ScrollStop
HomeFeaturesHow it worksPricingChrome ext.
Free tools
LinkedIn Profile SimulatorPREVIEWLinkedIn Post SimulatorPREVIEWAbout section generatorGENERATORHeadline generatorGENERATORHook generatorGENERATORComment generatorGENERATORProfile auditAUDIT
BlogAbout
Log inGet extension →
HomeFeaturesHow it worksPricingChrome ext.Free toolsBlogAbout
Log inGet extension →
legalprivacy · transparent · plain English

Privacy Policy.

What we collect, how we use it, and the choices you have. Applies to the web application and the ScrollStop Chrome extension.

LAST UPDATED: 3 AUGUST 2026

ScrollStop("we", "our", "us") respects your privacy. This policy explains what we collect, how we use it, and the choices you have. It applies to our web application and the ScrollStop Chrome extension.

What we collect

  • Account information. Email, name, and profile image you provide at sign-up (or that your Google / LinkedIn account provides on OAuth sign-in).
  • Authentication token. After you sign in, we issue a short-lived session token. The ScrollStop Chrome extension caches this token locally (in chrome.storage.local) so you stay signed in across browser sessions without logging in twice. The token lives on your device and is sent to our API only to authenticate your requests.
  • Profile + content data. Your voice profile, your engagement list, drafts, scheduled posts, comments you generated, saved posts, and any post analytics you sync. When you trigger a suggestion, the extension reads only the LinkedIn content relevant to that action.
  • Activity counts. We count how many comments, DMs and posts you generate with ScrollStop, so we can show your activity and enforce plan limits. The extension additionally records when you complete certain actions on LinkedIn (publishing a comment or post, sending a message, sending a connection request) so those totals reflect what you actually did. See Activity tracking below for exactly what this records, because it is the one thing the extension does without you clicking a ScrollStop button.
  • Usage metadata. Per-account daily counts (used to enforce plan limits), timestamps, and your plan tier.
  • Billing. Handled by Stripe on our web app. The Chrome extension never sees payment data. We do not see or store your card details.
  • Login activity. When you sign in or sign out, we record the timestamp, IP address, browser user-agent, and approximate country. This helps you detect unauthorised access to your account.

How we use it

Your inputs (post drafts, profile text, generation requests) may be sent to a third-party AI provider to produce suggestions. We store inputs and outputs so you can access your history. We use aggregate numbers (drafts created, comments suggested) to improve the product.

We do not sell, rent, or share your data with third parties for advertising or profiling.

Information about other people

ScrollStop helps you write to other people, so some of what we store is about them rather than about you. All of it is information already visible to you on LinkedIn at the moment you asked for a draft. We store it so your history and your lists still make sense when you come back to them.

  • People you draft messages to. Their display name, headline and LinkedIn profile identifier, saved alongside the drafts we generated.
  • Profile analysis for openers. When you ask for a DM opener, we analyse the profile sections visible on that page (about, experience, featured, and recent posts) and cache the result so a repeat request does not re-run the analysis.
  • Posts you save or comment on.The post text and link, plus the author's name, profile identifier and profile image URL.
  • People in your engagement lists. The LinkedIn member identifiers you add to a list.
  • People you send connection requests to. Their display name and profile identifier, recorded with the activity count described below.

We never contact these people, never build profiles on them for our own purposes, and never share this information with anyone else. Deleting the related draft, saved post, list entry or your account removes it.

Chrome Extension

The ScrollStop Chrome extension is the client that adds suggestion buttons to LinkedIn. Because browser extensions warrant an explicit data disclosure, here is exactly what it does and does not handle.

Data the extension sends to our servers:

  • The post or profile text relevant to the action you triggered - but only when you click a ScrollStop button. No background reading, no keystroke logging.
  • Message thread you are replying to.If you click "Draft a reply" inside an open LinkedIn message conversation, the extension reads the visible messages of that one conversation (up to the most recent 40) and sends them to our servers so we can generate a suggested reply in your voice. This happens only on that explicit click, only for the thread you have open, and only for the reply feature. We never read your inbox in the background, never read a thread you have not opened and acted on, and do not keep a running copy of your messages.
  • Your cached session token, attached as an Authorization header so our API knows which account is making the request.

Activity tracking

This is the one thing the extension does without you clicking a ScrollStop button, so we describe it separately rather than burying it.

To count what you actually did on LinkedIn (rather than only what you drafted), the extension watches for you completing four actions on the page: publishing a comment, publishing a post, sending a message, and sending a connection request. It does this by noticing when you click LinkedIn's own buttons for those actions. When one completes, it sends us a single event.

Each event contains only: which of the four action types it was, a timestamp, and - for connection requests only - the display name and profile identifier of the person you invited. It does not include the text of your comment, post or message.

What this is not: we do not log your clicks, keystrokes or mouse movement, we do not record what you read or scroll past, and we do not watch anything outside those four actions. The check runs only on LinkedIn pages.

Data the extension stores locally on your device (via chrome.storage.local, not transmitted anywhere):

  • Your cached session token and whether you are currently signed in.
  • Your theme and accent colour preference.
  • Your popup vs side-panel preference.
  • How you last sorted and ordered your engagement lists.
  • Your last-used drafting options: whether to mention the author, whether to like the post, and which DM intent you last chose.

Data the extension does not collect:

  • Web history. Content scripts only run on LinkedIn and only to inject ScrollStop buttons. We do not track which pages you visit, page titles, or visit timestamps.
  • Location. We do not access GPS, device location, or derive geolocation from your IP beyond the approximate country recorded in the login activity log above.
  • Your inbox or unopened messages. The only message data ScrollStop ever reads is the single conversation you have open at the moment you click "Draft a reply" (described above). We do not scan, index, or read your inbox, your other conversations, or any thread you have not explicitly asked us to reply to, and we do not read your emails or texts.
  • Financial information. The extension never handles card numbers, transactions, or credit data. All billing runs through Stripe on our web app.
  • Health information. Never collected.
  • Keystrokes, mouse movement, or what you read. The extension reads post or profile text only at the moment you click a ScrollStop button. It does detect when you complete one of the four LinkedIn actions listed under Activity tracking, which is a count of that action and nothing more - no content, and no record of anything else you click.

Browser permissions and why we need them

  • Access to linkedin.com. To add the ScrollStop buttons and read the content you ask us to work with. The extension runs on no other website.
  • Access to our own site. To pick up your session after you sign in, so you do not have to log in twice.
  • Storage. To keep the preferences and token listed above on your device.
  • Cookies. Read on our own domain only, to collect your session token after sign-in. We cannot and do not read cookies for any other site.
  • Scripting. Used only on our own site, to hand your signed-in session to the extension.
  • Tabs. Used to send updates to your open LinkedIn tabs, and to check whether your current LinkedIn search matches a saved list so we can highlight it. That URL check happens on your device and is never transmitted or stored.
  • Side panel. To open the ScrollStop panel next to LinkedIn.

Your data, your control

  • You can delete any draft, scheduled post, or comment from the relevant page in-app.
  • You can export your saved drafts and engagement list from Settings.
  • You can delete your account from Settings. This removes all stored content and account data.

Security

Data is stored on Supabase (Postgres) with row-level security so only you can read your own records. Traffic is encrypted with TLS. Authentication uses short-lived session tokens.

Cookies

We use essential cookies for authentication and a theme preference cookie. We do not use third-party advertising or tracking cookies.

Changes to this policy

If we make material changes, we will update the date above and, for signed-in users, show a notice on your next visit.

Contact

Questions? Email privacy@scrollstop.ai or see our Terms of Service.

ScrollStop

The LinkedIn workflow tool built on the 5Cs - Connections, Conversations, Comments, Content, Consistency. For founders, consultants and operators.

in▶@
Product
  • Features
  • How it works
  • Chrome extension
  • Pricing
  • Changelog
Free tools
  • About generator
  • Headline generator
  • Hook generator
  • Comment generator
  • Connection note
  • Profile audit
Resources
  • Blog
  • Help center
  • Roadmap
  • Status
Company
  • About
  • The $47 story
  • Contact
  • Privacy
  • Terms
  • Security
ScrollStop
© 2026 ScrollStop · Built in Melbourne.
v3.0 · LinkedIn workflow toolBuilt by Apptimistic