Privacy Policy
Last updated: September 28, 2026
1. Who we are
LinkedInScrap is independent software, not affiliated with LinkedIn Corporation. On the hosted instance (linkedinscrap.theboomer.dev) the domain operator is the data controller. If you self-host the backend, you are the controller: your data never leaves your infrastructure.
2. The extension: your data stays in your browser
Collection happens entirely inside your local, authenticated session. Extracted profiles are stored in browser storage (chrome.storage) and exported to CSV/JSON from your machine. During scraping the extension makes no network calls to us or to any third party.
3. Portal sync (optional and explicit)
Leads are sent over HTTPS to a backend only if you type your portal URL, create an API key and press "Sync to portal" — at which point you grant host permission for that origin. Synced leads can be deleted from the portal at any time.
4. Data processed by the portal
Authentication is handled by Clerk (account email/ID); Clerk's privacy policy covers that component. Business data: organization, synced leads, tags and statuses. Credentials: API keys are stored as SHA-256 hashes only. Payments are processed by Stripe; we never store card numbers. This site uses no tracking cookies or third-party analytics.
5. Your rights (GDPR/CCPA)
You can access, export, correct or delete your data — locally from the extension popup (clear queue / export) and in the portal from the UI or by deleting your account. For any request write to: [email protected].
6. Changes
Material changes to this policy will be announced on this page with a new date. This page is the governing version.
LinkedInScrap is independent software. LinkedIn is a trademark of LinkedIn Corporation.