Legal
Privacy Policy
How we collect, use, and protect your information.
Last Updated: April 17, 2026
Introduction
PumpWork AI (“the Service”) is provided by Devviy.com (“we,” “us,” or “our”) and consists of a Chrome extension, a companion website at pumpwork.devviy.com (for account management, settings, and subscription), and an optional Telegram bot for notifications. Our single purpose is to provide an AI-powered productivity suite for Upwork freelancers to manage job feeds, evaluate opportunities, and generate tailored proposals.
We are committed to protecting your privacy. This policy explains how we collect, use, and protect your information in compliance with the Google Chrome Web Store Developer Program Policies and the Chrome Web Store Limited Use Policy.
Information We Collect
A. Information You Provide Voluntarily
- Account Information: Name, email address, and Upwork User ID.
- Professional Profile (Resume Data): Job title, professional history, skills, languages, projects, education, and references you choose to provide.
- Job Preferences and Filters: Preferred and disliked countries, skills, job titles, budgets, and client metrics used to evaluate job relevance.
- User Content: Custom AI prompts and instructions you provide to guide the generation of cover letters or job evaluations.
- Telegram Handle (optional): Your Telegram user identifier, collected only if you choose to enable Telegram notifications.
B. Information Collected Automatically
- Job Data: Information from Upwork job listings that you choose to evaluate or apply for.
- Generated Content History: Job evaluations and AI-generated cover letters produced for you, stored so you can retrieve and reuse them.
- Token Usage and Billing Metadata: Records of AI token consumption, balance changes, subscription status, and payment events needed for billing and dispute resolution.
- Session and Device Fingerprint: A hashed device fingerprint and session identifier used to protect your account from unauthorized access.
- Analytics Events: Anonymous feature-usage events (such as page views, button clicks, and session duration) collected via Google Analytics on both the website and the Extension. These events are tied to a randomly generated client identifier, not to your name or email.
- Error and Diagnostic Data: Crash reports, stack traces, and anonymized runtime context collected via Sentry to detect and fix bugs.
- Usage Metadata: Technical logs including extension version, interaction timestamps, and feature usage patterns to improve functionality and diagnose errors.
C. Information We Do NOT Collect
- Browsing history outside of Upwork
- Personal files or documents from your device
- Financial information or payment card details (processed directly by our payment provider)
- Your Upwork password or account credentials
Permissions We Request
The Extension requests the following browser permissions to function:
| Permission | Purpose |
|---|---|
| sidePanel | Display the PumpWork AI interface in Chrome's side panel |
| cookies | Read your Upwork session cookie to fetch your personalized job feed on your behalf |
| storage | Save your preferences, session state, and cached data locally on your device |
| declarativeNetRequest | Modify request headers so the Extension can securely communicate with Upwork's GraphQL API |
| host_permissions (upwork.com) | Fetch job data, detect login status, and enable proposal autofill on Upwork application pages |
The Extension also communicates with our backend at pumpwork.devviy.com over standard HTTPS for account management, AI processing, and billing. This does not require a separate host permission.
How We Use Your Information
We use your data only to provide and improve the Service's core functionality:
- Displaying and filtering your Upwork job feed
- Scoring jobs against your preferences using a combination of deterministic rules and AI evaluation
- Generating personalized cover letters, cost estimates, and job evaluations via AI
- Verifying subscription status, managing token balances, and processing payments
- Delivering optional notifications via Chrome, audio, and Telegram (when enabled)
- Protecting your account from unauthorized access and preventing abuse
- Diagnosing errors and improving the accuracy and relevance of AI-generated content
We Do NOT:
- Sell, trade, or rent your personal data to third parties
- Use your data for personalized advertising or marketing
- Use your data to determine creditworthiness or for lending purposes
- Train third-party AI models on your personal data or use it for model fine-tuning
- Transfer your data to third parties for purposes unrelated to the Service's functionality
Data Sharing and Third Parties
We share data with third parties only when essential for the Service's functionality:
| Third Party | Data Shared | Purpose |
|---|---|---|
| AI providers (OpenAI, Anthropic, OpenRouter, X.AI) | Job descriptions, your resume data, and custom prompts | Generate cover letters and AI-assisted job evaluations. Requests are routed to the provider configured for the active model. |
| pumpwork.devviy.com (our backend) | Account data, preferences, job data, generated content, usage logs | Process requests, persist your settings, manage subscriptions and tokens |
| WayForPay | Email address and order details (card data entered directly with provider) | Process subscription and token purchases |
| Telegram Bot API (optional) | Your Telegram user ID and notification content | Deliver notifications only if you enable the Telegram integration |
| Sentry | Error stack traces and anonymized diagnostic context | Detect and fix crashes and runtime errors |
| Google Analytics | Anonymized usage events | Understand aggregate feature usage to improve the Service |
We may also disclose information if required by law or to protect against fraud or security threats.
Analytics and Error Tracking
We use analytics and error-tracking tools on both the website and the Extension to understand how the Service is used in aggregate and to diagnose bugs. These tools do not receive your job data, resume, prompts, or generated content.
Google Analytics (GA4)
We use Google Analytics to collect anonymous, aggregated usage events such as page views, feature interactions, and session duration. The Extension sends events directly via the GA4 Measurement Protocol; the website uses the standard gtag.js integration. Each install is associated with a randomly generated client identifier stored locally — not with your name, email, or Upwork ID.
Sentry
We use Sentry to capture crash reports and runtime errors. Error reports may include the extension version, a stack trace, and anonymized runtime context. Sensitive fields (tokens, cookies, prompts, resume content) are filtered before transmission.
Your Choices
You can block analytics at the browser level using your browser's tracking-protection settings, an ad/tracker blocker, or by opting out through the Google Analytics opt-out tool. Opting out does not affect the core functionality of the Service.
Data Storage and Security
- Encryption in Transit: All data transmitted between the Extension, Upwork, our backend, and third-party providers is encrypted via HTTPS/TLS.
- Encryption at Rest: Account data stored in our database is encrypted at rest.
- Local Storage: Cached preferences and session state are stored locally in your browser using chrome.storage.local.
- Authentication: Sessions are authenticated with cryptographically secure tokens and bound to a hashed device fingerprint. Auth and billing endpoints are rate-limited to prevent abuse.
- Server Security: Our backend applies security headers, least-privilege access, and standard operational controls.
Data Retention
- Active Accounts: Data is retained while your account is active.
- Inactive Accounts: Accounts inactive for more than 180 days may be automatically deleted along with all associated data.
- Account Deletion: When you request deletion, your account enters a 7-day grace period during which the action can be cancelled. After the grace period, your data is permanently removed from our servers within 30 days.
- Local Data: Cleared immediately when you uninstall the Extension.
- Billing Records: Anonymized billing records may be retained longer where required by tax, accounting, or legal obligations.
Your Rights and Control
You have the following rights regarding your data:
- Access: View your profile, resume, preferences, and token history within the settings area at pumpwork.devviy.com.
- Edit: Modify your profile, resume, preferences, filters, and cover letter prompts at any time.
- Export: Request a copy of your data by contacting support.
- Deletion: Delete your account and all associated data from your account settings, after which a 7-day grace period applies before permanent removal.
- Disconnect Integrations: Disable Telegram notifications and disconnect the Telegram bot at any time from the settings page.
- Revocation: Stop local data collection by uninstalling the Extension; server-side data is removed when you delete your account.
For EU/EEA Users (GDPR)
You have additional rights including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.
For California Users (CCPA)
You have the right to know what personal information is collected, request deletion, and opt-out of the sale of personal information. We do not sell your personal information.
Children's Privacy
The Extension is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by:
- Displaying a notice within the Extension
- Updating the "Last Updated" date at the top of this policy
Your continued use of the Extension after changes constitutes acceptance of the updated policy.
Contact Us
For questions regarding this policy or to exercise your data rights, please contact:
Email: [email protected]
This Privacy Policy complies with the Google Chrome Web Store Developer Program Policies and the Chrome Web Store Limited Use Policy.