Alpha: the Chrome Web Store listing is still in review. Download the extension and load it unpacked. Download for Chrome
Privacy · last updated 2026-10-06

Plain English.
Honest disclosure first.

This page summarizes how Listful, operated by Fulcop, Inc, treats LinkedIn sessions and export data. Questions? Email support@listful.so.
01

What we collect

  • We do not collect LinkedIn authentication cookies or other LinkedIn session credentials.
  • LinkedIn URLs you start exports from, plus the parsed rows built while assembling CSV files during those exports. Raw LinkedIn response bodies are not stored during the export, except page 0 of post comments and post reactions (needed to continue pagination). Those result rows are processed on Listful's servers.
  • The exported rows are other people's public LinkedIn data (for example names, headlines, companies, and public profile URLs) that your signed-in session can already see. We use them only to build your CSV, deliver your webhook, or keep the lists you create, and keep them for 24 hours without an account or 7 days with one (see Retention).
  • If you create Lists (Listful account only), the people from the exports you add to a list: name, headline, location, public profile URL, LinkedIn member id or public handle, and where you saw them (export type, LinkedIn link, date, and the comment text for post commenters).
  • Operational metadata needed to run the service — for example an HMAC of your LinkedIn member-id hash, export status, and timestamps.
  • If you use optional sign-in, we store the email address you verify and any settings you save (for example a webhook URL or a list's auto-add rule). Core CSV export in the extension does not require a Listful account.
02

How we use your LinkedIn session

  • The extension coordinates LinkedIn API requests using your signed-in session so rows reflect what LinkedIn shows you.
  • Your LinkedIn session stays in your browser. Listful receives parsed export rows (not raw LinkedIn response bodies, except page 0 of post comments and post reactions), not your authentication cookies.
03

What we don't do

  • Send connection requests, messages, posts, reactions, or comments on your behalf — read-only access for exports only.
  • Sell advertising profiles built from unrelated browsing outside the export flows described here.
  • Bypass LinkedIn authentication — we operate strictly within sessions you already established with LinkedIn.
04

Retention & revocation

  • The rare page-0 post response kept for pagination is deleted within 24 hours after an export finishes. If you pause an export, it is kept until you resume it, and deleted 26 hours after its last activity if you don't.
  • Parsed export rows and the CSV built from them are deleted 24 hours after an export finishes when it isn't linked to a Listful account. Exports linked to an account (you were signed in, or signed in within those 24 hours) are kept for 7 days so you can download them again, enrich them or add them to a list, then deleted.
  • The copy of exported rows kept so a webhook can retry or be replayed (webhook_payloads) is deleted after 7 days. Webhooks require an account.
  • People in a list are deleted 7 days after we last saw them in an export added to that list (seen again, the 7 days start over), when you remove them, or when you delete the list. List names, rules and per-export counts (no personal data) stay until you delete the list.
  • We keep up to 90 days of per-account export outcomes (surface, stop reason, row count, and time) so we can diagnose failures. We do not keep the LinkedIn URL, the CSV, or LinkedIn identifiers in that history.
  • Deleting your Listful account removes the account, export jobs, stored CSV results, lists and the people in them, and webhook configuration. Usage counters keyed only by an HMAC of your LinkedIn member id stay until the export cap window expires (they hold no identity beyond that hash).
  • Email support@listful.soto request deletion of retained operational records on our side. We'll comply subject to lawful retention obligations (and confirm timelines when those apply).
05

Processors & hosting

  • Vercel hosts the Next.js application surface serving marketing pages and /api routes. Vercel Web Analytics records anonymous page views on marketing pages and compatible app pages (Home, Settings, sign-in). Vercel Speed Insights records anonymous web vitals (performance) on the same surfaces. Those signals are not tied to the marketing analytics cookie and do not include LinkedIn session data. Admin pages and one-time sign-in links are not sent.
  • Neon Postgres stores structured operational state such as users, export metadata, webhook configuration when you set it, and auth-related tables.
  • Resend delivers transactional email for magic-link sign-in and support confirmations: your email address and the message content needed to send that email are processed by Resend as a subprocessor. Resend's own privacy notice governs how they handle data on their systems.
  • Docs Ask (optional) — when you use Ask on the site, the question and retrieved documentation snippets are sent to a model provider through Vercel AI Gateway to generate an answer. Cookies and LinkedIn session material are not included. We do not use Ask chats to train Listful models.
  • PostHog receives first-party product analytics (for example export and account events) and scrubbed server error reports from our application when the feature is enabled in our production environment. That data is stored in PostHog's US cloud. Those product events use the account or device identity already needed to run the product and do not rely on the marketing analytics cookie. Events sent from our servers do not include IP addresses, and email addresses are replaced by a keyed hash. The Support widget in your browser, loaded only when you escalate from Ask, sends the email you type into that form. Separately, when analytics cookies are accepted, marketing funnel clicks (for example Install CTA) are sent through our own API into the same PostHog project. Extension events (install, update, and whether a pasted link opened) go through that same API and do not include email or LinkedIn content. Export events recorded on our servers carry outcomes and counts — surface, pages, and stop reason — and do not include LinkedIn content. LinkedIn session cookies are not included. Listful does not use session replay, in the Chrome extension or on the site. Support ticket text from Ask escalate is stored in PostHog's US cloud.
06

LinkedIn & risk notice

LinkedIn's Terms discourage automated access. Listful only accesses lists your signed-in session already exposes to you and applies pacing/jitter, but automated exports remain inherently risky — rate limits or enforcement actions can occur even when behaving cautiously.

07

Who is responsible

Fulcop, Inc is the controller of account and operational data described on this page. For the exported LinkedIn rows, Fulcop, Inc acts on your instructions to assemble the CSV you asked for and to keep the lists you create. Contact: support@listful.so.

08

Legal basis

  • Contract: running exports, sign-in, webhooks, and support you request.
  • Legitimate interests: security, abuse prevention (rate limits), diagnosing failures, and product analytics that exclude IP addresses and raw email.
  • Consent: the optional marketing analytics cookie, which you can decline or withdraw at any time.
09

Your rights

Depending on where you live, you can ask to access, correct, export, or delete your personal data, object to or restrict processing, and withdraw consent. Email support@listful.so. If someone appears in an export and wants their row handled, write to the same address. Exports are deleted within 7 days at most, and people in lists 7 days after they were last seen, in any case. You can also complain to your local data protection authority.

Spot something stale? Email support@listful.so if this page is out of date — we update it as the product ships new phases.

Related: Terms · Security · Session identity