Privacy Policy
Effective date: September 20, 2026
Scope and controller
This policy covers the Linki mobile apps and the website at applinki.com, including its optional account and bookmark dashboard. The controller is Mele Apps / Erik Jaen in Bern, Switzerland. Privacy requests can be sent to info@applinki.com.
Data we process
- Without an account: bookmark libraries created in the mobile app remain on the device. Our hosting provider may still process ordinary security logs such as IP address, browser, requested URL, and timestamp.
- Account and sync: if you sign in, Firebase Authentication processes your email address, provider identifier, display details supplied by the provider, and authentication records. Firestore stores the bookmarks, categories, notes, tags, and settings you choose to sync.
- Metadata lookup: when a signed-in dashboard user asks Linki to fetch a page title or preview, the saved URL is sent to our Cloud Function in the United States. The function requests that URL, so the destination website also receives a request from Linki infrastructure. Avoid saving URLs that contain passwords, access tokens, or other secrets.
- Website analytics: only after you select “Allow analytics,” Google Analytics for Firebase may process page paths, interactions, browser/device information, approximate location derived from IP, and an analytics identifier. We do not use this for advertising or ad profiles.
- Support: the contact form opens your email app. Your message is processed by your email provider and ours, not submitted to a hidden website database.
Why we use data
We process account and sync data to provide the service you request; security and basic hosting logs for our legitimate interest in protecting Linki; support messages to answer you; and optional analytics only with your consent. Declining analytics does not reduce website or app functionality.
Free guide and email choices
When you request the free guide, we use your email address to send a confirmation link and, after you confirm, a link to the PDF. This does not create a Linki app account. The separate marketing checkbox is optional. We send practical Linki tips by email only if you choose it and confirm your address. You can withdraw that choice through the unsubscribe link in an email.
We store your email address, the version and date of your consent, confirmation and unsubscribe dates, a limited campaign source, and email sending status in a separate Firebase Firestore collection. This database is in the United States. Our backend can access these records; website visitors and app users cannot read the list. Google Workspace processes the confirmation and delivery emails. We do not add tracking pixels to these emails or send your email address to website analytics.
To limit automated signups, we keep temporary counters based on protected hashes of email addresses and IP addresses. These counters expire after two days. Unconfirmed guide requests are removed after 14 days. Confirmed guide-only requests and withdrawn subscriptions are removed after 90 days. Confirmed marketing subscriptions expire after 24 months unless you renew your choice. A protected hash of an unsubscribed address remains on our suppression list until you explicitly confirm a new subscription, so a later import cannot silently subscribe you again. Hosting and email providers may retain their own service and security logs.
To ask for access to or deletion of an email record, contact info@applinki.com from that address. Unsubscribing stops marketing emails; you can keep the guide.
Legacy Linki reactivation email
We may use an address from an existing Keeplink or Linki account where you previously permitted product emails, to send a limited reactivation campaign about the move from Keeplink to Linki and current app features. Google Workspace sends these emails. They contain no tracking pixel.
The local campaign runner reads the address from a private batch file and does not copy it into the send ledger or unsubscribe record. The ledger stores a stable, secret-keyed reactivation identifier, delivery status, provider message ID, timestamps, and technical campaign metadata. The unsubscribe record stores that protected identifier, the unsubscribe date, and technical scope and version fields. We retain the private batch and local ledger only while needed to prepare, deliver, and reconcile this limited campaign. We retain the minimal suppression record while needed to honor your opt-out and prevent later imports from restarting Linki reactivation emails.
Use the unsubscribe link in the email to stop Linki reactivation emails, or contact info@applinki.com from the address that received it.
Providers and international transfers
Linki uses Google Firebase for hosting, authentication, Firestore, Cloud Functions, Crashlytics, and optional Analytics. Google may process data in Switzerland, the EEA, the United States, and other locations. Where required, transfers rely on recognized adequacy mechanisms or contractual safeguards. App-store links take you to Apple or Google, whose own privacy policies then apply.
Retention and deletion
Local app data remains until you remove it or uninstall the app. Uninstalling does not delete synced cloud data. Account and synced data remain while the account is active and until deletion is requested, except where limited retention is required for security, legal, or dispute purposes. Optional analytics event data may be retained for up to 24 months and may then remain only in aggregated form. Support emails are kept only as long as needed to resolve the request and meet legal recordkeeping duties.
To delete your Firebase account and synced data, email info@applinki.com from the account email. We may need to verify ownership before deletion.
Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw analytics consent at any time using the button above without affecting earlier lawful processing. You may also complain to the Swiss Federal Data Protection and Information Commissioner or your local EEA supervisory authority.
Security
We use HTTPS, Firebase Authentication, owner-scoped database rules, restricted browser permissions, and security response headers. No internet service can guarantee absolute security. Do not place credentials or private access tokens inside bookmark URLs.
Changes and contact
We update the effective date when this policy materially changes. Questions, rights requests, or vulnerability reports can be sent to info@applinki.com.