Datamaxxing — Powered by ConvuLabs
Privacy Policy
This explains what Datamaxxing does with the data you give it — especially your LinkedIn archive, which contains personal data about other people. It applies to the Datamaxxing web app operated by ConvuLabs, based in Malmö, Sweden.
Last updated 29 July 2026. This page is maintained by ConvuLabs, based in Malmö, Sweden, and describes how Datamaxxing works today; it is not legal advice and not an independent certification.
1.Who is responsible for what
For your own account data — email address, name, LinkedIn URL and stated goals — ConvuLabs is the controller.
For the personal data about other people inside your LinkedIn archive, you are the controller and we act as your processor: we process it only to give you the analysis you asked for, only on your instructions, and we do not use it for our own purposes. You are responsible for having a lawful basis for that processing and for responding to those individuals' requests. This Policy, together with the Terms, forms our processing agreement with you; contact us if you require a separate DPA.
2.What stays on your device
When you upload a LinkedIn export, the ZIP is opened and parsed in your browser. The full parsed archive — connections, messages, comments, reactions, invitations, endorsements and any emails present in the export — is written to your browser's local storage (IndexedDB/localStorage) on that device. It is not uploaded to us in full, and it does not sync between your devices.
Because it lives in your browser, it can be lost by clearing site data, private browsing, browser storage eviction, or losing the device. Anyone with access to that browser profile can read it. Do not use a shared or public computer.
3.What leaves your device
The following is transmitted to our servers, and onward to the providers in clause 6:
- Analysis requests. For each person being ranked: a local row id (p1, p2 …) that means nothing outside your browser, their company, job title, a computed tie-strength score and a short summary of interaction signals (for example "12 DMs", "they invited me"). No name, no email address, no profile link and no message or comment text.
- Network shape requests. A sample of job titles and the most common company names, plus counts.
- Chat. Your question, plus a context block of aggregate counts and the same anonymous rows. People are referred to by row id only; their names are filled in on your device after the answer arrives.
- Draft messages. Company, title, why they matter and the shape of your history (counts and dates). The name is never sent — the model writes a placeholder that your browser replaces.
- Your setup answers. Goal, ICP, mechanism, wedge, geography, deal shape and competitors.
- Website reading. If you enter a company URL, our server fetches that public website and summarises it.
These requests are processed to generate a response and are not used to train third-party models. Names, email addresses, profile URLs and the text of messages and comments never leave your device at all — outbound requests are checked for them and blocked, and the server rejects them again on arrival. Whole archives, raw message logs and full contact lists are never uploaded.
4.What we store on our servers
- Account: email address, hashed authentication credentials or Google sign-in identifier, timestamps, and session tokens — handled by our authentication provider.
- Profile record: first and last name, email, LinkedIn URL and your stated goal, so Settings is not empty when you return.
- Operational logs: request metadata, IP address, user agent, timing and error traces, kept for security, abuse prevention and debugging.
Row-level security restricts your profile record to your own authenticated account.
5.Why we process it (legal bases)
- Performance of a contract — creating your account and delivering the analysis you requested.
- Legitimate interests — keeping the Service secure, preventing abuse, fixing faults and understanding aggregate usage; balanced against your rights.
- Consent — where you give it, for example for optional communications; you may withdraw it at any time.
- Legal obligation — where we must retain or disclose information by law.
- For third-party data in your archive, your instruction as controller is our basis for processing as your processor.
6.Who we share it with (subprocessors)
We do not sell personal data and we do not share it for advertising. We use:
- Lovable Cloud — application hosting, authentication and database, running on Supabase and Cloudflare infrastructure.
- The Lovable AI Gateway and the underlying model provider it routes to — inference for analysis, chat and drafted messages.
- Error and performance monitoring used by the hosting platform.
We may also disclose information where legally compelled, to enforce our Terms, or as part of a merger or acquisition (in which case this Policy continues to apply until replaced on notice).
7.International transfers
Our providers operate globally, so data may be processed outside your country, including in the United States. Where data leaves the EEA (including Sweden) we rely on appropriate safeguards such as the EU Standard Contractual Clauses, an adequacy decision, or any approved transfer mechanism under Swedish and EU data protection law. Contact us for details of the safeguards in place.
8.How long it is kept
- Archive and analysis in your browser: until you clear it in Settings, delete your account, or clear browser data. We cannot delete it remotely.
- Profile record and account: until you delete your account, after which it is removed immediately from our live systems and purged from routine backups within 30 days.
- Inference requests: retained only transiently by the AI provider for abuse monitoring, then deleted; not used for model training.
- Operational logs: typically up to 90 days, longer only where needed for a security investigation or legal obligation.
9.Security
Traffic is encrypted in transit with TLS, data at rest is encrypted by our infrastructure providers, database access is restricted by row-level security, and privileged operations run server-side only. Keeping the bulk of the archive on your device is itself a deliberate control — it means a breach of our servers cannot expose your message history.
No system is perfectly secure and we cannot guarantee absolute security. If a breach affecting your data occurs, we will notify you and any relevant regulator as required by law. Report a suspected vulnerability to legal@convulabs.com; please give us reasonable time to fix it before disclosing it publicly, and do not access other people's data while testing.
10.Cookies and local storage
We use strictly necessary browser storage only: an authentication session token, your theme and preference settings, and the local database holding your archive. We do not run advertising cookies or cross-site tracking.
11.Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, to portability, and to withdraw consent — under the EU GDPR and Swedish data protection law, and equivalent rights (including the right not to be discriminated against for exercising them) under the CCPA/CPRA and similar laws. We do not sell or "share" personal information as those laws define it.
Most rights are self-service: edit your details or wipe local data in Settings, and delete your account permanently from the same page. For anything else, or for a copy of your data, email legal@convulabs.com and we will respond within one month.
12.If you appear in someone's archive
If you believe your personal data was uploaded to Datamaxxing by one of your LinkedIn connections, please contact legal@convulabs.com. Because that user is the controller and the data sits in their browser, we will pass your request to them and assist them in responding; we will also delete anything held on our systems that relates to your request where we can identify it.
13.Automated decisions and profiling
The Service scores and categorises people using AI. These scores are suggestions for a human to review; the Service takes no decision about anyone by itself, and our Terms prohibit using it for decisions with legal or similarly significant effects, including hiring.
14.Children
The Service is not for anyone under 16 and we do not knowingly collect their data. If you believe a child's data has been provided, contact us and we will delete it.
15.Changes and contact
We will update this Policy as the Service changes and will notify you of material changes in the app or by email. For any privacy question, request or complaint, email legal@convulabs.com. If you are in Sweden or the EEA and are unhappy with our response, you may complain to your national data protection authority (in Sweden, the Swedish Authority for Privacy Protection — Integritetsskyddsmyndigheten, IMY).