Privacy Notice for Lynkr

Last updated: May 28, 2026

1. Controller & Contact

Controller: VitaApps S.R.L., Bucharest, Romania
Email: lynkr.app@vitaapps.dev
Data Protection Contact / DPO: lynkr.app@vitaapps.dev

2. Supervisory Authority

EU users may lodge complaints with their national Data Protection Authority (e.g., Romania's ANSPDCP).

3. Scope & Updates

This notice applies to personal data processed via the Lynkr mobile app, the Lynkr Chrome browser extension, and our website. Material changes will be communicated via app, extension, or email; continued use indicates acceptance.

4. What Data We Collect

4.1 Information You Provide

  • Registration data (email, username, password)
  • List titles, descriptions, and content
  • Links added to lists
  • Comments on links and lists
  • Sharing preferences and permissions
  • Support inquiries and survey feedback

4.2 Automatically Collected

  • Device metadata (IP, identifiers, OS, app version, logs, analytics)
  • Usage patterns (lists created, links shared, interaction frequency)
  • Performance data and crash reports

4.3 Third-Party Data

  • Profile info from social login or app stores
  • Anonymized data from analytics SDKs

4.4 AI Summarization (Chrome extension)

When you tap "Summarize" on a saved link in the Chrome extension, your browser fetches the public content of that link (article HTML, video metadata) and sends it — together with the link's URL and your account ID — to our Cloud Function backend, which forwards it to Google's Gemini AI to produce a summary. The generated summary is then stored in your Lynkr account so you can read it later. The fetched page content itself is not retained beyond the summarization call. Per the Google Gemini API terms, the content you submit is not used to train Google's AI models.

5. Legal Bases & Purposes

  • Service provision: performance of contract (list management, sharing, synchronization)
  • Security & admin: legitimate interests (fraud prevention, technical support)
  • Feature improvement: legitimate interests (app optimization, new features)
  • Marketing: subject to consent
  • Legal compliance: legal obligation

6. Data Sharing

  • With processors (hosting, analytics, support) under GDPR-compliant contracts
  • With other users when you share lists or make comments (as intended by the app functionality)
  • For legal obligations, court orders, or protection of rights
  • In case of business transfers (e.g., merger, acquisition)

Key processors we currently use:

  • Google Firebase (Authentication, Firestore, Cloud Functions, Cloud Storage) — hosts your account, links and collections.
  • Google Gemini API — generates AI summaries on demand (see Section 4.4).
  • RevenueCat — manages Premium subscriptions and entitlements.

We do not sell your personal data. We do not use your data for any purpose unrelated to the stated functionality, and we do not use it to assess creditworthiness or for lending.

7. International Transfers

Your data may be processed outside the EU (e.g., cloud servers). Transfers are protected via EU-approved safeguards (Standard Contractual Clauses).

8. Cookies & Tracking

We use cookies and SDKs for analytics, performance, and crash reporting. Non-essential tracking is subject to your explicit consent. Essential cookies (login/security) are exempt.

9. Data Retention

  • Account & user data: until account closure + legal retention period
  • Lists, links & comments: until you delete them or close your account
  • AI summaries: until you delete the underlying link or close your account
  • Shared content: may remain visible to other users until they remove it from their lists
  • Crash reports & diagnostics: up to 90 days (to analyze and fix app issues)
  • Logs & analytics: up to 180 days (longer for legal reasons)
  • Support communications: until resolution or deletion request

10. Your Rights

You may, under GDPR, CCPA/CPRA, and similar laws, access, correct, delete, object to processing, request data portability, or withdraw consent. Contact us at lynkr.app@vitaapps.dev.

11. Children's Privacy

Lynkr is not directed at children under 13. We do not knowingly collect data from minors; if discovered, it will be promptly deleted.

12. Security

We implement encryption, access controls, and secure infrastructure. While no system is 100% secure, we follow best practices to protect your lists and personal data.

13. Automated Decision Making

We currently do not use automated decision-making with legal or similarly significant effects on you.

14. Third-Party Links & Content

Users may share links to third-party websites and services. Each third party has its own privacy policy. Please review before sharing personal data or accessing external content.

15. Sharing & Collaboration Features

When you share lists with other users or make content public, that information becomes visible to the intended recipients. You control sharing permissions, but shared content may be copied or saved by other users.

16. Chrome Extension — Specific Disclosures

Single purpose.

The Lynkr Chrome extension does one thing: let you save any web page to your Lynkr lists from your browser, and (optionally) request an AI summary for a saved link as described in Section 4.4. It is not an ad blocker, tracker, or general browsing tool.

Permissions we request and why.

  • storage — keeps your sign-in token and a small cache of your recent lists in your browser so the popup opens instantly.
  • identity (Google sign-in only) — used by chrome.identity.launchWebAuthFlow so you can sign in with Google. Subject to the Google API Services User Data Policy, including the Limited Use requirements.
  • tabs / activeTab — read the URL and title of the page you are currently on, only when you explicitly open the Lynkr popup or click "Save to Lynkr". Never in the background, never on tabs you have not opened the popup on.
  • scripting (or a narrowly scoped content_scripts matcher) — extract the page's title, canonical URL, and Open Graph metadata at the moment you save the link, so the saved entry shows a meaningful preview. Runs only on the page you actively save.
  • Host permissions (e.g., <all_urls> if granted) — so you can save links from any website. We never read other tabs or pages you have not chosen to save.

What the extension handles vs. what it does NOT touch.

  • We process: the URL, title, and standard Open Graph metadata of pages you explicitly save; your Lynkr account ID; your authentication token; and — only when you tap "Summarize" — the public page content sent to our backend as described in Section 4.4.
  • We do not collect: your full browsing history, the content of pages you did not save, keystrokes outside the extension popup, form data, passwords from other sites, your bookmarks, or activity on tabs you did not interact with through the extension.

Pairing the extension with your mobile account.

If you sign in via the mobile app's "Pair extension" flow, the app creates a short-lived (≤ 5 minutes), single-use code in a server-only Firestore collection. Only our Cloud Function can read it; the function exchanges the code for a custom Firebase auth token bound to your account, then marks the code used. Neither the code nor your account ID is ever readable by other users.

Local storage in your browser.

The extension stores a Firebase authentication token (so you stay signed in) and a small cache of your most recent lists. Both are cleared when you sign out of the extension or remove it. The extension does not set tracking cookies on third-party sites and does not modify the content of pages you visit.

Limited Use of Google data.

If you sign in with Google via the extension, our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data for advertising, creditworthiness, or any purpose unrelated to providing the Lynkr service; we do not use it to serve advertising; and humans do not access this data except (i) where you explicitly request support, (ii) for security or abuse prevention, or (iii) as required by law.

17. Updates & Contact

This notice was last updated on May 28, 2026. You will be informed via app, extension, or email of significant updates. If you have questions, concerns, or wish to exercise your rights, contact us at lynkr.app@vitaapps.dev.