Legal

Privacy Policy

Last updated 30 July 2026

This Privacy Policy explains how Riffla (“Riffla”, “we”, “us”) collects, uses and protects information when you use the Riffla browser extension, dashboard and Smart Search (together, the “Service”). Riffla is used by teams in Australia, the UK, the European Economic Area (EEA), the US, Canada and elsewhere, and for the purposes of the UK GDPR and EU GDPR, Riffla is the data controller of the personal information described below.

1. Chrome Web Store Limited Use disclosure

Riffla's use of information received from the Riffla Chrome extension, and from Google APIs, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:

  • We use the data the extension collects only to provide and improve the extension's single purpose: capturing a LinkedIn profile as a lead, finding that lead's business contact details, drafting outreach for you to review, and syncing the lead to the CRM you have connected.
  • We do not use or transfer this data for personalised advertising, and we do not serve advertising in the extension.
  • We do not sell this data, and we do not transfer it to data brokers, information resellers, or advertising platforms.
  • We do not use or transfer this data to determine creditworthiness or for lending purposes.
  • We do not collect your web browsing activity. Riffla reads page content on linkedin.com only, and it does not record, monitor, or transmit the other websites you visit — see “Where the extension runs” below.
  • We do not allow humans to read this data, except: where you have given us explicit consent (for example, when you ask our support team to look into a problem with a specific lead); where the data has been aggregated and anonymised for internal operations; where it is necessary for security purposes such as investigating abuse; or where we are required to do so by law.
  • Where we send data to a service provider so that we can deliver a feature you asked for — for example, sending a lead's name and employer to a business-data provider when you click “Find email”, or sending profile details to a language model when you click “Generate” — that transfer is limited to what the feature requires, is triggered by your action, and is governed by contracts that prohibit the provider from using the data for their own purposes.

2. The Riffla browser extension

This section describes the Riffla Chrome extension specifically. It is deliberately written to match, one for one, the data disclosures on our Chrome Web Store listing.

Where the extension runs

Riffla is a side panel you open yourself, plus a small launcher button that appears on LinkedIn. It reads page content on linkedin.com only — capture works on LinkedIn member profile pages (addresses of the form linkedin.com/in/…), and the launcher is shown on no other site. Riffla's helper script is registered to load alongside pages you open so the launcher can appear the moment you reach a LinkedIn profile; anywhere other than linkedin.com it stays inactive — no launcher appears, no page content is read, and nothing is sent to us.

The extension is permitted to send your data to exactly one server: our own API at api.riffla.com, over HTTPS. It has no permission to send it anywhere else. Two other connections are made by your browser rather than by us — if you choose “Continue with Google”, your browser talks to Google's own sign-in service, and the profile photo shown in the panel loads from LinkedIn's image servers, exactly as it does on the page you are looking at.

What it reads, and when

When you open the Riffla panel on a LinkedIn member profile and ask it to read that profile, the extension reads the public professional information already rendered on that page in your own logged-in session: the person's name, headline, location, profile photo URL, summary, current and previous roles, education, certifications, languages, volunteering and listed skills, together with the profile's URL.

It reads this only for the profile you are looking at, only while you have the panel open on it, and only as a result of something you did. There is no background collection, no bulk extraction, and no queue.

The extension never asks for, receives, or stores your LinkedIn password, and does not interact with your LinkedIn account beyond reading the page you have open. It cannot send messages, send connection requests, or take any other action on LinkedIn on your behalf.

What it sends to us

  • Account and authentication data — your email address and password when you sign in or register, or a Google ID token if you use “Continue with Google”. The resulting sign-in tokens are stored locally on your machine in the browser's extension storage, where no web page can read them.
  • Captured lead data — the profile information described above, when you choose to save or enrich a lead.
  • Enrichment requests — when you click “Find email” or “Reveal mobile”, we receive that request and our servers query business-data providers to resolve the lead's business contact details.
  • AI drafting requests — when you click “Generate”, the captured profile details and the options you chose (objective, tone, length, call to action) are sent to our servers and passed to a language model, which returns a draft for you to review and edit. Drafts are suggestions and may be inaccurate; you are responsible for what you ultimately send.
  • Outreach you log — if you log a message against a lead, for example syncing it to your CRM as an activity, the text you settled on is sent to our API and written to the lead's record and to the CRM you connected. Treat anything you log as retained — see “Data retention” below.
  • CRM sync — when you click “Sync”, the lead fields you selected are sent to the CRM or ATS you connected. We also read back the minimum fields needed to detect duplicates before you capture: whether a matching record already exists, how confident that match is, and when it was last contacted.
  • Usage and diagnostics — our servers record the requests the extension makes (which action, when, from which account and the originating IP) so we can operate the Service, apply your credit balance and investigate faults. The extension contains no analytics or telemetry code of its own: it sends no page views, click streams, session recordings or heatmaps, and the analytics tools described in “Cookies & analytics” below run on our website only, never in the extension.

What it does not collect

  • Your browsing history, or any record of the websites you visit.
  • The content of any website other than the LinkedIn page you have open.
  • Keystrokes, mouse movement, form contents, or screen recordings.
  • Any profile, lead or contact data while you are signed out — capture, enrichment, drafting and sync all require you to be signed in.

Stored on your own device

Your sign-in tokens, your panel settings, your last-used message options, and a cached copy of the configuration that tells the extension which parts of a LinkedIn page to read are kept in the browser's local extension storage on your own device. Signing out clears your sign-in tokens. Uninstalling the extension removes all of it.

Your choices

Uninstalling the extension stops all collection by it immediately. To have data already held in your Riffla account deleted, email support@riffla.com and we will action it within 30 days.

3. Information we collect

  • Account information — name, work email, company name and password (hashed, never stored in plain text), or your Google account details if you sign in with Google.
  • Usage data — actions you take in the dashboard (leads captured, searches run, integrations connected), browser type, IP address and timestamps, collected automatically to operate and improve the Service.
  • Leads you capture — when you use the extension to capture a profile, the details already visible on that page (name, title, company and similar) are sent to your account and stored as a lead.
  • Enrichment results — when you request enrichment or run a Smart Search, we return verified contact details (such as a work email or direct dial) together with a confidence score.
  • Connected CRM/ATS data — when you connect a CRM or ATS, we access and sync the fields needed for lead creation, field mapping and duplicate detection, as configured by you.
  • Cookies & similar technologies — see “Cookies & analytics” below.

4. How we use information

  • Provide, secure and maintain the Service, including authentication, sessions, credits and support.
  • Run enrichment and Smart Search requests and return verified results.
  • Sync leads to your connected CRM/ATS according to the mapping rules you set.
  • Generate AI-drafted outreach messages you request, using the profile details you capture and the tone, objective and call to action you choose.
  • Communicate with you — service messages, support replies and, if you opt in, product updates.
  • Monitor, debug and improve the Service, including through error tracking and product analytics.
  • Enforce our Terms of Service and prevent abuse.

7. CRM & ATS integrations

Connecting JobAdder, Bullhorn, Vincere or a custom API integration requires you to authorize access, typically via OAuth. We store the access/refresh tokens needed to sync on your behalf and the field-mapping and sync-rule presets you configure. We only push the lead data you choose to sync, and only pull the fields needed for duplicate detection. Disconnecting an integration revokes our stored access — see “Data retention” below for what happens to records already synced.

8. Cookies & analytics

  • Essential — sign-in session cookies keep you logged in. We also store your last-used login email in your browser (not on our servers) purely to prefill the login form.
  • Analytics — where required, with your consent, we use Google Analytics and Microsoft Clarity to understand aggregate usage (pages viewed, session recordings/heatmaps, general traffic sources) so we can improve the product. These providers may set their own cookies; see their respective privacy policies for details.
  • Error tracking — if something breaks, we send a diagnostic report (the error, the page and your account ID/email if you're signed in) to our error-tracking provider so we can fix it. Lead and enrichment data is never included in these reports.

9. How we share information

We don't sell your personal information or your leads. We share information with: the CRM/ATS you explicitly connect; infrastructure and sub-processors that host, monitor or secure the Service (hosting, error tracking, analytics, email delivery), each bound to protect it; professional advisors or a successor entity in the event of a merger or acquisition; and authorities where required by law.

10. Data retention

We keep account and lead data for as long as your account is active, plus a reasonable period afterward to meet legal, accounting or dispute-resolution needs. You can request deletion of your account and associated data at any time — see “Your rights & choices” below; some records may be retained longer where the law requires it.

11. Security

Passwords are hashed, never stored in plain text. Data in transit is encrypted over HTTPS, and CRM/OAuth tokens are stored server-side, never exposed to the browser. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

12. Your rights & choices

You can update your account details from the dashboard, disconnect a CRM at any time, and reach us at support@riffla.com for anything else, including deletion requests.

  • If you're in the UK or the EEA (UK GDPR / EU GDPR) — you have the right to access, correct, erase or port your personal information, restrict or object to certain processing, and withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
  • If you're in Australia (Privacy Act 1988) — you have the right to access and correct the personal information we hold about you, and to complain, including to the Office of the Australian Information Commissioner (OAIC), if you believe we've mishandled it.
  • Wherever you're based — we extend the same access, correction and deletion rights on request, whether or not local law strictly requires it.

13. International data transfers

Riffla is used by teams across Australia, the UK, the EEA, the US, Canada and elsewhere. Where we transfer personal information out of the UK or the EEA — for example, to host or process it in Australia — we rely on recognised safeguards such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses, or an applicable adequacy decision. Using the Service means your information may be processed in a country other than your own, with these safeguards in place.

14. Children's privacy

The Service is intended for business use by adults. It is not directed to, and we do not knowingly collect information from, children.

15. Changes to this policy

We'll update the “last updated” date above whenever this policy changes and, for material changes, let you know via the dashboard or email.

16. Contact us

Questions about this policy or your data? Email support@riffla.com or visit our contact page.