Privacy
Effective July 31, 2026
Referral Assistant is an independent, personal-use browser extension and companion web app. It is not affiliated with LinkedIn. This notice describes the data the current production version uses.
Data kept in your browser
- Your message templates, referral contacts, recent job handoffs, LinkedIn Premium preference, queue state, and retry state.
- Optional AI settings. If you choose Claude, your API key is stored in your Chrome profile and is not sent to this app's server.
Account-scoped browser data is separated by the signed-in account. Uninstalling the extension or clearing site/extension storage removes the corresponding local copy.
Data stored by the companion service
- A random extension installation ID, first/last activity time, app version-independent usage counters, quota counters, and idempotency records used to enforce daily and weekly limits.
- If you sign in: your Auth0 account ID, verified email, plan, role, entitlement expiry, and the installation IDs bound to that account.
- If you use a Pro redemption code: a one-way hash of the code, its status and expiry, and the account and time that redeemed it. The complete redemption code is not stored by the service.
- Connect history: displayed LinkedIn name, profile slug and URL, company, pending/accepted status, and timestamps. This is stored so history can follow a signed-in user across devices.
- If you submit a payment claim: your account ID, verified email, an optional short note you type, the claim time, and its status — kept for up to 14 days or until the claim is processed.
- Client IP addresses are used transiently for per-endpoint rate limiting; those records expire automatically within about two hours.
The service does not store connection-note contents, Anthropic API keys, or job-description text. “Assisted note fill” counters record a successful draft fill, not proof that the user clicked Send.
Optional AI processing
Chrome's built-in model runs on the device. If you explicitly enable Claude, bounded visible recipient fields (name, headline, location, About, and recent activity), your “About you” text, and the base note are sent directly from the extension to Anthropic to create one icebreaker. The companion service does not proxy or receive that request. Anthropic's own terms and privacy notice apply.
Retention and deletion
Connect history is capped at 1,000 people per owner and remains until you use History → Clear all or ask for deletion. Short-lived quota and authorization records expire automatically. Redemption codes must be used within 180 days; their hashed audit records are retained for up to about one year. Account, plan, installation, and aggregate usage records currently remain while the service operates so entitlements and abuse controls continue to work.
To request deletion, email jhuang9705@gmail.com from the address on the account. Deletion requests cover your connect history, account record, email index, and payment claims; pseudonymous usage counters and the bounded entitlement audit log may be retained for abuse prevention. A self-service full-account deletion flow is not available in this version.
Sharing and security
Data is used to operate the product, enforce limits, troubleshoot failures, and provide account history. It is not sold. Hosting, authentication, Redis storage, and an AI provider you explicitly choose process data only as needed to provide their respective services. Access secrets are kept server-side and production traffic uses HTTPS.
The extension reads visible LinkedIn pages only for the workflow you initiate. It can open Connect, click Add a note, and fill a draft, but never clicks Send. LinkedIn may restrict browser automation or profile data access under its own terms; use the extension at your own account risk.