KipDo

Privacy Policy

How we collect, use, and protect your data.

© 2026 KipDo. All rights reserved.

Last updated: June 2026

1. Data We Collect

We collect the following categories of data:

  • Account data: Name, email address, and your KipDo login password (stored only as a secure one-way hash — never in plaintext)
  • LinkedIn browser connection: extension installation identifier, device-token hash, online/offline state, the current LinkedIn path without query parameters, command status, and bounded results needed to operate your campaigns. The extension does not export LinkedIn cookies to KipDo.
  • LinkedIn recovery credential: when you save a LinkedIn login email and password, they are stored in a dedicated encrypted vault and automatic local recovery is active. The password is released only as a one-time, end-to-end encrypted envelope to your paired browser when LinkedIn displays its normal login page. It is never sent to an AI provider and is never used by a server-side browser.
  • Campaign data: Target audience definitions, brand voice settings, message templates
  • Lead data: LinkedIn profile information of discovered leads. Source-visibility principle: our system only ever sees what your own connected LinkedIn account can see when logged in — we never access profiles whose visibility is restricted from you, and we operate no anonymous or public scraping path. We do not store full profile pages: only a short derived summary and a numeric embedding are kept, and the underlying profile is re-fetched live when needed.
  • Conversation data: LinkedIn messages synced for follow-up management
  • Appointment data: Invitee name, email address, optional phone number and notes, selected time, timezone, and booking status
  • Usage data: Action logs, agent events, and performance metrics
  • Payment data: Processed by Stripe; we store only Stripe customer IDs

What the LinkedIn connection does NOT collect:

  • Your email inbox or any email content.
  • Email verification codes, two-factor (2FA) codes, or phone verification codes.
  • Your browser history.
  • LinkedIn session cookies or cookies from any other website.

The KipDo browser extension runs approved actions inside your local LinkedIn tab and polls KipDo for work while Chrome is open. It stores a device key and scoped device token locally; it does not export your LinkedIn cookies.

Disconnecting: you can disconnect at any time in Settings → LinkedIn → Disconnect. This revokes the paired extension token and stops queued execution.

Verification challenges: if LinkedIn shows a checkpoint, CAPTCHA, email code, or two-factor prompt, you resolve it yourself on LinkedIn. KipDo never solves verification challenges and never reads your email.

2. How We Use Your Data

  • To provide and operate the Service (LinkedIn automation)
  • To authenticate with LinkedIn on your behalf
  • To generate AI-powered messages and content
  • To send transactional emails (verification, alerts, support)
  • To provide booking pages, prevent scheduling conflicts, and send appointment confirmations, calendar invitations, updates, and reminders
  • To improve the Service and fix issues

3. AI & LLM Processing

We use contracted third-party AI service providers to generate messages and qualify leads. The minimum context required for those features may be processed by the provider configured for your workspace under its applicable data-processing terms. We do not use your data to train AI models.

3a. Aggregated Benchmarks

To help every user improve, we compute de-identified, aggregated performance benchmarks (such as typical reply and meeting rates) across participating workspaces. Shared-learning records contain structured outcomes, not message text or contact identity. A benchmark is only computed when enough separate workspaces contribute that no individual workspace can be singled out. We use these aggregates to improve matching, timing, and coaching tips; we never expose one workspace's raw data to another user.

You can disable shared learning at any time in Settings → Account → Data & privacy. Disabling it stops future outcomes from contributing, removes your workspace's derived shared-learning events, and stops benchmark-based advice for your workspace. It does not stop the operational processing required to run campaigns, synchronize conversations, manage jobs and contacts, or schedule meetings.

4. Data Retention

  • Account data is retained while your account is active
  • After account deletion, data is soft-deleted and permanently removed after 30 days
  • Extension access is revoked immediately on disconnect; recovery credentials are removed through account deletion and can be replaced in Settings
  • Action logs and events are retained for up to 90 days
  • Appointment records are retained while the host account is active and are removed through the account deletion process
  • Lead data minimization: a lead we never actually engaged (no outreach beyond initial qualification and no messages) is automatically anonymized after 12 months — its name, headline, company, location, photo, summary, and embedding are erased, leaving only a pseudonymous identifier for deduplication. Conversation messages for closed deals are purged after 24 months.

5. Third Parties

We share data with the following third parties solely to provide the Service:

  • Stripe — Payment processing
  • Brevo (Sendinblue) — Transactional emails
  • AI providers — Message generation (provider depends on your settings)
  • LinkedIn — The platform your agent interacts with

We do not sell your data to any third party.

6. Data Security

  • LinkedIn recovery credentials and browser-command payloads are encrypted at rest with separate key domains; API and device tokens are stored hashed
  • API keys are encrypted before storage
  • All connections use HTTPS/TLS
  • Access to production systems is restricted to authorized personnel

6a. Session Replay (Support Diagnostics)

To diagnose problems and improve reliability, we may record how the app interface behaves during your session (using the open-source rrweb library) while you are signed in to the app. These recordings capture on-screen layout and interactions — not the content you type: all form inputs are masked at the moment of capture, so passwords and other typed values are never recorded. Recordings are visible only to authorized support staff, are automatically deleted after 7 days, and are never shared with third parties.

7. Your Rights

You have the right to:

  • Access your personal data at any time through the app
  • Correct inaccurate data in your account settings
  • Delete your account and associated data
  • Export your data by contacting support
  • Object to processing by closing your account

For leads and contacts: if you are a person contacted through the Service and wish to have your data erased, contact us (or the KipDo customer who contacted you) and we will erase your record on request — a right-to-be-forgotten deletion that removes the lead and all related data and keeps only an anonymous, hashed proof of erasure.

8. Cookies

We use session cookies for authentication. We do not use tracking cookies or third-party analytics on the application.

9. Changes to This Policy

We may update this policy. Material changes will be communicated via email. Continued use of the Service constitutes acceptance.

10. Contact

For privacy-related questions, contact us at our support page or email privacy@kipdo.com.