Free B2B Leads — Privacy Policy
Prospect Intelligence Chrome Extension · v12.0.0
Privacy Commitments at a Glance
- ✅ Declared, purpose-limited endpoints only. The extension talks only to the API hosts declared in its manifest: the supplier, CRM, sending, and advertising services you unlock with your own keys, the licensing server, and a small set of keyless public sources used to enrich the company you are viewing (for example WHOIS/RDAP, certificate transparency, DNS, the Wayback Machine, public registries, and logo/avatar services). It never contacts a host outside that declared list.
- ✅ On-page reading is local and capped. On the page you are viewing, the extension reads the domain, title, meta description and technology fingerprints, and — within per-page limits — scans the visible text for phone numbers, email addresses and any extraction patterns you have defined. That scan runs on your device: the page text is not uploaded or stored unless you choose to save a captured item. The extension does not crawl beyond the page you are on, and company intelligence itself comes from the public data APIs you configure.
- ✅ No browsing surveillance. The extension does not log your browsing history or report the pages you read to anyone. For Free Tier quota, only the company domains you look up are counted on our licensing server — never page content, form inputs, or your wider browsing (see Section 6).
- ✅ No data sold or shared. Your enriched lead data, API keys, and configured vendors are stored locally in your browser. Your leads are never transmitted to us or sold to third parties.
- ✅ Custom Audience uploads — opt-in only. An optional feature can upload your enriched contacts to your own Google Ads, Meta, or LinkedIn advertising accounts for retargeting. Disabled by default. You choose when, what, and where to upload.
- ✅ You choose the domains. You choose which domains the extension talks to via BYOV (Bring Your Own Vendor) configuration — the extension does not autonomously fetch from any domain.
1. What This Extension Does
Free B2B Leads is a Chrome extension that provides B2B contact intelligence in a persistent side panel. When you visit a business website, it can look up company information and contacts using third-party data supplier APIs that you configure.
2. Data We Collect
We do not operate data-collection servers for your leads. Contact enrichment happens directly between your browser and third-party APIs, using API keys that you provide — your enriched contacts never flow through our servers. Our licensing server stores only your signup details and Free Tier usage counters, described in full in Section 6.
3. What Runs Automatically
- Content script (domain detection) — Runs on every page you visit. Reads: the website domain name, page title, meta description, structured data (JSON-LD), script/stylesheet URLs for technology-stack detection, and a capped, local scan of the visible page text for phone numbers, email addresses, and any custom extraction patterns you define. That scan happens on your device; page text is not transmitted or stored unless you choose to save a captured item. Does not read passwords, form inputs, cookies, or browsing history.
- LinkedIn Person Mode — On LinkedIn profile pages (
linkedin.com/in/...), the content script additionally reads: the person's name, job title, company, and location from JSON-LD structured data, OpenGraph meta tags, and page heading elements. Only publicly visible profile information is read — no login credentials, messages, or connection data.
- Background health checks — Polls
localhost:8000 and localhost:9090 (your own local apps) every 30 seconds to check if Hunt Leads or Cockpit are running. No external servers are contacted.
- License check — Validates paid license keys against the configured license server (see Settings). A background alarm may re-check periodically. Local Hunt Leads / Cockpit health polling is separate.
4. What Runs Only When You Act
- Domain lookup — When a domain is detected or you trigger a lookup, the extension calls third-party APIs (Apollo, Hunter, PDL, etc.) using your API keys.
- CRM push — Contact data is sent to HubSpot, Salesforce, Pipedrive, or your webhook only when you click a push button.
- Auto-Sync — If you enable this optional feature in Settings, contacts are automatically pushed to a configured CRM destination after each lookup, with a 3-second cancellable delay. Off by default. You control which CRM destination receives auto-pushed contacts.
- AI analysis and drafting — If you provide an AI provider key (OpenAI, Anthropic Claude, or Google Gemini), company summaries and lead-scoring insights are generated by sending company metadata (name, domain, industry, employee count) to that provider. When you generate an outreach draft, the selected contact's name, job title, and email address are included in the prompt sent to the provider you chose; nothing is sent until you click. If you use Dictate or Transcribe Audio with an OpenAI key, the audio you record is sent to OpenAI for transcription. The provider's terms apply to what you send.
- Gmail compose assist — On Gmail pages, the extension can insert AI-drafted outreach text into a compose window when you click "Draft Outreach." It reads the recipient email address from the compose header to personalize the template. It does not read message bodies, attachments, or inbox content.
5. Data Storage
- API keys — Stored in
chrome.storage.local (device-only, not synced to Google cloud). Can be encrypted with AES-256-GCM when you set a passphrase in Settings.
- Preferences — UI settings stored in
chrome.storage.sync (synced across Chrome profiles). No sensitive data — only display preferences, AI model selection, and CPS template names.
- Cached data — Domain lookups cached in
chrome.storage.local with automatic pruning (max 200 entries, configurable TTL).
- Push history — A local log of contacts pushed to CRM destinations, used for duplicate prevention. Stored in
chrome.storage.local. Never transmitted externally.
6. Account, Free Tier & Licensing Data
Using Free B2B Leads — on the Free Tier or with a paid license — requires a one-time signup (the in-app setup wizard). This is what our licensing server stores and why:
- Signup details — Your name, business email, and company name, collected during the setup wizard. Used to create your account, deliver license keys you purchase, and send service notices. Never sold or shared.
- Machine identity — A hashed machine fingerprint generated by the optional native helper app. It contains no serial numbers, files, or personal information — it is a one-way identifier used to bind your account and license to your computer and to prevent quota abuse.
- Free Tier usage counters — To enforce the monthly Free Tier allowance (8 unique company domains), the server keeps the current month's count and the list of company domains you looked up that month (for de-duplication, so repeat lookups of the same company stay free). Counters reset monthly. This is quota accounting for lookups you initiate — it is not a log of your browsing.
- Install metadata — Install identifier and browser type (e.g., "chrome"), used for fraud prevention and support.
- License records — For paid users: your license key, plan, and activation status, validated against the server.
What is never stored on our servers: your enriched contacts and lead database, your API keys, page content, form inputs, or browsing history. Those stay on your device.
7. Optional Contributor Mode
Off by default. When enabled, discovered contacts may be shared with the DatabaseEmailer network. This is clearly labeled in Settings and requires you to enter a contributor email and verify it. This feature is currently marked "Coming Soon" and is not active.
8. Third-Party APIs
The extension can connect to the following categories of services, each only with credentials you provide and only for the feature you use. The complete host list is declared in the extension's manifest and shown by Chrome at install time:
- Apollo.io, Hunter.io, People Data Labs, Seamless.AI, FullContact — contact enrichment
- BuiltWith — technology detection
- Google Places, Abstract — business data and email validation
- Serper, SerpAPI, Google Custom Search — prospect search
- OpenAI, Anthropic, Google Gemini — AI analysis, outreach drafting, and (OpenAI) audio transcription (optional, user-supplied keys; see the AI analysis item above for what is sent)
- Gmail, Microsoft 365, Amazon SES — sending email you compose, only from accounts you connect
- Telephony provider you connect (Telnyx) — click-to-call and voicemail from your own account
- Google Ads, Meta, LinkedIn — optional Retargeting / Ad Audiences (off by default): hashed contact emails you choose to push to your own audience lists
- HubSpot, Salesforce, Pipedrive — CRM push (optional)
- Custom Webhook URL — universal integration (Zapier, Make, n8n, etc.)
Each service has its own privacy policy. We encourage you to review them.
9. Permissions Explained
- Content scripts (http/https matches) — General pages use
content.js; LinkedIn and Gmail use dedicated inject scripts. They read only metadata needed for enrichment (domain, title, meta tags, script URLs; LinkedIn public profile fields where applicable). No passwords, messages, or inbox body scraping.
- Host permissions - Declared API endpoints (suppliers, CRM, OpenAI, license server, Gmail, etc.). Optional broad
http(s)://*/* can be granted by the user for full-page features.
storage / unlimitedStorage — Save settings and cached lookups locally.
identity — Runs the browser sign-in flow when you connect your own Google (Gmail send and your email address), Microsoft 365 (mail send and profile), or Salesforce account. Outreach you send goes out from those accounts, or from Amazon SES with your own AWS credentials; the extension never sends from an address you have not connected.
scripting — Used by scanPageForDomains() to inject an on-demand domain scanner when you are browsing for prospects.
alarms — Hourly license re-check (backs off to daily if services are offline).
contextMenus — Adds right-click menu options for manual domain lookup, CPS queue, Hunt Leads enrichment, and Clip to Notes (captures page title, URL, and selected text into your local per-domain notes — stored only in chrome.storage.local, never transmitted).
sidePanel — The prospect-intelligence UI is a browser side panel.
activeTab / tabs — Identify the company website (or LinkedIn profile) you are viewing so it can be looked up.
notifications — Lookup-completion, low-balance, and offline-queue replay alerts (user-toggleable).
offscreen — Runs the bundled DuckDB WASM engine for local data work in an offscreen document.
nativeMessaging — Optional Hunt Leads desktop integration (a stable machine ID for seat enforcement); the extension works without it.
10. Chrome Web Store Limited Use Disclosure
This extension's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements:
- Data obtained through Chrome APIs is used solely to provide and improve the extension's user-facing features (domain enrichment, contact discovery, CRM push, and AI analysis).
- Data is not sold to third parties.
- Data is not used for advertising, user profiling, or creditworthiness assessment.
- Data is not transferred to third parties except as necessary to provide the features you configure (e.g., sending contacts to your CRM when you click Push, or querying supplier APIs with your keys).
- Human access to user data is limited to debugging with user consent or as required by law.
11. No Tracking
This extension contains no analytics, no telemetry, no advertising trackers, and no tracking pixels. We do not collect usage data beyond the Free Tier quota accounting described in Section 6. There are no calls to Google Analytics, Mixpanel, Segment, or any other analytics service from extension code.
12. Contact
For privacy questions, contact privacy@databaseemailer.com
Last updated: July 25, 2026 · v12.0.0