Legal · Recruit

Recruit Privacy Policy

Effective date: August 25, 2026 · Version: 2026-08-25

This Privacy Policy explains how INTOOLA LLC ("Intoola," "we," "our," or "us") collects, uses, stores, and shares information through Intoola Recruit. Intoola Recruit is available as a Chrome extension and as a signed-in web application at intoola.com/recruit; both surfaces authenticate against the same account, share the same Cloudflare Worker backend, and read and write the same recruiting data, so this Policy covers both together (the "Service") unless a section says otherwise.

Intoola Recruit helps you search for professionals connected to a school, company, position, or keyword; organize the people and companies you find into recruiting and networking lists; request a professional email address for a specific person you select; track your outreach, application, and interview status; and request AI-generated feedback, outreach drafts, and interview or coffee-chat preparation based on materials and context you choose to provide.

Please read this Policy together with the Recruit Terms of Service and Usage Limits, which describe what the Service does, your responsibilities when contacting other people, and the limits that apply to search, enrichment, and AI features. By affirmatively agreeing to the first-run consent screen or the paywall consent checkbox, you acknowledge this Policy.

1. Who operates Recruit

Intoola Recruit is operated by INTOOLA LLC, a New York limited liability company. Privacy questions, requests, and notices under this Policy can be sent to info@intoola.com or through the support contact listed in Intoola Recruit's Chrome Web Store listing.

2. Scope of this Policy

This Policy applies to the Intoola Recruit Chrome extension, the Intoola Recruit web application, the Cloudflare Worker backend they share, Recruit's subscription and billing features, professional search and email-enrichment features, tracking and export tools, and Recruit's AI feedback and coaching features.

This Policy does not apply to Intoola Study, a separate product with its own privacy policy, even though a limited amount of shared billing infrastructure is described in Section 3.10. It also does not apply to LinkedIn or any other third-party website, or to Google, Stripe, or Icypeas, each of which is governed by its own privacy policy referenced in Section 12.

3. Information we collect

The categories below are organized by where the information comes from and what it is used for, because Recruit handles several distinct kinds of data very differently. In particular, information about you as the account holder (Sections 3.1, 3.2, 3.10-3.13) is treated differently from information about other people you are researching or trying to reach (Sections 3.4-3.7), most of whom are not Intoola users. Section 5 addresses that second category in more detail.

3.1 Account and sign-in information

Recruit requires Google sign-in; there is no separate Intoola password. In the Chrome extension, sign-in uses Chrome's built-in chrome.identity API, which opens Google's own account-selection popup and returns an OAuth access token to the extension. In the web application, sign-in uses Firebase Authentication with the Google provider, which is also a Google account-selection popup, but issues a Firebase ID token instead of a Google OAuth token. In both cases, our Worker independently verifies the token directly with Google (via Google's token-validation and account-lookup endpoints) before trusting any identity claim, checks that the token was issued to Recruit's own application, confirms the required scopes and a verified email address, and derives your account identity from Google's response rather than from anything the client supplies. Intoola never receives, requests, or stores your Google account password.

3.2 Onboarding and profile information

During onboarding, Recruit asks whether you are currently a student, and if so your school level and school name, your target recruiting industry, your recruiting stage, and the area where you want the most help. These answers are stored under your verified account in a Recruit-specific Firebase Realtime Database record and cached locally so onboarding does not repeat.

3.3 Search criteria you submit ("People Search")

People Search is a typed-filter search, not a page-reading feature. You submit a school, company, current position, and/or keyword (the web application's search form also currently accepts a location field, though the backend does not yet act on it). The current version of the Chrome extension has no browser permission to read, inject scripts into, or otherwise access the content of any webpage, including LinkedIn or any other site — it can only exchange data with Intoola's own Worker. Your search filters are sent to that Worker, which forwards them to our search provider, Icypeas, described in Section 3.4.

3.4 Professional information about others, returned by our search provider

Icypeas is a third-party professional-data provider. When you run a People Search, our Worker sends only the filter text you typed (school, company, position, keyword) to Icypeas and receives back a list of normalized professional records, which may include a name, professional headline, position, company, school, general location, a provider-assigned identifier, a public profile URL (which may be a LinkedIn profile URL when Icypeas' underlying record includes one), and an email address only when Icypeas' data lawfully includes one. Intoola does not obtain this information directly from LinkedIn, does not access any LinkedIn account, and has no data-sharing partnership, endorsement, or licensing arrangement with LinkedIn — see Section 20. A repeated request for the same search page within an active search returns a cached, already-normalized copy of that page rather than a fresh query to Icypeas.

3.5 Professional email enrichment ("Add Emails")

Email enrichment runs only when you select a specific saved person and choose to look up an email. The Worker sends that person's first name, last name, and company/domain to Icypeas — not a LinkedIn URL — and Icypeas returns an email address if one is found, or a not-found result. A successfully found email is recorded against your account only, keyed to that specific profile, so you are not re-charged for the same profile twice; it is never shared with, or reused to answer, another subscriber's request. Unsuccessful lookups are not retained in any shared or cross-account cache — a legacy cross-account lookup cache that predated this design has been removed from our infrastructure.

3.6 People you add manually (web application)

The web application includes an "Add person" feature that is not available in the Chrome extension. It lets you type in a full name, company, role or headline, professional email, and profile URL directly, without an Icypeas lookup. Because this is information you are supplying about someone else from your own knowledge, you are responsible for having a lawful basis to hold and use it, consistent with the Terms of Service.

3.7 Recruiting and networking tracking lists

When you save people to Tracking (from a search result or a manual add), Recruit stores, per company: the company name and an optional logo URL; and per person: name fields, headline, position, company, school, profile URL, email (if found or entered), a connection/outreach status you choose from a fixed list (for example, Not contacted, Contacted, Follow-up sent, Replied, Meeting scheduled, No response), general location, and free-text mutual-connection notes if supplied. For backward compatibility with lists saved by earlier versions of the product, the underlying schema also accepts a legacy free-text snippet field (capped at 4,000 characters); the current Search, Add Emails, and manual-add flows do not populate this field.

3.8 Resumes, cover letters, and other documents you submit

Recruit's AI feedback feature accepts documents you choose to upload for review. In the Chrome extension, supported types are PDF, DOCX, and TXT, up to 8 MB per file; DOCX files are converted to plain text entirely inside your browser before anything is sent, so the original DOCX file is never transmitted to Intoola or to Google — only the extracted text is. In the web application, supported types are PDF and TXT only, up to 8 MB; DOCX is not currently accepted there. Documents are transmitted over HTTPS through Intoola's Worker to Google's Gemini API for the single review you requested and are not intentionally written to any Intoola database afterward — see Section 7 for more detail on AI processing.

3.9 AI prompts, generated content, and conversation context

What is included in an AI request depends on the tool and, in some cases, on which surface you use:

  • Resume/cover-letter feedback: the document you upload, plus any role or context text you type.
  • Outreach email writer: in the Chrome extension, only the recipient, company, role, context, and tone fields you type. In the web application, if you select a saved contact from the list before generating, the entire saved record for that person — name, company, school, headline, location, and email if one was found — is included in the prompt sent to Gemini, in addition to the fields you type. This is a materially broader data flow than the extension's outreach tool, and applies whenever you choose a saved contact on the web application's Outreach or Prep screens.
  • Interview/coffee-chat preparation ("Prep"): the industry, role, and context fields you type, plus, on the web application only, the full saved-contact record if you selected one, exactly as described above.
  • Follow-up messages: a limited number of your most recent conversation turns (up to roughly the last several messages) are resent with each follow-up so the assistant retains context. This conversation history is not saved by Intoola's backend; it exists only in your active browser session and is lost when you close the extension panel or reload the web app.

Intoola's Worker does not write the text of your prompts, uploaded documents, or Gemini's generated responses to any database. Content you submit is nonetheless subject to Google's own Gemini API terms, which govern how Google itself may process it; we encourage you to review those terms, linked in Section 12.

3.10 Billing and subscription information

Recruit's subscription is billed through Stripe. Our Worker creates and reads Stripe Customer, Checkout Session, Subscription, and Billing Portal Session objects, and attaches the version and acceptance timestamp of the Terms, Privacy Policy, and Usage Limits you agreed to at checkout as metadata on the Checkout Session and Subscription. Stripe subscription status is stored in a database table that is shared with Intoola's other product, Intoola Study, because both products use the same underlying billing infrastructure; Recruit-specific usage, search, enrichment, and AI records described elsewhere in this Policy are not shared with Study. Stripe webhook processing (the mechanism that keeps subscription status current) is handled by a separate Intoola-operated Worker used across products. Intoola does not receive or store your full card number, card expiration date, or bank account number — those are entered only on Stripe-hosted Checkout and Billing Portal pages.

3.11 Referral program information

An active paid subscriber may request a personal referral code after separately accepting the Referral Program Terms. We store the code, your account and subscription identifiers, the referral-terms version and acceptance timestamp, and redemption status. Referral rewards are implemented as a percentage-off Stripe coupon and a restricted, one-time-use Stripe promotion code applied to the referred person's own purchase and your own renewal — no separate cash-payout mechanism is used. Sharing your code by email uses a plain mailto: link that opens your own email client; Intoola does not send that email on your behalf or see its contents.

3.12 Device, request, and technical information

To protect the Service against abuse, our Worker computes a one-way cryptographic hash of the source IP address of each AI-feature request and stores only that hash together with a daily request count, to enforce a per-source daily rate limit; it does not store the raw IP address for this purpose. The extension version, and the verified Google account identifier and email described in Section 3.1, accompany requests to the Worker so it can enforce quotas correctly. Error logs on our backend capture only an error name and message, never the content of your documents, prompts, or search filters. Cloudflare, as our hosting and network provider, may separately retain standard edge/network request logs as part of operating its infrastructure; that logging is outside our direct control and governed by Cloudflare's own practices.

3.13 Local device and browser storage

In the Chrome extension: chrome.storage.local holds your local Tracking cache and general extension state until you delete a record, clear extension data, or uninstall; chrome.storage.sync holds your onboarding answers and completion flag (keyed to your Google account), and the version and timestamp of the Terms, Privacy Policy, Usage Limits, and Referral Program Terms you accepted. A separate local record holds only your display email and a "signed in" flag — the underlying Google OAuth token itself is cached and managed by Chrome, not by Intoola. In the web application: a small number of localStorage flags track whether this browser has signed in before and whether you have accepted the Referral Program Terms, and Firebase Authentication maintains your signed-in session locally so you are not prompted to sign in on every visit.

4. Information we do not collect

For clarity, Recruit does not:

  • collect your LinkedIn (or any other third-party platform) password, authentication cookies, or session tokens;
  • read, scrape, or otherwise access the content of any webpage — the current extension has no script-injection, active-tab, or third-party host permission of any kind, and performs People Search entirely through typed filters and Icypeas, as described in Section 3.3;
  • access your general browsing history, bookmarks, or data belonging to your other browser extensions;
  • collect or store your full payment card number or bank account number; or
  • send messages to other people on LinkedIn or any other platform on your behalf.

5. Professional information about people who are not Intoola users

Because Recruit is a recruiting and outreach tool, much of the professional information it processes concerns people other than the account holder — professionals you are researching or trying to reach, most of whom do not have an Intoola account and have not agreed to this Policy.

Categories: name, professional headline or title, employer, school, general location, a public or professional profile URL, and, only when our provider's data lawfully includes one, a professional email address.

Sources: Icypeas, a third-party data provider that aggregates publicly available and professional information (Sections 3.4-3.5), and information a user manually enters about someone they know (Section 3.6). Intoola does not independently verify the accuracy, currency, or consent basis of information a provider returns.

Purpose: this information is processed solely to help the requesting user identify and contact recruiting or networking prospects using the criteria that user supplies. Intoola does not use it for advertising, resale, or any purpose unrelated to that user's own recruiting activity, and does not compile it into a standalone people-search product independent of a specific user's request.

Correction, objection, or deletion: if you are not an Intoola user and believe professional information about you has been processed through the Service, you may contact info@intoola.com to request correction or deletion. We will make reasonable efforts to locate and remove or correct a matching record held in our systems (including a saved tracking record, if one of our users has saved it), but we do not control, and cannot directly remove, information held by Icypeas or by the underlying public source from which it originated; requests concerning those sources may need to be directed to that provider.

6. How we use information

We use information only as reasonably necessary to:

  • authenticate you and associate the correct subscription and saved data with your account;
  • run the People Search and Add Emails features you request and return results to you;
  • save, sync, and let you export the recruiting and tracking lists you build;
  • generate the AI feedback, outreach drafts, and preparation content you request;
  • create and administer Stripe Checkout, billing, and referral-program access;
  • enforce usage quotas, rate limits, idempotency, and per-account result caches described in Sections 3.4-3.5 and 7;
  • secure, debug, maintain, and improve the reliability of the Service;
  • investigate and prevent fraud, abuse, or security incidents;
  • comply with applicable law and enforce the Terms of Service; and
  • respond to support, privacy, or legal requests.

We do not use or transfer personal information for personalized advertising, ad targeting, creditworthiness or lending decisions, or building profiles independent of a specific user's own recruiting request. We do not currently operate any advertising or ad-tech integration within the Service.

7. How AI features process your information

Recruit's AI feedback, outreach, and preparation features are powered by Google's Gemini API. Your request — the prompt text described in Section 3.9, plus any uploaded document, limited to PDF or plain-text content — is sent from your browser through Intoola's Worker directly to Gemini over HTTPS, along with a fixed system instruction that restricts the assistant to resume, cover-letter, job-description, outreach, recruiting, and interview-preparation topics; instructs it to treat all uploaded documents and typed text as untrusted content rather than instructions; and directs it not to invent a candidate's experience, credentials, or facts.

Intoola's backend does not write the text of your prompts, uploaded documents, or Gemini's generated responses to any database. It tracks only aggregate usage metadata needed to enforce daily limits — the number of input bytes and output tokens used per account per day — and, on an error, logs an error name and message rather than request content. Because processing occurs on Google's infrastructure, your submitted content is also subject to Google's own Gemini API terms and privacy practices, including whatever retention or model-improvement policies Google applies under those terms; we do not control, and cannot make representations about, Google's own retention or training practices beyond what Google's published terms state, so we encourage you to review Google's Generative AI Additional Terms of Service directly at ai.google.dev/gemini-api/terms.

AI features are rate-limited per account and, separately, per hashed source IP address, to prevent abuse; requests that exceed a limit are rejected before reaching Gemini.

8. How search and email enrichment are processed

People Search sends only your typed filters to Icypeas and normalizes the response into the fields described in Section 3.4; usage is metered by the number of valid people returned, and a per-account monthly allowance applies as described in the Usage Limits. Add Emails performs a single, per-person lookup against Icypeas using name and company/domain only; a successful result is credited permanently to your account for that specific profile so you are not charged twice, while an unsuccessful result is not retained beyond the response returned to you at that moment. Repeat requests that use the same idempotency key return the previously computed result instead of triggering a new provider lookup, which helps prevent duplicate charges against your monthly allowance if a request is retried after a network error.

9. Recruiting and tracking data: storage and sync

Saved tracking lists are cached locally (Chrome extension storage or the web app's in-memory state, refreshed from the server) and synchronized, through the Worker, to a Recruit-specific Firebase Realtime Database that Intoola controls. That database's own security rules deny all direct client read or write access by default; every read and write actually happens through the Worker's own authenticated service-account credential after the Worker has independently verified your identity, so your tracking data cannot be reached by a client that has not been authenticated by Intoola's backend. Deleting a company from Tracking removes it from both your local cache and the synced Firebase record; there is currently no single "delete all data" action, so removing an entire account's synced data requires contacting us as described in Section 16.

10. Chrome extension permissions

The Chrome extension requests the following permissions, each limited to what a specific feature needs:

  • identity and identity.email — to run Google's interactive sign-in flow and read your Chrome profile's display email, as described in Section 3.1;
  • storage — to hold the local Tracking cache, onboarding answers, consent-acceptance records, and preferences described in Section 3.13;
  • sidePanel — to display Recruit as a Chrome side panel rather than a popup window;
  • downloads — to save the CSV files you export from Tracking to your computer; and
  • host access, limited to Intoola's own Worker domain — the extension has no permission to access any other website, including LinkedIn.

The extension requests no scripting, activeTab, or third-party host permission, and cannot read the content of any webpage you visit.

11. Cookies, local storage, and similar technologies

The authenticated Recruit web application does not use advertising or tracking cookies. It relies on Firebase Authentication's own session mechanism to keep you signed in and on the small localStorage flags described in Section 3.13. Intoola's general marketing website, including Recruit's public marketing pages, may separately run Firebase Analytics as part of Intoola's site-wide analytics practices; that general site analytics is unrelated to, and does not receive, your recruiting, tracking, document, or AI content.

12. Service providers

Information may be processed by:

  • Google — to run and verify Google/Firebase sign-in (Section 3.1), host the Firebase Realtime Database used for synced Tracking and onboarding data (Section 9), and process AI requests through the Gemini API (Section 7). See Google's Privacy Policy at policies.google.com/privacy and Google's Gemini API terms at ai.google.dev/gemini-api/terms.
  • Cloudflare — to host the Worker backend, its request database, rate-limit and usage counters, and network/security infrastructure.
  • Stripe — to create customers, process subscription payments, manage billing status, and store the billing and consent metadata described in Section 3.10. See Stripe's Privacy Policy at stripe.com/privacy.
  • Icypeas — to run People Search and Add Emails lookups using the filters and names you submit, as described in Sections 3.4-3.5 and 8.
  • Google Chrome — to provide the extension's identity, storage, side-panel, and download functionality.

We do not send your enrichment results, tracking data, or subscription information to LinkedIn or any other third-party platform, and we do not sell personal information to data brokers.

13. Disclosure of information

Beyond the service providers in Section 12, we may disclose information in the circumstances below.

Legal process and safety. We may access, preserve, or disclose information if we reasonably believe it is necessary to comply with a law, regulation, court order, subpoena, or other valid legal process; to enforce the Terms of Service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Intoola, our users, or the public.

Business transfers. If Intoola or substantially all of its assets are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information we hold may be transferred as part of that transaction. We will provide notice, where required by law, before your information becomes subject to a different privacy policy as a result of such a transaction.

De-identified and aggregated data. We may create de-identified or aggregated information (for example, aggregate feature-usage statistics) that does not identify you, and we may use or share that information for any lawful purpose, including to describe or improve the Service.

14. Data retention

Retention depends on the type of record:

  • local caches, onboarding answers, and preferences remain on your device until you clear extension storage, remove the relevant browser profile data, or uninstall the extension;
  • synced onboarding and tracking records remain in Intoola's Recruit Firebase database until you delete the relevant tracked company or request deletion as described in Section 16;
  • per-account email-credit records (Section 3.5), request idempotency records, and usage/rate-limit counters are retained as needed to enforce quotas, prevent duplicate charges, and prevent abuse, and roll forward automatically into new billing or daily periods rather than being purged on a fixed schedule;
  • unsuccessful search or enrichment results are not retained beyond the response returned to you at the time of the request;
  • AI prompts, uploaded documents, and generated responses are not retained by Intoola's backend, as described in Section 7;
  • billing, subscription, and consent-acceptance records are retained for as long as needed to provide the Service, resolve disputes, meet accounting or legal obligations, and prevent abuse; and
  • Stripe, Google, Cloudflare, and Icypeas each retain data they process under their own policies and legal obligations, independent of Intoola.

15. Security

Recruit transmits information to and from its backend over HTTPS. Identity tokens are independently validated with Google before any request is trusted (Section 3.1); the Firebase database that stores synced tracking and onboarding data denies all direct client access and is reachable only through the Worker's own authenticated service credential (Section 9); IP addresses used for abuse prevention are stored only as a one-way hash (Section 3.12); and payment-card details are entered solely on Stripe-hosted pages and never reach Intoola's own systems. We use commercially reasonable administrative, technical, and organizational measures designed to protect information, but no method of transmission or storage is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for securing your own Google account, device, and browser profile.

16. Your choices and rights

You may:

  • decline the consent screen or paywall checkbox and choose not to use or subscribe to the Service;
  • avoid Add Emails, the manual "Add person" feature, or selecting a saved contact in the web app's Outreach/Prep tools, to limit which data flows described above apply to you;
  • delete an individual tracked person or company at any time, which removes it from both your local cache and the synced Firebase record;
  • clear extension storage or uninstall the extension to remove your local cache (this does not, by itself, delete the synced copy in Intoola's Recruit database);
  • cancel your subscription at any time through Stripe's Billing Portal or another Intoola-provided subscription-management method; and
  • request access to, correction of, or deletion of the account-level data described in this Policy — including a full account deletion, since no self-service "delete all data" control currently exists in the product — by contacting info@intoola.com or the support channel in the Chrome Web Store listing.

We may need to verify your identity, using the same verified Google/Firebase account described in Section 3.1, before fulfilling a request. Deleting server-side billing, usage, or fraud-prevention records may be limited where retention is required for transactions, security, legal compliance, or the resolution of a dispute. Requests concerning data controlled independently by Google, Stripe, Cloudflare, or Icypeas may need to be directed to that provider.

17. California, Colorado, Connecticut, Nevada, Utah, Virginia, and other U.S. state privacy rights

Intoola does not sell, trade, or rent personal information, and does not sell personal information as that term is defined under the state privacy laws described below. Depending on where you live, you may have some or all of the following rights: to be informed whether we are processing your personal information; to access the personal information we hold about you; to correct inaccuracies in it; to request its deletion; to obtain a portable copy of the personal information you provided to us; and to opt out of processing your personal information for targeted advertising, the sale of personal information, or profiling in furtherance of decisions that produce legal or similarly significant effects — although, as noted above, Intoola does not engage in the sale of personal information or targeted advertising in connection with the Service.

California. If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended, including the rights described above, and you will not receive discriminatory treatment for exercising them.

Colorado, Connecticut, Utah, and Virginia. If you are a resident of Colorado, Connecticut, Utah, or Virginia, you have rights under that state's comprehensive privacy law — respectively, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, or the Virginia Consumer Data Protection Act — as described above.

Nevada. Intoola does not sell personal information. Nevada residents may still direct questions about our data practices to us using the contact information below.

Exercising your rights. You, or where the applicable law permits, your authorized agent, may submit a request to know, access, correct, delete, or obtain a copy of your personal information by emailing info@intoola.com. To verify your request, we may ask you to confirm your legal name, the email address associated with your account, your relationship to Intoola, and the state where you reside; an authorized agent must provide documentation of their authority to act on your behalf. We will respond to a verified request without undue delay and, in any event, within the time required by the applicable law (for example, 45 days, extendable once by an additional 45 days with notice to you where permitted). If we decline to act on a request, we will explain why, and you may appeal that decision by emailing info@intoola.com; we will respond to an appeal in writing, generally within 60 days, and will tell you how to escalate the matter to your state's Attorney General if your appeal is denied.

18. International users, including the European Economic Area, UK, and Switzerland

The Service is controlled and operated by Intoola from the United States and is not intended to subject Intoola to the laws or jurisdiction of any state, country, or territory other than the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, whose data-protection laws may differ from those of your home jurisdiction.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have rights under the GDPR or an equivalent local law, including: the right to be informed about how we use your data; the right to access the data we hold about you; the right to correct inaccurate data; the right to erasure of your data; the right to restrict our processing of your data; the right to receive a copy of your data in a portable format; and the right to object to our processing of your data. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. To exercise any of these rights, contact us at info@intoola.com.

19. Children and eligibility

Intoola Recruit is a professional recruiting and networking tool. Consistent with the Terms of Service, you must be at least 13 years old to use the Service, and if you are under the age of legal majority in your jurisdiction, a parent or legal guardian must review this Policy and authorize any subscription on your behalf. Do not use the Service to collect or enrich information about minors unless you are legally authorized to do so and all applicable child-privacy and employment-related requirements are satisfied.

20. Relationship to LinkedIn and other third-party platforms

Intoola Recruit is an independent product. It is not endorsed by, sponsored by, affiliated with, or operated in partnership with LinkedIn or any other professional-networking platform, and it has no data-license or data-sharing agreement with LinkedIn. Where this Policy notes that a profile URL Icypeas returns, or that you enter manually, may be a LinkedIn address, that reflects only the format of a public profile link — not any relationship between Intoola and LinkedIn, and not any suggestion that LinkedIn supplied that information to us directly.

21. Third-party links and services

The Service may display or let you open links to third-party sites, such as a professional's public profile URL. We do not control those sites and are not responsible for their content or privacy practices. Reviewing a third party's own privacy policy before providing information to that site is your responsibility.

22. Changes to this Policy

We may update this Policy as the Service, our providers, or applicable law changes. Material changes will be reflected in a new effective date and version above and disclosed through the extension, the web application, the paywall, the Chrome Web Store listing, or another reasonable channel. Where appropriate or legally required, we will request renewed consent before you can continue using the Service.

23. Contact

Privacy questions and requests may be sent to info@intoola.com or submitted through the support channel identified in Intoola Recruit's Chrome Web Store listing.