Privacy Policy
Last updated: May 21, 2026
This Privacy Policy explains how SocialScalr ("SocialScalr", "we", "us") collects, uses, and protects information when you use the SocialScalr Chrome extension and web dashboard (together, the "Service").
What we do NOT collect
- We never collect, store, or transmit your LinkedIn password or login credentials. The extension operates inside the LinkedIn session you are already logged into in your own browser.
- We do not access LinkedIn on our servers and we do not use the LinkedIn API. All LinkedIn page interaction happens locally in your browser.
- We do not sell your data, and we do not serve third-party ads.
Information we collect
- Account information: the email address and name you provide when you create a SocialScalr account.
- Campaign data: campaigns, leads, scheduled posts, and comment drafts you create. Lead records may include public LinkedIn profile information you choose to import or collect (name, headline, company, location, profile URL).
- Activity data: the outcome of actions the extension performs (for example, "invite sent" or "post published") and daily activity counters, so your dashboard can display progress.
- Local settings: your extension preferences and the pending action queue, stored on your device using the browser's local storage. This stays on your device except for the activity results described above.
- Billing information: if you subscribe, payments are processed by Square. We receive a subscription status and plan; we do not receive or store your full card details.
How we use information
- To operate the Service and run the campaigns you configure.
- To display your statistics, campaigns, and account in the dashboard.
- To provide support and to secure and improve the Service.
Browser permissions
The extension requests only the permissions it needs:
- storage - save your settings and action queue on your device.
- alarms - schedule actions at safe, human-like intervals.
- tabs - open and navigate a LinkedIn tab to perform actions.
- scripting - run the automation script on LinkedIn pages.
- Host access to linkedin.com - required so the extension can perform actions on LinkedIn on your behalf.
Where data is stored
Account and campaign data is stored in our database hosted on Supabase, and the Service is served through Cloudflare. Payments are handled by Square. These providers process data on our behalf under their own security and privacy commitments.
Data retention and deletion
We keep your data while your account is active. You may request deletion of your account and associated data at any time by emailing us. Uninstalling the extension removes all data stored locally on your device.
Security
We use industry-standard measures to protect your data, including encrypted connections and access controls. No method of transmission or storage is completely secure, but we work to protect your information.
Children
The Service is not directed to anyone under 18 years of age.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy or your data? Email support@socialscalr.com.