← How LinkDrop Works

Help

Privacy and security

What LinkDrop stores about you and your recipients, how share links are protected, and what deleting removes.

A plain-language summary. The Privacy Policy and Terms of Service take precedence.

How LinkDrop is hosted, backed up and secured, its subprocessors, its compliance status and how to report a vulnerability are on the Trust page.

Your account

Sign-in is through Google only. LinkDrop stores the email, name and account identifier Google provides. No password is stored. Card details for Pro are entered on Stripe's checkout page; LinkDrop never sees the full card number.

Your documents

LinkDrop stores the PDFs you upload, the text extracted from them, a preview image and an image of each page, plus the AI summaries, key points and version comparisons generated for them. Files are stored at unlisted addresses and served through the app under the share settings you set.

AI features use OpenAI's API. When a summary or version comparison is generated, the extracted text and, for some features, page images are sent. When a visit brief is written, the record of the visit is sent: the pages read, time on each and the order, which pages the reader came back to, spent time on, skimmed or skipped, a heading and short excerpt for the pages involved, and the full text of the pages that held the reader longest or that they came back to. The reader's name and email are sent when the workspace sees them, which it does on every plan. When a reader profile is made for a reader who introduced themselves, OpenAI runs the web search and writes the profile: it gets their name and their email's company domain (never the full address, which is never searched for), their approximate location (which also localises the search), browser language and time zone, and the titles and stored summaries of the documents they opened, plus what the search found. It never gets the documents' text, their IP address, their browser type or the site they came from, and never anything from a private (locked) project. See Contacts.

Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models, and LinkDrop has not opted in to any data-sharing program. New AI runs do not store the prompt or the response: LinkDrop keeps only the facts about each run (its kind, the model, timing, token counts, cost and whether it failed) for 30 days to count credits and investigate failures, then deletes them. Records of runs made before September 30, 2026 may still hold the prompt and response until they expire within 30 days of that date. Uploading a document means it will be processed this way.

What is recorded about recipients

When someone opens a share link, LinkDrop records:

  • That the document was opened, which pages were viewed, how long they spent on each page and how many times they returned to a page.
  • Whether they downloaded the PDF, if you allowed downloads.
  • Their IP address, kept for security and abuse prevention. It is not shown to you.
  • Their name and email, only if they chose to enter them in the viewer. A signed-in viewer's account identity is used instead.
  • An address they give, in the workspace's contacts: one row per person per workspace, with the documents they read and the dates. Contacts are never shared between workspaces and are never mailed anything.

You see all of these except the IP address, on every plan. Analytics explains each figure. The same facts, written for the person who opened the link, are in If you received a link.

To tell repeat visits apart, a random identifier is stored in the viewer's browser. It is not linked across different owners' documents. Clearing browser storage removes it.

LinkDrop does not fingerprint devices and runs no advertising trackers. It does not store browser user-agent strings, except once when a reader introduces themselves: that introduction record (IP address, browser type and language, the referring site and the approximate network location) is kept for 90 days, for the reader profile. The only third-party analytics is Vercel Web Analytics, which counts page visits in aggregate without cookies, on share pages as well as the app. Before a page address is sent, its query string is removed and any part that grants access, such as a share link's token, is replaced, so Vercel learns which kind of page was opened but never gets a working link. It never sees document contents. See section 4.2 of the Privacy Policy. The public homepage loads a map dataset from a public CDN for its animation; nothing like that runs inside the signed-in app.

  • Share links are addressed by a random identifier. A disabled, expired, archived or deleted link answers exactly like a link that never existed.
  • Share passwords are stored as salted hashes and, so that owners and admins can reveal them, in encrypted form. Wrong guesses are rate-limited per link and per address.
  • After a correct password, a signed cookie keeps the browser unlocked for 14 days. It does not contain the password. Changing the link's password locks every browser that unlocked it with the old one.
  • Share pages carry a no-index instruction and LinkDrop's robots rules tell crawlers not to fetch them, so documents stay out of search engines.

To cut off one recipient, disable their link; the document's other links keep working. Share links covers passwords, expiry and disabling.

Agents

  • An agent acts only in the workspace it was connected to.
  • Agent keys are shown once and stored only as a hash. Agents that connect by signing in hold tokens that are also stored only as hashes.
  • Revoking a key or a signed-in agent on the Agents page takes effect at once.
  • Deleting a document, share link, project or project link through an agent always asks you first.

See Connect your agent.

Emails and Slack

Workspace members are emailed when recipients open or finish reading a link, on by default, and every such email has a link to turn it off. The Privacy Policy tells viewers that the person who shared a link may be emailed when they open it. See Notifications and visit briefs.

If you connect Slack, LinkDrop stores the bot token Slack issues, encrypted and never shown back, and uses it only to post to the channels your workspace chooses. It also keeps Slack's id for each message it posted, so a reader summary can be posted as a reply under that visit's brief. The integration never reads your Slack. Activity in a private (locked) project posts only to the channel chosen for that project. Disconnecting deletes the stored token, and so does removing the app in Slack: Slack tells LinkDrop, and LinkDrop deletes that Slack workspace's connections and token. See Slack.

Deleting documents and workspaces

Deleting a document, project or workspace removes it from view and disables its share links immediately. 30 days after deletion it is permanently purged: its files, its share links, and the visits and activity of the people it was shared with. Documents in a deleted project are not deleted with it; they stay in the workspace. Something purged can remain in a backup until that backup expires. Contact support if you need something erased sooner. Viewer activity is kept for two years at most (see below). A reader summary is kept, one per contact, until it is rewritten, and is deleted when a document it was written from is purged and when its workspace is purged.

Only a workspace's owner can delete it: on the dashboard's Workspace tab, click Manage… next to the workspace, then Delete workspace…, and type delete followed by the workspace name. Other members can leave instead; see Teams and workspaces. Deleting a workspace takes its contacts out of reach with it, and they are erased with the rest of the workspace 30 days later. Its billing records are kept for accounting, without the name of the person who made them.

A workspace's owner can also reset it instead (Manage…, then Reset workspace data…, and type reset followed by the workspace name), or ask support to. Support also resets workspaces used for an app review, testing or a demo; the owner gets an email when it is done. A reset removes the workspace's documents, files, links, projects, contacts, analytics and activity immediately and permanently, with no 30-day window, and keeps the workspace, its members, settings and billing records. Like every permanent deletion, it leaves a record of what was removed (titles, sizes, counts and dates, never the files).

How long LinkDrop keeps things

LinkDrop is not a long-term archive, so keep your own copies of anything you need to keep.

  • Reader analytics (visits, time per page, the activity feed and visit briefs) are kept for two years, then deleted automatically. Your documents, links and their total counts stay: each link keeps one record per reader, which its view and download totals are counted from, for as long as the link exists.
  • Archived documents move to Recently deleted one year after you archive them. You can restore them from there for 30 days.
  • Inactive Free workspaces: if no member signs in for two years, the owner gets an email. If nobody signs in within 30 days, the workspace's content is removed and the workspace itself stays. Workspaces that have ever had a paid plan or bought credits are never removed this way.
  • Inactive accounts: an account that has never paid and has not been signed in to for three years gets an email, and is deleted 30 days later unless someone signs in.

Signing in once cancels either countdown. The full list is in the Privacy Policy.

Deleting your account

Open the dashboard's Account tab and click Delete account. To confirm, type delete my account.

  • Your account stops working straight away: you are signed out, your agent keys stop, and every share link in a workspace only you belong to stops opening.
  • Workspaces you share with other people carry on without you.
  • Your documents and data are kept for 30 days in case this was a mistake, then deleted for good, files included. To change your mind within those 30 days, email us.

There is no self-service data export yet. To receive a copy of your data, or to delete specific information without closing your account, email hi@lnkdrp.com and it is handled by hand.

Error records are deleted after 14 days. Billing records are kept as required for tax and accounting.

Still stuck? Talk to us. We reply within a business day.

Privacy and security - LinkDrop