Skip to content
Security

What it can read, and what it cannot

What can the Cuvy Chrome extension see?

The extension runs on the LinkedIn page you opened and reads what is rendered there. It asks Chrome for four permissions and two hosts, never for your password, and sends nothing from your account — no messages, no invitations. Lists live in your workspace, you can delete one at any time, and deletions are honoured within 30 days.

Chrome permissions
4
Sites it may run on
linkedin.com, app.cuvy.io
Password stored
None — you sign in to Cuvy
Deletion requests
Honoured within 30 days

50 addresses free every month · no card

Last updated

The shape of it

It reads a page. It does not hold an account.

The distinction that governs everything else on this page: Cuvy works in the browser you are already signed in to, rather than signing in from somewhere else.

Reading the page in your browser, against signing in from a server
RowCuvyA tool that signs in as you
Where the lookup startsThe page you openedA server, logged in as you
Your LinkedIn passwordNever asked forHeld, to keep the session alive
Where the code may runTwo hosts, enforced by ChromeAnywhere the account can reach
Messages and invitationsNone sentOften the point of it
When you sign out of LinkedInIt has nothing to readCarries on without you
What you can check before installingChrome's own permission listA page of assurances
The right-hand column describes the common alternative — a hosted tool that keeps your login and works while you are asleep — rather than a named product. The left-hand column is checkable: Chrome lists an extension's permissions under chrome://extensions at any time, and the manifest is in the package you install.
The permission list

Four permissions, and none of them is your browsing

This is the list Chrome shows under chrome://extensions. It is short on purpose, and it is the same list whether you are on the free plan or Scale.

sidePanel

Opens the panel beside the tab you are on. It is the panel you clicked, and it goes away when you close it.

storage

Keeps your Cuvy sign-in and your settings in the browser. No LinkedIn credential is ever part of that, because Cuvy is never given one.

notifications

Tells you a run has finished after you closed the tab. Switch it off in Chrome and the run still finishes.

alarms

A timer, so a long run survives Chrome putting the extension to sleep. It resumes what you started; it cannot start something you did not.

Plus two hosts: www.linkedin.com, where the panel draws itself, and app.cuvy.io, where your workspace is. There is no tab history permission, no cookie permission and no wildcard for the rest of the web.

What leaves the browser

The person in front of you, and nothing around them

What goes out
The details on the card you are looking at — a name, a title, a company, the profile URL — because that is what a lookup needs to work with. Cuvy does not walk your connections, open pages you did not open, or collect anything from the tabs beside it.
What is kept of your LinkedIn account
Nothing. No password, no copy of your session shipped to a server, no account of our own signing in behind the scenes. The only credential in the browser is your Cuvy sign-in, and it is the same one the web app uses.
What is sent from your account
No messages, no connection requests, no endorsements, no profile views beyond the pages you opened yourself. The extension reads and reports; there is no code in it that acts as you.
Deleting

Four steps, in order of how much you meant

Most people who say delete mean the list. Some mean the people. A few mean all of it, and that is a different request.

  1. Take a copy first, if you want one

    Settings, then Data and exports, then Download everything. It is every person the workspace holds in one CSV, built by the same export the rest of the app uses.

    One file
  2. Delete the list

    The list goes, along with its membership and the runs attached to it. The people in it stay in your workspace — usually they are in a second list too.

    The list only
  3. Delete the people to remove them properly

    The row goes and their profile photo is erased from storage with it, not merely unlinked from the row. They stop appearing in the app and in anything exported after that.

    Photo included
  4. Ask for the whole workspace, if that is what you meant

    Write from the address on the account to support@cuvy.io and say so. Deletion requests are honoured within 30 days, and you get a reply telling you when it was done.

    Within 30 days
What deletion means

The part most pages leave out

Deleting a list deletes the list. The people in it stay, and that is a decision rather than an oversight: the same person is usually in another list, and a delete that swept them out would turn re-importing them into a fresh charge for an address you had already bought. So the two actions are separate, and the app tells you how many people a list delete kept.

Deleting a person is the one that removes them. The row goes, their photo is erased from storage, and they are gone from every list at once. What stays is the ledger entry showing a credit was spent — that is an accounting record, and rewriting it would make your own invoice unverifiable.

An export already downloaded is a file on your machine and we cannot reach into it. Neither does deleting a person unpublish an address that was public somewhere before you ever looked them up; deletion removes what Cuvy holds, which is the only thing Cuvy can honestly promise about.

If you would rather not keep addresses indefinitely, a workspace can switch on an expiry — the setting on the Data and exports screen clears found addresses older than 24 months. The person stays, the address is wiped, and looking them up again afterwards costs nothing.

Security review

A questionnaire is answered by a person

There is no portal, no gated PDF and no badge.

Send it to support@cuvy.io in whatever format your procurement team uses — a spreadsheet, a portal invitation, a list of questions in an email — and somebody will fill it in and say where an answer is "not yet" rather than dressing it up.

Cuvy holds no third-party security certification. That is worth reading twice if your process requires one, because it means the answer to that row of your questionnaire is no, and no amount of asking will turn it into a yes this quarter. What can be described is behaviour: what the extension may run on, what leaves the browser, where a workspace's data sits, and how a deletion request is handled. The trust centre carries the current detail, and a DPA is available on request.

Questions

What a security review asks first

Which Chrome permissions does the extension declare?

Four — the side panel it draws in, storage for your Cuvy sign-in and settings, notifications for when a run finishes, and alarms so a long run survives the browser putting it to sleep. Two hosts go with them: www.linkedin.com and app.cuvy.io. There is no tab history permission, no cookie permission and no wildcard for the rest of the web, and Chrome lists them under chrome://extensions at any time.

If we uninstall the extension, what is left behind?

In the browser, nothing: Chrome removes what an extension kept in storage when it is removed, which here is your sign-in and your settings. What stays is your workspace on the web — the lists, the people and the credits — because that is the account rather than the extension, and it is there whether the extension is installed or not.

If we delete a person, is their address gone from Cuvy entirely?

It is gone from your workspace: the row, the photo and every list they were on. What a delete cannot reach is a sighting of that address that existed before you looked anybody up — that came from somewhere else and is not your workspace to erase. If it is their own data the person wants removed, that is a separate request and it is handled as one.

Can we make found addresses expire on their own?

Yes. A workspace can switch on an expiry — the setting offered today clears addresses older than 24 months — and after that the address is wiped from the row while the person stays. Exports you already took are untouched, and finding that person again later costs nothing, because they were charged for once.

Someone who is not a customer wants to know what you hold about them. What then?

They can ask, without an account, and the answer names where each sighting of their address came from rather than reciting the address back at them. They can also ask for it to be removed. support@cuvy.io routes both, and neither requires them to sign up for the thing they are asking to leave.

Where does a list actually sit while a run is going?

On Cuvy, not in the browser. The extension reads the results page and hands the rows over; the lookups happen on the server and each person is written into your workspace as they finish. Nothing is held in the extension itself, which is why closing the tab loses nothing and why uninstalling removes no data.