Inven Chrome Extension Privacy Disclosure

This section describes how the Inven Chrome Extension ("Extension") collects, uses, stores, and shares data. It supplements the general Inven Privacy Policy and applies specifically to users who install and use the Extension.

1. Data Collected by the Extension

1.1 Account and Authentication Data

When you sign in, the Extension receives your email address and an authentication refresh token from app.inven.ai and stores them locally in your browser using chrome.storage.local. It also stores Cognito session tokens (JSON Web Tokens) and your username in chrome.storage.local to maintain your authenticated session across browser sessions. Authentication traffic is routed to AWS Cognito (hosted in the EU North 1 region: cognito-idp.eu-north-1.amazonaws.com).

1.2 Browsing Context (Active Tab Domain)

When the Extension's side panel is open, it reads the URL of your active browser tab using the tabs permission. Only the registrable domain (e.g. example.com) is extracted and used — the full URL path, query parameters, and page content are not accessed or transmitted. The current domain is stored temporarily in chrome.storage.local and sent to the Inven API (api.inven.ai) to retrieve:

  • Company intelligence and information for the website you are viewing
  • Related news articles about the company
  • CRM integration data (if you have configured a CRM connection)

The Extension does not inject content or display its side panel on linkedin.com pages, but it does access LinkedIn cookies and API endpoints when LinkedIn Sync is enabled (see Section 1.3).

1.3 LinkedIn Session Cookies

When you enable the LinkedIn Connections Sync feature, the Extension reads your LinkedIn session cookies — specifically li_at and JSESSIONID — from https://www.linkedin.com using the cookies permission. These cookies are used to authenticate requests made directly from the Extension to LinkedIn's internal API. The cookie values are stored temporarily in chrome.storage.local (as linkedInSession) to avoid re-reading them on every sync cycle. Cookie values are not transmitted to Inven's servers.

1.4 LinkedIn Connection Data

When the LinkedIn Connections Sync feature is enabled (opt-in), the Extension fetches your LinkedIn connections list by making authenticated requests to LinkedIn's Voyager API (https://www.linkedin.com/voyager/api/relationships/dash/connections). The data retrieved consists of the public LinkedIn profile identifiers of your connections — names, profile URLs, or other personal details are not extracted. These connection identifiers are then transmitted to Inven's API (api.inven.ai) so that Inven can display which of your connections have relationships with the companies you are researching.

Sync checks run periodically in the background (every 60 seconds when the Extension is open), but actual data synchronization occurs at most once per day to respect rate limits and minimize data transfer. You can disable sync at any time from the LinkedIn Sync screen within the Extension.

1.5 People and Contact Lookup Data

When you use the people search or contact lookup features within the Extension, the following data is sent to the Inven API (api.inven.ai):

  • The current website's domain (used to scope the search)
  • Search parameters (e.g. title search terms, requested result count)
  • For contact detail lookups: the person's name, job title, LinkedIn profile URL, and company name

This data is used solely to retrieve contact information from Inven's database and is processed in accordance with the main Inven Privacy Policy.

1.6 List and Project Management

When you add or remove companies from lists or projects within the Extension, the relevant company and project identifiers are sent to the Inven API (api.inven.ai) to update your account.

2. Data Stored Locally in Your Browser

The Extension stores the following data in your browser using Chrome's local and session storage APIs:

Storage type Data stored
chrome.storage.local Authentication tokens (JWTs), username, auth state, current domain, company data, company project lists, selected list ID, side panel state, LinkedIn session identifier, LinkedIn sync timestamps and flags
chrome.storage.session User project list, company data cache, company project cache (held in memory for the duration of the browser session)

This data is stored exclusively on your device and is not accessible to other websites or extensions.

3. Data Shared with Third Parties

The Extension shares data with the following third parties:

Party What is shared Purpose
Inven (api.inven.ai) Active tab domain, LinkedIn connection identifiers (when sync is enabled), people search parameters, contact lookup fields (name, title, LinkedIn URL, company), list/project management actions Core extension functionality: company intelligence, news retrieval, connection mapping, CRM list management
AWS Cognito (cognito-idp.eu-north-1.amazonaws.com) Authentication credentials (email, password, refresh token) during sign-in and token refresh flows User authentication and session management
LinkedIn (www.linkedin.com) Session cookies are used to authenticate requests sent directly from the Extension to LinkedIn's API during connection sync Fetching your LinkedIn connections list when sync is enabled
Logo CDN (logo.dev.inven.ai) Company domain (as URL parameter for logo image requests) Loading company logos for display in the Extension
Google User Content (s2.googleusercontent.com, gstatic.com) None (images loaded only) Displaying user profile pictures and cached images

The Extension does not use any third-party analytics, advertising, or tracking SDKs. No data is sold to third parties.

4. User Control and Opt-Out

  • LinkedIn Connections Sync is an opt-in feature. You can enable or disable it at any time from the LinkedIn Sync screen within the Extension. Disabling sync stops all future LinkedIn cookie reads and connection fetches.
  • You can sign out of the Extension at any time, which clears all locally stored authentication tokens and session data.
  • You can uninstall the Extension at any time via your browser's extension management page (chrome://extensions), which removes all locally stored Extension data.

5. Data Retention

  • Local browser storage is retained until you sign out, uninstall the Extension, or clear your browser data.
  • LinkedIn connection identifiers synced to Inven's servers are retained as described in the main Inven Privacy Policy and deleted upon account deletion request.
  • Session storage data (company and project caches) is cleared automatically when the browser session ends.

6. Contact

For questions about this disclosure or to exercise your data rights, contact us at info@inven.ai.