Legal

Privacy Policy

How we handle your data, in plain language. We never store your platform passwords or cookies, never sell your data, and never train AI on it. Prowlify works inside your own logged-in browser sessions.

Effective July 17, 2026

1. Who We Are

Prowlify ("we", "us", "our") operates the Prowlify browser extension and the web dashboard at getprowlify.com. This policy explains what data we handle and how.

2. What Data We Collect

2.1 Account Information

When you create an account we store your email address and a user ID. Passwords are managed by our authentication provider and are never stored in plain text.

2.2 Your Platform Usernames

The extension detects your public username or handle on each connected platform (Reddit, LinkedIn, X) to display your connection status in the dashboard. This is your public identity only — the same name or handle visible on your profile.

Prowlify never asks for or stores your platform passwords. Requests to Reddit, LinkedIn and X use your browser's existing logged-in session, the same way each website does when you visit it directly.

2.3 Platform Content You Choose to Scan

When you configure what to look for — such as subreddits and keywords, LinkedIn searches, or X queries — and run a scan (or ask the agent to hunt), the extension fetches content from the supported platforms on your behalf. This works the same way as visiting those pages in your browser — no special access or elevated permissions are used.

The fetched content is sent to our backend for lead analysis and AI qualification. We only fetch what matches the searches and keywords you configure. We do not crawl the platforms broadly or access private content you could not otherwise see.

2.4 Extension Status

The extension sends periodic status updates to our backend containing: a random extension instance ID, browser name, per-platform connection status (connected or disconnected for each supported platform), and the extension version. This is used solely to show connection health in your dashboard.

2.5 Leads, Replies, and Messages

Posts and profiles identified as leads, AI-generated reply and message drafts, and any replies or direct messages you send through Prowlify are stored in your account so you can review them.

3. How We Use Your Data

  • To operate the lead scanning, reply generation, and messaging features you configure
  • To display your results and engagement history in the dashboard
  • To publish replies and send messages you have approved or instructed Prowlify to send — on the platforms where you have enabled write access
  • To show your extension's connection status in the dashboard

4. What We Do NOT Do

  • We do not ask for or store your Reddit, LinkedIn or X passwords
  • We do not transmit your platform session cookies to our servers
  • We do not track your browsing activity outside the supported platforms
  • We do not inject ads or collect data from unrelated websites
  • We do not sell, rent, or share your data with third parties
  • We do not post, comment, or message on any platform without your instruction — and never at all on a platform unless you have enabled write access for it
  • We do not use your data to train AI models

5. How the Extension Works

The Prowlify extension acts as a companion to your dashboard. It carries out the actions you ask Prowlify to perform on the supported platforms:

  • Fetching content your dashboard or the agent requests (read-only)
  • Publishing replies and sending direct messages you approve — only on platforms where you have turned on write access
  • Reporting its per-platform connection status so you know it's active

All requests use your browser's existing logged-in sessions on Reddit, LinkedIn and X. The extension does not use any external API keys or elevated access — it acts on each platform on your behalf in the same way the platform's own website does.

Prowlify is read-only by default. The agent takes no autonomous write actions — posting, replying, commenting, direct messages, votes or reactions — unless you have both accepted the Automated Actions Terms and enabled the write-access switch for that platform. You can switch write access off at any time to return to read-only immediately. See our Terms of Service for details.

6. Data Storage and Security

Your data is stored in an encrypted, managed database on secure cloud infrastructure. All communication between the extension and our backend uses HTTPS. Local extension state (such as your dashboard login session) is stored in your browser's extension storage, which is sandboxed and not accessible to other extensions or websites.

7. Data Retention

We retain your data for as long as your account is active. When you delete your account, all associated data is permanently removed within 30 days.

8. Your Rights

  • Access — View all data we hold about you through your dashboard
  • Delete — Request complete account and data deletion at any time
  • Disconnect — Uninstall the extension to immediately stop all data collection
  • Export — Request an export of your data

9. Browser Extension Permissions

The extension requests only the permissions it needs:

PermissionPurpose
alarmsSchedule periodic connection status checks
cookiesRead your existing logged-in session state on the supported platforms locally, so requests run from your own browser. Your session cookies are never sent to our servers.
declarativeNetRequestWithHostAccessManage the network-request rules for the supported platforms so fetches made from your browser are accepted
scriptingRead your sign-in state from a platform tab you already have open
storageStore your dashboard login session locally in the browser
tabsDetect whether you have a supported-platform tab open so the extension knows if you're signed in
host: reddit.com, *.reddit.comFetch Reddit pages and carry out the actions you approve
host: matrix.redditspace.comReddit's chat server — used to read and send Reddit direct messages
host: www.linkedin.com, *.linkedin.comFetch LinkedIn content and carry out the actions you approve
host: static.licdn.comLinkedIn's static asset host — load images and assets referenced by LinkedIn content
host: x.com, *.x.com, twitter.com, *.twitter.comFetch X (formerly Twitter) content and carry out the actions you approve
host: abs.twimg.comX's static asset host — load images and media referenced by X content
host: getprowlify.comCommunicate with the Prowlify dashboard API

10. Third-Party Services

We use the following categories of third-party services:

  • Cloud database hosting (for storing your account data and leads)
  • AI language model providers (for lead qualification and reply suggestions — your data is processed via API and is not used for model training)

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a notice in the dashboard.

12. Contact

For privacy questions or data deletion requests:

[email protected]