Privacy
RolodexIn exists to hold things you would not write anywhere public. The short version: your notes are yours, nothing is sold, nothing trains a model, and LinkedIn is never told any of it.
The short version
- We never sell your data, and we never share it with other users.
- We never use it to train models.
- LinkedIn is never sent your notes, tags, statuses or reminders.
- The extension reads five fields from profiles you open yourself, and nothing else.
- It automates nothing — no messages, no connection requests, no API calls, no bulk collection.
- You can export everything as CSV on every plan, including the free one, and deleting a contact deletes it.
- This website uses no analytics and sets no cookies.
The rest of this page is the detail behind each of those.
Last updated 8 September 2026
Who we are
RolodexIn ("we", "us") provides a Chrome extension and a web dashboard that let you keep private notes on LinkedIn profiles you visit. This policy covers both, and this website. Questions go to support@rolodexin.com.
What the extension reads
When you open a LinkedIn profile, the extension reads five fields from the page you are already looking at: name, headline, company, profile URL, and photo URL.
It does not read anything else. Specifically:
- It does not read your feed, your inbox, or your messages.
- It does not read or transmit any LinkedIn cookie, session, or authentication token.
- It calls no LinkedIn API.
- It adds nothing to LinkedIn's page. Its panel renders inside its own shadow root beside LinkedIn's markup, never within it.
- It never collects in bulk. A record is created one at a time, by your visit or by your click.
What we store
For each contact you save, we store what the extension read plus what you wrote:
- Name, headline, company, profile URL and photo URL.
- The relationship status you set, and the tags you type.
- Your notes, including earlier versions — the note history is the feature, so previous text is retained rather than overwritten.
- Follow-up reminder dates and labels.
- Campaign membership: which campaigns a person is in, their stage and role in each, whether you flagged them as pivotal, and any interactions you logged against them.
- Saved views: the search, filters and sort you named.
For your account, we store your name, email address, profile photo URL, your plan, and identifiers linking your account to Google sign-in and, if you subscribe, to Paddle.
One disclosure that matters, because it is the one place this is not airtight. Contact photos are not copied onto our servers. We store LinkedIn's own image URL, and your browser loads the picture directly from LinkedIn's image CDN when a face is drawn on screen — including in the dashboard. That means LinkedIn's CDN sees a request from your browser for each photo rendered, and could in principle infer from timing and volume that you opened your dashboard and roughly how many contacts you hold. It never learns your notes, tags, statuses or reminders.
We accept this deliberately: the alternative — copying the images onto our servers — would mean our servers making a request to LinkedIn per person and storing LinkedIn's assets, which is worse on exactly the terms this policy cares about. Two mitigations are in place: photo requests are sent with no referrer, so the page you are on is not disclosed, and they load lazily, so only the faces you actually scroll to are fetched.
Signing in
The only way to create an account is Google sign-in. We receive your name, email address, profile photo URL and a stable Google account identifier. We never receive your Google password, and we request no access to your Gmail, Drive, Calendar or contacts.
Sessions use a short-lived access token (fifteen minutes) alongside a refresh token valid for thirty days, which is rotated each time it is used. Signing the extension in from the dashboard uses a single-use handoff code that expires immediately after it is exchanged.
Who else is involved
- Google — sign-in only, as described above.
- Paddle — our merchant of record for paid plans. Paddle handles the payment itself, along with tax, invoicing and dunning. We never see or store your card details. Paddle tells us which plan you are on; that is the whole of what we receive.
- Our hosting provider — the application and its database run on a single rented virtual machine. Ordinary web server logs are kept there.
- Backup storage — encrypted nightly database backups are stored with two independent storage providers, so that losing one does not lose your data.
- Sentry — where enabled, application errors are reported to Sentry so we can fix crashes. Error reports carry technical diagnostics, not the content of your notes.
We do not sell your data to anyone, we do not share it with advertisers, and we do not use it to train machine-learning models — ours or anyone else's.
LinkedIn is not one of the parties above. We send LinkedIn nothing. Your notes, tags, statuses, reminders and campaigns are never transmitted to LinkedIn, and nothing about the extension is visible on LinkedIn's own page. The single indirect exposure is the photo loading described above.
Keeping and deleting
- Your data is kept for as long as your account exists.
- Deleting a contact deletes it. It is removed from your account immediately and permanently purged after thirty days, which is the window in which a deletion can still be reversed if you ask.
- Deleting your account removes your data. Encrypted backups age out on their own retention cycle afterwards.
Getting your data out
From the dashboard, at any time: your contacts as CSV and every campaign as CSV, on every plan including the free one. Paid plans add full-history JSON containing your notes and logged interactions. There is no plan on which your data is locked in.
Cookies and analytics
This website sets no cookies and runs no analytics. There is no tracking script on any page you are reading here.
The dashboard, at app.rolodexin.com, sets what it needs to keep you signed in. That is a functional session, not tracking, and it is not shared with anyone.
Your rights
You can access your data (export it), correct it (edit it in the app), and delete it (delete contacts, or your account) at any time from the dashboard without asking us. If you would rather we did any of it for you, or you want to object to a use, write to support@rolodexin.com.
Children
RolodexIn is a tool for working professionals and is not directed at children under 16.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects how your existing data is handled, tell account holders directly.