This Privacy Policy explains how Bartosz Cioch ("we," "us," "our") collects, uses, stores, and protects information through the LinkedIn/Gmail Mini-CRM Chrome extension and associated backend service (together, the "Service").
We collect only what the Service needs to let you tag, note, and track your professional contacts inline on LinkedIn and Gmail. We do not collect data from LinkedIn or Gmail beyond what is described here.
When you view a LinkedIn profile with the extension active, we read fields already visible to you as a logged-in LinkedIn user directly from the page you're viewing:
We do not collect LinkedIn connection lists, messages, or any data from profiles the extension does not actively render a sidebar on. We do not use LinkedIn's API or any automated scraping/bulk-export mechanism — data is read only from the DOM of the single profile page you have open, in the same browsing session you're already in. The extension makes zero outbound network requests to linkedin.com from any code path, performs no auto-scroll/auto-pagination/synthetic clicks to force additional content to load, and does not read or capture data from background or inactive tabs.
With your explicit, narrowly-scoped OAuth authorization (the gmail.metadata scope), we access Gmail message headers only — never message body content — to help you track your interaction history with contacts:
We do not read, store, or process message body content, attachments, or snippets. This keeps the requested Google OAuth scope narrow (non-sensitive tier) and keeps the data we hold on your behalf to the minimum needed for interaction tracking. We never send email on your behalf, never modify or delete your Gmail data, and never access Gmail data outside the specific threads relevant to contacts you are actively tracking.
All data described in Section 1 is collected for one purpose: to power the core CRM functionality of the Service — letting you tag, annotate, and track professional contacts you encounter on LinkedIn and correspond with over Gmail, in a sidebar next to the page you're already viewing.
We do not use your data to train third-party AI models, do not use it for advertising, and do not use it for any purpose beyond delivering and improving the Service you signed up for and billing you for your subscription tier.
Regardless of your location, you may exercise the following rights by contacting us at mini-crm@jack-killsone.com:
If you are in the EU/EEA, UK, or California, you have specific statutory rights under GDPR or CCPA/CPRA respectively (right to know, delete, correct, and opt out of sale/sharing — noting we do not sell or share data, so this right is satisfied by default). We will respond to verified requests within the legally required timeline (30 days under GDPR, extendable once; 45 days under CCPA, extendable once).
We share data only with the following categories of service providers (subprocessors), each bound by a data processing agreement limiting their use of your data to providing their service to us.
| Third Party | Purpose | Data Shared |
|---|---|---|
| Stripe | Subscription billing and payment processing | Your email address and billing/subscription status are sent to Stripe to create and manage your subscription. Stripe collects your payment card details directly (we never receive, transmit, or store your full card number, CVV, or bank account details). Stripe acts as an independent data controller for its own payment-processing and fraud-prevention obligations under its own privacy policy (see stripe.com/privacy). |
| Hosting provider | Backend infrastructure and database hosting | All account and contact/interaction data described in Section 1, as needed to run the Service. Backend/database: Railway (United States). Public website/privacy policy pages: Cloudflare Pages. |
| Google APIs | OAuth sign-in and read-only Gmail metadata access to power interaction tracking | OAuth token exchange and Gmail metadata API requests scoped to the gmail.metadata non-sensitive tier. Gmail content is read directly by our backend/extension under your authorization and is not shared with Google beyond the standard API request itself. |
We do not sell your personal data. We do not share your data with data brokers or advertisers. No analytics, advertising, or marketing subprocessor is currently in use.
We never share your data with LinkedIn. The extension reads publicly-visible-to-you profile data locally in your browser; we do not report your usage, notes, or tags back to LinkedIn, and LinkedIn has no access to our backend or database.
We may disclose data if required by law, subpoena, or valid legal process, or to protect the rights, safety, or property of our users or the Service.
The Service is not directed at, and we do not knowingly collect data from, individuals under 16. If we learn we have collected data from a child under 16, we will delete it.
We apply industry-standard technical and organizational measures — encryption in transit and at rest, access controls limiting who can view production data, and least-privilege API scopes — to protect your data. No system is perfectly secure; if a breach occurs that affects your data, we will notify affected users without undue delay, consistent with applicable law.
We may update this Privacy Policy as the Service evolves. Material changes will be notified via the extension or email to your account address at least 14 days before taking effect. The "Last Updated" date at the top of this document reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
For any privacy question, data subject request, or concern:
Email: mini-crm@jack-killsone.com
Location: Wrocław, Poland.
If you are in the EU/EEA or UK and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.