Privacy Policy

Last updated: 2026-08-11

This policy covers the Quick Ping website, CRM, Chrome extension, and related services. If there is a conflict between older product copy and this page, this page controls unless we provide a more specific notice for a particular feature. Manage Gmail access.

Scope

Quick Ping operates a website and CRM at https://aquickping.com and a related Chrome extension. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website, CRM, Chrome extension, and related services.

This policy is the source of truth for both the website and the Chrome extension unless a product-specific notice explicitly says otherwise.

Information We Collect

We collect information you provide directly, information needed to operate your account and workspace, and limited technical information about how the service is used.

  • Account and workspace information, such as your name, email address, authentication details, billing or subscription details, and workspace settings.
  • CRM and productivity data that you choose to create, upload, import, or sync from non-Gmail sources, including records, notes, contacts, company details, and job application data.
  • Public-web and user-directed extension data, such as job-listing details you choose to capture while using the extension.
  • User-started LinkedIn enrichment records. One Start click begins an approved company/people flow, and one Verify click begins an approved profile check. Once started, completed approved pages automatically sync the research described in "How User-Started LinkedIn Enrichment Works" below; ordinary LinkedIn browsing does not start this enrichment or by itself sync an enrichment record.
  • Personal communications you explicitly choose to save. If you click save on a LinkedIn conversation, the text of the job-related messages in that thread is added to your CRM. Messages in the same thread that are not job-related are counted but their content is not sent. Your LinkedIn inbox is never read in the background — your conversations are collected only on that click.
  • Public LinkedIn hiring-post data, if you turn on the optional hiring-post scan in the extension. This includes personal information about people who are not Quick Ping users: the name, profile headline or job title, profile link, and post text of someone who has posted publicly about hiring. See "How The LinkedIn Hiring-Post Scan Works" below. This scanner is separate from user-started enrichment: it runs on a schedule once enabled, stores findings locally, and sends only an individual capture you choose to Keep.
  • Technical and operational data, such as device or browser details, log data, configuration state, diagnostics, timestamps, and connection events needed to run, secure, and troubleshoot the service.

How Gmail Access Works

If you choose to connect Gmail, the Chrome extension requests Google Gmail read-only access so Quick Ping can help identify prior applications, companies, stages, and recruiter context.

Quick Ping does not inject tools into Gmail.com, scrape Gmail.com pages, send email, compose email, modify messages, or delete messages.

Gmail is read only through the Gmail API at gmail.googleapis.com. Quick Ping does not load, inject into, or scrape Gmail.com web pages.

Gmail OAuth tokens stay in local Chrome extension storage and are never sent to our servers. Gmail message content — subjects, bodies, snippets, sender addresses, message and thread identifiers — is processed and stored on your device, and is never stored on or transmitted through our servers.

We want to state the boundary precisely rather than more broadly than we enforce it. A record that Gmail merely helped you notice is not itself Gmail content: the extension labels the values it takes from Gmail with where they came from, a value labelled Gmail is refused, and the remaining CRM row syncs to your workspace like any other. The application status you see in the cloud CRM is read from the job site page itself — the confirmation or rejection notice that site displayed to you — not from your mail. What never leaves your device is the Gmail message content itself and any value labelled as derived from it.

How that is enforced, stated as precisely as we can: the extension labels each record with where it came from, and our servers refuse any record whose label says Gmail, whose label they do not recognise, or that carries a raw email message. Records are also refused if they use a field name reserved for email content. We are deliberately not claiming that our servers can recognise email text that arrives with no label and under an ordinary field name — a note you typed and a paragraph pasted from an email look the same to software, and we would rather tell you where the boundary really is than describe a check we do not perform.

  • Requested Google Gmail scope: read-only.
  • Gmail.com extension injection: disabled.
  • Gmail.com page scraping: disabled.
  • User controls: you can disconnect Gmail in the extension, revoke Google account access, clear extension storage, or uninstall the extension. See /help/gmail-access for Gmail access management and deletion help.

How User-Started LinkedIn Enrichment Works

Ordinary LinkedIn browsing does not start this enrichment and does not by itself sync a LinkedIn enrichment record. The extension first requires one explicit click on Start for a company/people flow, or Verify for a profile check.

That one Start or Verify click begins the user-approved enrichment. After the click, each approved LinkedIn company, people-search, or profile page that finishes capture automatically saves its extracted research on your device and syncs it to your Quick Ping cloud CRM. There is no separate Keep decision for each completed page. The extension does not treat every LinkedIn page you visit as approved; the page must be the active step in the enrichment you started.

The synced person data can describe people who are not Quick Ping users. It can include names, profile headlines or job titles, LinkedIn profile URLs, profile-image URLs, publicly displayed locations, current-company matches and employment status, position titles, employers, position descriptions, and evidence text or snippets supporting the current-company match.

For up to the first 20 visible people-search results, the extension also uses your signed-in LinkedIn session to call LinkedIn’s authenticated /voyager/api/identity/profiles/{publicIdentifier}/profileView endpoint, with the base profile endpoint as a fallback. It can add the returned headline, location, positions, position descriptions, and evidence snippets to the company-research record before that automatic sync.

This user-started enrichment is separate from the optional hiring-post scan below. Enrichment pages sync after the initial Start or Verify approval without a per-page Keep step. The hiring-post scan follows a different boundary: it records scanner findings in Chrome extension storage and sends an individual capture to our servers only if you choose to Keep it.

  • Initial trigger: one explicit Start click for a company/people flow, or one explicit Verify click for a profile check.
  • Ordinary browsing: does not start this enrichment and does not by itself sync an enrichment record.
  • After approval: each completed approved page saves and syncs automatically, without a separate Keep decision for that page.
  • Authenticated people lookup: up to the first 20 visible people-search results through LinkedIn profileView, using the LinkedIn session already signed in in your browser.

How The LinkedIn Hiring-Post Scan Works

The Chrome extension includes an optional hiring-post scan that looks for public LinkedIn posts from people who say they are hiring. This is a separate feature from the user-started enrichment above, and it is off unless you turn on automatic scanning in the extension.

When you turn it on, this scan runs unattended and on a schedule. About once an hour, between 7am and 8pm in your local time, the extension opens LinkedIn search pages in background tabs using the LinkedIn session you are already signed in to, and reads the public posts in up to six searches. You do not need to be present, you do not need to be viewing LinkedIn, and no click is required for a scan to run. It keeps running on this schedule until you turn automatic scanning off or uninstall the extension.

The hiring-post scan itself reads public posts and public search results only. It does not open your LinkedIn inbox, and it does not use private LinkedIn APIs.

What this hiring-post scan finds is stored on your device first. Only when you choose to Keep a captured post is that individual capture sent to our servers and stored in your CRM workspace. That capture contains personal information about the person who wrote the post — their name, their profile headline or job title, their profile link, and the text of their post — even though that person is not a Quick Ping user and has not interacted with us. Keeping a post may also create contact, company, or job records for that person in your workspace.

If you use the CRM assistant, saved hiring-post captures can be read by deterministic CRM tools and templates to answer an explicit request. They are not sent to a remote model provider.

  • Automatic scanning: off unless you turn it on.
  • Schedule once enabled: roughly hourly, 7am to 8pm local time, running unattended in the background.
  • What is scanned: public LinkedIn posts and search results. LinkedIn private messages are not scanned.
  • For this hiring-post scan, what reaches our servers: only the captures you choose to Keep, not everything the scan finds.
  • Third-party personal data: names, job titles, profile links, and post text of people who posted publicly about hiring.
  • Retention: no fixed period, and no automatic deletion. See Data Retention below.
  • Your controls: turn automatic scanning off in the extension, dismiss captures instead of keeping them, delete kept records, or uninstall the extension.

How We Use Information

We use information to provide and maintain the service, authenticate users, operate the CRM and extension, improve performance and reliability, respond to support requests, prevent abuse, comply with legal obligations, and protect our users and systems.

We do not sell your personal information. We do not use Gmail message content for advertising, marketing profiles, or generalized model training.

Google API Data Commitments

When you connect Gmail, Quick Ping uses Google API data only to provide or improve user-facing features that you request, such as before-you-apply job search context.

Quick Ping's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Gmail API we use is one of the Google Workspace APIs, so where you connect a Google Workspace account, our handling of that data adheres to the Google User Data Policy on the same terms.

Except where required for security, legal compliance, fraud prevention, or with your affirmative direction, we do not allow humans to read restricted Google API content and we do not share restricted Google API content with third parties.

We do not scrape Gmail.com, build permanent copies of Gmail or Google Workspace user data, or use Gmail or Gmail-derived data to create, train, or improve generalized AI or machine learning models.

How We Share Information

We share information only as reasonably necessary to operate the service, comply with law, enforce our agreements, or protect rights, safety, and security.

  • Service providers that help us run the service, such as hosting, authentication, data storage, customer support, billing, or email delivery providers.
  • Professional advisers and counterparties in connection with legal, security, compliance, or corporate matters.
  • Law enforcement, regulators, or other parties when required by law or when we believe disclosure is reasonably necessary to protect users, the public, or the service.
  • A successor entity in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to applicable confidentiality and legal obligations.

Sub-Processors We Use

We use a small number of third-party providers to run the service. This list is checked on every build against three places in our codebase: the allow-list of outbound destinations our servers are permitted to reach, the scripts our web pages load into your browser, and the destinations the Chrome extension is permitted to connect to. A provider introduced on any of those three routes fails our build until it is named on this page.

We are deliberately not claiming that check covers every conceivable route a provider could be added by. It covers those three, and we would rather tell you which check we actually run than imply a broader one. If you want to know about a specific provider that is not named here, ask us.

Not everything below is contacted by our servers. Featurebase is loaded by your browser, and the on-device model files and public job listings are fetched by the Chrome extension on your device. We list them here anyway, because from your point of view the question is who receives your data, not which of our machines sent it.

Several of these are contacted only when you use the feature that calls them. If you do not use the research or contact-lookup features, those providers are not contacted on your behalf.

Gmail message content is processed and stored on your device, and is never stored on or transmitted through our servers. Records that Gmail merely helped you notice are ordinary CRM rows, and they sync to your workspace like any other, so they can reach the hosting and database providers below in the same way the rest of your CRM data does.

It is worth being exact about what the providers your own device contacts actually receive, rather than leaving it to the boundary above. Featurebase is given your email address, and that is the whole of what it gets from us. The Hugging Face request downloads model files onto your device rather than uploading anything to them. The job-board request carries a company public listing identifier.

  • Hosting for the website and CRM: Vercel.
  • Account sign-in and authentication: Clerk.
  • Cloud database that stores your workspace and CRM records: Convex.
  • Subscription billing: Stripe.
  • CRM assistant processing: remote model providers are disabled. Server-side assistant routes use deterministic rules, templates, and explicit tools. The Chrome extension can run supported models on your device; its prompts and records are not uploaded to a model provider.
  • Web search and page retrieval used by the research features: Firecrawl, Serper, DuckDuckGo, and Google. These receive the search terms and page addresses the feature builds, which can include company and person names taken from your records.
  • Finding and checking a contact address: Voila Norbert receives a contact first name, last name, and company domain; Reoon receives an email address to confirm it is deliverable.
  • Transactional email delivery: Resend, which receives the recipient address and the message we send.
  • Speech synthesis: server-side voice generation is disabled. Video renders remain silent unless narration is added through a supported on-device browser feature.
  • Integrations you connect yourself, such as Discord. These are contacted only after you connect them, and they receive what that integration is for — for Discord, the job title, company, status, and notes in the notification.
  • Product feedback, surveys, changelog, and the help widget: Featurebase. When you are signed in, our pages load a Featurebase script into your browser and give the survey widget your email address, so that your response and any feedback you send can be attributed to you. This one runs in your browser rather than on our servers, and it receives your email address whether or not you answer the survey.
  • On-device analysis model files for the Chrome extension: Hugging Face. When the extension runs its on-device analysis, it downloads the model files it needs from Hugging Face onto your device, and the analysis itself then runs locally. This is a download: your CRM records, and your Gmail message content, are not sent to Hugging Face.
  • Public job listings the Chrome extension reads: Greenhouse, Lever, and Ashby. When the extension checks whether a company has public openings, it asks that company public job board for its listings. The request carries the company public job-board identifier, not your data.
  • Job and recruiting websites the Chrome extension is permitted to open or read: LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, Workday, Ashby, SmartRecruiters, iCIMS, BambooHR, Workable, Jobvite, and Taleo. This browser permission lets the extension work on supported job pages; the permission alone does not upload your CRM records or Gmail data to those sites. LinkedIn can also be contacted by the user-started enrichment and optional hiring-post scan described above.

Data Retention

We retain account, workspace, CRM, and operational data for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce our agreements, and maintain legitimate business records.

To say that plainly for the cloud CRM: the records you create in the CRM, and the ones the extension syncs to your workspace, are held in our cloud database for as long as your account exists. There is no fixed retention period and no automatic expiry, and nothing deletes them on a schedule. They remain until you delete the record, delete your account, or ask us to delete them. We would rather state that than publish a retention schedule we do not actually enforce.

That same CRM retention applies to user-started LinkedIn enrichment records, including third-party names, profile details, locations, employment information, and evidence text that the approved pages automatically sync.

Hiring-post captures that you choose to keep, including the third-party names, job titles, profile links, and post text they contain, are stored on our servers with no fixed retention period. We want to be plain about this rather than imply a limit we do not enforce: there is no automatic expiry and nothing deletes these captures on a schedule. They remain until you delete the record in your workspace, delete your account, or ask us to delete them.

Deleting your account removes the user-scoped records covered by our account-deletion registry, including saved hiring-post captures. Linked child rows are deleted with their parent. Workspace-scoped records are deleted only when you are the workspace's sole remaining member, because deleting a shared workspace would erase other members' data.

Some records remain after account deletion. The account row is anonymized rather than erased. We retain limited billing and financial audit records, records that prove deletion was performed, shared product, job, and company reference records, platform-wide configuration and template records, and aggregate operational metrics that do not identify an account holder. A billing workspace record may retain the former owner's account ID and email alongside subscription identifiers.

Three known legacy shared-reference datasets do not yet carry a reliable account link. Because of that, third-party hiring-team details, sample business email addresses, or unattached entry backups in those datasets may remain after account deletion. Contact us at jovanny@aquickping.com if you want us to check for or remove records we can identify.

To have hiring-post captures or the CRM records created from them removed, delete them in your workspace or contact us at jovanny@aquickping.com and we will delete them for you.

If old Gmail-derived extension data exists locally from a previous version, it generally remains on your device unless you clear extension data, revoke prior Google access, or uninstall the extension.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, and alteration. No system is perfectly secure, and we cannot guarantee absolute security.

Your Choices And Rights

Depending on your location and the nature of your relationship with us, you may have rights to access, correct, export, or delete certain information. You may also be able to disconnect integrations, revoke Google access, or close your account.

To request deletion, export, or another privacy-related action, contact us at jovanny@aquickping.com.

For Gmail-specific controls, see our Gmail access help page at /help/gmail-access.

Children

The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes To This Policy

We may update this Privacy Policy from time to time. If we make a material change, we will update the effective date on this page and may provide additional notice where appropriate.

Contact

If you have questions about this Privacy Policy or our privacy practices, contact jovanny@aquickping.com.