Sortinghat

LinkedIn Sourcing: What Our Chrome Extension Collects, and What It Does Not

A plain account of how the extension works, what it collects, where that data goes, how long it is kept, and the questions your client's legal team will ask you about it.

By , Founder9 min read

LinkedIn sourcing with our extension works like this: it runs in your browser, on profiles you open yourself, at the speed a person browses. When you are looking at a profile, it reads the publicly visible parts of it and lets you add that person to your database as a candidate or a lead, against a specific job or company.

That is the whole mechanism. Most of what follows is about the boundaries, because that is what actually gets asked in a vendor review and almost nobody in this category writes it down.

Key takeaways

  • It works on profiles you visit, not on a background crawl. The extension operates inside your browsing session at human speed rather than running automated bulk collection.
  • It reads what is publicly visible. Experience, education, skills and the About section. Not private fields, not connections, not anything behind a paywall you have not paid for.
  • Candidate notice is available but not automatic. You can run notice campaigns over email, WhatsApp or call. They are off unless you switch them on, and firms placing into the EU or UK should switch them on.
  • Data is isolated per client and deleted when they leave. No pooled dataset, no model training, no third-party sharing.

How the LinkedIn sourcing extension works

It is a Chrome extension, not a server-side scraper. The distinction matters more than it sounds.

You browse LinkedIn as you normally would. When you open a profile you are interested in, the extension reads the page you are already looking at and offers to add that person to your database. You choose whether they go in as a candidate against a specific job, or as a lead against a company.

Two consequences follow from the architecture. It operates at the pace of a person clicking through profiles, because it is a person clicking through profiles. And it only ever sees what you see, because it is reading your session rather than running its own.

We are not going to promise you that no automated tool carries any account risk, because no vendor can honestly promise that about a third party's platform. What we can tell you is the mechanism, which is above, and our published position, which is in the guidelines linked in the site footer.

Sortinghat profile from a LinkedIn-sourced record: experience, career timeline, education and summary
Fig 1A sourced profile once it lands in the database: experience, education and the About section, structured against the person.

What the extension collects, and what it does not

The publicly visible parts of a profile you have opened:

CollectedNot collected
Work experience and rolesPrivate or connection-only fields
EducationYour connection graph
SkillsPrivate messages or InMail content
The About sectionAnything behind a paid tier you do not hold

What that gives you is enough to evaluate someone and enough to enrich a record you may already hold. It is not a contact database, and it does not pretend to be one.

The enrichment case is the more valuable of the two and the one people overlook. If your database already holds someone from a role in 2023, the useful thing is not adding them again. It is updating what they are doing now, which is the problem covered in the talent pool audit.

Sortinghat Move to Job panel: adding a sourced candidate to one of six open roles with client names shown
Fig 2Adding a sourced person to a live role. It is a deliberate action by a recruiter, not something the extension does on its own.

Where sourced candidate data goes, and for how long

Three separate commitments, worth keeping distinct because they often get muddled in vendor answers.

Isolation

Data collected for a client is stored for that client alone. We do not access it, do not pool it across customers, do not use it for model training, and do not share it with third parties. There is no cross-customer dataset that your competitor benefits from because you did the sourcing.

Retention

Data is retained for as long as the client is on the platform, and removed when they leave.

Commercial terms are a separate thing

Our subscription carries a minimum eleven-month commitment with two months' notice to exit, so that migration off the platform can be planned properly rather than done in a panic. That is a contractual arrangement. It is not a data retention position, and the two should never be presented as one, by us or by anyone else you are evaluating.

Candidate notice under GDPR and DPDP: the honest answer

This is the question a serious buyer will ask, so here is the position without hedging.

Notice to candidates is not sent automatically. The platform can run notice campaigns over email, WhatsApp or AI call, with wording and timing you control, but they are off by default and you decide whether to switch them on.

What that means practically depends on where your candidates are. Under the GDPR, obligations attach to personal data you hold about someone even when you obtained it indirectly, and Article 14 sets out both the information you owe them and the timing. The UK regime mirrors it. India's DPDP Act sets out its own notice and consent expectations.

If your desks touch EU or UK candidates, treat the notice campaign as required rather than optional, and take your own advice on the wording.

We would rather write that down than have you discover it during a client's vendor review. Any vendor who tells you sourcing carries no notice obligations at all is either not thinking about it or hoping you are not.

What the extension does not do

Stating the limits is more useful than another feature list.

  • It does not run a background crawl. If your browser is closed, nothing is happening.
  • It does not collect private fields, connections or message content.
  • It does not produce personal contact details that are not visible to you.
  • It does not send candidates anything on its own. Outreach is a separate, deliberate action, covered in our guide to building an outbound campaign.
  • It does not decide anything. Adding someone to a job is a person clicking a button.

Why a talent pool beats a sourcing licence

A sourcing licence is rented access. You pay per seat per year, and when the licence lapses you keep nothing you found with it.

A pool compounds. The profile you add in March is in your database in September, by which point it has been enriched, worked once and possibly spoken to. The next role in that vertical starts from a warm list instead of a blank search box.

DimensionRented licenceOwned pool
Cost modelPer seat, per yearOne-off collection, no per-search cost
What you keep on exitNothingEverything
Second role in the same verticalStarts coldStarts from a worked list
Enrichment over timeNoneCompounds with every search
Where it still winsReach into people you have never touchedLimited to what you have collected

That difference is the entire argument for putting sourced profiles into a database you own rather than working out of someone else's interface. It is also why the boundary questions above matter: a pool you own is only an asset if you can defend how it was built.

Which signals actually indicate an active job seeker

Most sourcing effort goes to people who are not looking. The subset who are leaves signals, and no single one is reliable on its own.

Explicit signals

The open-to-work flag, a recent application to you or anyone, a reply to earlier outreach, and a profile updated in the last month. These are the strongest and the rarest. Only a minority of people looking will set the flag, because most of them are looking while employed.

Tenure signals

Time in current role approaching the typical tenure for that level and function. A senior engineer at three years in the same role is statistically more available than one at eight months, and the profile tells you both.

Context signals

Public layoffs, a funding round that did not happen, an acquisition, a leadership change, or a contract with a visible end date. These are the ones a recruiter reads in the market rather than on a profile.

Your own history

The cheapest signal and the most ignored. People who looked eighteen months ago and did not move very often look again. Your database knows this about them and no external platform does, which is the practical argument for keeping the record rather than renting the reach.

Used together, these are a ranking input rather than a filter. Treating any one of them as a yes-or-no test will exclude most of the people worth contacting.

Adding sourced profiles without creating duplicates

Sourcing into a database with no matching is how firms end up with three records for one person, each holding a third of the history.

Four routes create duplicates, and all of them are normal operations rather than mistakes:

  • The same person applies to several of your roles across a few years
  • A recruiter uploads a CV without checking whether the person already exists
  • A referral arrives with a different name spelling or a personal address
  • A bulk import lands without matching against what is already there

The fix is matching at the point of entry rather than a cleanup later. When a sourced profile arrives, it should be checked against existing records on more than one identifier, because names collide and email addresses change. Where a match is found, the right behaviour is to update the record, not create a second one.

Where a merge is genuinely needed, it has to preserve everything: notes, call history, attachments, submission and placement history, and stage changes with their timestamps. A merge that loses the 2023 note explaining why a client rejected someone will cost you that client's trust the day you submit them again.

Frequently asked questions

How does a LinkedIn sourcing Chrome extension work?

It runs inside your browser on profiles you open yourself, reads the publicly visible sections of the page you are already viewing, and lets you save that person into your own database against a job or a company. It works at the pace you browse, because it is reading your session rather than running its own automated collection.

What candidate data does a LinkedIn sourcing extension collect?

Publicly visible profile information: work experience, education, skills and the About section. It does not collect private fields, connection graphs, message content, or anything behind a paid tier you do not hold.

Do candidates need to be told their profile is in a recruiter's database?

Under the GDPR, the UK regime and India's DPDP Act, notice obligations apply to personal data you hold, including data gathered without direct contact. Our platform can run notice campaigns over email, WhatsApp or call, but they are not enabled by default. Firms placing into the EU or UK should enable them and take their own legal advice on wording and timing.

How long is sourced candidate data retained?

For as long as the client remains on the platform, after which it is removed. Data is isolated per client, is not pooled across customers, is not used for model training, and is not shared with third parties.

Is sourced candidate data used to train AI models?

No. There is no cross-customer training set and no secondary use of client data. This is a question worth asking every vendor you evaluate, and worth being suspicious of any answer that takes more than a sentence.

Is scraping LinkedIn profiles legal for recruiters?

The position depends on jurisdiction, on the platform's own terms, and on how the data is collected, stored and used. What matters legally is the basis on which you process personal data rather than the label attached to the method. Ask any vendor to state, in writing, what they collect, where the collection happens, and on what basis.

Five questions to ask any sourcing vendor

Whether or not you buy from us, these five separate a serious vendor from a risky one.

  1. What exactly do you collect, and from where?
  2. Does collection happen in my browser or on your servers?
  3. Is my data pooled with other customers, or used for training?
  4. How long do you keep it, and what happens when I leave?
  5. What do you do about candidate notice, and is it on by default?

A vendor who answers all five in plain language is telling you they have thought about it. A vendor who redirects to a feature list has answered question three by accident.

See sourcing feed straight into your own pool

We will show you the extension working on live profiles, where the data lands, and exactly what your team can and cannot do with it.

Book a demo

Founder of Sortinghat, an AI-native ATS and CRM for staffing, search and RPO firms. Writes about recruiter capacity, sourcing economics and what actually changes when AI reaches a delivery desk. More about the author