Chrome Extension Privacy Policy
Privacy policy for the TalentBrief Chrome Extension
Effective date: 14 April 2026 · Last updated: 14 April 2026
1. Introduction
TalentBrief (“we”, “our”, or “us”) operates the TalentBrief Chrome Extension (“Extension”), a browser extension for importing LinkedIn candidate profiles directly into the TalentBrief recruitment platform. This policy covers the Extension only and describes the data the Extension collects, how it is used, and your rights as a data subject.
This policy does not cover the main TalentBrief platform. For the main platform privacy policy, please visit talentbrief.io/privacy.
We are committed to protecting personal data and processing it in accordance with the General Data Protection Regulation (GDPR) and all applicable data protection legislation.
2. What the Extension Does
The Extension adds an import button to LinkedIn profile pages. When a recruiter clicks the button, the Extension reads the visible profile data from that page and sends it to TalentBrief to create or update a candidate record.
Data extraction is always user-initiated. The Extension does not collect data passively or in the background. No profile data is read, stored, or transmitted unless the user explicitly clicks the Import button on a LinkedIn profile page.
3. Data We Collect
When a user imports a LinkedIn profile, the Extension collects the following categories of data from that profile:
- Name and identity — First name, last name, professional headline, and profile photo URL.
- Professional history — Job titles, company names, employment dates, and role descriptions from the experience section.
- Education — Institution names, degrees, fields of study, and attendance dates.
- Skills — Skill names listed on the profile.
- Languages — Language names and stated proficiency levels.
- Contact information — Email addresses and phone numbers, if they are visible on the LinkedIn profile.
- Location — Country, city, and full location string as shown on the profile.
- Birthday — Day and month, if visible on the LinkedIn profile.
- LinkedIn identifiers — Numeric LinkedIn ID, member ID, public profile slug, and profile URL. These are used for duplicate detection and to link the TalentBrief candidate record back to the original LinkedIn profile.
Only data that is visible on the LinkedIn profile page at the time of import is collected. The Extension does not access private or hidden LinkedIn data.
4. Data We Do NOT Collect
The Extension does not collect:
- Browsing history — The Extension does not record which websites or pages you visit.
- Keystrokes or form inputs — No keyboard activity or form data is monitored or transmitted.
- Profiles you do not explicitly import — Data is only read when you click the Import button. Viewing a LinkedIn profile without importing it does not trigger any data collection.
- LinkedIn credentials or passwords — The Extension does not access or store your LinkedIn username, password, or two-factor authentication codes.
- Personal data about the extension user — The Extension collects candidate profile data only. It does not collect information about the recruiter using the Extension, beyond what is required for authentication with TalentBrief.
- Analytics or telemetry data — The Extension does not send usage metrics, crash reports, or behavioural analytics to any service.
- Cookies stored or transmitted externally — The Extension reads the LinkedIn JSESSIONID cookie locally to authenticate with the LinkedIn Voyager API. This value is used only within the browser session and is never stored persistently or transmitted to TalentBrief or any third party.
5. How We Use Your Data
The Extension uses collected data solely for the following purposes:
- Candidate import — Profile data is sent to TalentBrief servers to create or update a candidate record in the recruiter’s account.
- Duplicate detection — The candidate’s LinkedIn numeric ID is checked against existing records to prevent duplicate entries.
- Authentication — The LinkedIn JSESSIONID cookie is used locally within the browser to call the LinkedIn Voyager API on your behalf. It is never transmitted to TalentBrief or any third party.
- Session state — A boolean indicating whether you are logged into TalentBrief is stored in Chrome extension storage to determine whether to show the login prompt or the import button.
The legal basis for processing is the performance of the contract between you and TalentBrief (Article 6(1)(b) GDPR) and your explicit, user-initiated action to import a candidate profile.
6. Data Storage
Data collected by the Extension is stored in three locations:
| Location | What is stored | Retention |
|---|---|---|
| TalentBrief servers | Imported candidate profile records | Until the user deletes the candidate or closes their account |
| Chrome session storage | Current candidate data being imported, authentication status, import result | Cleared automatically when the browser session ends |
| Chrome local storage | UI preferences only (popover open state, theme preference) — no personal data | Persists until the Extension is uninstalled |
7. Third-Party Data Sharing
Imported candidate data is sent exclusively to TalentBrief’s own servers. It is not shared with any third party.
- No analytics services receive candidate data.
- No advertising networks receive any data from the Extension.
- No data brokers or third-party enrichment services are used.
- Candidate data is not sold, rented, traded, or shared for any commercial purpose.
8. Extension Permissions
The Extension requests the following browser permissions. Each permission is required for the Extension to function and is used only for the stated purpose:
| Permission | Why it is needed |
|---|---|
cookies | Reads the LinkedIn JSESSIONID cookie to authenticate with the LinkedIn Voyager API, and reads TalentBrief cookies to determine your login status. The cookie value is never stored persistently, exported, or shared. |
tabs | Detects when you navigate to a LinkedIn profile page to activate the import button, and opens a TalentBrief tab when you need to log in. |
storage | Persists UI preferences (popover state, theme) and temporary session data between page navigations. |
activeTab | Reads the current tab URL to identify which LinkedIn profile is being viewed and whether to display the import button. |
Host permission: linkedin.com | Injects the import button into LinkedIn profile pages and fetches profile data from the LinkedIn Voyager API on behalf of the logged-in user. |
Host permission: talentbrief.io | Sends imported candidate data to the TalentBrief API and checks your authentication status and whether a candidate already exists. |
9. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights with respect to candidate data imported through the Extension:
- Right of access (Article 15) — You may request a copy of the personal data we hold.
- Right to rectification (Article 16) — You may request correction of inaccurate personal data.
- Right to erasure (Article 17) — You may delete an imported candidate directly from your TalentBrief account, or request full account deletion by contacting us. We will process erasure requests within 30 days.
- Right to restrict processing (Article 18) — You may request that we limit how we process candidate data in certain circumstances.
- Right to data portability (Article 20) — You may request candidate data in a structured, machine-readable format.
- Right to object (Article 21) — You may object to processing based on our legitimate interests.
Uninstalling the Extension removes all locally stored data (Chrome session storage and local storage) immediately. Candidate records stored on TalentBrief servers persist until you delete them from your account or request account deletion.
To exercise any of these rights, please contact us at support@talentbrief.io. We will respond within 30 days. If you believe your rights have not been respected, you have the right to lodge a complaint with your local supervisory authority.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Extension’s functionality or for legal, operational, or regulatory reasons. When we make changes, we will update the “Last updated” date at the top of this page. Where changes are material, we will notify users via a prominent notice in the Extension or via email. Continued use of the Extension after the effective date of any change constitutes your acceptance of the updated policy.
11. Contact
If you have questions, concerns, or requests relating to this Privacy Policy or data collected by the TalentBrief Chrome Extension, please contact us:
Email: support@talentbrief.io
For the main TalentBrief platform privacy policy, please visit talentbrief.io/privacy.