We're building the future of hiring in India.

Legal · Chrome Extension

Josh Junior Privacy Policy

This policy describes how the Josh Junior Chrome extension (“Extension”) collects, uses, and protects information when recruiters use it with Naukri Resdex and Naukri job response pages. Josh Junior is part of the Josh AI platform.

Effective date: August 14, 2026 · Josh AI platform privacy policy

1. Who this applies to

This Extension is intended for authorised recruiters and hiring teams who have a Josh AI account. By installing the Extension, connecting it with an install token, and accepting the in-app data-processing consent, you confirm that your organisation is the Data Fiduciary for candidate personal data you process through Naukri, and that you are authorised to accept these terms on its behalf.

2. Information the Extension reads on Naukri

When you use Josh Junior on Naukri Resdex or Naukri hiring pages, the Extension reads information visible in your logged-in recruiter session, including:

  • Candidate names, headlines, experience, skills, and location
  • Profile and list-page metadata shown by Naukri
  • Resume or CV preview content (HTML rendered in-page)
  • Email addresses and phone numbers when you or Naukri reveal them on the profile
  • Naukri candidate / application identifiers needed to match results

The Extension does not run on sites other than the Naukri domains declared in its Chrome Web Store listing. It does not click “Download Resume” on Naukri (which can consume Naukri credits); it reads inline CV previews where available.

3. Information stored locally in your browser

The Extension stores the following in Chrome local/sync storage:

  • Your Josh AI install token and short-lived access token
  • Selected job campaign and user preferences
  • Cached match scores and candidate processing state for the active session
  • Consent acceptance record (version and timestamp)

Tokens are credentials — do not share your install token. You can revoke tokens from the Josh AI web app at any time.

4. Information sent to Josh AI servers

Candidate data and match requests are transmitted over HTTPS to the Josh API at https://josh-ai-production-9dbe.up.railway.app. This includes profile fields, resume content you process, contact details when available, campaign identifiers, and audit metadata (timestamps, Naukri IDs) needed to score candidates and record your sourcing actions.

Background workers may process data on separate Josh AI infrastructure. We do not sell candidate personal data to third parties.

5. How we use the information

  • Score and rank candidates against your active job description
  • Display match results in the Extension side panel and on-page badges
  • Support shortlisting, funnel, and outreach workflows you initiate
  • Maintain an audit trail for compliance (DPDP and organisational policy)
  • Improve DOM selectors and reliability (configuration updates, not sale of PII)

6. Permissions explained

Josh Junior requests Chrome permissions solely to provide its features:

  • Naukri host access — read candidate list and profile pages
  • Side panel — show match results and controls
  • Tabs — open candidate profiles during deep processing
  • Storage — save auth, preferences, and session cache
  • Scripting / downloads / alarms — automate in-page actions you request and refresh auth

7. Data retention and deletion

Data retention on Josh AI servers follows your organisation's Josh AI account settings and applicable law. You may clear local Extension data by removing the Extension or signing out. To request deletion of server-side candidate records, contact your Josh AI account administrator or our support team.

8. Security

All API communication uses TLS (HTTPS). Access tokens are short-lived and refreshed automatically. Install tokens should be treated as secrets. We apply reasonable technical and organisational measures to protect data in transit and at rest.

9. Your choices

  • Decline in-app consent — you will not be able to use matching features
  • Revoke your install token in Josh AI Settings
  • Disable in-page badges in Extension Settings
  • Uninstall the Extension to remove locally stored data

10. Children

Josh Junior is a B2B recruiter tool and is not directed at children under 18.

11. Changes to this policy

We may update this policy when the Extension or applicable law changes. Material updates will be reflected on this page with a new effective date. Continued use after an update constitutes acceptance where permitted by law.

12. Contact

Questions about this policy or the Extension: contact Josh AI support.

Last updated: August 14, 2026