Mentions légales
Privacy Policy
Cette politique est publiée en anglais. La version anglaise fait foi. Lire en anglais
Short version: Yang's Upwork Toolkit is local-first. Your Upwork profile, job history, and proposal drafts live in your browser, not on our servers. We do not collect your Upwork account or proposal history. We process your payment email only for billing and subscription restore. Message threads are the one place another person's words are involved, so they get their own rules — see section 6.
1. What we do not collect
- Your Upwork username, account ID, or login credentials
- Your real name
- Your email address, except for Pro billing and explicit subscription restore
- Your payment card details (handled by Creem, our payment processor)
- The text of jobs you view, except in the narrow case described in section 4
- The text of your Upwork messages, except in the narrow case described in section 6
2. The only identifier we use
When you install the extension, it generates an anonymous
install_id (a random UUID) and stores it in your browser. We
use this ID to:
- Check whether you are on the Free or Pro plan
- Enforce per-install rate limits on AI-assisted reviews
The install_id is not linked to your real identity. Two
installations on different devices are two different IDs to us.
3. What stays on your device
The following is stored in your browser's local extension storage and is never sent to our servers:
- Your profile snapshot: title, overview, skills, proof assets, strong/weak stack lists
- Your screening rules (auto-reject thresholds, banned skills, etc.)
- Your review history
- Proposal drafts you generate
- UI preferences (language, expanded sections, etc.)
Uninstalling the extension removes all of this data.
4. What gets sent to our Worker
Our backend (a small Cloudflare Worker at
upwork-toolkit-api.yangworks.dev) receives
the following account and usage data:
- Your
install_id - Subscription metadata returned by Creem (plan, status, expiry)
- Your payment email when Creem returns it for billing, or when you enter it to restore a subscription
- Device binding metadata used to restore Pro on another browser profile
- A hashed restore code when you request subscription recovery
- An HMAC signature on AI-review requests to prevent replay attacks
- Hosted AI usage events and quota counters
When hosted AI is disabled, job content, profile content, and proposal drafts do not go to the Worker.
When you explicitly enable hosted AI and run an AI action, the Worker also receives a whitelisted, trimmed payload for that one action: the current job fields, a profile summary, and the local review result. The Worker uses that payload to call the AI provider and enforce quota. We do not store raw job text, profile text, or proposal drafts in our database.
5. What gets sent to the AI provider
AI-assisted review is off by default. It runs only when you:
- Have hosted AI quota available (Free trial quota or Pro quota)
- Have explicitly enabled AI assist in the extension settings
- Click a specific review or rewrite action
When all three are true, we send only the fields needed for that action to our AI provider (an OpenAI-compatible endpoint):
- For job review: the current job's title, URL, trimmed description, budget, type, skills, and visible payment / proposal / hire facts
- For job review: a summary of your profile and the local review result we already computed
- For profile rewrite: the selected profile section, current value, profile summary, and action hint
- For a reply draft: see section 6. Message text is never sent unless you click Draft a reply.
We do not send: your local review history, your proposal drafts, browser exports, or raw Upwork page data.
6. Upwork message threads
The extension can help you reply to a client inside an Upwork message room. A conversation contains another person's words, so this feature is handled more narrowly than everything above.
What is read, and when
Only when a message room is the tab you are looking at, the extension reads the messages already rendered on that page: who wrote each message, its text, the name shown for the other party, and the job the thread is attached to. It makes no request to Upwork, opens no other conversation, and reads nothing in the background.
What happens locally
The risk flags, the intent line, and the suggested next moves are computed entirely inside your browser by pattern matching. No network request is involved, and this part works on the Free plan with no AI configured.
What leaves your browser, and only if you ask
Nothing from a conversation is sent anywhere until you click Draft a reply. When you do, the thread text, the name of the other party, the linked job title, your profile summary, and the tone you picked are sent for that single action — to our Worker and its AI provider if you are using hosted AI, or directly from your browser to whichever endpoint you configured if you are using your own API key. With your own key, that endpoint is your choice and your responsibility; the request does not pass through our servers and we cannot see it.
What is never stored
Message text and generated replies are held in memory for as long as the panel is showing that conversation, and nowhere else. They are not written to your browser's extension database, they do not appear in your review history, and they are not included in a JSON export. We do not store them on our servers. The AI provider receives them only for that one request; we do not ask it to retain them, but we cannot control its own logs. Closing the panel or switching to another thread discards the draft.
What we never do
The extension does not click Send. A drafted reply is written into Upwork's composer only after you click Fill, and sending it is always your own deliberate action.
7. Third parties
We share data with the following third parties:
- Creem — payment processing for Pro subscriptions. Creem receives the data needed to bill you (your card details and email). See Creem's privacy policy.
- Resend — email delivery for one-time subscription restore codes. Resend receives the payment email and restore email content only when you request restore.
- Our AI provider — only when you actively use hosted AI, and only the fields listed in sections 5 and 6.
- Cloudflare — hosts the Worker and this site. Standard infrastructure logs apply.
We do not sell or share data with advertisers, analytics platforms, or data brokers.
8. Your choices
- Stop using the extension: uninstall it; all local data is removed.
- Delete subscription records: email [email protected] with your
install_idand we will delete it from our Worker within 7 business days. - Restore a subscription: enter your payment email in the extension and confirm the one-time code sent to that email.
- Opt out of AI assist: disable the toggle in the extension settings. The toolkit still works fully on local-only review.
- Skip the reply assistant: never click Draft a reply. The local risk read stays in your browser, and nothing from a conversation leaves it.
9. Children
Yang's Upwork Toolkit is not directed at children under 16 and we do not knowingly collect data from them.
10. Changes
We will post material changes to this page and update the "Last updated" date. Continued use of the extension after changes are posted constitutes acceptance.
11. Contact
Questions or requests: [email protected]