Legal · Recruit

Recruit Privacy Policy

Effective date: August 19, 2026 · Version: 2026-08-19

Native People Search

When you submit a People Search, Intoola sends the school, company, position, and keyword filters you entered to its authenticated Cloudflare Worker. The Worker sends those filters to Icypeas and returns normalized professional records, which may include a name, position, company, school, location, provider identifier, optional profile reference, and an email only when the provider lawfully includes one in the search result. Intoola records the number of valid people returned and request-idempotency metadata for billing-period usage enforcement. It does not automatically run Email Finder.

Search results are kept in the extension session for the active search and are not added to Firebase tracking until you select people and choose Add Selected to Tracking. Saved tracking records may be stored locally and in the account-scoped Recruit Firebase database. Historical saved records remain supported.

This Privacy Policy explains how Intoola Recruit ("Intoola," "we," "our," or "us") collects, uses, stores, and shares information when you use the Intoola Recruit Chrome extension, its Cloudflare Worker, subscription features, professional email enrichment, synced tracking tools, exports, and related services (collectively, the "Service").

Intoola Recruit helps authorized users organize professional connections, enrich selected contacts with professional emails, track outreach, export lists, and request AI feedback on resumes and cover letters they intentionally submit.

1. Prominent data disclosure

Recruit reads connection information displayed on the Recruit People Search you intentionally select. Search results are processed locally. When you save a tracking list, it is cached in Chrome extension storage and synced through Intoola's authenticated Worker to an Intoola-controlled Firebase Realtime Database so it remains associated with your signed-in account.

During first-run Recruit onboarding, the extension sends your onboarding progress and answers—including student status, school level and school name when applicable, target recruiting industry, recruiting stage, and requested help area—through Intoola's authenticated Worker to Intoola's Recruit Firebase Realtime Database. These records are explicitly labeled as Recruit onboarding data and are kept separate from Studying-extension onboarding data.

If you use the third-party professional data platforms demonstration during onboarding, Recruit locally reads and displays the supported connection cards currently visible on the company People page you selected. The onboarding Firebase record stores whether you completed or skipped the demonstration, the company name, and the number of visible people collected; it does not store those people's names or profile details as part of the onboarding record. The demonstration does not perform email lookups. Professional-email finding remains locked until subscription and occurs only when you later request it for an individual saved contact.

When you choose Add Emails, the extension sends selected first and last names, normalized professional profile URLs, and the relevant company name to Intoola's Cloudflare Worker and to Icypeas so a professional email can be located. Returned email addresses and lookup status are sent back to the extension. Successful results may be stored in your account-level credit ledger, local results, and any local tracking list you save. Results are not reused across subscriber accounts.

When you choose AI Application Feedback, the extension sends the resume, cover letter, optional job-description files, and follow-up questions you intentionally provide through Intoola's authenticated Cloudflare Worker to Google Gemini. For DOCX files, the extension extracts document text locally and sends that extracted text rather than the original DOCX container. The Worker returns Gemini's feedback to the extension. Intoola uses server-side per-account token and rate-limit records for this feature; submitted document contents and chat responses are not intentionally stored by Intoola's application backend.

The Service also sends a Google OAuth access token to Intoola's Worker over HTTPS. The Worker validates the token with Google, verifies that it was issued to Intoola Recruit's exact OAuth client, and derives the trusted Google account identifier and email. The extension does not use a locally supplied email as proof of subscription ownership.

By affirmatively selecting the first-run agreement button or paywall consent checkbox, you consent to these uses and acknowledge this Privacy Policy.

2. Information processed locally

The extension may locally process and store:

  • onboarding answers, including student status, school level, school name, recruiting industry, recruiting stage, and the area where you want the most help;
  • names, profile URLs, headlines, connection degree, location, mutual-connection text, and other text visibly rendered in selected People Search results;
  • the selected third-party professional data platforms company name, company slug, company logo URL, and page URL context;
  • collected search results and the export fields you select;
  • saved company tracking lists, contact status, saved and updated timestamps, and returned email addresses;
  • subscription status and monthly usage information received from Intoola's Worker;
  • account-specific legal and referral-terms acceptance versions and timestamps stored in Chrome sync storage;
  • the locally cached Google OAuth token and display email used to maintain your signed-in session; and
  • extension preferences and operational state.

Onboarding answers and completion status are stored in chrome.storage.sync under an account-specific key so onboarding stays completed for that signed-in account, and they are also synced through the authenticated Recruit Worker to the Recruit Firebase database. The local tracking cache remains in chrome.storage.local until you delete it, clear extension data, remove the Chrome profile, or uninstall the extension. Deleting a company through Tracking also deletes its synced Firebase record. Clearing only the local cache or uninstalling does not by itself delete server copies. CSV exports are saved wherever your browser places downloads and are then controlled by you.

3. Information sent to Intoola's Worker

Depending on the feature you use, the extension sends the following over HTTPS to intoola-recruit.intoola-recruit.workers.dev:

  • a Google OAuth access token in the Authorization header;
  • Chrome account identifier, extension version, and authenticated Google email as verified by Google;
  • subscription checkout selection and the versions and timestamp of the legal documents you accepted;
  • when you request your referral code, the current referral-terms version and your acceptance timestamp;
  • Recruit onboarding progress, visited onboarding pages, completion status, and the onboarding answers listed in Section 2;
  • for the optional onboarding third-party professional data platforms demonstration, completion or skip status, selected company name, and visible-person count, but not the collected people's names or profile details;
  • for Add Emails, selected first and last names, normalized professional profile URLs, company name, and an idempotency key;
  • for Tracking, saved company names and slugs, company logo URLs, saved contact fields and professional emails, outreach statuses, and saved/updated timestamps;
  • for AI Application Feedback, the resume, cover letter, job description, attached PDF or text files, and follow-up questions you intentionally submit;
  • email-enrichment usage requests; and
  • ordinary HTTP and security metadata processed by Cloudflare in delivering and protecting the Worker.

The Worker does not receive your third-party professional data platforms password, third-party professional data platforms authentication cookies, complete browsing history, private third-party professional data platforms messages, or payment-card number. Tracking records are sent only when you use the saved Tracking feature, and Add Emails data is sent only when you intentionally request enrichment.

4. Server-side records

Intoola may store the following in Cloudflare D1, Stripe, Firebase, and operational systems:

  • billing-user ID, record key, authenticated email, Chrome account or installation identifier where available, Stripe customer ID, and timestamps;
  • Stripe subscription ID, status, price lookup key, current period end, cancellation status, and invoice reference;
  • accepted legal-document versions and acceptance time in Stripe Checkout and subscription metadata;
  • shared Intoola referral or discount code, billing-user ID, authenticated email, Stripe customer and subscription IDs, referral-terms version and acceptance timestamp, redemption status, and any Stripe Global Payout identifier needed to prevent duplicate partner payouts;
  • monthly email-credit totals and billing-period keys;
  • per-account records showing which normalized profiles have already produced credited emails;
  • per-account provider-attempt totals used to cap third-party enrichment requests, including unsuccessful searches;
  • request idempotency records and completed Add Emails responses used to prevent duplicate processing;
  • account-scoped Recruit onboarding progress and answers in Firebase Realtime Database, stored under a Recruit-specific path and labeled intoola_recruit / recruit_onboarding;
  • account-scoped saved company tracking lists and outreach statuses in Firebase Realtime Database; and
  • per-account daily AI input-byte and output-token totals and atomic D1 request-rate counters.

Email-enrichment results are account-scoped. Intoola does not use one subscriber's result to answer another subscriber's request.

5. How information is used

We use information only as reasonably necessary to:

  • authenticate the user and associate the correct subscription;
  • create and administer Stripe Checkout and subscription access;
  • locate and return professional email results the user explicitly requests;
  • maintain quotas, rate limits, idempotency, caches, and account-level credit ledgers;
  • provide local search, synced tracking, and export functions;
  • secure, debug, maintain, and improve reliability of the Service;
  • investigate fraud, abuse, security incidents, or violations;
  • comply with law and enforce the Terms of Service; and
  • respond to support, privacy, or legal requests.

We do not use or transfer personal or sensitive information for personalized advertising, creditworthiness, lending, or sale to data brokers.

6. Service providers and disclosures

Information may be processed by:

  • Google, to issue and validate the OAuth token, return the verified account identifier and email, host the Firebase Realtime Database used for synced Tracking, and process intentionally submitted application materials through Gemini;
  • Cloudflare, to host the Worker, D1 database and atomic usage controls, networking, and security infrastructure;
  • Stripe, to create customers, process subscription payments, manage subscription status, and store billing and legal-acceptance metadata;
  • Icypeas, to search for professional email addresses using selected names and company context; and
  • Google Chrome, to provide extension identity, storage, tabs, side-panel, and download functionality.

third-party professional data platforms supplies the webpage content visible to your account, but Intoola does not send enrichment results or your Intoola subscription information to third-party professional data platforms.

We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse or security incidents, or complete a merger, acquisition, financing, reorganization, or sale of assets subject to applicable notice and consent requirements.

7. Google and Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

We limit Google account information and extension-obtained user data to providing or improving Intoola Recruit's disclosed single purpose, related security and operational functions, legal compliance, and user-requested support. We do not sell that information, use it for personalized advertising, transfer it to advertising platforms or data brokers, or permit human access except with the user's specific consent, for security or abuse investigation, to comply with law, or for appropriately aggregated internal operations where permitted.

8. Retention

Retention depends on the record:

  • local onboarding answers, the local tracking cache, and preferences remain until you clear extension storage, remove the applicable Chrome profile data, or uninstall; server-side Recruit onboarding records remain until you submit a valid deletion request, and synced tracking records remain until you delete the relevant tracked company in the extension or submit a valid deletion request;
  • rate-limit counters are overwritten by newer time windows, while usage totals are retained as needed to enforce the applicable billing-period or daily limit;
  • unsuccessful provider results are not stored in a cross-account cache;
  • account-level email-credit ledgers, idempotency, billing-user, subscription, and transaction records may remain while needed to provide the Service, prevent duplicate charges, resolve disputes, enforce limits, comply with accounting or legal duties, and protect against abuse; and
  • Stripe and other providers retain data under their own policies and legal obligations.

Intoola may de-identify or aggregate operational data and retain it where allowed by law. We will delete or anonymize data upon a valid request unless retention is required or permitted for security, fraud prevention, legal compliance, billing, dispute resolution, or exercise of legal rights.

9. Security

The extension transmits server-bound information over HTTPS. OAuth tokens and provider keys are used only for their intended authentication or service purpose. Intoola's Worker validates OAuth audience, subscription status, price configuration, legal consent versions, rate limits, quotas, and idempotency server-side. Payment-card details are entered on Stripe-hosted pages and are not stored by the extension.

No security method is perfect. You are responsible for securing your Google, Chrome, third-party professional data platforms, and device access and for protecting exported CSV files and tracking data.

10. Your choices and rights

You may:

  • decline the paywall consent checkbox and not subscribe;
  • avoid Save to Tracking and Add Emails to keep transient collected connection data local;
  • delete individual tracking lists through the extension;
  • clear extension storage or uninstall the extension to remove the local cache (this does not delete the synced Firebase copy);
  • cancel your subscription through an available Stripe or Intoola subscription-management method; and
  • request access, correction, deletion, or other applicable privacy rights through the support/contact channel in the Chrome Web Store listing.

We may need to verify your identity before fulfilling a request. Deleting server-side billing or usage records may be limited where retention is required for transactions, security, fraud prevention, legal compliance, or legal claims. Requests concerning data controlled independently by Google, third-party professional data platforms, Stripe, Cloudflare, or Icypeas may need to be directed to that provider.

11. International processing

Intoola and its providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, appropriate legal mechanisms should be used for international transfers.

12. Children

Intoola Recruit is a professional recruiting and networking tool and is not directed to children. Do not use the Service to collect or enrich information about minors unless you are legally authorized and all applicable child-privacy and employment requirements are satisfied.

13. Changes

We may update this Privacy Policy as the Service, providers, or legal requirements change. Material changes will be disclosed through the extension, paywall, Chrome Web Store listing, or another reasonable channel. When appropriate or legally required, we will request renewed consent and update the version date.

14. Contact

Privacy questions and requests may be submitted through the contact or support channel identified in Intoola Recruit's Chrome Web Store listing.

This policy is adapted from Intoola's existing product privacy materials for Recruit's specific data flows. It should be reviewed by qualified privacy counsel before publication, including the operator's legal identity, contact information, retention schedule, international-transfer mechanism, and jurisdiction-specific notices.