简历助手 · 雏鹰
浏览器扩展隐私政策
「简历助手 · 雏鹰」是一个 Microsoft Edge 扩展:用你自己的账号登录后端,读出你名下的简历,一键填进当前网页的求职表单,并提供可选的「AI 辅助填充」。这一页说明它碰哪些数据、这些数据在什么时候去了哪里、哪些只留在本机,以及你可以怎样控制、撤销与删除它们。
不点按钮,它什么也不做
读取页面表单、AI 辅助填充,都发生在你按下按钮之后。扩展没有登记任何自动运行的内容脚本,也没有对普通网站的长期访问权限。
表单匹配只在本机进行
自动填充读到的表单字段只用于本地匹配与填写,不会离开浏览器。只有「AI 辅助填充」会把简历与页面内容发出去。
不埋点、不出售、不共享
没有分析统计、没有广告网络,不采集浏览历史、书签或下载记录,也不做任何形式的数据经纪。
填错了能还原,对话能清空
每次填充都附一份逐格清单和一个「撤销」按钮;AI 对话可一键清空;退出登录会清除本机的登录凭证、选中的简历与对话记录。
简历助手 · 雏鹰 · 隐私政策
1. 这个扩展做什么,数据流向哪里
「简历助手 · 雏鹰」做三件事:一是用你自己的账号登录后端、读出你名下的简历;二是把选中的那份简历填进你正在填的那张网页表单(「自动填充当前页面」);三是一个可选的「AI 辅助填充」,把简历与当前页面交给 AI,让它给出填写方案(会员功能,见 2.2)。
它只访问一个后端地址:默认是 https://eaglet.net.cn/apply/api。这个地址是编译进安装包里的常量,界面上没有地方可以修改(「关于」页只把它显示出来)。扩展不向任何其它服务器发请求。
下面这张表是全部的数据流向,后文逐条展开:
| 数据 | 什么时候发生 | 去哪里 |
|---|---|---|
| 账号与密码 | 你在侧栏里点「登录」时 | 只发给你自己账号所在的那台后端,用于换取登录凭证;密码只用于这一次登录校验。 |
| 简历里「已填写」的字段 | 只在你点「AI 辅助填充」并发出消息时 | 先到你自己的后端,再由它转发给该后端配置的 AI 供应商。身份证号除外(见 2.2)。 |
| 页面可填控件的标签、类型、是否已有内容 | 同上 | 同上。只有控件自身的说明文字,不包含这些框里已经填好的值。 |
| 当前页面的标题与正文 | 同上 | 同上。正文默认最多 4000 字,上限由该后端的运维配置。 |
| 你在 AI 对话框里输入的文字 | 同上 | 同上。 |
| 运行配置(分享链接 / 正文上限 / 对话轮数 / 可选模型清单) | 每次打开侧栏各一次 | 一次普通读取:不带账号、不带 token、没有请求体,也不发送你的任何内容;回来的只有上面这几项。不打开侧栏就不会发生。 |
2. 会离开你浏览器的数据
分三种情形:第一种是登录;第二种只在你主动使用「AI 辅助填充」时才会发生;第三种只取一份运行配置,不发送你的任何数据。
2.1 登录:账号与密码
你在扩展侧栏里输入的账号与密码,会发给你自己账号所在的那台后端(源码里的默认地址是 https://eaglet.net.cn/apply/api),用来换取一个登录凭证(token)。此后读简历、发对话都用这个凭证鉴权(请求里带 Bearer token),不再重复发送密码。
2.2 使用「AI 辅助填充」时
这个功能要把下面四样交给 AI 才能工作。它只在你点下那颗按钮、并且真的发出消息之后才会发生:
- 你选中那份简历里已经填过的字段(空着的字段不会被列出、也不会被发送)。这些字段包括就业推荐表 / 网申表常问的那些:性别、出生日期、民族、籍贯、政治面貌、婚姻与子女情况、身高体重、第二专业、毕业论文题目、英语等级与成绩、紧急联系人等。唯独身份证号不会 —— 它是这批字段里唯一一项「泄露了没法补救」的,填表用不用得上都不值当交出去;普通的自动填充照旧能填身份证格,只是不让模型看见它。
- 当前页面上可填控件的中文标签、控件类型、以及是否已经填了内容(不含这些框里已填的值)。
- 当前页面的标题与正文(多半就是那个岗位的招聘描述;正文默认最多 4000 字,上限由该后端的运维配置)。
- 你在那个对话框里输入的文字。
这些内容先发给上面那台后端,再由它转发给你在这个扩展里选中的那个 AI 供应商(可选项由该后端的运维在管理页面上配置,可能包含第三方的模型服务商)。请求里还带着你选中那一个供应商的编号(一串随机 id,用来告诉后端该转发给谁;它不含你的任何身份信息)。
这一项完全由你决定要不要用。不点那颗按钮,就不会有上述任何内容被发送。另外两点也说明一下:它是会员功能 —— 账号没有开通时这颗按钮是禁用的,会提示「解锁 VIP」,不影响普通的自动填充;它还要求后端已经配置好 AI 供应商,没有配置时模型下拉是空的、消息发不出去。
这条路写进页面的文字是模型生成的,不是简历原文;它会在模型给出方案后自动写入,不需要你再点一次。相应的保护措施写在第 4 节。
2.3 打开侧栏时读取一次运行配置
打开侧栏时,扩展会向同一台后端取回四样东西:分享链接、页面正文上限、对话保留轮数,以及「模型」下拉里可选的模型清单(每个模型的名字与单次回答上限,不含供应商的地址与密钥)。
这一次是普通的读取:不带账号、不带 token、不带页面内容、没有请求体 —— 发出去的信息只有「扩展想拿这份配置」本身,回来的也只是上面那几样。它不区分你是谁,也不记录你是谁。不打开侧栏就不会有这次请求。
关于传输安全。默认地址是 https://,账号与密码是加密传输的。
扩展界面上没有修改后端地址的入口;如果你是自行修改源码、重新打包后连到自己的后端,任何远程地址都必须使用 https:// —— 明文 HTTP 传密码是不安全的;唯一的例外是本地回环地址(http://localhost),那种流量不出本机。请只连你自己信任的后端。
3. 只存在你本机的数据
以下几项写在浏览器的本机存储 chrome.storage.local 里,都不上传、不同步、不与任何人共享:
- 登录凭证(token) —— 登录成功后由后端签发,用于向同一台后端证明「还是这个人」。退出登录或卸载扩展时被删除。
- 你选中的那份简历 —— 为了把内容交给页面里的填充脚本,会短暂写进本机存储。退出登录时一并清除。
- 「AI 辅助填充」的对话记录 —— 你在对话框里说过的话、以及模型回给你的话(最多保留最近若干轮)。它关掉侧栏、重开浏览器都还在,退出登录即清除;也可以在对话框里点「新对话」随手清掉。它按账号区分,换个账号登录看不到上一个人的对话。服务端不保存它。
- 你选的模型编号 —— 就是「模型」下拉里选中的那一个供应商 id。它只是一条偏好设置,不含任何个人信息,因此退出登录不会清除。
4. 会读取、会写入的页面内容
4.1 读取
只在你点击侧栏里的「自动填充当前页面」之后,扩展才会读取当前这一个标签页里的表单字段(字段名、标签文字、占位提示),用来判断哪一格对应简历里的哪一项。
- 读到的内容不会离开浏览器,只在本机用于匹配与填写。
- 扩展没有申请任何针对普通网站的长期访问权限,也没有登记自动运行的内容脚本 —— 你没点按钮的时候,它不会出现在任何页面上。
- 它不读取其它标签页,也不读取浏览器历史、书签或下载记录。
「AI 辅助填充」会多读一点:除了上面那些表单字段,它还会读这一个页面的标题与正文(正文默认最多 4000 字),好让 AI 知道这个岗位在招什么。这段正文与第 2.2 节里那几样东西一样,只在你点了那颗按钮之后才会被读取并发送。
4.2 写入与撤销
匹配到的格子会被填入你选中那份简历里的原文。扩展不会编造你简历里没有的内容,不会覆盖你已经填过的格子,不会替你勾选任何「我同意」一类的复选框。
单选按钮组也会填 —— 性别、政治面貌、婚姻情况、有无子女在网申表里多半是一组单选按钮。规则是:只在选项文字与简历里那一项对得上时才选中那一颗(简历写「男」,选项「男」「男性」都认,「女」不认);对不上就整组不动。这一组里已经有人选过的,也整组不动 —— 换掉别人已经做出的选择,比少填一格糟得多。
「AI 辅助填充」这条路上,写进页面的是模型生成的文字,不是简历原文(措辞可能被调整过),并且会在你问完、模型给出方案之后自动写入。所以这条路的保护换成了另外几条:已经填了内容的格子一律不覆盖;复选框与单选按钮组一律不碰(上面那条「按组填」只属于规则那条路,这条路上组根本不在可填清单里);写进去之后侧栏会立刻列出逐格清单,并提供撤销按钮一键还原。同样地,AI 只会看到你已经填过的简历字段(身份证号除外),提示词里也明确要求它不得编造简历里没有的事实(例如期望薪资、身份证有效期、家庭成员)。用不用这条路,由你自己判断是否合适 —— 提交之前请自己核一遍那几格。
无论走哪条路,填完都会在浏览器侧栏里列出每一格用了什么值、依据是什么,并提供一个撤销按钮还原本次填写。撤销对单选按钮组同样有效:还原就是让那一组回到「没有选中任何一项」—— 能填的那组本来就一定是没人选过的。页面上只留一行很快消失的提示(写着填了几项),不覆盖页面内容;那份填充清单只存在侧栏的内存里,关掉侧栏就没了,也不会写进任何存储。(AI 对话是另一回事:它按第 3 节存在本机,退出登录才清除。)
5. 你对这些信息的控制
- 要不要用 AI,由你决定 —— 不点「AI 辅助填充」这颗按钮,简历与页面内容就不会发给 AI。
- 撤销填写 —— 每次填充的逐格清单旁边都有「撤销」,可还原本次写入的每一个格子(含单选按钮组)。
- 清空 AI 对话 —— 对话框里的「新对话」会同时清掉界面上的记录与本机存的那份。
- 退出登录 —— 一键清除本机的登录凭证、选中的简历与 AI 对话记录。换一台机器或换个人使用前,请退出登录。
- 卸载扩展 —— 本机存储由浏览器随扩展一并删除。
- 查看与修改简历 —— 简历本体保存在你自己账号所在的那台后端,可以在学员端后台(eaglet.net.cn/apply/pages/dashboard)查看与修改;扩展本身只读,不会改动它。
- 删除后端侧的数据 —— 由运营那台后端的服务方负责,本扩展不保存、也接触不到服务端的数据。
6. 不做什么
- 不收集浏览记录、书签、下载记录。
- 不读取剪贴板。只有你点侧栏里那颗「分享」时,扩展才会向剪贴板写入一条固定的分享链接(写的是官网公开地址,不是你的任何数据);除此之外不碰剪贴板。
- 不采集统计与埋点,不出售、不共享任何数据,也不做数据经纪。
- 不加载任何远程代码:全部逻辑都在安装包里,未压缩、未混淆,可随时查看。(AI 那一条是普通的接口调用,不是把模型或脚本下载下来执行。)
- 不面向儿童:本扩展面向求职者,不主动收集儿童的个人信息。
7. 保留与删除
- 本机数据:退出登录即清除;卸载扩展时由浏览器一并删除。
- 后端侧的数据:由你自己部署或使用的那台后端负责 —— 它保存什么、保存多久,取决于那份后端的实现与配置,本扩展既不控制也不参与。本扩展官方版本所连的后端(
https://eaglet.net.cn/apply/api)由北京朗晟英才科技有限公司运营。 - 扩展本身不设任何服务器,也不在第三方留存任何数据。
8. 变更与联系方式
若将来的版本出现与上述内容不一致的行为,本政策会先更新,并在扩展的版本说明中注明。这一页的「最近更新」日期会随之变化。
与本政策或数据处理有关的任何问题、查询或删除请求,可以通过以下方式联系我们:
- 邮箱:13483322210@163.com
- 或使用 Microsoft Edge 加载项商店列表页上「支持联系方式」一栏所列的方式
运营方:北京朗晟英才科技有限公司。本政策适用于「简历助手 · 雏鹰」浏览器扩展;eaglet.net.cn 官网与学员端应用本身的数据处理,见站内《隐私政策》。
Resume Helper · Eaglet — Privacy Policy
Effective date: 2026-10-03 · Last updated: 2026-10-03 · Applies to: the 简历助手 · 雏鹰 (Resume Helper · Eaglet) extension for Microsoft Edge.
1. What the extension does, and where data goes
The extension does three things: it signs in to the backend with your own account and reads the resumes under it; it fills the resume you selected into the web form you are looking at (自动填充当前页面, "fill the current page"); and it offers an optional AI 辅助填充 ("AI-assisted fill") that sends your resume and the current page to an AI so it can propose values (a membership feature — see 2.2).
It talks to exactly one backend address, https://eaglet.net.cn/apply/api by default. That address is a constant compiled into the package, and there is no user interface for changing it (the About page only displays it). The extension sends requests to no other server.
This table is the complete data flow; the sections below expand each row:
| Data | When it happens | Where it goes |
|---|---|---|
| Username and password | When you click "log in" in the side panel | Sent only to the backend your own account lives on, to obtain a session token; the password is used for that one sign-in check. |
| The fields in your resume that are already filled | Only when you click "AI-assisted fill" and send a message | First to your own backend, which forwards it to the AI provider that backend is configured with. Never the national ID number (see 2.2). |
| Labels, control types and already-filled flags of the page's fillable controls | Same as above | Same as above. The controls' own descriptive text only — not the values already typed into them. |
| The current page's title and body text | Same as above | Same as above. The body text is capped at 4000 characters by default; that cap is configured by whoever operates the backend. |
| Whatever you type into the AI chat box | Same as above | Same as above. |
| Runtime config (share link / body-text cap / chat turns / selectable models) | Once each time the side panel opens | A plain read: no account, no token, no request body, none of your content. Only those values come back. If you never open the side panel, it never happens. |
2. Data that leaves your browser
Three cases: signing in; AI-assisted fill, which happens only when you actively use it; and a config read that sends none of your data.
2.1 Signing in: username and password
The username and password you type into the extension's side panel are sent to the backend your own account lives on (the source default is https://eaglet.net.cn/apply/api) to obtain a session token. Reading your resumes and sending chat messages afterwards are authenticated with that token (a Bearer token in the request); the password is not sent again.
2.2 When you use "AI-assisted fill"
Four things are needed for this feature to work. It happens only after you click that button and actually send a message:
- The fields in your selected resume that are already filled (empty fields are neither listed nor sent). They include what a Chinese graduate recommendation form or job application asks for — gender, date of birth, ethnicity, native place, political status, marital and parental status, height and weight, second major, thesis title, English test level and score, emergency contact. But never the national ID number: it is the one field in that group where a leak cannot be undone, and it is not worth handing over whatever the form asks. Rule-based fill still fills an ID-number field; the model simply never sees it.
- The Chinese labels, control types and already-filled flags of the fillable controls on the current page (not the values already typed into them).
- The current page's title and body text (usually that job posting; capped at 4000 characters by default, configured by whoever operates the backend).
- Whatever you type into that chat box.
This is sent first to the backend above, which forwards it to the AI provider you selected in the extension (the choices are configured by whoever operates that backend and may include third-party model providers). The request also carries the id of the one provider you selected — a random id that tells the backend where to forward, and contains none of your identity information.
Whether to use this at all is your choice. If you never click that button, none of the above is sent. Two limitations are worth stating plainly: it is a membership feature — on an account without it the button is disabled and shows an "unlock VIP" hint, which does not affect ordinary fill; and it requires the backend to have an AI provider configured, otherwise the model dropdown is empty and messages cannot be sent.
The text this path writes into the page is model-generated, not verbatim from your resume, and it is written automatically once the model proposes it. The protections for that path are in section 4.
2.3 Reading the runtime config when the side panel opens
When the side panel opens, the extension fetches four values from the same backend: the share link, the page-body cap, how many chat turns to keep, and the models selectable in the "model" dropdown (each model's name and per-answer cap — never a provider's address or key).
This is a plain read: no account, no token, no page content, no request body. The only thing that leaves is the request for that config itself, and only those values come back. It does not identify or record you. If you never open the side panel, this request never happens.
Transport security. The default address uses https://, so credentials travel encrypted.
There is no way to change the backend address from the extension's interface. If you modify the source and repackage it against your own backend, any remote address must use https:// — sending credentials over plain HTTP is not safe. The one exception is a loopback address (http://localhost), where traffic does not leave your machine. Only point it at a backend you trust.
3. Data stored only on your machine
The following are kept in the browser's local storage, chrome.storage.local. None of them are uploaded, synced, or shared with anyone:
- The session token — issued by the backend after sign-in, used to prove to the same backend that it is still you. Deleted when you log out or uninstall.
- The resume you selected — written briefly to local storage so the filling script in the page can read it. Cleared on logout.
- Your "AI-assisted fill" conversation — what you typed into the chat box and what the model replied (only the last few turns). It survives closing the panel and restarting the browser, is deleted when you log out, and can be cleared at any time with the "new conversation" button in that chat box. It is keyed to the account, so a different account never sees the previous person's conversation. The backend does not store it.
- The model you selected — the id of the provider chosen in the "model" dropdown. It is a preference that contains no personal information, so logging out does not clear it.
4. Page content that is read and written
4.1 Read
Only after you click "自动填充当前页面" in the side panel, and only for the current tab, does the extension read that page's form fields (names, label text, placeholder hints) to work out which field corresponds to which resume item.
- What it reads never leaves the browser; it is used locally for matching and filling.
- The extension requests no persistent host access to ordinary websites and registers no automatically running content scripts. It never appears on a page you did not click for.
- It does not read other tabs, browsing history, bookmarks, or downloads.
AI-assisted fill reads a little more: besides those form fields, it reads this page's title and body text (4000 characters by default) so the AI knows what the posting asks for. Like the items in 2.2, that text is read and sent only after you click that button.
4.2 Writing and undo
Matched fields receive the exact text from the resume you selected. The extension does not invent values, does not overwrite fields you have already filled in, and does not tick any consent checkbox on your behalf.
Radio button groups are filled too — on a job application, gender, political status, marital status and "has children" are usually a set of radio buttons. The rule: an option is selected only when its text matches the resume value (a resume saying 男 matches options 男 and 男性, not 女); if nothing matches, the whole group is left alone. A group someone has already answered is left alone as well — replacing a choice that has already been made is far worse than filling one field less.
On the AI-assisted path the text written into the page is model-generated, not verbatim from your resume (the wording may be adapted), and it is written automatically once the model proposes it. The protections on this path are therefore: fields that already have a value are never overwritten, checkboxes and radio buttons are never touched (the "fill by group" rule above belongs to the rule-based path only — here a group is not even in the list of fillable controls), and the side panel immediately lists every field it wrote with an undo button. The AI sees only the resume fields you have already filled (except the national ID number), and the prompt explicitly forbids inventing anything not present in them (expected salary, ID expiry date, family members, and so on). Whether to use this path is your call — please review those fields before submitting.
On either path, afterwards the extension's browser side panel lists every field, the value used and the evidence for the match, with an undo button that restores the previous values. That undo covers radio groups too: restoring one means putting the group back to "nothing selected", which is exactly the state it had to be in for the extension to fill it. The page itself only shows a short line that fades away (how many fields were filled) — nothing is drawn over the page, and that list lives in the panel's memory only: closing the panel drops it and nothing is written to storage. (The AI conversation is a separate case: it is saved locally as described in section 3, and cleared on logout.)
5. The control you have
- Whether to use AI is your decision — if you never click "AI-assisted fill", no resume or page content is sent to an AI.
- Undo — every fill comes with a per-field list and an undo button that restores every field it wrote (radio groups included).
- Clear the AI conversation — the "new conversation" button clears both the on-screen log and the copy stored on your machine.
- Log out — clears the local session token, the selected resume and the AI conversation in one step. Please log out before handing the machine to someone else.
- Uninstall — the browser removes the extension's local storage with it.
- View or change your resume — the resume itself lives on the backend your account belongs to, where you can view and edit it in the student dashboard (eaglet.net.cn/apply/pages/dashboard). The extension only reads it; it never modifies it.
- Delete server-side data — that is the responsibility of whoever operates that backend. The extension stores nothing on the server and cannot reach it.
6. What it does not do
- No browsing history, bookmarks, or downloads.
- The clipboard is never read. The only clipboard use is a write: when you click the "share" button in the panel, the extension puts one fixed share link on your clipboard — a public site address, never any of your data. Nothing else touches the clipboard.
- No analytics, no telemetry, no selling or sharing of data, and no data brokering.
- No remote code: all logic ships inside the package, uncompressed and unobfuscated. (The AI path is a plain API call — no model or script is downloaded and executed.)
- Not directed at children: the extension is for job seekers and does not knowingly collect children's personal information.
7. Retention and deletion
- Local data: cleared on logout, and removed by the browser when you uninstall.
- Server-side data: the responsibility of the backend you deploy or use. What it stores and for how long depends on that service and your configuration; the extension neither controls nor participates in it. The backend the official build connects to (
https://eaglet.net.cn/apply/api) is operated by Beijing Langsheng Yingcai Technology Co., Ltd. - The extension runs no server of its own and retains no data with any third party.
8. Changes and contact
If a future version behaves differently from what is written here, this policy will be updated first and the change noted in the release notes; the "last updated" date above will change with it.
For any question, request or deletion request about this policy or about data handling, contact us:
- Email: 13483322210@163.com
- Or via the support contact listed on the extension's Microsoft Edge Add-ons listing page
Operator: Beijing Langsheng Yingcai Technology Co., Ltd. This policy covers the 简历助手 · 雏鹰 browser extension; data handling by the eaglet.net.cn website and student app itself is covered by the separate privacy policy published on that site.