Privacy Policy
Last updated 10 September 2026
Wyatt is a Chrome extension that browses LinkedIn, X, and Instagram in your own browser, under your own logged-in session, to find people matching a description you write and to draft messages to them. This page explains what leaves your browser, who it goes to, and how long it is kept.
The short version
- Wyatt works inside your browser. We never receive your platform passwords, your session cookies, or the ability to sign in as you.
- To judge a person and draft a message, the profile details Wyatt read from the page are sent to our server and on to a language-model provider. We keep the cost and token record of that call, not the message.
- We do not sell personal data. We do not use anything Wyatt read for you — the profiles, the drafts, the people you found — to target advertising.
- Wyatt reads pages only while a run you started is going. It is not a background tracker of your browsing.
What we collect
Your account
When you create an account we store your email address, a scrypt hash of your password, the time you signed up, and an anonymous install identifier generated by the extension. If you arrived from an ad we store the campaign parameters from that link. Your session is stored as a SHA-256 hash of the session token, so a copy of our database does not let anyone sign in as you.
Payments
Payments are processed by Stripe. Card numbers are entered into Stripe’s own fields and never reach our servers. We store the Stripe customer identifier, the identifier of a saved payment method, your auto top-up preferences, and a ledger of the time you have purchased. Stripe’s handling of your payment details is governed by its own privacy policy.
What Wyatt reads while it runs
During a run, Wyatt reads the pages you sent it to: search results, and the public profiles of the people it finds. The details it takes from a profile — name, headline, employer, location, recent posts, and the profile URL — are sent to our server, which passes them to a language-model provider to decide whether that person fits your description and to draft a message. Where a page cannot be read from its markup, Wyatt captures an image of the visible tab and sends that image to the same provider to be read. Those images are used for that one request and are not stored.
To plan a search and to check what it finds, the model may also search the open web. We record which pages it was given, alongside the cost of the call.
Contact details of the people you find
When you ask Wyatt for a work email address, we send that person’s profile URL to a third-party business-contact data provider and store what comes back: their work history, their current employer, and a work email address with the provider’s assessment of whether it is deliverable. That record is keyed by the profile URL and is shared between accounts, because a person’s work history does not depend on who is asking. It carries no record of which user requested it. It is kept until deleted on request.
Operational records
We log each call to a model or a data provider: the time, the route, the model, the number of tokens, the cost, and whether it succeeded. These records carry your user or install identifier, so we can tell what an account costs to serve. We also count how many result pages were read per platform per hour, with no identifier attached, so we can tell when a platform has changed its layout.
Product events — that a run started, that a step finished — are written to our server logs and read in aggregate.
Stored on your own machine
The extension keeps the state of a run in Chrome’s local storage: where the run got to, the people already seen, your saved settings, the install identifier, and the time you installed. This stays on your computer. Only the install identifier is ever sent to us, and — while we are running ads, and only if you arrived from one — on to Meta as described under Advertising below.
Who we share it with
We use a small number of processors and share with each only what it needs to do its job: OpenRouter, which routes requests to language-model providers; a business-contact data provider, for the work histories and email addresses described above; Stripe, for payments; Vercel, which hosts our application; Turso, which hosts our database; and, while we are running ads, Meta — described in full in the next section. We do not sell personal data or share it with data brokers. We will disclose data where the law requires it.
Advertising and this website
While we are running ads, we tell Meta when someone who came from one of them reaches a milestone, so we can work out which ads are worth paying for. The milestones are: a page on this site was viewed, Wyatt was opened for the first time, a first search was started, an account was created, and a card was added. That is the whole list. Meta can also use it to show you Wyatt’s ads again elsewhere.
This reaches Meta two ways, and you should know about both:
- In your browser. Pages on hirewyatt.com load Meta’s pixel, which sets a cookie. A tracker blocker stops it, with no effect on the product.
- From our server. We send the same milestones to Meta’s Conversions API. This is how the first search is counted at all — it happens in the side panel, where there is no web page for a pixel to sit on. With it we send your IP address, your browser’s user-agent string, the Facebook click identifier from the ad you arrived on, and your anonymous install identifier. Blocking scripts does not stop this half.
What we never send is the work. No profile Wyatt read, no person it found, no message it drafted, and no search you wrote reaches Meta or any other advertising service, and none of it is used to target advertising — the milestone we send says a search started, never what it was for. The pixel is not in the extension.
If you would rather none of it happened: the pixel and the server-side events both key on having arrived from an ad, so a visit that did not come from one carries no click identifier to match. You can opt out of this kind of ad targeting in your Meta account settings, and you can ask us to delete your records at any time.
The permission Chrome asks you to grant
Chrome warns that Wyatt can read and change data on all websites. It needs that because you choose which network to search, and because a run has to follow links to profiles wherever they lead. Wyatt injects its reader only into a tab belonging to a run you started, and only on the platform that run targets. It does not read the other tabs you have open.
How long we keep it
- Your account and purchase ledger: until you ask us to delete the account.
- Sessions: until you sign out, or the session is revoked.
- Model and provider call records: kept for cost accounting, and pruned by age.
- Contact records for the people you looked up: until deleted on request.
- Screenshots and drafted messages: not stored.
Your choices
You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Deleting your account removes your account record, your sessions, your ledger, and your run history. You can also ask us to delete the record we hold for a particular person, whether or not that person is you — send us the profile URL. Clearing the extension’s data in Chrome removes everything stored on your machine.
Depending on where you live you may have further rights over your personal data, including the right to object to processing and to complain to a data protection authority.
Children
Wyatt is a tool for work and is not intended for anyone under 16.
Changes
If this policy changes we will update the date at the top of this page. Material changes will be announced in the extension before they take effect.
Contact
Write to support@hirewyatt.com for access, correction, or deletion requests, or with any question about this policy.