Privacy Policy
Last updated: July 23, 2026
Summary
It’s your personal LinkedIn account, so you stay in control of your data. The connections Outscore tracks are stored in your own browser and are never sold or shared with your employer. They leave your machine only when you choose, to a CSV file you download or to your own CRM that you connect. The extension sends us only anonymous, non-content usage data, plus the email address you use at checkout if you buy Outscore Pro, and anything you choose to type into the short form we show if you uninstall (including an email address, only if you want us to reply about it).
What the extension accesses
When you are logged into LinkedIn and trigger a sync, the extension reads publicly-visible information from three pages in your own LinkedIn account:
- Sent invitations page (
linkedin.com/mynetwork/invitation-manager/sent/): names, profile URLs, and the date you sent each connection request. - Connections page (
linkedin.com/mynetwork/invite-connect/connections/): names, profile URLs, headlines, and the date each connection was made. - Received invitations page (
linkedin.com/mynetwork/invitation-manager/received/): names, profile URLs, headlines, and the date of each person-to-person invitation you have received, plus your Accept or Ignore action when you take it. Invitations to follow companies, newsletters, pages, or other non-person entities are excluded; only person-to-person invitations are tracked.
The extension only reads data you can already see yourself when logged in. It does not read your posts, private details, or any data outside these pages. Messages are handled by the pipeline view described in Your messages below: conversation previews already on your screen, and conversations you explicitly choose to add. Nothing else.
Your messages: the pipeline view
When you add a conversation to Outscore, or browse LinkedIn messaging with Outscore installed, Outscore derives your outreach timeline for contacts you track: when you sent the first message, when they first replied, and the date and direction of the latest message. Outscore stores these timestamps and one short preview of the latest message per contact, on your device only. Full conversations are never stored by Outscore. This data appears in your dashboard and in exports you choose to create, and clearing Outscore’s data removes it. It is never sent to Outscore’s servers.
Two reads make this work, both limited to what is already on your screen: the list of conversation previews LinkedIn shows you (read passively; Outscore never opens a conversation), and the full text of a conversation you opened yourself and explicitly added. Outscore never navigates to messaging on its own and never opens a thread in the background.
If you connect a CRM, adding a conversation can also copy its messages into your CRM as activities. The messages travel from your browser to your own CRM. They are never sent to us, never stored on our servers, and never shared with anyone else.
Where your data is stored
- Locally, on your device.Your tracked connections are stored in your browser’s IndexedDB and
chrome.storage.local. - Your tracked LinkedIn connection data is never sent to the developer’s servers.Names, companies, notes, and connection history stay on your device unless you choose to send them (see “When your data leaves your browser” below).
- No tracking of your browsing. The extension reports home only an anonymous health ping and anonymous usage counts, both described below, and never your LinkedIn content.
When your data leaves your browser (only when you choose)
- CSV export (Pro):clicking Export saves a CSV to your computer via Chrome’s download manager. It is not transmitted to us.
- CRM sync (Pro): if you connect a CRM (HubSpot), you choose exactly which connections and fields to send, and those contacts are written directly from your browser to your own CRM account, not through our servers. If a connection you track shared contact details in their LinkedIn Contact info (email address, phone number, birthday, or the date you connected), Outscore can read them (they are visible to you because your connection chose to share them with you) and include them when you push that contact. They are never looked up or guessed from outside databases, and like every pushed field they travel only from your browser to your CRM, never to us. To make this work our backend brokers the connection: it stores your CRM’s authorization (an encrypted refresh token) and issues your browser short-lived access tokens. You authorize the CRM on the provider’s own consent screen, so we never see or store your CRM password. Disconnecting revokes the authorization and deletes the stored tokens.
- CRM dashboard summaries (Pro): when a CRM is connected, the extension also sends anonymous summaries of your outreach (counts and rates such as total requests sent, acceptance rate, and how many are still pending) to our backend, so they can appear on your dashboard inside your CRM. These summaries contain no names and no contact details. Your contacts stay in your browser and reach your CRM only when you choose to push them.
Anonymous health ping and usage counts
The extension sends a small diagnostic ping to our backend when it is installed or updated, and after each sync. The ping contains only counts and status labels: the random per-install identifier (a UUID generated in your browser, not derived from you or your accounts), the extension version, whether each LinkedIn page could be read and how the sync ended, how many list entries each page showed versus how many were read, how long the sync took, a coarse score band, and aggregate outreach tallies (how many of your invitations are currently accepted, pending, or declined). Counts only, never who: the ping carries no names, no profile URLs, and no message content.
The extension also sends anonymous product-usage events, feature counts such as “connected a CRM” or “pushed N contacts,” tied to the same anonymous install identifier. These contain no contact data and nothing you typed; we use them only to understand which features are used.
We use this to know when a LinkedIn interface change has broken syncing so we can ship a fix quickly, and the outreach tallies let us spot a tracking bug (for example, statuses flipping when they should not) across all installs the same day it ships. The ping never includes LinkedIn data, names, profile information, your email, browsing history, or anything you typed, and the identifier is not linked to your identity. To have your install record deleted, use the contact form.
Website analytics
This website (connectiontracker.org, not the extension) uses Google Analytics to understand how visitors find us. Unless you allow cookies in the banner, analytics runs in cookieless mode and we receive only anonymous, aggregated counts. The extension itself contains no Google Analytics and no tracking of any kind beyond the health ping described above.
Data export
You may export your tracked data as a CSV file at any time via the extension popup. The CSV is saved directly to your computer by Chrome’s download manager. It is not transmitted anywhere.
Data deletion
To delete all local data, uninstall the extension or clear the extension’s site data via chrome://extensions→ Details → “Extension options” / site data controls. All local data will be removed.
To delete your license or anonymous install record from our backend, use the contact form and we’ll remove your email and associated records from our database. If you hold a paid license, this also revokes the license. Request a refund first if you want your money back.
Your privacy rights
You can ask us what personal data we hold about you, ask for a copy, or ask us to delete it. Because of how Outscore is built, the answer is usually short: the only personal data we hold is the email address you gave at checkout (if you bought Pro), an anonymous per-install identifier with feature-usage counts, and anything you sent us through the contact or feedback form.
Your tracked LinkedIn data is not ours to hand over or delete. It lives in your own browser, and in your own CRM if you chose to push it there. We never receive a copy. You can export it yourself to CSV from the extension at any time, and remove it entirely by uninstalling the extension.
To make a request, use the contact form. We accept requests sent any other way too. We will verify your request against the email address on file before acting, so that nobody can use a request to reach someone else’s data. We acknowledge within 5 business days and complete within 30 days, usually much sooner. If deleting your records would revoke a paid license, we will tell you before we do it so you can request a refund first.
If you are a person whose details were added to someone else’s CRM using Outscore, that CRM account holder controls that data, not us, and the request needs to go to them. We hold no copy of it and cannot delete it on their behalf, though we are happy to help them action it.
License data
Outscore is free to use. If you buy Outscore Pro, checkout is handled by Lemon Squeezy and the email you provide there is stored together with a per-install identifier (a random UUID generated in your browser) so we can deliver and validate your license key and reply to support requests you initiate.
We do not send newsletters, marketing email, or any other communication to this address, and your connection data and LinkedIn activity are never sent to us.
Permissions explained
storage: Save your tracked connections locally in your browser.downloads: Save CSV exports to your computer when you click Export.alarms: Schedule automatic background syncs at your chosen interval.tabs: Open LinkedIn’s sent-invitations, connections, and received-invitations pages during a sync, then close them when done.identity: Run the OAuth flow to connect your own CRM (HubSpot). Opens the provider’s official consent screen; the extension never sees your CRM password.- Access to
linkedin.com: Required so the extension can read the sent-invitations, connections, and received-invitations pages on your behalf. - Access to
api.hubapi.com: When you connect HubSpot and choose to sync, write the connections you selected into your own HubSpot account, from your browser.
Third parties
The extension does not use any analytics SDKs, advertising networks, or tracking pixels. Your tracked LinkedIn connection data is never sent to the developer’s servers; it only goes to a destination you choose (a CSV file, or your own CRM).
The following third-party services are used for operational purposes only, and receive only the data described below:
- Lemon Squeezy: processes your payment and issues license keys. Lemon Squeezy is the merchant of record and has its own privacy policy. Receives your email and payment details at checkout.
- HubSpot: the CRM you optionally connect. When you sync, the connections you selected are written from your browser into your own HubSpot account. You authorize HubSpot via OAuth on its own consent screen, and you can disconnect at any time.
- Neon: hosts the PostgreSQL database that stores license records, anonymous install/usage records, and the encrypted CRM authorization. Data is held in the United States.
- Vercel: hosts the website and the backend API routes that activate license keys, record anonymous usage events, receive Lemon Squeezy payment webhooks, and broker the CRM OAuth connection. Receives the same request payloads that Neon stores.
- Web3Forms: delivers messages submitted through the extension’s in-app feedback form and the website’s access-request and contact forms to the developer’s inbox. Receives only what you type into those forms (the message text and, optionally, the name/email you enter). We do not submit any form data on your behalf. It only fires when you click Send.
Children
The extension is not directed at children under 13 and does not knowingly collect data from anyone.
Changes
If this policy changes, the updated version will be published at the same URL with a new “Last updated” date.
Contact
Questions? Use the contact form and we’ll reply by email.