Privacy Policy
Last updated: 1 October 2026
In short: The Barrier reads job listing pages on supported job sites, and nothing else. It does not track your browsing on other sites, read your emails, sell your data, or access anything unrelated to job postings. An account is required to use it.
1. What The Barrier Does
The Barrier is a Chrome extension that analyzes job listings for scam patterns, ghost jobs, and exploitative hiring practices. It works by:
- Reading job listing text on supported platforms (Naukri, Dice, We Work Remotely, Wellfound, CrawlJobs, and ZipRecruiter)
- Sending that text to our backend, which uses Anthropic's Claude AI to write a plain-language explanation of the risk score
- Displaying the results directly in your browser
The extension only activates on job listing pages. It does not run on Gmail, social media, banking sites, or any other websites.
2. What We Collect (And Why)
Job listing text (sent for analysis, not stored)
- We extract the text of the job description you're viewing so we can check it for red flags
- Up to the first 4,000 characters are sent to Anthropic (Claude) to write the explanation, along with the page URL and the red flags we detected. No account, device or other personal information is sent to Anthropic
- The listing text is not stored by us once the explanation is written
Analysis cache (stored for 60 days)
- To avoid re-analyzing the same listing, we store: the job page URL, a hash derived from the URL and text, the risk score, severity and confidence, the AI-generated explanation, and the red-flag categories we found together with the short phrases from the listing that matched them (a few words each, never the full description), plus a timestamp
- Stored entries are deleted automatically after 60 days, or immediately if community reports confirm the listing as a scam (see below)
Anonymous device identifier
- A randomly generated ID created by the extension and kept in its local storage — not a cookie, and not readable by the websites you visit
- We store it on our servers together with your browser's user-agent string (browser name, version and operating system), your install date and your last-active date, so we can count installations
- It is also sent with each community report (see below), and to our own website, thebarrier.co, when you're signed in there in the same browser, so your account page can show that the extension is installed and link it to your account
- You can reset it at any time by uninstalling and reinstalling the extension
Community reports
- When you report a job listing, we store an identifier derived from the job's URL, a timestamp, and your device identifier. Reports are keyed by device, not by account, and the device identifier is used only to stop one installation reporting the same listing twice
- You must be signed in to report, but your account is only checked, not stored with the report — no name, email, or other personal information is attached to it
Account (required to use the extension)
- Creating an account is required to use the extension — you must sign in before any job listing can be analyzed
- You can create an account with Google Sign-In or with an email address and password
- If you sign up with a password, we never see or store it in plain text — authentication is handled by Supabase Auth, which stores only a cryptographically hashed version
- If you sign in with Google, we receive the email address associated with your Google account
- Signing in on our website hands your session to the extension so it can verify you're signed in before scanning — this happens automatically when you sign in or visit your account page, and stays local to your browser
- Your daily analysis limit is tied to your account, not to any specific device or installation, and applies the same way regardless of which device or browser you're signed in on
- The extension stores your sign-in session tokens in its local storage so it can prove you're signed in when it analyzes a listing. It never sees your password
Waitlist email address (optional, early-access notifications only)
- If you submit your email through our early-access waitlist form, it is stored with Brevo (our email service provider)
- Used only to notify you when early access opens, or to send occasional product updates
- Never required to use the extension, and entirely separate from the account system described above
Website analytics (thebarrier.co only, not the extension)
- We use Google Analytics 4 to understand visits to our website: pages viewed, how you arrived (for example from search or a link), approximate location, and your device and browser. It uses cookies, and Google processes this data under its own privacy policy
- We also use Vercel Web Analytics, which counts page views and where visits came from without cookies and without identifying individual visitors
- Neither runs on our account, sign-in or password-reset pages
- Google Analytics only sets cookies if you choose Accept in our cookie banner. You can change your choice anytime in Cookie settings
- You can block Google Analytics with your browser's cookie settings or Google's opt-out browser add-on
3. What We DO NOT Collect
We do NOT collect, access, or store:
- Your browsing history on any site other than the supported job listing pages
- Your job applications or resumes
- Personal emails or messages
- Your password — sign-in is handled by Supabase, which stores only a hashed version
- Financial information
- Location data (beyond what you voluntarily provide in job searches)
- Social media activity unrelated to job listings
4. Chrome Extension Permissions (Explained)
The Barrier requests the following Chrome permissions. Here's why:
- Host access to supported job platforms — Naukri, Dice, We Work Remotely, Wellfound, CrawlJobs, and ZipRecruiter. This allows us to read job listing text on pages you visit on these specific sites. We only read job listing content, not your personal data or activity on those sites, and the extension does not run on any other website.
- "Storage" — Used to save your anonymous device identifier and your sign-in session locally, entirely within your browser, so you don't have to sign in every time you open a job listing.
- Communication with thebarrier.co — Lets our own website hand your sign-in session to the extension after you sign in, so it can verify you're signed in before scanning. Only thebarrier.co can communicate with the extension this way — no other website can.
We do NOT request permissions for:
- Your browsing history
- All websites — only the specific job platforms listed above
- Clipboard access
- Microphone or camera
- Access to any tab beyond the supported job platforms
5. How Data Is Processed
Real-time analysis (not stored permanently):
- When you view a job listing, the extension extracts the text
- The text is sent to our backend API hosted on Vercel
- Our backend sends the text to Anthropic's Claude AI to write a plain-language explanation
- The result, with the job page URL and matched phrases described above, is cached in Supabase for 60 days and displayed to you
- The listing text itself is not stored
Third-party services we use:
- Anthropic (Claude) — Receives the listing text (up to 4,000 characters), its URL and our detected red flags to write the explanation. No personal data is sent.
- Supabase — Community reports, analysis cache, and account authentication (Google Sign-In and email/password) are handled here. Supabase is a secure, privacy-focused database and authentication provider.
- Google — If you choose to sign in with Google, Google authenticates you and shares your email address with us via Supabase Auth.
- Vercel — Our backend API and website are hosted on Vercel's infrastructure. Vercel Web Analytics provides cookieless page-view counts for our website.
- Google Analytics — Measures visits to thebarrier.co (pages viewed, traffic sources, approximate location, device and browser) using cookies. Not used in the extension or on account and sign-in pages.
- Brevo — Email addresses from the early-access waitlist are stored in Brevo for sending updates.
6. Data Retention
- Job analysis cache — Automatically deleted after 60 days, or immediately if a listing is confirmed as a scam by community reports.
- Community reports (URL identifier, device identifier, timestamp) — Kept indefinitely to maintain accurate per-job report counts.
- Installation records (device identifier, browser user agent, install and last-active dates) — Kept while you use the extension; deleted on request.
- Account data (email, hashed password, Free/Pro status) — Retained for as long as your account exists; deleted if you request account deletion.
- Waitlist email addresses — Retained until you request removal.
7. We Do Not Sell Your Data
The Barrier does not sell, rent, share, or trade any user data — anonymous or otherwise — to third parties for commercial purposes. Ever.
We use this data only to provide The Barrier's job-analysis features. It is never used for advertising or to assess creditworthiness, and it is never transferred except to the providers above as needed to run the service.
8. Your Rights
You have the right to:
- Request deletion of your account and all associated data
- Request removal of your email address from our early-access waitlist
- Reset your anonymous device identifier at any time by uninstalling and reinstalling the extension
- Uninstall the extension at any time — no data remains on your device after uninstall
To exercise any of these rights, email us at
support@thebarrier.co
and we will respond within 7 days.
9. Children's Privacy
The Barrier is not intended for use by anyone under the age of 16.
We do not knowingly collect information from minors.
10. Changes to This Policy
If this policy changes in a meaningful way, we will update the date at the top of this page
and notify beta users by email where applicable.
11. Contact
Questions about this policy? Reach us at:
support@thebarrier.co