1. Scope and responsibility
This policy applies to the LinkAvro website, authenticated web application, and optional browser helper. LinkAvro determines why and how account and workspace information is processed. Customers are responsible for having an appropriate basis to upload and use information about their prospects and recipients.
LinkAvro is an independent product and is not affiliated with or endorsed by LinkedIn Corporation. It does not ask you to type or upload your LinkedIn password. If you deliberately connect the official LinkAvro browser extension, the extension reads the currently signed-in LinkedIn session only for that connection request and sends it directly to the authenticated LinkAvro backend over HTTPS; it does not expose the raw values to the portal page. LinkAvro does not access private inbox content. If you deliberately choose Sync my connections, the local connector reads and transmits the public names, headlines, and profile URLs shown in your LinkedIn connections directory so that the list can be searched in your workspace.
2. Information LinkAvro collects
- Account information: name, email address, authentication provider, verification state, and account ID.
- Workspace content: profile URLs, names, professional details, email addresses you supply, tags, notes, message drafts, schedules, campaign settings, and outcomes.
- Service and security data: feature usage, quota counters, errors, provider event identifiers, delivery status, suppression records, and technical logs needed to protect and operate the service.
- Optional website analytics: if you choose to allow analytics in the public-site preference banner, Google Analytics receives aggregate page views, referrers, device information, and interaction events. LinkAvro does not send LinkedIn cookies, workspace content, or authentication values to Analytics. You can change this choice with the Analytics settings button.
- Billing information: subscription status, billing interval, customer and transaction identifiers, and billing contact details. Paddle handles payment-card data when billing is enabled.
- Browser-helper information: the public URL and display name of the LinkedIn profile you deliberately connect, public profile URLs selected for a campaign you approve, an optional invitation note or direct-message body you supply, action status and safety outcomes, a random local connector installation identifier, and the connector version. When connection-directory sync is enabled, LinkAvro receives the public names, headlines, and profile URLs shown in your LinkedIn connections directory. When desktop analytics sync is enabled, LinkAvro also receives the connection-count snapshot and a one-way fingerprint plus participant name or public profile URL for unread conversations that may match verified LinkAvro outreach. Message previews and conversation bodies are used only locally to create the fingerprint and are not uploaded. The browser extension and Windows desktop connector do not ask you to provide passwords or private message content. The official browser extension may read the `li_at` and `JSESSIONID` session cookies only for an explicit connection or verified refresh, sends them directly to the authenticated backend over HTTPS, and keeps the raw values out of the page, extension storage, logs, analytics, and AI prompts. Server storage contains only encrypted credential envelopes. When the local invite-page launcher is enabled, the extension sends a temporary random launcher token and the selected public vanity slug only to the same-computer 127.0.0.1 listener so it can open the next page after a new invitation confirmation. This handoff is not sent to LinkAvro or LinkedIn.
- Provider authorization information: when the LinkedIn-approved OAuth connection is enabled, LinkAvro stores the provider member identifier, granted permission scopes, token expiration times, and encrypted access or refresh tokens. Tokens remain in a server-only collection and are deleted when you revoke the connection.
Do not upload passwords, authentication codes, government IDs, financial account details, health information, or other sensitive personal data. LinkAvro is not designed for those categories.
3. How information is used
LinkAvro uses information to:
- create and secure your account and private workspace;
- normalize lists, prevent duplicates, prepare drafts, and manage review queues;
- apply limits, suppressions, sender checks, and other safety controls;
- process subscriptions and provide billing support when billing is enabled;
- diagnose errors, prevent abuse, and improve reliability; and
- meet legal obligations and enforce responsible-use terms.
Depending on applicable law and context, processing may rely on performing the service you request, legitimate operational and security interests, consent, or compliance with legal obligations.
Chrome Web Store Limited Use
LinkAvro's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Browser-helper data is used only to provide and secure the user-facing LinkedIn account connection, optional connections-directory sync, analytics, and approved outreach workflow described above. LinkAvro does not sell this data or use it for personalized advertising.
5. Retention and security
Account and workspace information is retained while your account is active and as reasonably needed to provide the service. Some billing, security, suppression, and legal records may be retained longer where necessary to prevent abuse, resolve disputes, or meet legal obligations. Provider backups and logs may take additional time to expire under provider retention schedules.
LinkAvro uses verified authentication, user-scoped database rules, server-controlled entitlements, restricted provider fields, and encrypted network connections. LinkedIn browser-session values are encrypted with application-layer AES-GCM and Cloud KMS before they are stored in a server-only collection; the active version is the only one used for processing. Raw values are excluded from browser storage, logs, analytics, and AI prompts. No internet service can guarantee absolute security. Report suspected unauthorized access promptly.
6. Your choices and privacy rights
You can correct core profile information in your account and export saved people from the People page. Depending on where you live, you may also request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on consent. LinkAvro may verify your identity before completing a request and may retain information where legally permitted or required.
Account deletion is not yet an instant self-service action. Use the secure form below while signed in to submit a verified request. You may also complain to the privacy or data-protection authority where you live.
7. Children
LinkAvro is a business service and is not directed to children under 18. It does not knowingly collect information from children.
8. Changes to this policy
Material changes will be posted on this page with a revised date. Where appropriate, LinkAvro will also provide an in-product notice before a change takes effect.
9. Contact
Submit access, correction, export, restriction, or deletion requests through this verified-account form. Do not include passwords, authentication codes, or identity documents.