Skip to content

Privacy Policy

For the Chrome extension "VScout - Agentic recruiting in the browser"

Chrome Web Store item ID: phfpblfpocjacdippjlhgfjjlajmmfjo

Last updated: September 25, 2026

This page is the dedicated privacy policy for the VScout Chrome extension. It describes the personal and sensitive user data the extension accesses, collects, uses, and shares, and the parties with which any such data is shared. For all other VScout services, see the main privacy policy.

Published by VScout (operated by Inevitable AI Group). Contact: admin@vscout.co.

Short version

  • We only read profile pages on linkedin.com and github.com, and only when you visit them. The extension reads no other site.
  • Your API key lives in Chrome's encrypted local storage on your device. We do not have access to it.
  • We use your microphone and a call tab's audio only when you press Record, and only until you stop. We never use your camera, do not track your browsing history, and do not sell or share your data with third parties for advertising.
  • Uninstalling the extension deletes everything it stored locally. Candidate records you saved into VScout are managed under your account settings.

1. Data the extension collects (Chrome Web Store categories)

The VScout Chrome extension accesses and collects the following categories of personal or sensitive user data, as defined by the Chrome Web Store Developer Program Policies:

  • Personally identifiable information - the user's VScout account name and email address (used to authenticate API calls).
  • Authentication information - the user's VScout API key, stored locally in chrome.storage.sync on the user's device.
  • Website content - the public profile DOM on linkedin.com and github.com that the user chooses to source (name, title, company, location, headline, skills, public bio, repositories visible on the profile).
  • Personal communications (audio) - only when the user presses Record: the audio of the call tab they chose and their microphone, for the interview they picked. It is kept on the device only until the upload to their VScout account is confirmed.

How we use this data: only to provide the recruiting service the user signed up for in their VScout account (adding candidates, running searches, chatting with the VScout agent, and recording or transcribing interviews). This data is not sold, not shared with third parties for advertising, and not used to train AI models.

Parties with which data is shared: see Section 5 (Third parties) below.

2. What the extension reads

When you visit a LinkedIn or GitHub profile while signed into the extension, the extension reads the public information visible on that page so it can offer to add the candidate to your VScout pipeline. This includes:

  • Name, current title, current company
  • Location, headline, profile URL
  • Visible skills, listed experience, public bio
  • For GitHub: username, repositories visible on the profile, primary languages

The extension does not read messages, private connections, your inbox, or any content behind a login wall other than the profile you are viewing. It reads no other site. The only other thing it can capture is the audio of a call tab you explicitly record (Section 4).

3. What is stored locally

Chrome's chrome.storage.sync (encrypted) holds, on your device:

  • Your VScout API key (used to authenticate API calls)
  • Your VScout base URL (defaults to https://app.vscout.co)
  • The current chat conversation ID, so the side panel can resume sessions
  • While you record, the recording itself (in the extension's IndexedDB), so a crash or a closed laptop never loses the interview. It is deleted as soon as VScout confirms the upload, or when you discard it.

We do not have access to this storage. Uninstalling the extension deletes it.

4. What is sent to VScout servers

When you click "Add to VScout" or send a chat message, the extension makes an authenticated HTTPS request to app.vscout.co (or to your self-hosted VScout instance, if you configured one) containing:

  • The candidate data you chose to add (name, title, URL, skills, notes)
  • Your chat messages and the active page context for grounding
  • When you record an interview: the audio file, uploaded to your VScout account's storage and attached to that interview
  • The standard request headers (browser version, IP) needed to make HTTPS work

All requests are authenticated with your API key. Data sent to VScout is governed by the main VScout privacy policy.

5. Third parties

The extension itself does not call third-party services directly. When you launch the interview notetaker, the VScout server dispatches a bot via Recall.ai to join your meeting; recording and transcription are handled there per their privacy policy. When you record a call in the browser instead, the VScout server sends that recording to Google's Gemini API to transcribe it; the copy there is deleted once the transcript is returned.

We do not sell, rent, or share your data with advertisers or data brokers. We do not use your data to train models without your account-level consent.

6. Why each Chrome permission is needed

  • storage - Persist your API key, base URL, and chat conversation ID locally so you stay signed in.
  • activeTab - Read the active tab URL when you click the toolbar icon to auto-detect Zoom/Meet/Teams meeting URLs.
  • tabCapture (asked for the first time you press Record) - Capture the audio of the call tab you chose to record. Chrome only allows it on a tab where you clicked the VScout icon, the right-click item, or the shortcut.
  • offscreen - Keep a recording running when the side panel is closed.
  • alarms - Schedule the slow background task that fills in missing candidate photos.
  • sidePanel - Open the VScout chat in Chrome's native side panel.
  • contextMenus - Right-click "Add to VScout" on LinkedIn or GitHub links, and "Record this call with VScout" on a meeting page.
  • tabs - Open the connect flow and candidate detail pages in new tabs.
  • Host access to linkedin.com / github.com - Read the profile DOM you are viewing so it can be saved as a candidate.
  • Host access to media.licdn.com - Download the profile photo of a candidate you saved, from their own LinkedIn profile.
  • Host access to app.vscout.co - Send candidate creates, search, and chat-stream traffic to the VScout API.

7. Deleting your data

Local data: Uninstall the extension from chrome://extensions. Chrome deletes the extension's local storage on uninstall.

Server data: Delete candidates, conversations, or your whole account from VScout settings. Full account deletion follows the schedule in the main privacy policy (30-day soft delete, then permanent erasure).

8. Children

VScout and the VScout Chrome extension are not intended for users under 16. We do not knowingly collect data from anyone under 16.

9. Changes

If we change how the extension handles data, we will update this page and, where the change is material, notify signed-in users via in-product banner or email.

10. Contact

Questions about this policy or about specific data the extension has touched, write to admin@vscout.co. We aim to reply within 2 business days.

For data subject requests under GDPR, CCPA, or other regimes, see the main privacy policy → Your rights.
Privacy Policy - Chrome Extension | VScout