Minimal data.
Explicit lifetimes.
Draft updated September 2, 2026
What Linkifact processes
- Artifact data: the HTML, title, immutable versions, size, status, and expiry needed to publish a link.
- Account data: provider identifiers and the name, email address, or profile image returned by GitHub or Google, plus sessions, plan, collections, and hashed API-key records.
- Safety data: validation results, pseudonymous quota and abuse-prevention keys, reports, optional reporter contact details, and moderation state.
- Operations data: request IDs, timestamps, coarse outcome and performance data, and infrastructure security events. Application logs are designed to exclude HTML bodies, cookies, raw API keys, management capabilities, and raw IP addresses.
Why it is processed
We use this data to provide requested publishing and account features, enforce limits, prevent abuse, investigate reports, secure the service, diagnose failures, and meet legal obligations. We do not sell personal data or place third-party advertising or analytics inside artifacts or the account application.
Who handles it
Cloudflare provides application, database, object-storage, queue, DNS, and edge-security infrastructure. GitHub or Google handles the sign-in flow you choose and sends Linkifact the account fields disclosed on that consent screen. Those providers process data under their own notices. Access inside Linkifact is limited to service operation, support, safety, and legal needs.
Retention
A guest artifact stops serving at its stated 30-day expiry, even if asynchronous byte cleanup is still running. Deleted bytes are queued for prompt removal and a minimal tombstone may remain for up to 30 additional days to make deletion responses deterministic and deter abuse. Free-account retention restarts after each successful update. Account, collection, security, and report records are kept only while needed for the service, safety, disputes, or law; a final retention schedule is a public-launch requirement.
Your choices
You can delete an artifact through its guest management link or signed-in owner controls, revoke API keys, and avoid creating an account by using guest publishing. To request access, correction, export, or account deletion, contact privacy@linkifact.com. We may need to verify that the request belongs to you.
Security and children
Linkifact separates untrusted content onto another registrable domain and uses scoped credentials, private storage, browser sandboxing, and retention jobs. No system is perfectly secure, so do not publish secrets or sensitive personal data. The service is not directed to children, and the final minimum-age rule will be set with counsel before launch.
Questions
Privacy questions can be sent to privacy@linkifact.com. Security reports belong at security@linkifact.com.