Skip to content
← Back to ClientRadar

Privacy Policy

Last updated 1 August 2026

This Privacy Policy explains what information ClientRadar processes, why, where it is stored, and who it is shared with. It covers both the ClientRadar browser extension and the getclientradar.com website. ClientRadar is a browser extension that helps freelancers, consultants and small agencies find and reply to potential clients on the social platforms they already use.

1. Who we are

ClientRadar is operated by the company below, the data controller for the purposes of the EU General Data Protection Regulation (GDPR):

Global Charity Solutions Kft.
Vajda János utca 25., 2120 Dunakeszi, Hungary
Company registration number (Cégjegyzékszám): 13-09-212415
Tax number (Adószám): 29210727-2-13
Email: [email protected]

2. What ClientRadar does (its single purpose)

ClientRadar watches the Facebook Groups, Reddit communities, X feeds and LinkedIn feeds you already belong to, using your own logged-in browser session, and flags public posts where somebody is asking for the kind of help you sell. It then drafts a reply that you review and send yourself. Every data practice described below exists to serve that single purpose. ClientRadar never posts, comments or messages on its own — nothing is published until you press send.

3. What the extension collects, uses, stores and shares

This section states the extension's data practices in the categories used by the Chrome Web Store user-data disclosure: what is collected, how it is used, where it is stored and for how long, and who it is shared with.

DataCollected?How we use itWhere it is stored & for how longWho it is shared with
Personal communications — public posts, comments and threads on Facebook, Reddit, X and LinkedIn that you choose to scan, including author names and handles as they appear publiclyYes — read in your browser; the text is sent to our backend only when a score or a draft is generatedSolely to score buying intent and draft your repliesResults and lead cards are stored locally on your device until you delete them; our servers process the text transiently and keep only a short-lived cached scoring result (section 9)Shared transiently with our AI sub-processors DeepSeek and Anthropic to generate the result — nobody else
Website content — the text of the platform pages the extension reads inside your logged-in sessionYes — read in your browser; sent to our backend only when an AI feature you trigger needs itSolely to find, score and reply to potential clientsStored locally on your device until you delete it; server-side processing is transient (section 9)Shared transiently with DeepSeek and Anthropic to generate the result — nobody else
Authentication information — the session and CSRF cookies your browser already holds for the platforms you connect (see section 4 for the exact cookie names)Yes — read locally, on your device onlySolely to make requests inside your own logged-in session, exactly as the platform's own website would, and to tell which of your accounts is active so data from one account is never shown under anotherHeld only in memory for the duration of the request. Never written to our servers, never written to disk by us, never included in any request to ClientRadarNobody. Cookie values are sent only to the platform they came from (for example the Reddit token is sent only to oauth.reddit.com). They are never transmitted to ClientRadar or to any third party
Your Brand DNA & settings — first-party details you type in yourself (your offer, voice, niche and keywords)Yes — stored locally in your browserSent along with AI requests to personalize your scores and draftsOn your device until you delete it; not retained server-sideOnly the AI sub-processors above, as part of the request — not shared beyond them
Licence & usage data — your licence key, an anonymous install identifier, counters of how much AI you have used, and — only if you pair a phone with Pocket Radar — a random paired-device identifier plus a one-way hash of that device's secretYesTo validate your plan, meter AI credits fairly, let a paired phone prove it is yours, and keep the service secureOn our Cloudflare backend for as long as your licence is active (section 14); the paired-device credential is destroyed when you unpairCloudflare, as our hosting sub-processor. Not shared with anyone else
Encrypted lead data (Pocket Radar) — the individual leads you choose to send to your phone, encrypted on your own computer before they are sentOnly if you turn on Pocket Radar — the feature is off until you doSolely to carry that lead to your paired phone so you can read, approve or dismiss it thereOn our Cloudflare backend as ciphertext we cannot decrypt, for up to 24 hours — and deleted sooner, as soon as you act on itNobody. Cloudflare stores the ciphertext as our hosting sub-processor; the decryption key is generated on your computer and travels only to your phone, so no party — including us — can read it
Push notification address (Pocket Radar) — the endpoint your phone's own push service issues for your phone. This is a device-specific identifier, not an anonymous counterOnly if you turn on Pocket Radar and allow notifications on your phoneSolely to send a content-free "you have leads waiting" ping — it carries no lead textOn our Cloudflare backend while that phone stays paired; deleted when you unpair, when you turn notifications off, or when the push service reports the subscription expiredYour phone's own push service — Apple, Google or Mozilla, depending on your phone and browser — which is the only party able to deliver the ping
Email address (Pocket Radar fallback, optional) — one address you type in yourselfOnly if you switch the email fallback on — it is off unless you doSolely to email you a count and a link when a lead is waiting and the push did not arriveOn our Cloudflare backend until you switch the fallback off or unpairResend, our transactional email provider, to deliver that message

4. Your logged-in platform sessions and cookies

ClientRadar deliberately has no relay servers, no shared bots and no scraping farm. It works by making requests from your own browser, inside the session you are already logged into. To do that the same way the platform's own website does, the extension reads a small number of session and CSRF cookies that your browser already holds. We disclose them by name:

PlatformCookie the extension readsWhy
Facebookc_user, i_userTo identify which of your Facebook accounts (or Pages) is currently active, so leads and history from one account are never shown under another
Reddittoken_v2Your Reddit web session's own OAuth token. It is used as the Authorization header on requests to oauth.reddit.com — the same endpoint Reddit's own site uses — so that reading and replying happen as you, through Reddit's official API rather than by scraping. How it is located: Reddit stores this cookie under different hosts and partitions depending on how you signed in, so if a direct lookup misses, ClientRadar asks Chrome for the reddit.com cookie list and picks out the entry named token_v2. Any other Reddit cookie returned by that lookup is discarded unread in the same instant — none is stored, sent anywhere or used for anything
Xct0X's CSRF token. X rejects requests without it; it is sent back to X as the x-csrf-token header
LinkedInJSESSIONIDLinkedIn's CSRF token. It is sent back to LinkedIn as the csrf-token header

What this means in practice, stated plainly:

  • These values are read on your device only and used only in requests back to the platform they came from.
  • They are never transmitted to ClientRadar's servers, never stored in our database, never logged, and never shared with any third party — including our AI providers.
  • They are never publicly disclosed in any form.
  • We never ask for, see, receive or store your passwords for any platform. ClientRadar has no login form for Facebook, Reddit, X or LinkedIn, because it never needs one.
  • If you log out of a platform, ClientRadar simply stops working for that platform. It cannot and does not keep a copy of your session.

Posting as one of your own Facebook Pages

Facebook decides which identity authors a post from the value of its own i_user cookie. So when you choose to publish or comment as one of your own Facebook Pages, ClientRadar temporarily sets that cookie to the Page's ID for the duration of that single action and then always restores your previous value immediately afterwards. This is the only cookie ClientRadar ever writes, it only ever happens on facebook.com, it only happens for an action you initiated, and it only ever switches between identities that are already yours. No cookie is created, read or written for any other website.

5. Browser permissions and why ClientRadar needs them

Chrome shows you the permissions an extension requests at install time. Here is what each one is for, and what it is not used for.

PermissionWhat ClientRadar uses it for
storage, unlimitedStorageStores your leads, notes, pipeline, settings and Brand DNA locally on your device. Your lead database has no server-side copy, so the raised quota exists to stop Chrome silently evicting your own business records. It transmits nothing.
cookiesReads the session and CSRF cookies listed in section 4, and temporarily sets Facebook's i_user when you choose to act as your own Page. Values never leave your device.
tabsKeeps the single pinned ClientRadar dashboard tab alive so scheduled scans can run, and opens a platform's own login page when you click "connect". When it looks for its own dashboard, it asks Chrome only for tabs whose address is ClientRadar's own extension page — so the other tabs you have open are never returned to it, never inspected and never recorded.
alarmsRuns the periodic, human-paced scan on a schedule.
notificationsTells you when a new high-intent lead is found.
offscreenRuns the scan loop in an offscreen document so it keeps working when the tab is in the background.
webRequestPassive observation, limited to x.com API traffic. X rotates the internal identifiers of its own GraphQL operations, which breaks integrations that hard-code them. ClientRadar watches request URLs matching x.com/i/api/graphql/* in your own browsing and reads the current operation identifier out of the URL, so the X integration keeps working when X changes it. Only that identifier is kept — stored locally on your device. No URL, no page content, no browsing history and nothing about your activity is stored or transmitted, and nothing is blocked or modified.
declarativeNetRequestNormalizes request headers (Origin, Referer, Sec-Fetch-*) and relaxes framing/CSP response headers, only on requests to facebook.com, reddit.com, x.com, linkedin.com and Facebook's own media CDN fbcdn.net (which serves the post images and avatars shown in your lead list), so the extension can read the public posts you can already see as the logged-in user, without a third-party proxy. These rules are declarative: Chrome applies them, and the extension does not get to read the traffic through them. No authentication token is injected and no user data is exfiltrated.
Site access — facebook.com, reddit.com, x.com, linkedin.com, and the platforms' own media CDNs (abs.twimg.com, licdn.com)The four supported platforms and the CDNs they serve their own images and avatars from. ClientRadar does not request access to all websites, and has no access to any other site you visit. Our own backend (api.getclientradar.com) is deliberately not in this list: it needs no site-access permission, because it answers the extension's requests under ordinary cross-origin rules like any public API.
Optional site access — https://*/*Never requested at install. Chrome asks you for this at the moment you add an outbound webhook (Slack, Discord, Zapier), purely so we can POST your new-lead notifications to the URL you chose. If you never add a webhook, it is never requested and never granted.
Content script on facebook.com/messages/*A single small script whose only job is to write a draft you already approved into the Messenger composer, so you do not have to paste it. It does not read your messages or conversations, makes no network request of any kind, and never sends — you review the text and click send yourself.

6. Data stored locally on your device

Your leads, contacts, notes, pipeline stages, tracked keywords, target groups, settings and your Brand DNA are stored locally in your browser's storage. By default this information stays on your device and we keep no copy of it, except where it is needed transiently to run an AI feature you trigger. There is one deliberate exception and it exists only if you switch it on: Pocket Radar (section 9) sends the individual leads you pick to your own paired phone, and to get them there it holds them on our servers as encrypted ciphertext we cannot read, for up to 24 hours or until you act on them. Nothing else in your local database is copied to us. You can export or delete all of it at any time from within the extension, and uninstalling the extension removes it.

7. How the AI features work

When you ask ClientRadar to score a post or draft a reply, the relevant text (the public post's text and your Brand DNA) is sent over an encrypted connection to our backend on Cloudflare Workers, which relays it to our AI providers — DeepSeek and Anthropic — to generate the result and return it to you. This happens only when ClientRadar actually checks a post or you request a draft. We use it to produce your scores and drafts. We do not build a hidden profile of you, we do not sell it, and we do not use your content to train our own models.

8. What else the extension sends, and to whom

Beyond the AI requests in section 7, the extension makes the following requests — and no others:

Licence validation and AI metering. Your licence key, an anonymous install identifier and counters of AI usage, so we can confirm your plan and meter credits fairly.

A live connection while Pocket Radar is paired. If — and only if — you have paired a phone, your computer holds an open WebSocket to api.getclientradar.com so an approval you make on your phone reaches your computer in seconds instead of waiting for the next poll. It stays open while the extension is running and reconnects if it drops. What travels over it is the same material described in section 9: encrypted lead items your phone can read and we cannot, the approvals coming back, and small keep-alive and presence messages so each end knows the other is there. With Pocket Radar off, this connection is never opened.

Reliability signals. When scanning structurally breaks on a platform — for example after that platform changes its site and our reader needs updating — ClientRadar sends an aggregated, anonymised reliability signal so we can detect and fix the break quickly. It contains only the platform name, a short failure-class label and the extension version. It carries no account identity and no lead content.

Fleet safety counters. To publish our public Ban-Risk Index, ClientRadar counts anonymised, identity-free safety events — scans, replies, posts and cooldowns, per platform — across all active installs. These are plain totals by platform and date and carry no account, licence or content data. We rely on our legitimate interest in measuring and publishing how safe the tool is.

Market counters. To publish our public Lead Market Index, ClientRadar also counts anonymised, identity-free, niche-level signals: how many client-ready leads and won deals are detected per freelance niche and platform. These are plain totals and coarse value bands by niche, platform and date, carrying no account, licence or content data, and a niche only appears once enough installs contribute to report it honestly. Legitimate interest, as above.

Upgrade prompts. When you tap a prompt to upgrade your plan, ClientRadar records which prompt you tapped and the plan you were viewing, tied to your anonymous ClientRadar licence, so we can improve our pricing and the prompts themselves. This is your own first-party licence identifier only — it carries no third-party identity and no lead content, is never shared with any third party, and grants you nothing on its own. Legitimate interest; you can ask us to delete it at any time.

Install & activation attribution. To measure which of our ad campaigns and landing pages lead to installs and paying customers, we keep a pseudonymous journey record keyed to your extension's random instance identifier — a UUID generated on your device, not your name, email or any social identity. It records only campaign attribution (landing page, and any UTM or ad-click parameters your visit arrived with) and the timestamps of milestones like install, activation and purchase. It holds no lead content and no message text, ever, is stored first-party in our Cloudflare KV storage, is never shared with or sold to any third party, and is deleted automatically after about 90 days. Legitimate interest; you can ask us to delete it at any time.

Cited-by-AI checks. While cited-by-AI tracking is enabled in Authority Autopilot (on by default on paid plans), ClientRadar sends the URLs of your own published posts and the target questions derived from them to Perplexity and Google (Gemini), acting as data processors, to check whether those engines cite your content. We send only your public post URLs and their derived questions — never your leads, drafts or contacts. You can turn this off at any time in Autopilot → Settings → Safety; checks stop immediately.

Feedback and support requests. If you send us feedback or a support request from inside the extension, we receive what you type (up to 2,000 characters), the topic you picked, and — only if you choose to fill the optional field — your email address, so we can reply. The field is clearly labelled as optional and used for nothing else: no marketing, no list, no profile. This is the only place the extension can collect a personal identifier, and it only happens because you typed it in. We keep it for as long as needed to answer you, and you can ask us to delete it at any time.

Diagnostic support bundle. If you ask us for help from inside the extension, it can prepare a small diagnostic file (version, settings and recent error messages — never your leads, drafts or contacts) that downloads to your device. It reaches us only if you choose to attach it to an email you send yourself. Nothing is uploaded automatically.

Webfonts. The extension's dashboard loads its two typefaces (Inter and JetBrains Mono) from Google's font service at fonts.googleapis.com. Like any web request, this discloses your IP address and browser user-agent to Google, which states that it uses font requests only to serve the fonts. Nothing else is sent with it — no account data, no licence, no identifier, and no lead content.

9. What our backend stores

With Pocket Radar switched off — which is how ClientRadar arrives — our servers keep: your licence record (licence key, plan, status and expiry); per-licence AI-usage counters for credit metering; a short-lived cache of scoring results — kept for up to 30 days and keyed by an irreversible content hash so re-scoring the same post is free, where the cached entry holds the scoring result (the score, labels and a one-sentence reason) and not the post text itself; the anonymised counters and attribution records described in section 8; and service configuration. Everything is encrypted in transit with modern TLS and stored with Cloudflare-managed encryption at rest.

Pocket Radar — what is added when you switch it on

Pocket Radar is an optional feature that lets you read, approve and send your replies from your phone instead of your computer. It is off until you turn it on, and turning it on means four further things sit on our servers. Here are all four:

  • Encrypted lead data. The leads you choose to send to your phone are encrypted on your own computer before they are sent, using a key that is generated there and travels only to your phone in the pairing code — it never reaches us. What we hold is ciphertext we cannot decrypt and therefore cannot read: not the post, not the author, not the score, not your notes. See section 15 for how long we keep it.
    One part of this is not encrypted, and we would rather say so than let you discover it: each stored item is filed under the lead's own identifier — for example the platform's post id — so that your phone and your computer can refer to the same lead and so a reply can be matched to the right one. That identifier sits beside the ciphertext in plain text. It contains no post text, no author name and nothing you wrote, but it does point at a specific public post, so for the duration we hold it (see section 15) it is not accurate to say the record reveals nothing at all. It is deleted with the rest of the item.
  • A push subscription endpoint. If you allow notifications, your phone's own push service (Apple, Google or Mozilla, depending on your phone and browser) issues an address we can post to, and we store that address. We want to be plain about what it is: it is a device-specific identifier that points at your particular phone, not an anonymous counter, so we disclose it here rather than fold it into "usage data". We use it for one purpose only — sending a content-free "you have leads waiting" ping that carries no lead text. It is deleted when you unpair the phone, when you turn notifications off, or when the push service reports the subscription has expired.
  • A paired-device credential. Pairing mints a random device identifier and a random secret that together let your phone prove it is the phone you paired. We store the identifier and a one-way hash of the secret — never the secret itself. The credential does not contain, encode or derive from your licence key, and it unlocks nothing beyond your own encrypted leads. Both sides are destroyed when you unpair, and pairing a new phone revokes the old one.
  • An optional email address. Only if you switch on the email fallback — off unless you do — we store one address per licence, so we can email you when a lead has been waiting and the push did not reach your phone. That message carries a count and a link, never lead content. Switching the fallback off removes the address.

Because the leads are encrypted with a key we never hold, the honest summary is this: we can count your notifications, we cannot read them. Everything in this section applies only while Pocket Radar is switched on; with it off, none of these four records exists.

10. Payments, email and our website

The processing in this section happens on getclientradar.com, not inside the extension.

Payments. Paid plans are sold and processed through Stripe's Link checkout, with Link, LLC acting as merchant of record — not solely as our processor. At checkout, Link collects your name, email, billing address, payment details and, for business buyers, a business name and VAT ID, processed by Stripe/Link under their own privacy policy. We never receive or store your full card number — only limited order and subscription data (such as your email and plan) to provision and support your account. No payment information is ever entered into or handled by the extension.

Transactional licence-key email. When you buy a plan we send a welcome email containing your licence key to your checkout email address, and you can re-send that key to yourself at any time at getclientradar.com/resend. To do this we store your email address mapped to your licence key, kept for about 400 days while your plan is active and used only to deliver or re-send your key; the record of each individual email is kept for about 40 days for delivery reliability and then deleted automatically. Emails are delivered by Resend. The legal basis is performance of your purchase contract (Art. 6(1)(b) GDPR). This is transactional, not marketing.

Playbook & tips list. If you request the ban-safe client-finding playbook via the on-site popup, we store the email you submit — together with the work type, niche and platforms you selected — solely to email you the playbook and occasional client-finding tips. This is processed on the basis of your consent, given by submitting the form. We record the time of your consent and the version of the disclosure wording as proof, plus which page you signed up on and any campaign parameters your visit arrived with. Your record is stored first-party in our Cloudflare KV storage — no third-party marketing platform receives it. You can unsubscribe from any email or ask us to delete your record at any time.

Website measurement. On our funnel pages only — the pricing page, the post-checkout page and our campaign landing pages — we load the Google tag to measure how our ad campaigns perform. It is consent-gated using Google Consent Mode v2: it loads with all advertising and analytics storage denied by default, and a banner lets you accept or reject with equal-weight buttons. If you reject, or simply ignore the banner, no Google cookies or advertising identifiers are set. Our blog, help centre and every other page carry no tracker at all.

Demo video. Our homepage embeds a 60-second demo using the privacy-enhanced youtube-nocookie.com player, which loads only after you click play — no request is made to Google before that.

11. What ClientRadar does NOT collect

  • No passwords for any platform — ever, for any reason.
  • No health information.
  • No financial or payment information inside the extension — purchases run through Stripe's checkout on the web, never in the extension. We never publicly disclose financial or payment information.
  • No web browsing history. We do not build, store or transmit a list of the pages you visit, their titles or your visit times. The extension has no access to sites other than the four supported platforms; its tabs access is used only to locate its own dashboard tab; and the single narrow URL observation it performs is limited to X's own API traffic and keeps nothing but an API operation identifier (section 5).
  • No keystroke logging, no mouse-position or scroll tracking, no screen recording, and no reading of your private messages. We do record a small amount of in-product activity — which upgrade prompt you tapped, and journey milestones such as install and activation — which is described in full in section 8.
  • No location data beyond the coarse technical IP metadata that any web request carries.
  • No name, postal address, age, date of birth or government identification number — the extension has no field for any of them and never asks. There are exactly two personal identifiers it can collect, and both only because you typed them in: an email address in the optional feedback field (section 8), and an email address in Pocket Radar's optional fallback (section 9). Note that scanned public posts naturally carry their authors' public names and handles, which is covered in section 3.
  • No public disclosure of authentication information — the session cookies in section 4 are read only on your own computer, used only in requests back to the platform they came from, and are never disclosed to us or to anyone else. Pocket Radar does not change this: pairing a phone gives it its own credential and never transfers a platform session to it.

In line with the Chrome Web Store's user-data policy, we certify that we do not sell or transfer user data to third parties outside the approved use cases described here; we do not use or transfer user data for purposes unrelated to the extension's single purpose — finding and replying to potential clients; and we do not use or transfer user data to determine creditworthiness or for lending purposes.

12. Who we share your data with — the complete list

These are all the parties any user data is shared with. There are no others, and we do not sell your data to anyone.

PartyWhat they receiveRegion
Cloudflare, Inc.Hosts our backend (Workers, KV, Durable Objects). Processes everything described in sections 7–9 as our infrastructure provider. If you turn on Pocket Radar this also covers the encrypted lead data, the push subscription address and the paired-device credential — the lead data reaches Cloudflare only as ciphertext neither Cloudflare nor we can decrypt.USA / global edge
DeepSeekThe post text and your Brand DNA, at the moment you request a score or a draft, in order to generate it.Outside the EEA
Anthropic, PBC (Claude)The post text and your Brand DNA, at the moment you request a score or a draft, in order to generate it.USA
PerplexityOnly the URLs of your own published posts and their derived questions, and only while cited-by-AI tracking is on (section 8).USA
Google (Gemini)Only the URLs of your own published posts and their derived questions, and only while cited-by-AI tracking is on (section 8).USA
Google (Fonts)Your IP address and browser user-agent, when the extension's dashboard loads its two typefaces from fonts.googleapis.com. No account, licence or lead data.USA / global
Stripe / Link, LLCCheckout, billing, receipts and worldwide tax. For purchases Link, LLC acts as merchant of record, collecting name, email, billing address, payment details and, for business buyers, VAT ID. Website only.USA / global
ResendYour email address and licence key, to deliver transactional licence-key emails. Also delivers Pocket Radar's optional email fallback (a count and a link, never lead content) if you switch that on.EU (eu-west-1)
Apple, Google or Mozilla (push delivery)Only if you turn on Pocket Radar and allow notifications: whichever push service your phone's browser uses receives the push address it issued and the content-free "you have leads waiting" ping. No lead content, no licence data and no account identity is sent with it.USA / global
Google (Google tag)Consent-gated ad-campaign measurement on our funnel pages only. Website only; never in the extension.USA
Google (YouTube)Only if you click play on our homepage demo video, via the privacy-enhanced no-cookie player. Website only.USA

We may also disclose data where we are legally required to do so, or to establish or defend legal claims. If ClientRadar is ever involved in a merger or acquisition, we will tell users before their data becomes subject to a different privacy policy.

13. Legal bases

We rely on: performance of a contract (to provide the extension and the AI features you request, and to manage your subscription); legitimate interests (to keep the service secure, to measure reliability and safety, and to understand which marketing works — balanced against your rights); consent where required, which you can withdraw at any time; and legal obligation (for accounting and tax).

14. International transfers

Some providers are located outside the European Economic Area (including the USA and, for AI inference, outside the EEA). Where data is transferred outside the EEA we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision — and send only what is needed to deliver the feature.

15. How long we keep data

Local data stays on your device until you delete it, and by default we keep no copy. AI request data is processed to generate your result and is not retained by us to build a profile (any retention by AI sub-processors is governed by their own policies). Cached scoring results expire after up to 30 days. If you turn on Pocket Radar, what we hold for it is encrypted lead data we cannot read, deleted within 24 hours or as soon as you act on it. Its push address and paired-device credential last only as long as the phone stays paired, and the optional fallback email address only until you switch that fallback off. Attribution records are deleted after about 90 days. Licence-key email records are kept for about 400 days while your plan is active. Account, order and billing records are kept as needed to provide the service and meet legal obligations. Security logs are kept for short periods only.

16. Your rights, and how to delete everything

Because most of your data lives only on your device, you are already in control of it: you can export or delete your leads, notes and settings from inside the extension at any time, and uninstalling the extension removes the local database.

If you are in the EEA you also have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent where processing is based on it. Contact [email protected] for anything we hold and we will help. You can also complain to your local supervisory authority — in Hungary, the National Authority for Data Protection and Freedom of Information (NAIH), Falk Miksa utca 9-11, 1055 Budapest, naih.hu.

17. Security

All data sent between the extension and our backend is encrypted in transit using modern TLS; we make no requests over plain HTTP, and we do not place personal data in URLs or query strings. Your CRM is kept on your own device rather than in a central database, our backend stores the minimum described in section 9, and data at rest is encrypted by Cloudflare. We collect as little as possible by design.

18. Children

ClientRadar is a business tool intended for adults and is not directed to anyone under 18. We do not knowingly collect data from children.

19. Changes and contact

We may update this policy as the product evolves. We will revise the "Last updated" date and, for material changes, take reasonable steps to let you know. Questions? Email [email protected] or write to Global Charity Solutions Kft., Vajda János utca 25., 2120 Dunakeszi, Hungary.

Terms of Service · Refund Policy · Privacy, explained visually