Is Findy: Email Search and Outreach by Reply safe?

Medium risk

Findy reads your LinkedIn session cookies and auth headers and sends them to Reply.io to operate LinkedIn on your behalf.

The background worker captures your LinkedIn cookies (li_at, li_a, JSESSIONID, csrf-token, bcookie, liap) and Voyager API request headers, bundles them as linkedInAccountV2Credentials, and forwards them to the Reply.io web app so its servers can drive LinkedIn for outreach. It also intercepts your authenticated Google Contacts hovercard request on contacts.google.com (the 'at' token and f.req payload) and stores it to replay the Contacts API server-side for contact enrichment. These data flows are part of the product's sales-outreach function; a Reply.CE OAuth client_secret is also hardcoded in the shipped bundle.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

reply.iov3.18.18Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

run.reply.ioapi.reply.iooauth.reply.io
Updated 17 September 2026amcdijdgmckgkkahhcobikllddfbfidi