ProspectLens ("we", "our", or "the Extension") is dedicated to protecting user privacy, ensuring absolute transparency, and operating under a strict local-first, minimal-permission architecture. This Privacy Policy outlines what information ProspectLens analyzes, why specific permissions are required under Chrome Web Store policies, and how your data is handled.
1. Single Purpose Statement
In accordance with the Chrome Web Store Developer Program Policies, ProspectLens has a single, focused purpose:
ProspectLens does not function as a generalized web crawler, ad injector, browsing monitor, or affiliate tracker. All computational analysis is executed strictly on-demand when explicitly triggered by the user.
2. Information Analyzed & How It Is Handled
A. Public Business Information (Analyzed On-Demand)
When you open the side panel and initiate an analysis of a public website, ProspectLens parses the active tab's Document Object Model (DOM) to extract:
- Business Identity: Company or organization name, domain, brand category, and publicly displayed social media profile links (e.g., LinkedIn, X/Twitter, Facebook, Instagram, YouTube).
- Public Contact Points: Visible telephone numbers (hyperlinked via
tel:tags or visible regex patterns), publicly posted email addresses (hyperlinked viamailto:tags), and physical business addresses displayed in the page footer or contact sections. - Website Conversion Health Signals: Structural and technical elements such as primary hero headline clarity, presence of clear Call-To-Action (CTA) buttons, lead capture forms, customer testimonial badges, video embeds, viewport responsive tags, and Schema.org structured data.
B. Information We NEVER Collect or Access
- No Personal Browsing History: We do not track, monitor, log, or record URLs you visit outside of an explicit analysis click.
- No Keystrokes or Private Forms: We do not capture password fields, credit card inputs, search engine queries, or form submissions.
- No Personal Authentication Data: We do not inspect session cookies, authentication headers, tokens, or private accounts.
- No Automated Background Scraping: ProspectLens never executes in the background without user interaction.
- No Private Network Access: ProspectLens does not inspect intranet or local network endpoints without explicit user intent.
3. Chrome Extension Permissions Justification
ProspectLens requests only the minimum set of permissions necessary to deliver its core features. The justification for each declared permission in manifest.json is detailed below:
| Permission | Technical Need & Justification |
|---|---|
sidePanel |
Allows the extension to render the copilot workflow in Chrome's dedicated side panel companion view, keeping the target webpage fully visible without injecting intrusive overlays into the page. |
activeTab |
Grants temporary, user-consented access to inspect the DOM of the single webpage the user is actively viewing when they open the side panel or request an audit. |
scripting |
Enables programmatic injection of our lightweight, read-only extraction script into the active tab to safely inspect HTML elements and Schema.org markup. |
storage |
Permits the extension to save your prospect pipeline, user settings (such as your agency name and custom services), and audit history locally on your machine using chrome.storage.local. |
host_permissionshttp://*/*https://*/* |
Required to allow the user to analyze arbitrary public business websites across both HTTP and HTTPS protocols. No extraction occurs unless the user triggers the action. |
4. Local-First Architecture & Data Storage
ProspectLens operates on a Local-First philosophy:
- All prospect records, generated pitch copy, and executive audit summaries reside in your browser's local sandbox storage (
chrome.storage.local). - We do not operate remote databases that aggregate, store, or profile the prospects you analyze.
- Generated PDF documents (such as the 1-Click Client Growth Audit PDF) are compiled entirely within your browser using client-side JavaScript. No document generation request is sent to an external server.
5. Chrome Web Store User Data Compliance & Non-Sale Guarantee
ProspectLens strictly adheres to the Google Chrome Web Store Developer Program Policies, including the Limited Use requirements:
- No Sale of Data: We do not sell, rent, lease, or monetize user data, browsing information, or extracted prospect details to any third-party brokers, data aggregators, or advertising networks.
- No Ad Targeting: Extracted data is never utilized for targeted advertising, credit assessment, or personalized ad profiling.
- No Unrelated Use: Analyzed data is exclusively used to display conversion metrics and provide outreach suggestions inside the extension interface.
6. Regulatory Compliance & Protected Categories
ProspectLens incorporates automated non-scrape filtering (isRestrictedProspect) that programmatically excludes professional categories subject to strict solicitation and confidentiality regulations:
- Legal Practices: Law firms, attorneys, legal defense counsel, and solicitor chambers.
- Real Estate Brokerages: Real estate agencies and brokerages subject to MLS/IDX data protection rules.
When such websites are detected, ProspectLens halts automated extraction and alerts the user to respect industry-specific outreach standards.
7. Optional Third-Party Webhooks (GoHighLevel / Zapier / Make)
ProspectLens provides an optional feature allowing users to sync prospect data to external customer relationship management (CRM) systems:
- Webhook endpoints are configured entirely by the user in the extension Settings panel.
- ProspectLens only sends an HTTP POST request to the designated webhook URL when the user explicitly clicks "Sync to CRM".
- The payload transmitted contains only the public business contact details and audit summary currently displayed on screen.
8. User Control, Data Retention & Deletion
You maintain complete ownership and control over all data stored within ProspectLens:
- Export Data: You may export your entire saved pipeline at any time as an RFC-4180 compliant CSV file with UTF-8 BOM encoding.
- Purge Storage: You can wipe all saved prospects, audit histories, and configured settings at any time by navigating to Settings → Clear All Stored Data.
- Uninstall Deletion: Removing or uninstalling ProspectLens from Google Chrome instantly purges all data stored in
chrome.storage.local.
9. Security Architecture
ProspectLens complies with modern web extension security standards:
- Manifest V3 Compliance: Operates strictly under Manifest V3 specifications. Arbitrary code execution (e.g.
eval()) and remote script injection are completely disallowed. - Sanitized UI Rendering: All dynamic text retrieved from external web pages is sanitized and rendered via React text nodes to prevent Cross-Site Scripting (XSS).
- No Hardcoded API Secrets: The extension requires no client-side secret keys and handles operations through secure, user-managed configurations.
10. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. When changes are made, the "Last Updated" date at the top of this policy will be revised. Significant changes will be announced in release notes on our public GitHub repository.
11. Contact Information & Support
For inquiries regarding this Privacy Policy, permissions justification, or data handling practices, please contact our team: