← Back to LinkTaps

Privacy Policy for LinkTaps

Effective Date: January 17, 2026 Last Updated: October 6, 2026

Introduction

LinkTaps ("we," "our," or "us") is a minimal link redirect service that operates on a privacy-first principle. We are committed to collecting only the minimum amount of data necessary to provide our service and comply with legal requirements.

This Privacy Policy explains what information we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Our Commitment to Minimal Data Collection

LinkTaps is designed from the ground up to minimize data collection. We:

Our Commitment to Minimal Permissions

Unlike most services that request broad access to your social media accounts upfront, LinkTaps only requests the specific permissions absolutely required for the features you choose to use. We believe you should have full control over what access you grant.

Data Controller

LinkTaps acts as the data controller for the personal data we collect through our service.

Contact Information: Email: support@linktaps.io


1. Information We Collect

1.1 Information You Provide Directly

Account Information:

Link/Campaign Data:

Link-in-Bio Data:

Feedback and Support:

CSV Import Data:

1.2 Information Collected Automatically

Click Analytics (for your links): When someone clicks on your short link, we collect:

App install and open reports (for your links): If you use install attribution, your app-attribution provider (such as Branch or AppsFlyer) or your app can tell us that a click on your link led to an install or an open of your app. For each report we store:

A report contains no device identifier. Of what a report sends us, we read and store only the fields above; we do not store an advertising identifier (IDFA or GAID), IP address or user ID it carries. A report is kept as long as the click it belongs to: after 37 calendar months both are folded into daily totals, which keep counts and no click identifiers. A report is deleted sooner when the link, the Domain LinkTaps site or its workspace is permanently deleted.

When your provider reports a click that we cannot match to one of your links, we count it per workspace, day, event and reason, so that you can see a broken integration. These counts hold no visitor data and are kept 400 days.

IP Addresses:

Bot Filtering:

Web Analytics (Cloudflare Web Analytics):

1.3 Cookies

We set no marketing, advertising or cross-site tracking cookies, and no third party sets cookies through our service. Every cookie below is first-party: it is set by the site you are on, and only for the feature described.

On linktaps.io, when you use the LinkTaps app:

Session Cookie (__sid):

Device Cookie (__did):

Connection Cookie (lt_oauth_bind):

AI Assistant Sign-in Cookie (__mcp_authz):

On LinkTaps short links, when someone clicks one:

These cookies are short-lived, HttpOnly and SameSite=Lax. They are used only to count one click once and to carry that click out of an in-app browser (such as Instagram's). None of them lasts longer than 10 minutes, and none identifies a visitor across visits.

On websites that use the LinkTaps snippet (Domain LinkTaps): the snippet sets no cookie.

Internal: lt_vdebug (30 days) is set only on devices of LinkTaps staff who unlock the debug console with a secret token. It is never set for visitors.

We do NOT use:

The cookies we set on linktaps.io and on short links are strictly necessary for the features described, so you will not see a cookie consent banner on our site.

1.4 Information We Do NOT Collect or Store

1.5 Social Media Automation and Meta Platform Data

LinkTaps includes optional automation features that integrate with Facebook and Instagram through the Meta Platform APIs. This section describes what data we collect, how we use it, and how you can delete it.

Minimal Permission Model

We request only the Meta permissions strictly necessary for the features you activate. When you first connect, we request only the permissions required for the feature you chose to set up -- comment monitoring and messaging if you set up DM or comment automations, or publishing permissions if you set up Upload and Publish. Permissions for insights, content management, or other capabilities are never requested until you explicitly choose to enable those features. You can see exactly which permissions have been granted at any time in Settings > Connected Accounts, and you can upgrade or revoke permissions individually. This gives you complete control over what LinkTaps can and cannot do with your accounts -- a level of granularity that most automation services do not offer.

What We Collect via Meta APIs

When you connect a Facebook Page or Instagram account to LinkTaps, and when users interact with your connected posts, our system may receive the following data:

We do not collect email addresses, phone numbers, friend lists, or any private data beyond what is listed above through the Meta APIs.

How We Use Meta Platform Data

We use the data described above exclusively to:

Real-time processing. When Meta sends us a webhook notification about a new comment or direct message on your connected account, our application server processes it in real time: it matches it against your keyword rules, sends any configured replies, and records the activity in our database for your activity log and to prevent duplicate replies. Our application logs (see section 4) record that an event was processed; we keep the text of comments and messages, and the names, usernames and IDs of the people who wrote them, out of those logs.

Profile picture fetching. When you choose to pull a profile picture from a social media platform during account setup, we fetch the publicly available profile page to extract the image URL. Our application server makes this request directly, and no login credentials or private data are accessed. The fetched image is stored in Cloudflare R2 as your profile picture.

We do not use Meta Platform Data for advertising, profiling, selling, or any purpose other than providing the automation and publishing features you configure.

Storage and Retention of Meta Platform Data

Data TypeRetentionPurpose
Comment IDs (dedup cache)7 daysPrevents duplicate replies to the same comment
Reply review queue (AI replies waiting for your review, sent, rejected or not answered, with the comment or message each one answers)90 days after the reply was queuedReviewing AI replies before they are sent, and showing the questions the AI could not answer
Activity log (commenter name, comment text, reply sent, action taken)Until you delete it, or 180 days after the account is disconnectedAudit trail for your automation activity
Post metadata (caption, media URL, permalink)Until you deactivate or delete the post, or 180 days after the account is disconnectedMonitoring and rule matching
Keyword rules and DM rulesUntil you delete them, or 180 days after the account is disconnectedAutomation configuration
Direct messages and conversationsWhile the account is connected; 180 days after you disconnect it; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deletedYour inbox, and keyword matching for DM automations
Repost queueWhile the account is connected; 180 days after you disconnect itScheduling the reposts you set up
Connected account tokensUntil you disconnect the accountAPI access for automation and publishing
Disconnected accounts (the account's identity and automation setup, without its tokens)180 days after you disconnect, then permanently deleted; we email the workspace owner 14 days before if the account still has an automation, or 10 or more conversations or queued repostsSo that reconnecting restores your setup
Publish job recordsUntil you delete themPublishing status tracking
Deleting Your Meta Data

You can delete all Meta Platform Data stored by LinkTaps at any time:

When you disconnect an account connected through Facebook Login, we also attempt to revoke its permissions on Meta's side, unless that would also cut off other accounts still connected to LinkTaps with the same Facebook login. Disconnecting does not end the permissions of accounts connected through Facebook Login for Business, Instagram login or Threads; only Meta can, when you remove LinkTaps there: in Business Suite > Settings > Integrations > Connected Apps for Facebook Login for Business, in your Instagram settings on instagram.com for Instagram login, and in Settings > Website Permissions on threads.com for Threads. Resetting the Meta integration does not revoke permissions on Meta's side; to end them, disconnect accounts connected through Facebook Login first, or remove LinkTaps in your Facebook settings or in the places above.

1.6 AI-Powered Replies and Third-Party AI Processing

When you enable the AI Replies feature, comment text and commenter context from your connected posts may be sent to a third-party AI provider (OpenRouter) for processing. This is used solely to generate a relevant reply based on the knowledge base you configure.

Direct messages are sent to the AI provider too, when you use AI for them. If you turn on AI replies to direct messages, each incoming direct message is sent to OpenRouter to decide whether your knowledge base answers it and to write the reply. If you ask for a suggested reply in your LinkTaps inbox, the latest message is sent in the same way.

You can disable AI replies at any time from the AI Replies tab in the dashboard.

Keyword rules also use AI, whether or not AI Replies is enabled. When a keyword rule fires on a comment that contains the keyword mid-sentence, or on a rule set to answer general questions, the comment text is sent to an AI provider to decide whether the commenter is actually asking for what the rule sends. This runs on keyword automations on their own, so it is not covered by the AI Replies toggle above.

To stop this, turn off the keyword rule, or set it to exact-match only.


2. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

Data TypeLegal BasisPurpose
Email address, account dataContractual necessityTo provide you with the link redirect service you requested
Click analytics dataLegitimate interestsTo provide you with analytics about your links' performance
Security logs, rate limitingLegitimate interestsTo protect our service from abuse and ensure security
Email delivery metadataLegitimate interestsTroubleshooting delivery and preventing abuse of our email; kept 1 year
IP address (geolocation)Legitimate interestsTo provide country-level analytics for your campaigns, and to route location-targeted links by approximate country/region
Cloudflare Web AnalyticsLegitimate interestsTo improve our website and service
Meta Platform Data (comments, posts)Contractual necessityTo provide the automation features you configured
AI processing of commentsContractual necessityTo generate AI-powered replies you enabled

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Service Delivery

3.2 Service Improvement

3.3 Security and Compliance

3.4 Communication

- Free tier reminder emails as you approach your 2,000-action limit (sent at 1,000 / 1,500 / 1,800 / 2,000 actions). These are necessary to operate the service and are not opt-out while you remain on the free tier. - Pro plan reminder emails when you cross 4,000 monthly actions, so you can anticipate overage charges.


4. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

Data TypeRetention PeriodReason
Account informationUntil account deletionService provision
Campaign/link dataUntil you delete the campaign or its workspace is deleted (deleting your account deletes the workspaces you own; a campaign in someone else's workspace stays with that workspace)Service provision
Deleted workspaces30 days after deletion, then permanently deletedSo a workspace deleted by mistake can be restored; everything in it, including direct messages and the uploaded images we can attribute to it, is deleted when the 30 days end
Holds on a deleted workspace's username, account handles and Domain LinkTaps domain60 days after deletionSo nobody else can take over the links, handles or domain of a workspace that was just deleted
Click analytics37 calendar months as individual clicks, then as daily totals until the link or its workspace is deletedAnalytics for your links. Daily totals keep counts by day and by country, browser, operating system, platform, whether the link opened an app, and referring site (the site only, not the page), and no click identifiers
Click identifiers (clickid)37 calendar months with the individual click, or sooner if the campaign or its workspace is deleted; daily totals keep noneUsed for analytics accuracy and, on the link's destination, for the link owner's attribution; not for cross-session tracking
Install and open reports37 calendar months with the click they belong to, then as daily totals that keep no click identifiers; sooner if the link, the Domain LinkTaps site or its workspace is permanently deletedTelling the link's owner which clicks led to an install or an open of their app; no device identifiers
Unmatched install and open counts400 days, then deletedShowing you reports we could not match to your links; per workspace and day, no visitor data
Domain LinkTaps daily countsUntil the site or its workspace is deletedPer-day totals for your site's analytics; no visitor data
Email audit metadata1 year (365 days)Troubleshooting delivery and preventing abuse of our email
Security logs1 year (365 days)Security monitoring and incident response
Application logs30 days, then automatically deletedTroubleshooting and investigating outages. They can include error details, and email and IP addresses in masked form (the first letter and domain of an email address, and an IP address without its last part), but not access tokens or the text of comments or messages from your connected accounts
Backups30 days, then automatically deletedEncrypted copies of our database, kept so the service can be restored after a failure. Data you delete can remain in a backup until that backup is deleted
Records of deletion requests1 year (365 days) after the request is completed; kept until resolved if it fails or while part of it is still outstanding; a record of deleting a workspace that had a Stripe billing customer is kept for that year or until our payment provider confirms the customer record is deleted, whichever is laterSo the status of a deletion request, including a Meta data deletion confirmation code, can still be checked; a billing record is kept so that a later payment by that customer cannot bring a deleted workspace back
Rate limit countersUntil the counter's time window ends, then deletedAbuse prevention
Sign-in attempt counters and account lockoutsA lockout ends after 24 hours; the records themselves are not yet deleted on a schedule, except that those naming your email address are deleted with your accountProtecting accounts from repeated sign-in attempts
Session cookies90 days after your last activity, or until you log outAuthentication
Reply review queue90 days after the reply was queued, then deletedHolding AI replies for you to review before they are sent, and showing the questions the AI could not answer; each entry keeps the comment or message it answers and who wrote it
Meta automation activity logsUntil you delete it, or 180 days after the account is disconnectedAudit trail
Meta comment dedup cache7 daysDuplicate prevention
Connected Meta account dataUntil you disconnect the account, then 180 daysAPI access; access tokens are deleted at once when you disconnect
Meta direct messages and conversationsWhile the account is connected, then 180 days after you disconnect it; a conversation that another account still connected to the same workspace can take over is kept with that account rather than deletedYour inbox and DM automations
Meta repost queueWhile the account is connected, then 180 days after you disconnect itScheduling the reposts you set up
Disconnected Meta accounts180 days after you disconnect, then permanently deletedSo that reconnecting restores the account's automations, messages and repost queue
You can request deletion of your data at any time by contacting us or deleting your account.


5. Data Sharing and Disclosure

We do NOT sell your personal data to third parties.

We may share your information only in the following limited circumstances:

5.1 Service Providers (Data Processors)

We use the following third-party service providers who process data on our behalf:

ProviderPurposeData SharedLocation
ConvexDatabase hostingAll account and campaign dataUnited States
Amazon Web Services (AWS SES)Email deliveryEmail addresses, metadataUnited States
CloudflareWeb analytics, CDN, DDoS protectionIP addresses, browsing dataGlobal
ip-api.comIP geolocation (country/region) when CDN geo headers are unavailableIP addressGlobal
Cloudflare WorkersUptime monitoring of our own siteNone (it requests our public pages and health check)Global
TypeSafeKeyword-intent decisions on incoming commentsComment text (truncated, no PII), rule keywordUnited States
Fly.ioApplication hostingHTTP request dataUnited States
AxiomApplication log storageApplication logs: error details, and masked email and IP addressesUnited States
Cloudflare R2Media file storage; encrypted database backupsUploaded images and videos; encrypted copies of our database (see Backups in section 4)Global
OpenRouterAI reply generationComment text, knowledge base context (no PII)United States
StripePayment processing for Pro subscriptionsEmail, billing details (Stripe handles card data directly -- we never see or store it)United States
All processors are contractually bound to protect your data in compliance with GDPR.

5.2 Legal Requirements

We may disclose your information if required by law, such as:

5.3 Business Transfers

If LinkTaps is involved in a merger, acquisition, or sale of assets, your data may be transferred. You will be notified of any such change.


6. International Data Transfers

LinkTaps is operated from the United States. If you access our service from outside the United States, your data will be transferred to and processed in the United States.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland:


7. Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights:

7.1 Right to Access

You can request a copy of the personal data we hold about you.

7.2 Right to Rectification

You can request correction of inaccurate or incomplete data.

7.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data by:

Deleting a workspace is different from deleting your account, and only the workspace's owner can do it. A deleted workspace stops working within a minute: its links, pages and automations stop, its connected Meta accounts are disconnected, and any subscription on it is cancelled at once, with no further charges. Messages and comments that reach its connected accounts while it is deleted are not answered and not kept. Everything in the workspace is kept for 30 days so that the owner can restore it, and is then permanently deleted, including direct messages people sent to its connected accounts and the images and media uploaded to it that we can attribute to the workspace. Any uploaded file we cannot attribute to it is kept for manual review and then removed by hand. For 60 days after deletion, the workspace's username, its connected accounts' handles and its Domain LinkTaps domain stay reserved, so nobody else can take them over. A restored workspace comes back with its content, but its Meta accounts must be reconnected and its subscription started again. Direct messages and comment replies that were due to be sent while it was deleted are not sent, and posts scheduled for that time are not published; reposts resume on their normal schedule.

Deleting your account is immediate and cannot be undone; there is no restore window. Every workspace you own is deleted with everything in it, including any you deleted in the last 30 days, which can then no longer be restored. That includes direct messages people sent to their connected accounts and the images and media uploaded to them that we can attribute to a workspace; any uploaded file we cannot attribute is kept for manual review and then removed by hand. Any subscription on those workspaces is cancelled at once, with no further charges. Subscription fees and overage already incurred are not refunded. You are removed from every workspace you are a member of, and your MCP keys and connected AI apps are deleted; content you created in someone else's workspace stays with that workspace. Your sessions, devices, login codes and the invitations sent to your address are deleted. Security records of actions you took are kept, with you shown as "deleted user", as are the records of usernames, account handles and Domain LinkTaps sites you deleted. In security records about your account, your address and the details of the event are removed, except in a few records whose purpose is the address itself (the deletion, changes of email address or username, session revocations and data exports), which keep your address for fraud prevention. Records of what other people did that concern you, such as an invitation to a workspace or an administrator's action on your account, do not keep your address; where they identify you at all, it is by your account or by a one-way fingerprint of your address. The record of emails we sent you keeps only a one-way fingerprint of your address, and no address in any email subject. For 60 days after a workspace you own is deleted, its username, its connected accounts' handles and its Domain LinkTaps domain stay reserved, so nobody else can take them over.

Note: Security logs and the record of emails we send are kept for the periods in section 4, and Stripe keeps its own records of past transactions under its own retention policy.

7.4 Right to Restriction of Processing

You can request that we limit how we use your data in certain circumstances.

7.5 Right to Data Portability

You can request a machine-readable copy of your data to transfer to another service.

7.6 Right to Object

You can object to processing based on legitimate interests (such as analytics).

7.7 Right to Withdraw Consent

Where we rely on consent, you can withdraw it at any time (though this doesn't apply to most of our processing, which is based on contract or legitimate interests).

7.8 Right to Lodge a Complaint

You can file a complaint with your local data protection authority (DPA) if you believe we have violated GDPR.

To exercise any of these rights, contact us at: support@linktaps.io

We will respond to your request within 30 days.


8. Security Measures

We implement industry-standard security measures to protect your data:

Technical Measures:

Organizational Measures:

However, no system is 100% secure. If you discover a security vulnerability, please report it to support@linktaps.io.


9. Children's Privacy

LinkTaps is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If we learn that we have collected data from a child without parental consent, we will delete it immediately.

If you believe a child has provided us with personal data, please contact us at support@linktaps.io.


10. Do Not Track (DNT)

Some browsers offer a "Do Not Track" (DNT) signal, and some offer Global Privacy Control (GPC). When a click on a short link comes from a browser sending either signal, we do not add a click identifier to the link's destination, and we do not create one at all unless the click came from an in-app browser (where it is used only on our own pages, to record the move to an external browser). Beyond that, because there is no industry standard for DNT, we do not currently respond to these signals. However, we already minimize tracking by:


11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, contact us at support@linktaps.io.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will:

Continued use of our service after changes constitute acceptance of the updated policy.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: support@linktaps.io

Mailing address: LinkTaps LLC, Ramsey County, Minnesota, United States

Data Protection Inquiries: For GDPR-specific requests, please include "GDPR Request" in the subject line.


14. Key Takeaways (Summary)

For your convenience, here's a summary of our privacy-first approach:

  • ✓ Minimal Data Collection: We collect only what's necessary to run our services
  • ✓ No Cookie Banner: We use only essential authentication cookies
  • ✓ No Email Content Storage: Only metadata is stored for compliance
  • ✓ No Data Selling: We never sell your data to third parties
  • ✓ Cookieless Analytics: Cloudflare Web Analytics doesn't use cookies
  • ✓ GDPR Compliant: Full user rights support (access, deletion, portability, etc.)
  • ✓ Minimal Permissions: Only the permissions you need, upgraded one at a time under your control
  • ✓ Meta Data Transparency: Clear documentation of what Meta Platform Data we collect and why
  • ✓ Self-Service Deletion: Delete all Meta data anytime from Settings > Workspace > Reset Meta Integration
  • ✓ AI Transparency: We tell you what comment and direct-message text is sent to AI providers, and we never send them commenters' or senders' names or IDs
  • ✓ Privacy by Design: Built with data minimization as a core principle

  • Thank you for trusting LinkTaps with your link management needs.