Extension Privacy Policy
Last updated: 2026-09-23
This policy describes how the Wannalead browser extension ("the extension") collects, uses, and shares data.
Who we are
Wannalead ("we") provides automation APIs for LinkedIn and Instagram. The extension connects a user's existing sessions to Wannalead so that requests made through the product can run from that user's own browser.
Single purpose
The extension has one purpose: connect the user's already-authenticated social network sessions in their browser to Wannalead, and execute the requests the user asks for through the Wannalead API. It does nothing else.
What the extension accesses and why
- LinkedIn session cookies (presence and metadata). The extension reads whether the LinkedIn authentication cookies (
li_at,JSESSIONID) are present in the browser and derives the session validation token required by LinkedIn. This is used to (a) confirm the user is logged into LinkedIn and (b) execute the user-requested LinkedIn requests with the user's own session. Cookie values are never logged. Only presence flags and a non-reversible hash of the cookie set are sent to Wannalead to detect session changes. - LinkedIn request results. When the user requests a LinkedIn action through Wannalead, the backend sends the extension a fully-resolved request (method, LinkedIn URL, allowed headers). The extension performs that request against
linkedin.comusing the user's session and returns the raw response to Wannalead so the product can parse and return it to the user. - Instagram session status, when enabled. Instagram access is optional and off by default. After the user enables it in the popup, the extension checks whether the required Instagram session cookies are present and live. It then executes only allowlisted reads and workspace-enabled writes requested through Wannalead, returning the response needed for the request, private mirror, or campaign. It does not send raw Instagram cookie values.
- Local extension state (
chrome.storage): pairing state, extension connection identifier, service endpoint, and last-known status metadata.
What the extension does NOT do
- It never asks for or stores the user's LinkedIn or Instagram password.
- It never injects UI into LinkedIn or Instagram pages and never reads arbitrary browsing history.
- It never executes remote code. The backend sends data (which request to run), never executable code.
- It does not sell user data, does not use it for advertising, and does not transfer it to data brokers.
Data we transmit and store
Data is sent over encrypted connections to Wannalead servers (wannalead.co): authentication status for enabled networks, browser/extension metadata, and the payloads needed to fulfil the user's requests. Instagram cookie values are not sent. Data is used solely to provide the Wannalead product to that user (Limited Use). We retain it only as long as needed to provide the service and honor deletion requests.
Per-user scope — no data pooling
Every network request is fulfilled in-flight from the connected user's own session, bounded by what that user can already see and do from their own account. We do not pool, cross-reference, resell, or maintain a shared dataset across users, and we do not perform cross-account lookups. Data obtained through one user's session is used only to provide the Wannalead product to that same user.
Limited Use compliance
Our use of data received from the extension complies with the Chrome Web Store Limited Use policy: data is used only to provide and improve the user-facing features of Wannalead; it is not sold, not used for ads, and not transferred except as required to operate the service or by law.
Your choices
Uninstalling the extension stops all data collection. Users can disable the optional Instagram access in the popup, revoke either network session from that network's settings, and request deletion of their data by contacting us.