Lantern

Privacy Policy

Last updated: 2026-07-18

What Lantern is

Lantern is a tool that helps founders identify and contact investors. It comprises a web app and a Chrome browser extension. The extension reads pages on linkedin.com (only when you direct it to) and sends structured data to the Lantern web app, which stores it in your account.

What we collect

  • Account info you provide: name, email, password hash, your LinkedIn profile URL, and any campaign details you type into the dashboard.
  • Investor profile data the agent scrapes for you: names, public job titles, public headlines, location, public LinkedIn profile URLs, and the visible mutual connections between you and those investors. This data is fetched from LinkedIn pages that you are logged into; the extension uses your own session cookie. We do not sell or share this data.
  • Email addresses returned by our email-finder agent: when you click "Find email", we ask a third-party email-finder service for the address corresponding to a LinkedIn profile URL. Any verified address is stored on your account.
  • Operational logs: we record when each agent action runs, how long it took, and how many results it produced (per-user). We do not log the content of scraped pages.

What we do not collect

  • We do not read or store your LinkedIn password. The extension only reads the session cookie that LinkedIn already set in your browser; we use it to make requests on your behalf to the same pages you can already see.
  • We do not access pages outside linkedin.com or our own dashboard origin. The extension's host_permissions are scoped to those two origins.
  • We do not sell, rent, or share your data with advertisers.

Third-party services

Lantern uses Anymailfinder as the email-finder backend. When you click an "Agent" find-email button, we send the target's LinkedIn profile URL to Anymailfinder; their service returns a candidate email address along with a verification status. Anymailfinder is the data processor for that lookup; their privacy policy is here.

Google user data (Gmail)

You can optionally connect your Gmail account so Lantern can send your outreach emails from your own address. This uses Google OAuth; we never see your Google password. If you connect Gmail:

  • What we access: permission to send email on your behalf (gmail.send), and read-only access that we use solely to check the From/Subject/Date headers of the specific email threads Lantern itself created — so we can tell whether a recipient replied before sending your scheduled follow-up. We do not read, index, or store your inbox, message bodies of replies, attachments, contacts, or any thread Lantern did not create.
  • What we store: your OAuth tokens (encrypted at rest), a copy of each email you composed and sent through Lantern (for your own audit history), and a replied/not-replied status per outreach thread.
  • What we never do with Gmail data: sell it, share it with third parties, use it for advertising, or let humans read it — except with your explicit permission, when required for security or legal reasons, or when aggregated and anonymized for internal operations.
  • Limited Use: Lantern's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • No AI/ML training: we do not use any data obtained from Google APIs — or any other data you entrust to Lantern — to develop, improve, or train generalized artificial intelligence or machine-learning models.
  • Disconnecting: you can disconnect Gmail at any time from Account settings — we delete the stored tokens immediately — or revoke Lantern's access from your Google account permissions. Deleting your Lantern account deletes all stored Gmail data.

How we protect your data

  • Encryption in transit: all traffic between your browser, the Lantern extension, our servers, and Google's APIs uses HTTPS/TLS.
  • Encryption at rest: Gmail OAuth tokens are encrypted with AES-256-GCM before being stored; the encryption key is held separately from the database as a deployment secret and is never stored in code or alongside the data it protects. The database itself runs on managed cloud infrastructure with provider-level encryption at rest.
  • Access controls: your data is scoped to your account — every query in the application is bound to the authenticated user, and no other user can read your campaigns, contacts, or Gmail data. Production database credentials are restricted to Lantern's operators and are never checked into source code.
  • Retention and deletion: Google user data is retained only while your Gmail connection is active. Tokens are deleted immediately on disconnect; deleting your account removes all associated data, including Gmail data, within 30 days.
  • Incident response: if we become aware of a security breach affecting your data, we will notify affected users by email without undue delay and describe what happened and what we are doing about it.

How we store data

Data lives in a Postgres database on infrastructure we operate. Backups follow standard cloud retention. Sessions use HttpOnly cookies signed with NextAuth.

How to delete your data

Email us at jason@adamantventures.com and we will delete your account and all associated data within 30 days. We will confirm the deletion by reply.

Changes to this policy

We will update the "Last updated" date above when we change this policy. Material changes will be communicated to users by email.

Contact

Questions about this policy: jason@adamantventures.com.

See also: Terms of Service