If our database were stolen, there would be no LinkedIn sessions in it.
You are handing us your clients' LinkedIn accounts. That deserves a specific answer, not a badge wall. This page describes how sessions are actually handled, what we store, what we deliberately do not, and where we still have work to do.
Your session cookie is never written to our database.
Most tools in this category keep your LinkedIn cookie in their database and load it into a cloud browser on demand. We removed that pattern entirely. The cookie exists in exactly one place: an encrypted browser profile on our automation server. There is no cookie column anywhere in our schema, and a regression test fails our build if one is ever added.
Three categories, no fine print.
- Your LinkedIn session cookie, in any form, even temporarily
- A password for your CampaignStack account (sign-in is passwordless)
- Proxy credentials or API keys in logs
- Message bodies or scraped content in our log pipeline
- LinkedIn login credentials, only if you opt in to automatic session recovery (AES-GCM, dedicated rotatable key)
- Ad platform OAuth tokens and app secrets (AES-256-GCM)
- Email app passwords (AES-256-GCM)
- Your name, email, and workspace settings
- Lead and company data your campaigns work with
- Campaign, workflow, and conversation history
Disconnect means destroy.
When you disconnect a LinkedIn account, the encrypted browser profile on our server is destroyed, the account record is deleted, any stored recovery credentials are wiped, and the deletion is retried automatically until the server confirms it. The account's proxy goes back to the pool with a fresh IP, so the next customer never inherits an address with your account's history.
Shared where it helps you, walled where it matters.
Public professional data (people, companies, public posts) lives in one shared database, the same model Apollo uses, so every customer benefits from enrichment work already done. Everything that is yours stays yours: campaigns, ICPs, lead lists, tags, notes, conversations, and anything derived from your outreach is scoped to your workspace and gated on membership. Other customers can never see who you contacted, what you sent, who replied, or that your workspace exists.
Logs leave the machine through an allowlist.
Our log shipper is built the opposite way from most: instead of removing sensitive fields from log records, it copies out a fixed list of operational fields (timing, error class, job id, outcome) and drops everything else by construction. Message content, scraped data, cookies, tokens, and HTTP bodies cannot reach the log vendor because no field carries them. References to your data appear as opaque database ids, not names or URLs.
LinkedIn automation is against LinkedIn's rules. Ours too.
Every LinkedIn automation tool operates against LinkedIn's User Agreement, including this one. Vendors who imply their limits are somehow approved are selling you a story. What we can honestly offer: per-account daily budgets capped below observed platform limits, gradual warm-up for new accounts, human-hours pacing, one dedicated residential IP per account, and automatic pauses the moment an account shows risk signals. Those measures reduce risk. They do not eliminate it, and nobody can.
Passwordless by default.
You sign in with a one-time email code, a magic link, or Google SSO. We never hold a password for your CampaignStack account, so there is no password database to breach. Payments run entirely on Stripe; your card details never touch our servers.
Who touches your data, and why.
The complete list of vendors involved in running CampaignStack. If this list changes, this page changes.
| Vendor | What it does for you |
|---|---|
| Convex | Application database and backend functions |
| OVHcloud | The server that runs browser automation and holds the encrypted profile vault |
| Webshare | Static residential proxies, one per connected LinkedIn account |
| Stripe | Payments and billing. Card details never touch our systems |
| Resend | Transactional email (sign-in codes, notifications) |
| Anthropic, OpenAI, DeepSeek, Perplexity | AI drafting and analysis. Prompts include the lead context needed to write a message |
| Sentry | Error tracking |
| Axiom | Operational logs, restricted to an allowlist of technical fields |
| PostHog | Product analytics, gated behind cookie consent on the website |
What we do not have yet.
Report a vulnerability.
Write to security@campaignstack.io and you will get a human answer, fast. We publish a security.txt at the standard location. We do not run a paid bounty program yet, but we credit reporters who want credit and we fix what you find.
Get started
Start building your stack.
Your LinkedIn accounts will be safer with CampaignStack than doing it by hand. That's not a pitch. It's a measurable claim.