Privacy Policy
Effective date: 21 July 2026 · Last updated: 31 July 2026
This Privacy Policy explains how Mastros processes personal data when you use Mastros – LinkedIn Data Exporter, the mastros.online website, subscription and billing services, support channels, and related services collectively referred to as the "Service."
1. Controller and contact
The controller responsible for personal data processed directly by Mastros is Mastros. Privacy questions and requests may be sent to admin@mastros.online.
Mastros is an independent product and is not affiliated with, endorsed by, sponsored by, or authorized by LinkedIn Corporation, LinkedIn Ireland Unlimited Company, Microsoft Corporation, or their affiliates.
LinkedIn separately determines how it processes personal data through LinkedIn and Sales Navigator. LinkedIn's own privacy terms apply to its services.
2. Summary of the Service's data architecture
The extension is designed as a local-first data-export tool.
Information extracted from LinkedIn pages is processed within your browser. Extracted LinkedIn records are not intentionally uploaded to Mastros' servers.
However, the extension does communicate limited account, subscription, usage, anti-abuse, configuration, and product-analytics information to Mastros and its service providers.
This means "local-first" does not mean that the extension makes no network requests or that no information ever leaves your device.
3. LinkedIn information processed locally
When you start an extraction, the extension may read information that LinkedIn has loaded or displayed in your active browser session.
Depending on the page and extraction mode, locally processed information may include:
- names and profile identifiers;
- profile and company URLs;
- job titles and professional headlines;
- company names and company information;
- location and industry information;
- visible profile descriptions;
- visible connection information;
- people and company search results;
- Sales Navigator leads, accounts, and list information;
- job listings and job descriptions;
- posts and visible post information;
- names of visible commenters or people reacting to a post;
- timestamps, result positions, and source pages;
- information from supported profile, company, job, or activity pages opened for optional detail collection; and
- other fields clearly displayed in the extension before extraction.
Some of this information is read from responses that LinkedIn's own application requests while you browse, rather than from the rendered page. One extension script runs in the page's JavaScript context for this purpose, limited to recovering post permalinks, which LinkedIn does not place in the rendered page. It does not issue, alter, block or delay any request, and it does not read authentication cookies or credentials.
The exact fields depend on what LinkedIn displays, the user's LinkedIn plan, privacy settings, geographic location, page type, and changes made by LinkedIn.
The extension is not designed to extract LinkedIn authentication cookies or request your LinkedIn password.
3.1 First-run LinkedIn plan detection
Once per installation, on first run, the extension opens a LinkedIn page in an inactive background tab in order to determine which LinkedIn plan your account has, so that extraction limits and interface options match your account.
When detection completes or times out, that tab is navigated to the LinkedIn homepage and brought to the foreground; it is not closed silently.
The information read during this check is limited to plan indicators. The detected plan is stored locally, and a plan-detection event containing the detected plan category, detection source, and detection confidence — but no profile or account information — is included in the product analytics described in section 7.
This check does not run again after the first installation.
4. Local storage and downloaded files
Extracted datasets may be held temporarily in memory and saved locally in the extension's IndexedDB database.
Local information may include:
- extracted records;
- dataset names and identifiers;
- extraction mode;
- source page;
- start and completion times;
- record and duplicate counts;
- extraction status;
- export preferences;
- Activity Guard counters;
- detected LinkedIn plan settings;
- extension preferences; and
- recent extraction state.
When you export a dataset, the file is downloaded to a location controlled by your browser and device.
Mastros does not control downloaded files. They remain on your device or in any storage, CRM, spreadsheet, cloud service, or other system to which you subsequently move them.
Local datasets remain until you delete them, clear extension or browser storage, reset the extension, or uninstall it, subject to Chrome's own storage behaviour.
5. Account and identity information
The extension may process the following account-related information:
- your Google or Chrome profile email address, where available through Chrome's identity permission;
- an installation identifier generated by the extension;
- an installation identifier stored through Chrome local storage and, where Chrome Sync is enabled, Chrome synchronized storage;
- your Mastros plan;
- subscription and payment status;
- billing-cycle start and renewal dates;
- usage totals, such as unique records and API-call counts;
- Stripe customer and subscription identifiers;
- account restoration requests;
- extension version;
- backend synchronization status; and
- account creation and update timestamps.
The extension does not require a separate Mastros password in the reviewed version. Paid access can be associated with the email used through Chrome or Stripe.
Your installation identifier may persist across devices or reinstallations where Chrome Sync is enabled.
6. Browser characteristic identifier
The reviewed extension creates a pseudonymous browser characteristic identifier for account integrity and free-plan abuse prevention.
The identifier is derived from a combination of:
- screen dimensions;
- browser language;
- reported time zone; and
- browser platform.
These values are converted into a short identifier before being sent to the Mastros backend. Mastros does not receive the uncombined values through this particular process, but the resulting identifier may still be personal data because it can help distinguish a browser installation or recognize a probable reinstall.
The identifier is used to:
- detect likely reinstalls;
- reduce repeated free-plan registrations;
- merge relevant usage totals; and
- protect subscription and quota functionality.
It is not used to identify LinkedIn members contained in an exported dataset.
7. Usage and product analytics
The extension may send pseudonymous product and reliability events to PostHog's European service.
These events may include:
- a pseudonymous per-installation analytics identifier;
- extension version;
- installation or application-open events;
- extraction surface or mode;
- whether an extraction started, completed, stopped, or failed;
- non-content status and error information;
- requested and completed record counts;
- duplicate counts;
- extraction duration;
- export format;
- plan category;
- detected LinkedIn member plan and Sales Navigator plan category, with detection source and confidence;
- quota events;
- Activity Guard state;
- warning or challenge categories;
- feature-selection events; and
- upgrade-button interactions.
The analytics implementation uses an allow-list intended to exclude extracted dataset content.
Mastros does not intentionally send to PostHog:
- exported names;
- professional headlines;
- company names;
- profile or company URLs;
- LinkedIn search queries;
- job or post content;
- connection lists;
- raw page text; or
- complete exported datasets.
Although these events do not intentionally contain extracted LinkedIn content, they are pseudonymous rather than guaranteed anonymous. PostHog and network infrastructure may also receive ordinary technical request information, such as an IP address and HTTP metadata, when a request is transmitted.
Analytics are used to measure adoption, understand feature performance, identify selector failures, diagnose errors, improve reliability, and understand when plan allowances are reached.
7.1 Uninstall feedback
If you uninstall the extension, Chrome opens a feedback page on the Mastros website.
The address of that page includes your Mastros plan, the number of days since installation, an approximate band for the number of records exported (for example "1k-10k" rather than an exact figure), your interface language, and the extension version.
It contains no email address, no installation identifier, and no extracted LinkedIn data. Completing the form is entirely optional.
8. Website analytics and communications
When you visit mastros.online, Mastros may process technical information such as:
- pages viewed;
- approximate region;
- browser and device type;
- referral source;
- timestamps;
- IP address as processed by hosting and network providers; and
- security and request logs.
The website may use Cloudflare Web Analytics or other disclosed privacy-oriented analytics services.
If you contact Mastros by email or through a website form, we process the information you provide, including your email address, name, message, attachments, and any technical information reasonably necessary to respond.
Website forms may be processed through SplitForms or another provider identified on the relevant form.
Do not send LinkedIn passwords, authentication cookies, security codes, or complete exported datasets unless support specifically requires a limited sample and you are legally authorized to disclose it.
9. Payment information
Payments and subscription-management functions are processed by Stripe.
Stripe may process:
- your name;
- email address;
- billing address;
- payment method;
- transaction information;
- tax information;
- subscription status;
- invoices;
- fraud-prevention information; and
- technical information associated with payment requests.
Mastros does not directly store your complete card number or card security code.
Mastros may receive and retain Stripe customer IDs, subscription IDs, plan information, billing-cycle dates, payment status, and limited transaction information required to activate and administer your subscription.
Stripe processes information under its own privacy policy and legal obligations.
10. Purposes and legal bases
Mastros processes personal data for the following purposes and legal bases, as applicable.
Providing the Service and subscription
We process account identifiers, plan information, usage totals, settings, and billing status to provide the extension, enforce plan allowances, restore purchases, and administer subscriptions. The legal basis is performance of a contract or taking steps requested before entering into a contract.
Billing and legal records
We process payment and transaction information to collect subscription fees, maintain accounting records, handle disputes, and comply with tax and financial obligations. The legal bases are performance of a contract and compliance with legal obligations.
Security, integrity, and abuse prevention
We process installation identifiers, the pseudonymous browser characteristic identifier, usage information, technical logs, and security events to prevent misuse, protect free and paid plans, and maintain service integrity. The legal basis is Mastros' legitimate interest in protecting the Service, users, and commercial model.
Product analytics and reliability
We process pseudonymous extension events to understand product usage, identify failures, maintain compatibility, and improve functionality. The legal basis is Mastros' legitimate interest in measuring and improving the Service. Where applicable law requires consent for a particular analytics activity, Mastros will rely on consent.
Support and communications
We process contact information and message content to answer questions, resolve technical issues, handle complaints, and communicate important service information. The legal bases are performance of a contract, legitimate interests in customer support, and compliance with legal obligations where applicable.
Legal claims and compliance
We may process relevant records to investigate misuse, enforce agreements, respond to lawful requests, establish or defend legal claims, and protect the rights and safety of Mastros or others. The legal bases are legal obligation and legitimate interests in protecting legal rights.
11. Chrome permissions
The extension requests permissions used for the following purposes:
LinkedIn host access
Access to LinkedIn pages allows the extension to detect supported pages and read information displayed or loaded there when providing its export functionality. This includes reading responses that LinkedIn's own application requests during your session, as described in section 3, and opening the one-time plan-detection page described in section 3.1.
Storage
Chrome storage and IndexedDB are used for settings, datasets, account state, installation identifiers, plan information, usage counters, Activity Guard information, and extraction state.
Identity and email
Chrome identity permissions may be used to retrieve the email address associated with the active Chrome profile. This supports account association, subscription activation, and purchase restoration.
Mastros API access
Access to the Mastros Cloudflare Worker API supports account synchronization, quota management, subscriptions, billing-portal access, purchase restoration, and configuration. Configuration retrieved from this endpoint consists of settings values only and never executable code.
PostHog access
Access to PostHog's European endpoint supports the pseudonymous product and reliability analytics described above.
Mastros limits its use of information obtained through Chrome permissions to providing, maintaining, securing, supporting, and improving the disclosed functionality. It does not sell information obtained through these permissions or use extracted LinkedIn data for unrelated advertising.
12. Data sharing and processors
Mastros does not sell or rent personal data.
Personal data may be processed by providers necessary to operate the Service, including:
- Cloudflare, for hosting, API infrastructure, databases, key-value storage, security, and website analytics;
- Stripe, for checkout, recurring payments, billing portals, invoices, tax-related functions, and fraud prevention;
- PostHog, for pseudonymous extension analytics and reliability monitoring;
- Google and Chrome, for extension distribution, identity permissions, browser storage, and synchronized storage;
- SplitForms, where used for website contact forms;
- email and support providers;
- professional advisers, such as accountants and lawyers; and
- public authorities where disclosure is legally required.
Providers are permitted to process information only for the relevant service, their lawful independent obligations, or as otherwise described in their own terms where they act as independent controllers.
We may also transfer relevant information as part of a merger, financing, restructuring, sale, or transfer of the Mastros business, subject to applicable law and appropriate confidentiality protections.
13. What Mastros does not do with extracted LinkedIn data
Mastros does not intentionally:
- upload complete exported LinkedIn datasets to Mastros servers;
- sell exported LinkedIn records;
- provide exported records to data brokers;
- use exported records to build advertising audiences;
- use exported profile, job, company, or post content to train general-purpose artificial-intelligence models;
- send messages or outreach to people in an exported dataset;
- determine the purpose for which you use an exported dataset; or
- independently enrich exported records with private contact information.
If you voluntarily send exported records to Mastros support, those specific records will be processed only as necessary to investigate your request, protect the Service, or comply with law.
14. Your role regarding exported data
You decide:
- which LinkedIn page to open;
- which extraction mode to use;
- how many records to request;
- whether to collect optional details;
- which file format to download;
- where to store the exported file;
- who receives it;
- how long it is retained; and
- how it is subsequently used.
Accordingly, you will generally act as the independent controller or responsible party for personal data contained in exported records.
You are responsible for:
- establishing a lawful basis;
- providing any required privacy notice;
- respecting objections and opt-outs;
- applying appropriate security and retention;
- responding to data-subject requests;
- complying with direct-marketing restrictions; and
- ensuring your processing does not unlawfully infringe privacy, intellectual-property, confidentiality, employment, or anti-discrimination rights.
Visibility on LinkedIn does not automatically mean that information may be freely collected, retained, republished, sold, or used for marketing.
15. Retention
Extracted datasets
Extracted datasets stored inside the extension remain locally until you delete them, clear browser or extension storage, reset the extension, or uninstall it, subject to Chrome's storage and synchronization behaviour. Downloaded files remain until you delete them from your device or other storage locations.
Account and subscription information
Account identifiers, plan status, usage totals, billing references, and subscription information are retained while necessary to provide the Service, manage subscriptions, prevent abuse, resolve disputes, and comply with accounting or legal obligations. Where an account is no longer required, information will be deleted or anonymized unless continued retention is necessary for a legal obligation, fraud prevention, security, or legal claim.
Payment records
Transaction, invoice, and tax-related records may be retained for the period required by applicable accounting and tax law.
Analytics
Pseudonymous analytics are retained for the period configured in Mastros' analytics system and are deleted or aggregated when no longer reasonably necessary for product measurement, security, and reliability.
Support communications
Support communications are retained for as long as reasonably necessary to resolve the request, maintain support history, prevent abuse, and establish or defend legal claims.
16. International data transfers
Mastros and its providers may process information in countries outside your country of residence.
Where personal data is transferred outside the European Economic Area, the transfer may rely on:
- an adequacy decision;
- approved standard contractual clauses;
- another legally recognized transfer mechanism; or
- a permitted legal exception.
You may contact admin@mastros.online for additional information about applicable safeguards.
17. Security
Mastros uses reasonable technical and organizational measures intended to protect information processed through its systems.
These measures may include:
- encrypted HTTPS connections;
- access controls;
- restricted backend credentials;
- separation between exported data and account systems;
- Stripe-hosted payment processing;
- pseudonymous analytics identifiers;
- analytics property allow-lists; and
- signed verification of Stripe webhook events.
No system is completely secure. Mastros cannot guarantee that information will never be lost, altered, accessed without authorization, or affected by a third-party vulnerability.
You are responsible for securing your device, browser profile, Google account, LinkedIn account, downloaded files, and any system into which you import data.
18. Your data-protection rights
Depending on your location and applicable law, you may have the right to:
- obtain information about personal data Mastros processes about you;
- request access to that data;
- request correction of inaccurate data;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent where processing relies on consent; and
- lodge a complaint with a competent supervisory authority.
These rights relate to data controlled by Mastros.
Because extracted LinkedIn records normally remain locally under your control, requests concerning those locally stored records should generally be handled by you through the extension, browser storage, downloaded files, or systems to which you transferred the data.
To exercise a right concerning information held by Mastros, contact admin@mastros.online. We may need to verify your identity before completing the request.
Where the GDPR applies, Mastros will normally respond within one month, subject to any lawful extension.
19. Deleting local and account information
You may remove locally stored information by:
- deleting datasets within the extension;
- clearing the extension's site or browser storage;
- deleting downloaded files;
- disabling Chrome Sync where relevant; or
- uninstalling the extension.
Uninstalling the extension does not automatically cancel a Stripe subscription or delete backend billing records.
To request deletion of account information held by Mastros, contact admin@mastros.online. Certain transaction, security, or legal records may need to be retained after an account deletion request.
20. Children
The Service is not directed to children under 16.
Mastros does not knowingly create subscriptions for or collect account information directly from children under 16. Contact admin@mastros.online if you believe a child has provided personal data to Mastros.
Users must not use the Service to systematically collect information about children where such activity is unlawful or inappropriate.
21. Automated decision-making
Mastros does not use personal data collected through the extension to make decisions that produce legal or similarly significant effects about LinkedIn members contained in exported datasets.
Automated systems may be used to:
- calculate plan usage;
- enforce subscription allowances;
- detect probable reinstalls or quota evasion;
- classify technical events; and
- temporarily restrict access where usage or payment conditions are not satisfied.
These operational decisions concern access to the Mastros Service and may be reviewed by contacting admin@mastros.online.
22. Do Not Track and marketing
The extension does not use extracted LinkedIn data for third-party behavioural advertising.
The website and extension may not respond to browser "Do Not Track" signals because there is no universally accepted technical standard for those signals.
Mastros may send transactional messages concerning subscriptions, payments, security, support, or material service changes. Marketing communications, where used, will include any opt-out mechanism required by applicable law.
23. Changes to this Privacy Policy
Mastros may update this Privacy Policy to reflect changes in the Service, providers, law, or processing practices.
The revision date will be updated at the top of the page. Material changes will be communicated through the website, extension, email, or another reasonable method where required by law.
24. Contact
Privacy requests and questions may be sent to Mastros at admin@mastros.online.