Privacy Policy — Dunno Session Connector
Last updated: 29 July 2026
Dunno Session Connector (“the extension”) connects your LinkedIn and Reddit sessions to your own Dunno account so Dunno can run automated outreach on your behalf. This policy explains exactly what the extension does with your data.
The short version
- The extension is network-free. It never sends your data to us or to any third-party server. It has no analytics, no tracking, and no telemetry.
- It reads your session cookies only after you explicitly click Connect (or consent to a manual export), and hands them only to a Dunno tab open in your own browser, over a same-origin browser message.
- Your Dunno account then uploads the session to Dunno’s own servers so your automations can run.
What data the extension accesses
When you start a connection, the extension reads the session cookies for the site you are connecting:
- LinkedIn — cookies on
linkedin.com(including theli_atsession cookie), read via Chrome’scookiespermission. - Reddit — cookies on
reddit.com, read the same way.
Alongside the cookies it collects minimal, non-sensitive metadata to make the session usable: the active tab’s URL and title, the cookie count, and your browser’s user-agent string.
The extension does not read your email, contacts, browsing history, page content, or cookies for any site other than the one you are connecting.
How the extension uses that data
There are two paths, both started by you:
- One-click connect (default). You click Connect on a LinkedIn or Reddit card inside a Dunno tab. The extension reads the session cookies and passes them to that Dunno tab using an in-browser
postMessage. The Dunno page uploads them to your Dunno account. - Manual export (advanced). You tick the consent box in the popup and click Capture, then Download or Copy. The session JSON is written to your own device (or clipboard). Nothing is transmitted by the extension.
In both cases the extension itself makes no network requests. Cookie values are never shown in the popup status area — they are redacted.
What the extension does not do
- It does not send data to the extension’s developers.
- It does not use analytics, tracking pixels, advertising IDs, or fingerprinting.
- It does not sell, rent, or share your data with third parties.
- It does not run in the background collecting data — it acts only when you start a connection.
Data retention
The extension stores no personal data persistently. It keeps only a small piece of transient state (chrome.storage.session) to track an in-progress sign-in, which is cleared as soon as the connection completes or the browser session ends.
Once your session reaches your Dunno account, its storage, encryption, and retention are handled by Dunno. You can disconnect or delete a stored session at any time from within Dunno.
Permissions and why they are needed
| Permission | Why it is required |
|---|---|
| cookies | Read the LinkedIn/Reddit session cookie so it can be connected. A web page cannot read these HttpOnly cookies itself. |
| tabs | Open the LinkedIn/Reddit login tab and hand the session to your Dunno tab. |
| activeTab | Detect which supported site the current tab is on for manual capture. |
| downloads | Save the session JSON to your device when you choose Manual export. |
| storage | Track an in-progress sign-in so the connection can complete reliably. |
| Host access to linkedin.com, reddit.com, and your Dunno domain | Read the session on those sites and relay it to your Dunno tab. |
Children
The extension is a business tool and is not directed to children under 13.
Changes to this policy
If this policy changes, the “Last updated” date above will change and the new version will be published at the same URL before the change takes effect.
Contact
Questions about this policy or your data: contact@comet.la.