Security & Transparency
Privacy Policy
Effective Date: September 14, 2026 · Last Updated: September 14, 2026
This Privacy Policy describes how RevLabz Solutions LLP ("RevLabz", "we", "us", or "our") collects, uses, protects, and discloses information when you use our website (https://www.revlabz.ai), our web platform, and the RevSDR Chrome Browser Extension.
Summary of Our Privacy Commitments
- • We never sell your data: We do not sell, rent, trade, or monetize personal data or prospect information to third parties.
- • No broad web tracking: The RevSDR Chrome Extension does not record, track, or inspect your browsing history across the web outside LinkedIn.
- • User-initiated capture: Prospect records from LinkedIn are only extracted when explicitly commanded by the user.
- • Google API Limited Use Adherence: Use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- • Encrypted data handling: Communication uses TLS 1.3 in transit. Sensitive OAuth provider tokens are encrypted at rest with Fernet/AES on backend databases.
1. Information We Collect
We collect only the minimum data strictly required to deliver our sales automation and prospecting functionality:
A. Account & Authentication Information: When you sign in via Google OAuth or Microsoft OAuth, we collect your name, business email address, avatar, and authentication tokens to authenticate your session with RevSDR.
B. User-Initiated Prospect Data (Chrome Extension): When you click "Add to List" or run bulk search extraction on LinkedIn or Sales Navigator, the extension parses public profile information to populate your prospect lists:
- Full Name, professional headline, and current company name
- Job title, role, location, and public LinkedIn profile URL
- Public business email addresses or contact details where exposed
C. Connected Mailbox Information (Optional): If you connect a Google Workspace / Gmail account to dispatch outbound sales campaigns, we securely store encrypted OAuth refresh tokens on our backend to send approved messages and detect prospect replies.
D. Local Preferences: The extension stores session tokens and UI state locally using chrome.storage.local so you remain logged in across browser sessions.
2. Information We DO NOT Collect
RevLabz is built on strict data minimization principles. We explicitly do not collect:
- No Browsing History: We do not monitor, record, or transmit URLs or tabs you visit outside LinkedIn.
- No Financial Data: We never capture credit cards or payment credentials inside the extension.
- No Private Messages: We do not read or access your private LinkedIn direct messages or personal chats.
- No Keystroke Tracking: We do not log keystrokes, passwords, or background user activity.
3. How We Use Your Data
Collected data is used strictly to fulfill RevSDR's single purpose: sales prospecting and campaign execution:
- Organizing and managing prospect lists inside your private RevSDR workspace.
- Checking for duplicate records in real-time to avoid contacting the same lead twice.
- Syncing selected prospects to user-approved outreach drip sequences.
- Generating contextual, AI-assisted message drafts personalized to the prospect's public role and company.
- Delivering scheduled, user-approved email outreach and detecting replies.
4. Google API Services User Data Policy & Limited Use Disclosure
RevSDR's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy, including the Limited Use requirements.
- • No AI Model Training: RevSDR does NOT use Google user data (such as emails, recipient details, or profile information) to develop, train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models.
- • Limited Use: Google user data is accessed solely to provide user-facing features (authenticating your account and sending user-approved outreach emails from your connected mailbox).
- • No Data Reselling or Transfer: We do not transfer or disclose Google user data to third parties, except as strictly necessary to deliver or improve the user-facing functionality of RevSDR, comply with applicable law, or as part of a corporate merger or acquisition.
- • Human Review Restrictions: No human at RevLabz reads your Google email data unless: (1) you have provided explicit affirmative consent for a specific message (such as for customer technical support); (2) it is strictly necessary for security purposes, such as investigating abuse or a vulnerability; (3) required to comply with applicable law; or (4) the data is aggregated and de-identified for internal operations.
5. Chrome Extension Permissions Justification
Google Chrome Web Store requires explicit explanations for every permission requested by the extension:
| Permission |
Justification & Implementation |
identity |
Authenticates users with Google OAuth to connect their RevSDR workspace. |
storage |
Stores active list selections, session tokens, and preferences locally in the browser (chrome.storage.local). |
scripting & activeTab |
Renders the RevSDR prospecting sidebar on LinkedIn tabs. |
tabs |
Coordinates pagination across multi-page LinkedIn search result pages during bulk extraction. |
https://*.linkedin.com/* |
Reads public lead attributes (headline, title, company) and mounts the prospecting UI. |
RevSDR API Origin |
Transmits captured leads and fetches outreach sequences from your private workspace. |
6. Data Sharing & Third Parties
We do not sell user data. We do not share or distribute any prospect data with data brokers, advertisers, or third-party marketing companies.
We only transmit data to verified infrastructure providers (subprocessors) strictly necessary for hosting, authentication, and core functionality:
- Google Identity & Microsoft Entra ID: To authenticate your user account securely.
- Secure Cloud Infrastructure: Encrypted cloud database storage (MongoDB, PostgreSQL, Redis) for your customer workspace.
- AI Providers: OpenAI, Anthropic, or Google Gemini APIs for drafting messages, operated under enterprise privacy terms with zero retention for model training.
- Mailbox Delivery Providers: Gmail API and mailbox connectors used solely to send user-approved messages and detect replies.
7. Security & Data Retention
All network communications between the extension, your browser, and RevSDR servers are encrypted with HTTPS/TLS 1.3. Sensitive OAuth provider tokens are encrypted at rest with Fernet/AES-256 on backend servers.
You may delete any prospect, list, or campaign at any time directly through the RevSDR dashboard. Upon account closure, all associated data is permanently erased from active systems.
8. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you have the right to access, rectify, port, or request permanent deletion of your personal data. To exercise any statutory data privacy rights, email our team at support@revlabz.com.