Privacy Policy
Last updated: October 9, 2026
1. Scope and Applicability
This Privacy Policy describes how LinkNest (“we,” “us,” or “our”) collects, uses, stores, and shares information in connection with the LinkNest web application (the “Service”). LinkNest is operated by Oui Digital, a doing-business-as (“DBA”) of Kalyxo LLC, a California limited liability company.
It applies to:
- Registered users who create and manage LinkNest accounts and pages
- Visitors who view publicly published LinkNest pages
This policy applies only to the Service as currently implemented and does not cover third-party websites or services linked from user pages.
2. Information We Collect
a. Information You Provide Directly
When you create or use an account, we collect:
- Name
- Email address
- Password (stored only as a bcrypt hash, where applicable)
- Profile image (if provided through Google or GitHub OAuth)
- Workspace name, page titles, bios, links, text, images, and other content you choose to create
b. Authentication and Account Data
Depending on the login method you use, we collect:
- OAuth profile data from Google or GitHub (name, email address, profile image)
- Authentication tokens provided by OAuth providers
- Verification tokens for email verification or magic link login (temporary)
c. Usage and Analytics Data
On publicly published pages only, we collect limited usage data:
- Page views
- The domain of the page that linked to the visited page, as reported by the visitor's browser (for example instagram.com). Only the domain is kept; the full address is never stored. Browsers often omit it, in which case nothing is recorded.
- Link click events (including the link label, destination URL, and internal block identifier). Clicks on social icons, the announcement banner and embedded media count as link clicks.
Events are sent to our own server and forwarded to PostHog with a random identifier generated for each event, without cookies, local storage or visitor IP addresses. Events cannot be linked to one another or to a visitor.
d. Technical and Security Data
We collect limited technical data for security and abuse prevention purposes:
- IP address of a visitor who submits an abuse report (stored to enforce rate limits)
- Error logs, stack traces, and performance data collected via Sentry
We do not log or store IP addresses of general page visitors at the application level.
e. Subscriber Information
When a visitor signs up through an email sign-up form on a published page, we collect:
- The email address entered
- The page signed up on, and the consent sentence shown with the form
- When the request was made, confirmed and, if applicable, unsubscribed
Nobody is added to a list until they confirm by clicking the link in the confirmation email. Each page has its own list: signing up on one page does not add anyone to another page's list, even if the same account manages both. The visitor's IP address is used briefly to limit abuse and is not stored. Every confirmation email includes an unsubscribe link.
3. How We Use Information
We use collected information to:
- Provide and operate the Service
- Authenticate users and secure accounts
- Display user-created public pages
- Process subscriptions and manage billing status
- Monitor usage and performance of public pages
- Send email sign-up confirmations and make each page's subscriber list available to that page's owner. Page owners are responsible for how they contact their subscribers.
- Detect, prevent, and respond to abuse, fraud, or technical issues
4. Publicly Visible Information
Only content that a user explicitly publishes is publicly visible. Public information may include:
- Page title, bio, avatar image
- Links, text blocks, headers, images, and other published content
- Custom URL slug and SEO metadata
Unpublished pages, dashboards, analytics, subscriber lists, billing information, and account settings are private and accessible only to the authenticated user. A subscriber list is visible only to the owner of the page it belongs to.
5. Cookies and Tracking Technologies
Essential Cookies
We use authentication cookies set by our authentication provider to keep users logged in. These cookies are:
- HTTP-only and secure
- Required for the Service to function
Analytics
We do not use analytics cookies, local storage or any other identifier stored on the visitor's device. Each analytics event is recorded on its own, with no visitor identity.
We do not use advertising cookies or third-party tracking pixels.
6. Third-Party Service Providers
We rely on the following third-party services to operate the Service:
- Neon (PostgreSQL database hosting)
- Cloudflare R2 (image and file storage)
- Google OAuth and GitHub OAuth (authentication)
- Emailit (transactional email delivery, including sign-up confirmations)
- Cloudflare Turnstile (bot protection on forms)
- Stripe (payment processing and billing)
- PostHog (analytics for public pages)
- Sentry (error monitoring and performance diagnostics)
- Upstash (rate limiting infrastructure)
- Google Safe Browsing (URL threat classification)
- Google Fonts (font delivery)
- Hosting provider (application hosting and network delivery)
- YouTube (privacy-enhanced mode), Vimeo, Spotify and Calendly, when a page owner embeds their content. Embedded media loads only after a visitor chooses to play or open it; at that point the provider receives the visitor's IP address under its own privacy policy. Preview images are copies stored by LinkNest, so nothing is requested from these providers before that choice.
Each provider processes data according to its own privacy policies.
7. Payments and Billing Data
Payments are processed entirely by Stripe. We do not collect or store credit card numbers or payment credentials.
We store limited billing-related information, including:
- Stripe customer ID
- Subscription status, plan, and billing period
- Workspace identifier associated with a subscription
8. Data Retention
We do not currently enforce a fixed data retention schedule.
- Account data and user-generated content remain stored until deleted by the user (where deletion is available)
- Verification tokens expire automatically
- Email sign-ups that are never confirmed are deleted 7 days after the request
- Confirmed subscribers are kept until they unsubscribe or the page owner deletes them; after unsubscribing, the address stays visible to the page owner for 30 days and is then deleted
- Rate-limit data expires automatically
- Analytics and error data retention is controlled by third-party providers
9. Data Security
We implement reasonable technical and organizational measures, including:
- HTTPS encryption for data in transit
- SSL-encrypted database connections
- Hashed password storage (bcrypt)
- Authentication and authorization checks on all protected routes
- Server-side input validation and file upload controls
- Rate limiting on sensitive operations
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
Depending on your location, you may have rights to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information
- Opt out of certain data uses where applicable
At this time, account deletion and data export tools are not implemented. Requests must be made by contacting us directly. Subscribers can leave a list at any time with the unsubscribe link in the confirmation email, or ask us to delete their address from any list.
11. International Users
LinkNest is operated from the United States. If you access the Service from outside the U.S., your information may be processed and stored in the United States or other jurisdictions where our service providers operate.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
13. Contact Information
For privacy-related questions or requests, contact us at support@linknest.click.