Your data, your rules

Security & Privacy

Managed storage supports features such as Unibox and campaigns. Export and deletion options follow the lifecycle and exceptions described in our Privacy Policy.

Your data, your rules

Managed storage powers features such as Unibox. Export and deletion options follow the lifecycle, limitations, and exceptions described in the Privacy Policy.

Controlled credential handling

Crispy supports hosted connection and direct credential or session-cookie methods. Connection material is sent to the connection provider and may be stored where technically needed to operate and secure the session.

API keys hashed at rest

API keys are stored as SHA-256 hashes. The plaintext key is shown once at creation and cannot be retrieved. Revoke any key instantly from the dashboard.

Permission scoping

Each connected profile has granular permission scopes. Restrict tools to read-only, outbound-only, or full access. Employees control their own scope.

Infrastructure

Hosted on Railway with Supabase database controls, including row-level security represented in repository migrations. Production regions and transport configuration still require verification.

Privacy controls

A DPA is available upon request for eligible customer agreements. Data-rights information is public; final execution terms, vendor contracts, regions, and transfer mechanisms require verification and approval.

What data touches our servers?

The service stores and processes the categories described below.

Data typeStored?Details
Contacts & activitiesManaged (default)Stored for Unibox & campaigns. Export and deletion options follow the Privacy Policy lifecycle
LinkedIn credentialsProvider-managedCredentials or session material can be received and transmitted to the connection provider and stored where technically necessary
API keysSHA-256 hash onlyPlaintext shown once, then discarded
Usage logs (tool name, timestamp)90 daysRate limiting & analytics only
Email & billingWhile activeLocal account teardown applies, while exact billing, vendor, audit, and legal retention schedules remain under review

Security FAQ

Do you need a DPA (Data Processing Agreement)?

Managed storage can process contact and activity data on your behalf. A DPA is available upon request for eligible customer agreements and becomes effective only through valid execution or incorporation.

What happens if Crispy gets breached?

Managed storage can contain contacts, messages, activity, and LinkedIn session material. API keys are SHA-256 hashed in the documented generation path. See the Privacy Policy and draft security annex for current limitations and pending verification.

Can my employer see my LinkedIn messages?

Only if you grant them access. Each team member controls their own permission scope. An admin can see usage logs (which tools were called) but message content is only accessible through the Unibox if the account is in their workspace.

How do daily safety limits work?

Crispy enforces per-profile daily action caps (connection requests, messages, posts) that stay within LinkedIn's acceptable usage patterns. These limits cannot be overridden, even by API.

Is Crispy SOC 2 certified?

Crispy itself is not SOC 2 certified. The repository uses Railway hosting and Supabase database controls, including row-level security migrations. Production transport, regions, and control effectiveness still require verification.

Can I run a pentest against Crispy?

Yes. Contact us at [email protected] to coordinate. We welcome responsible disclosure.

The complete LinkedIn API. Ready when you are.

Connect your first LinkedIn profile in under 5 minutes. Every tool, every seat, no feature gates. Safe limits, warm-up, and full permission control built in.