Kolvera Chrome Extension — Privacy Policy

Last updated: 18 August 2026

This policy covers the Kolvera — LinkedIn Prospect & Candidate Finder Chrome extension (the “Extension”). The Extension is published and operated by Zionic Group Pty Ltd (ABN 51 689 146 861), a company registered in Australia, trading as Kolvera. Zionic Group Pty Ltd is the data controller for the information described below. Personal information you save into your Kolvera workspace is additionally governed by Kolvera’s main Privacy Policy.

1. Single purpose

The Extension has one purpose: to let a signed-in Kolvera user capture professional profile and conversation data from LinkedIn, Sales Navigator and LinkedIn Recruiter into that user’s own Kolvera workspace, and to manage their hot lists and candidate pipelines from the browser side panel. Every data practice described below exists to serve that purpose.

2. What we collect

2.1 Authentication data

We never collect, receive, or store your LinkedIn username, password, or LinkedIn session cookies. The Extension operates inside your own, already-signed-in LinkedIn session.

2.2 Professional profile and company data

When you save a profile, run a capture, or open a page the Extension is configured to sync, it collects the professional information shown on that page: name, headline, job title, current and past employer, location, public profile URL, profile photo URL, skills, education, and company details such as name, size, industry and website. This is business-context information about professionals and employers, collected so that it can be filed in your workspace. It is read from the page you are viewing and, on some LinkedIn surfaces, from the responses LinkedIn’s own API returns to your browser for that page — see 2.3.

2.3 LinkedIn conversation content

The Extension reads LinkedIn message threads on pages you have open, in two ways: from the page’s visible content, and by observing the responses LinkedIn’s own messaging API returns to your browser. This observation is read-only — the Extension never issues write calls to LinkedIn and never sends, edits or deletes anything on your LinkedIn account. Where you have enabled conversation sync, the collected thread — participant name, participant profile URL, message text, sender and timestamps — is sent to your Kolvera workspace so the conversation appears against the right candidate or prospect record, and so that Kolvera’s AI features can draft a reply in context.

Only threads on tabs you have open are read. The Extension does not crawl, enumerate, or bulk download your LinkedIn inbox in the background.

2.4 Local settings

Your Extension preferences (selected desk, side-panel state, capture options) are stored locally in your browser.

2.5 Diagnostic telemetry

When the Extension cannot locate an expected page element — usually because LinkedIn has changed its layout — it reports: the surface (linkedin / salesnav / recruiter), the internal selector key that failed, a URL pattern with no query string (e.g. /in/*), the Extension version, and an optional non-reversible hash of the page structure. These reports contain no profile content, no names, no message text, and no personal data.

2.6 Scope of the API observation

To read the data described in 2.2 and 2.3 the Extension observes the responses that LinkedIn’s own API returns to your browser, on the LinkedIn domains listed in section 8 only. This observation is limited to the profile, search and messaging responses LinkedIn already returns for the page you are on. The Extension does not log keystrokes, mouse position, scrolling or clicks; does not monitor network traffic on any other site; and does not observe requests made by any other tab, extension or application.

2.7 What we do not collect

The Extension does not collect health information, financial or payment information, authentication credentials for any third party, personal communications outside LinkedIn messaging as described in 2.3, location data, web history, or your activity on any site other than the LinkedIn domains listed in section 8. It contains no advertising, analytics or fingerprinting code, and loads no remote code — all executable code ships inside the Extension package.

3. How we use it

We do not use any of this data for advertising, for building profiles unrelated to your use of Kolvera, for credit or employment decisions made by us, or to train publicly available or third-party AI models.

4. How it is stored

5. Who we share it with

We do not sell your data, and we do not transfer it to third parties for advertising, data brokerage, or any purpose unrelated to the single purpose in section 1. Data captured by the Extension is transmitted only to the Kolvera API. From there, the following service providers may process it strictly to deliver the features you use:

We may also disclose data where required by law, or to protect the rights and safety of Kolvera, our users, or the public. If Kolvera is involved in a merger or acquisition, workspace data may transfer to the acquiring entity under this same policy, and you will be notified.

6. How long we keep it

7. Your choices and rights

8. Permissions and why each is needed

No other site is accessed.

9. Limited use

Kolvera’s use of information received from the Extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we use the data only to provide and improve the single purpose stated in section 1; we do not transfer it except as necessary to provide that purpose, for security purposes, or to comply with applicable law; we do not use or transfer it for serving advertisements; and we do not allow humans to read it except with your explicit consent, for security or support purposes, to comply with applicable law, or where the data has been aggregated and de-identified.

10. Security incidents

We maintain access controls, encryption in transit and at rest, and audit logging. In the event of an eligible data breach we will notify affected users and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

11. Children

The Extension is a business tool and is not directed at, or intended for use by, anyone under 16. We do not knowingly collect data from children.

12. International users

Data is stored in Australia. If you access the Extension from the European Economic Area or the United Kingdom, our lawful basis for processing is performance of our contract with you (for workspace data) and legitimate interests in business-to-business communication (for third-party professional contact data). You may exercise your access, rectification, erasure, restriction, portability and objection rights via the contact address below.

13. Changes to this policy

We may update this policy as the Extension changes. The “Last updated” date at the top of this page will change, and material changes affecting how we collect, use or share personal information will be notified in the Kolvera app and, where required, by email before they take effect. The current version is always published at www.kolvera.io/extension-privacy.

14. Contact

Zionic Group Pty Ltd (ABN 51 689 146 861), trading as Kolvera, Australia.
Privacy enquiries: privacy@kolvera.io
General support: support@kolvera.io