Privacy Policy
Last updated: April 8, 2026
LinkDecoder (“we,” “us,” “our”) provides a link testing, monitoring, and creation service. This policy explains what information we collect, why we collect it, and the choices you have. We wrote it in plain English on purpose. If anything is unclear, email us at cxiqadmin@gmail.com.
1. Information we collect
We collect three categories of information:
a. Account information
When you create an account we collect your email address and a password hash (or, if you sign in with Google or GitHub, an OAuth identifier from that provider). We do not collect your name, phone number, billing address, or payment details during the beta.
b. URLs and analysis data
When you submit a URL for analysis, we fetch that URL from our servers and follow its redirect chain. We store: the URL you submitted, every hop in the chain, response headers, status codes, timing data, the final HTML body (capped at 512 KB), AASA / Android App Links files, Open Graph metadata, and any analytics tags or attribution platforms we detect. If you save a test, this data is associated with your account and viewable in your test history.
Important: Do not submit URLs that contain personal health information, government identifiers, financial credentials, or other sensitive personal data in their query string. Once submitted, the URL is stored as part of your test history.
c. Operational data
We log IP addresses for rate limiting, abuse prevention, and basic operational debugging. We use cookies to keep you signed in. We do not use third-party advertising or analytics cookies.
2. How we use your information
- To provide the link testing, monitoring, and creation features you request.
- To send transactional emails (alerts when a monitored link breaks, password resets, account confirmations).
- To enforce plan limits and prevent abuse.
- To debug errors and improve product reliability.
- To respond to your support requests.
We do not sell your data, share it with advertisers, or use it for cross-site tracking.
3. Subprocessors
We use the following service providers to operate LinkDecoder. Each processes the data described below on our behalf, under data processing agreements where applicable.
| Provider | Purpose | Data |
|---|---|---|
| Vercel | Hosting, serverless compute, edge network | All request and operational data |
| Supabase | Authentication and Postgres database | Email, OAuth IDs, account state, analysis history |
| Upstash | Redis caching, rate limiting, scheduled job queue (QStash) | Cache keys, IP addresses, scheduled monitor IDs |
| Resend | Transactional email delivery | Email address, alert content |
| OAuth sign-in (only if you choose it) | Google account email and OAuth identifier | |
| GitHub | OAuth sign-in (only if you choose it) | GitHub account email and OAuth identifier |
| Sentry | Error tracking and performance monitoring | Error stack traces, request paths (query strings stripped), response codes, and hop timings. No URLs, cookies, auth headers, or IP addresses are forwarded. |
We will update this list when subprocessors change. Material changes will be communicated via email or in-app notice before they take effect.
4. Artificial intelligence and model training
LinkDecoder is built using AI-assisted development tools. However:
- We do not train AI models on your data. Your URLs, analysis results, account information, and any other data you submit are not used to train any machine learning model, ours or any third party’s.
- We do not send your data to third-party LLM providers as part of the analysis pipeline. The redirect tracer, header parser, health scorer, and detection systems are all deterministic code running on our infrastructure.
- If we add AI-powered features in the future (e.g., natural-language summarization of test results), we will update this policy and the feature will be opt-in.
5. Data retention
- Account data: retained for as long as your account is active. Deleted within 30 days of account deletion.
- Test history: retained until you delete it or your account.
- Monitor checks: retained for the lifetime of the monitor; deleted with the monitor.
- Cached analysis results: 5 minutes (used to deduplicate identical requests for performance).
- IP-based rate-limit counters: 60 seconds.
- Operational logs: typically 30 days, longer if required to investigate a security incident.
6. Your rights (GDPR, CCPA, and similar)
Regardless of where you live, you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data — you can do this yourself from the Settings page; deletion is immediate and cascades through every user-owned table.
- Export your test history in JSON format (email us and we will send it within 30 days).
- Object to a particular use of your data.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email cxiqadmin@gmail.com. We respond within 30 days.
7. International data transfers
Our infrastructure is hosted in the United States and the European Union via Vercel and Supabase regional deployments. By using LinkDecoder you consent to your data being processed in these regions. We rely on Standard Contractual Clauses for transfers out of the EU where required.
8. Security
We use industry-standard practices to protect your data: HTTPS everywhere, hashed passwords (handled by Supabase Auth), database row-level security, encrypted backups, and least-privilege access for our team. No system is perfectly secure, but we treat security incidents seriously and will notify affected users without undue delay if a breach occurs.
9. Children
LinkDecoder is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with information, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the product evolves. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated by email or in-app notice.
11. Contact
Questions about this policy or our handling of your data? cxiqadmin@gmail.com