only the code travels.
Anything not on the list is dropped, not stored. We check that list three times: in the page, in the extension, and again on our server. No words from your file can reach us, even from a broken or tampered-with copy of the extension.
A firm can set up its own Google account and switch on an employer lookup. When a client form has no employer phone number or address, the extension asks Google for the employer's contact details.
It runs on your firm's own Google key. We never supply one and we never see it, so this is between your firm and Google. It's off by default and it's never available on a trial or an individual licence.
Licence records (your email, install ID, licence status and event history) are stored with our database provider, Supabase. Our licence server runs on Netlify. Licence replies are signed so they can't be faked. We don't sell or share any of it.
The extension keeps its licence state and your settings in Chrome's extension storage. Uninstalling removes all of it.
Client details read from a form, and the deal notes you type, sit in your browser's memory while you work. They're never written to your hard drive and they're gone when you close Chrome.
Your install ID is kept in Chrome's synced storage, so your licence survives reinstalling the extension. That means it follows your Google account to your other computers.
We follow Australia's rules for reporting data breaches. If we had reason to suspect one, we'd check it within 30 days. If it turned out to be serious, we'd tell the people affected and the privacy regulator (the OAIC) as soon as we could.
Worth being clear about the size of that. Our systems hold licence records and fill reports. There are no client names, addresses, incomes, account numbers or documents in them, because none of that is ever sent to us. Someone breaking in would get the email addresses and subscription status of the people who use the software. Not their clients' files.
Email help@mycrmautofill.com from your signup address and we'll delete your licence record.
This website, not the extension, uses GoatCounter to count page visits. It uses no cookies and collects nothing personal.
If this policy changes, the date at the top changes too. We'll note anything important on the website.
MyCRM AutoFill is independent software built by working Australian mortgage brokers. It is not affiliated with, endorsed by, or supported by LMG (Loan Market Group). MyCRM is a product of LMG.