← Back to home

Privacy Policy

Last updated: June 2026

This policy describes how NetworkFlow ("we", "us") handles information when you use our web dashboard and Chrome extension.

What NetworkFlow is

NetworkFlow is a personal networking CRM — a notebook for tracking outreach, notes, and follow-ups. It is not affiliated with, endorsed by, or sponsored by LinkedIn.

Data you provide

When you sign in with Google or a magic link, we receive your email address and name through our authentication provider (Supabase Auth).

In Settings, you may optionally add profile fields — school, major, graduation year, current role, and bio. These help personalize AI-generated outreach messages.

LinkedIn data the extension reads

The Chrome extension reads only visible information on linkedin.com/in/* profile pages you are already viewing. It does not crawl connections, bulk-export profiles, or access pages you have not opened.

When you save a contact, we store: name, headline, company, role, school, location, profile image URL, and LinkedIn profile URL.

What we store

Your data is stored in Supabase (PostgreSQL). Each account can access only its own contacts, notes, pipeline stage, tags, generated messages, and activity history.

Generated messages are saved so you can reference past outreach. They are never sent to LinkedIn on your behalf.

Authentication and local storage

The web dashboard uses session cookies to keep you signed in.

To sync with the Chrome extension, you click Connect extension on the web app. Only your access token is shared with the extension at that moment — not your password or Google credentials.

The extension keeps your session in Chrome session storage, which is cleared when you fully close the browser. You may need to connect again after a restart or when the session expires.

What we do not do

NetworkFlow never auto-connects with people on LinkedIn, auto-sends messages, auto-fills LinkedIn forms, bulk-exports connections, or scrapes LinkedIn search results.

All outreach is copy-to-clipboard only — you paste and send messages yourself.

AI processing

The Generate Next Step feature sends your contact context and optional profile fields to OpenAI to draft a message. Usage is rate-limited.

AI output is shown in the app and copied to your clipboard. It is not transmitted to LinkedIn.

Analytics

When enabled, we use PostHog for product analytics — page views, key actions such as saving a contact or generating a message, and error reports to improve reliability. PostHog may associate events with your account email.

Analytics run on the web dashboard only; the Chrome extension does not send analytics events.

Third-party services

We use Supabase (authentication and database), Vercel (web hosting), OpenAI (message generation), Google (OAuth sign-in), and PostHog (analytics, when enabled). Each provider processes data according to their own privacy policies.

Data retention and deletion

You can delete individual contacts from the web dashboard at any time. Deleting a contact removes its notes and related records.

During beta, full account deletion is available on request — contact us using the support channel on our Chrome Web Store developer profile.

Changes to this policy

We may update this page as the product changes. The last updated date at the top reflects the most recent revision.

Contact

For privacy questions or account deletion requests, use the support contact listed on our Chrome Web Store listing.