If our database were stolen, there would be no LinkedIn sessions in it.
You are handing us your clients' LinkedIn accounts. That deserves a specific answer, not a badge wall. This page describes how sessions are actually handled, what we store, what we deliberately do not, and where we still have work to do.
Your session cookie is never written to our database.
Most tools in this category keep your LinkedIn cookie in their database and load it into a cloud browser on demand. We removed that pattern entirely. The cookie exists in exactly one place: an encrypted browser profile on our automation server. There is no cookie column anywhere in our schema, and a regression test fails our build if one is ever added.
Three categories, no fine print.
- Your LinkedIn session cookie, in any form, even temporarily
- A password for your CampaignStack account (sign-in is passwordless)
- Proxy credentials or API keys in logs
- Message bodies or scraped content in our log pipeline
- LinkedIn login credentials, only if you opt in to automatic session recovery (AES-GCM, dedicated rotatable key)
- Ad platform OAuth tokens and app secrets (AES-256-GCM)
- Email app passwords (AES-256-GCM)
- Your name, email, and workspace settings
- Lead and company data your campaigns work with
- Campaign, workflow, and conversation history
Disconnect means destroy.
When you disconnect a LinkedIn account, the encrypted browser profile on our server is destroyed, the account record is deleted, any stored recovery credentials are wiped, and the deletion is retried automatically until the server confirms it. The account's proxy goes back to the pool with a fresh IP, so the next customer never inherits an address with your account's history.
Shared where it helps you, walled where it matters.
Public professional data (people, companies, public posts) lives in one shared database, the same model Apollo uses, so every customer benefits from enrichment work already done. Everything that is yours stays yours: campaigns, ICPs, lead lists, tags, notes, conversations, and anything derived from your outreach is scoped to your workspace and gated on membership. Other customers can never see who you contacted, what you sent, who replied, or that your workspace exists.
Logs leave the machine through an allowlist.
Our log shipper is built the opposite way from most: instead of removing sensitive fields from log records, it copies out a fixed list of operational fields (timing, error class, job id, outcome) and drops everything else by construction. Message content, scraped data, cookies, tokens, and HTTP bodies cannot reach the log vendor because no field carries them. References to your data appear as opaque database ids, not names or URLs.
LinkedIn automation is against LinkedIn's rules. Ours too.
Every LinkedIn automation tool operates against LinkedIn's User Agreement, including this one. Vendors who imply their limits are somehow approved are selling you a story. What we can honestly offer: per-account daily budgets capped below observed platform limits, gradual warm-up for new accounts, human-hours pacing, one dedicated residential IP per account, and automatic pauses the moment an account shows risk signals. Those measures reduce risk. They do not eliminate it, and nobody can.
Passwordless by default.
You sign in with a one-time email code, a magic link, or Google SSO. We never hold a password for your CampaignStack account, so there is no password database to breach. Payments run entirely on Stripe; your card details never touch our servers.
Who touches your data, and why.
The complete list of vendors involved in running CampaignStack. If this list changes, this page changes.
| Vendor | What it does for you | Where it runs |
|---|---|---|
| Convex | Application database and backend functions | United States |
| OVHcloud | The server that runs browser automation and holds the encrypted profile vault | European Union (France) |
| Webshare | Static residential proxies, one per connected LinkedIn account | United States; proxy addresses in the account's own country |
| Stripe | Payments and billing. Card details never touch our systems | United States |
| Resend | Transactional email (sign-in codes, notifications) | United States |
| Anthropic, OpenAI | AI drafting, critique and analysis of lead data. The only model providers that receive a person's profile or message text, under a data processing agreement | United States |
| DeepSeek, Perplexity | DeepSeek also runs the browser agents that read profiles and inbox threads on the automation server. Otherwise non-personal text only: website audits, topic labels, company news, search research | China (DeepSeek), United States (Perplexity) |
| Sentry | Error tracking | United States |
| Axiom | Operational logs, restricted to an allowlist of technical fields | United States |
| PostHog | Product analytics, gated behind cookie consent on the website | United States |
What we do not have yet.
Report a vulnerability.
Write to security@campaignstack.io and you will get a human answer, fast. We publish a security.txt at the standard location. We do not run a paid bounty program yet, but we credit reporters who want credit and we fix what you find.
Questions about security
Do you store my LinkedIn session cookie?
No, and there is no column for one. The cookie is consumed once into an encrypted browser profile on the automation server, and a regression test fails the build if a cookie field is ever added to the schema. An account without that profile cannot run anything, so there is no fallback path that accepts a raw cookie at job time.
What would an attacker get from your database?
No LinkedIn sessions. The encryption passphrase lives in a root-protected file read only by the system service that mounts the vault: never in source control, never in the application's environment, never on a command line. Optional recovery credentials are encrypted with a separate rotatable key and are never returned by any client-facing query.
What happens when I disconnect a LinkedIn account?
The encrypted browser profile is destroyed, ciphertext included, the account record is deleted, and stored recovery credentials are wiped in the same operation. Deletion retries until the server confirms it. The proxy returns to the pool with a fresh IP, so nobody inherits an address carrying your account's history.
Can another customer see my clients or my outreach?
No. Public professional data, meaning people, companies and public posts, lives in one shared database, the same model Apollo uses, so enrichment work is never repeated. Everything derived from your outreach stays scoped to your workspace: no other customer can see who you contacted, what you sent, who replied, or that your workspace exists. CSV imports and manually entered data land in workspace-private tables.
Is LinkedIn automation against LinkedIn's terms?
Yes, and that includes this product. Any vendor implying their limits are somehow approved is selling you a story. What we can honestly offer is per-account daily budgets capped below observed platform limits, gradual warm-up for new accounts, human-hours pacing, one dedicated residential IP per account, and automatic pauses the moment an account shows risk signals.
Do you hold a password for my CampaignStack account?
No. You sign in with a one-time email code, a magic link, or Google SSO, so there is no password database to breach. Payments run entirely on Stripe and your card details never touch our servers.
What reaches your logging vendor?
A fixed list of operational fields: timing, error class, job id, outcome. The shipper copies that list out and drops everything else by construction, so message content, scraped data, cookies, tokens and HTTP bodies cannot reach it. References to your data appear as opaque database ids, not names or URLs.
How do I report a vulnerability?
Write to security@campaignstack.io and you will get a human answer, fast. A security.txt is published at the standard location. We do not run a paid bounty program yet, but we credit reporters who want credit and we fix what you find.
Get started
Start building your stack.
Your LinkedIn accounts will be safer with CampaignStack than doing it by hand. That's not a pitch. It's a measurable claim.