Extension privacy policy
Lidoru
Last updated: 2026-08-03
What this extension reads
- LinkedIn session cookie (JSESSIONID) - read locally from your own browser's cookie jar. Used as a CSRF token for the Easy Apply API calls the extension makes on your behalf. Never transmitted to Lidoru servers or any third party.
- Form structure on LinkedIn Easy Apply pages - the extension fetches the job application form definition from LinkedIn so it can fill fields with answers from your Lidoru profile.
- Supporting LinkedIn data - to prepare the queued Easy Apply flow, the extension fetches your own LinkedIn profile (name, headline, location), job-posting metadata, job-seeker preferences, and notification counts. The extension does NOT read message bodies, connection lists, or content on other users' profiles.
- Browser environment - timezone, language, and display resolution from your browser. These values are embedded in the
x-li-trackheader sent to LinkedIn alongside the Easy Apply API calls, matching what your own browser would send when you use linkedin.com directly. They are never sent to Lidoru servers.
What is sent to Lidoru servers
All traffic goes to lidoru.com over HTTPS.
- Submission outcome for each application you queue (applied / failed / skipped) plus a snapshot of the form fields that were filled, minus your LinkedIn session cookie.
- Health events (HTTP 429, CAPTCHA encountered, auth errors) used to power the kill switch that protects your LinkedIn account when dispatch looks unsafe.
- Your profile answers and tailored resume content, for the resume-on-dispatch tailoring step.
What is NEVER collected or transmitted
- Your LinkedIn login credentials (email / password). The extension only operates inside your already-authenticated session.
- The value of your LinkedIn session cookie (JSESSIONID, li_at, etc.). The cookie is read locally for CSRF binding but never leaves your browser.
- Messages, connection requests, or content on other users' profiles.
- Your browsing history outside linkedin.com or the Lidoru dashboard.
- Financial or payment information, health information, or precise geolocation.
Data use
- Not sold to third parties.
- Not used or transferred for purposes unrelated to filling job applications on your behalf.
- Not used or transferred to determine creditworthiness or for lending purposes.
- Lidoru's use and transfer of information received from Chrome extension APIs and the user's browsing session adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Kill switch
The extension polls a backend-controlled flag every minute. If Lidoru flips the kill switch (for example in response to a takedown request or to protect accounts during a LinkedIn incident), the extension stops dispatching new applications within one minute.