Privacy policy

What LinkedSpark reads, sends, and stores.

Last updated September 5, 2026

LinkedSpark is a Chrome extension that helps you draft LinkedIn outreach content — comments, replies, connection notes, and messages — using AI. You always send, post, like, or connect yourself; LinkedSpark never takes a final action on LinkedIn on its own. This page explains what data LinkedSpark reads, what it sends elsewhere, what it stores, and how to delete it.

What LinkedSpark reads from LinkedIn

While you're browsing LinkedIn with the extension enabled, LinkedSpark's content script reads text that's already visible to you on the page, to detect things it can help draft a response to:

  • Post and comment text on pages you visit, and on your own posts specifically
  • Commenter names and their comments, when checking for replies to your own posts
  • Notification text (birthdays, work anniversaries, promotions, new roles, comments on your posts, and — for reshare-target and keyword-match detection — "X posted:" previews, which LinkedIn itself truncates for longer posts)
  • Message previews and sender names in your Messaging inbox, for messages already marked unread
  • Search results pages you visit: post text and author names (same reshare-target and keyword-match detection as above), and people results' visible name and headline (for connection matching against your configured target list) — only from searches you ran yourself, never one LinkedSpark runs on your behalf
  • Profile text (About/Experience/headline) on a profile page you visit, when checking whether that person matches your connection targets or is eligible for a recommendation draft

LinkedSpark's own automatic background scanning never opens a page, thread, or post you haven't already navigated to yourself — everything above is read from whatever's already rendered on the page you're currently viewing. The only things that read more than a preview — opening an InMail thread, or opening a post's own page to read its full text — only ever happen as the direct result of a button you clicked; they never run during passive scanning.

InMail messages are a special case: LinkedIn's conversation list only shows an InMail's subject line, not its content. If you turn on the optional "Open InMail threads to draft from the full message" setting (off by default), approving an InMail item in your Review Queue opens that specific thread to read the real message before drafting. Opening the thread does mark it read on LinkedIn's side, the same as if you'd opened it yourself; LinkedSpark offers a one-click way to open LinkedIn's own "mark as unread" menu afterward, but LinkedIn's mutual read-receipt indicator (if you have it turned on) cannot be undone once the thread has been opened.

Reshare and keyword-match replies work the same way: the initial match runs against the notification preview only, but drafting the actual caption or comment happens after you approve the item, when LinkedSpark opens the post's own page to read its full, untruncated text — again, only as the result of your Approve click, never during background scanning.

LinkedSpark does not read your LinkedIn password, payment details, or private account settings.

What gets sent to our servers, and to Anthropic / OpenAI

When you (or an automatic detection you've enabled in Settings) trigger a draft, the relevant text — e.g. a post's content, a comment, a message, your notes for a recommendation — is sent to our backend (hosted on Supabase) and from there to Anthropic's Claude API, solely to generate a draft reply. This includes, depending on which features you've enabled:

  • Post/comment text and commenter names (comment-reply, reshare, and keyword-match drafting) — the full post text once you approve the item, not just the notification preview it was detected from
  • Message text and sender first names from your unread Messaging inbox (DM reply drafting) — only sent if you've enabled "Direct message replies" in Settings, off by default. For InMail specifically, only the subject line is used unless you've also enabled full-message drafting
  • Profile text and notes you provide (connection notes, recommendations)
  • Draft rewrites: if you use a "Shorter" / "Warmer" / "More formal" button on a queued draft, the current text in that draft box (including any edits you've made) is sent to regenerate it in that style
  • Follow-up nudges, if enabled (off by default): the message-list preview of your own last message in a conversation, and your contact's first name, are sent to draft a follow-up — only for conversations you sent the last message in and haven't heard back on in 5+ days
  • Voice notes, if you've filled them in: free-text notes about your writing style, sent as context alongside every draft request so responses sound more like you. Entirely optional and off by default
  • Post images (Pro plan): if you use the image-generation feature on a post idea, the prompt text describing the desired image is sent to OpenAI's image API solely to generate that one image

None of this data is used to train any AI model, and none of it is sold or shared with anyone besides Anthropic (for text drafting), OpenAI (for Pro image generation, only when you use that feature), and our own backend infrastructure (Supabase, for your account and the drafts feature itself).

What gets stored, and where

  • Your account: your email address, used for passwordless sign-in via a one-time code or magic link (managed by Supabase Auth). LinkedSpark never asks for or stores a password.
  • Your settings: tier lists, templates, reshare/connect/keyword targets, voice notes, and feature toggles — stored both locally (chrome.storage.local) and synced to your Supabase account so they follow you across devices.
  • Review Queue items: drafted text and a short excerpt of the source content (e.g. a comment snippet), stored locally only, until you approve or skip them (capped at the 30 most recent).
  • A daily usage counter: how many drafts (and, on Pro, images) you've requested today, stored server-side, purely to enforce your plan's usage cap — no draft content is kept in this counter.
  • Activity log: a local record of actions you've taken through the Review Queue (sent, skipped, liked), kept for 30 days, used only to show you your own recent activity.
  • Billing information, once billing is live: subscription status and plan tier only. Card details are handled entirely by Stripe — LinkedSpark and Supabase never see or store your card number.

Draft request text itself is not retained after the AI response is generated and returned to you — LinkedSpark's backend doesn't log or store the post/comment/message content it processes, beyond what's listed above (the Review Queue item, until you act on it).

How to delete your data

Signing out and uninstalling the extension removes everything stored locally. To delete your account and its synced settings and activity log from our servers, email hello@linkedspark.app from the address on your account — we'll confirm and delete it within 30 days. There is no self-serve delete button in the extension yet; if that changes, this page will be updated to reflect it.

Your control over every feature

Every automatic-detection feature (comment replies, direct message replies, InMail full-content drafting, follow-up nudges) is off by default and must be explicitly turned on in Settings. Even when on, LinkedSpark only ever drafts — it copies a draft to your clipboard or types it into LinkedIn's own compose box for you to review, edit, and send yourself. It never clicks Send, Post, Like, or Connect on your behalf, and it never opens a page, thread, or post you haven't either navigated to yourself or approved LinkedSpark opening on your behalf via the Review Queue.

Changes to this policy

We'll update this page whenever our data practices change, and update the date at the top when we do. Material changes (a new third party we send data to, a new category of data we read) will also be reflected in the extension's own release notes.

Contact

Questions about this policy or your data: hello@linkedspark.app