Legal
Privacy Policy
Last updated: October 4, 2026
1. Introduction
LinkDrop is a service of LNKDRP Technologies LLC, a California limited liability company ("we", "us", or "our"), which is the controller of the information described here. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our document sharing platform and related services (collectively, the "Service").
It applies to two kinds of people: account holders who upload and share documents, and viewers who open a link someone shared with them. Section 5 is written for viewers.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Sign-in is through Google only. When you sign in, Google gives us your email address, name, Google account identifier, and profile picture URL. We store these and the time of your last sign-in. We do not store a password.
- Documents and Content: We store the PDF documents you upload or import from a URL, along with the text we extract from them, a preview image, an image of each page, and your document titles and settings.
- AI Output: Summaries, key points, and version comparisons generated for your documents are stored with them. Visit briefs (a written account of one reader's visit) and reader summaries (a written account of one contact's reading across all their visits) are stored in your workspace, as are reader profiles (who a reader who introduced themselves is, from public professional sources); see sections 5 and 6. We also keep a record of each AI run for 30 days, so we can count credits and debug problems. That record holds only the facts about the run (which kind it was, the model, how long it took, how many tokens it used, what it cost and whether it failed), never the prompt sent or the response received.
- Workspace Information: If you create or join a workspace, we store the workspace name, optional icon, its members and their roles, and any invitation you send (including the invitee's email address if you enter one).
- Preferences: Notification settings, starred documents, and similar choices you make in the app.
- Communication: When you contact us for support, we collect your email address and any information you provide in your message.
- Payment Information: If a workspace upgrades to Pro, you enter your card details on Stripe's checkout page. Stripe gives us a customer identifier, subscription status, billing period dates, and metered usage totals. We never see or store your full card number.
2.2 Information Collected Automatically
- Anonymous Identity: If you use parts of the Service without signing in, we create a random identifier and secret stored in your browser so your uploads stay attached to that browser until you sign in and claim them. We store only a hash of the secret.
- Product Usage (signed-in users): Which pages of the app you visit, the page that referred you, and how long you stay, tied to a hashed per-session identifier. We use this to understand which features are used.
- Viewer Activity on Share Links: Described in section 5. This includes the viewer's IP address.
- Error and Security Logs: When something fails we record the route, the error message and stack trace, your user identifier if you were signed in, and a sanitized copy of the request context. Error records are deleted automatically after 14 days. Our rate-limiting records key on IP address (and, for download requests, a hash of the email entered) and expire automatically after the limit window.
- Hosting Logs: Our hosting provider keeps standard request logs (IP address, timestamp, URL, browser type) for a limited period as part of operating the Service.
We do not fingerprint devices and we do not run any advertising trackers. We do not store browser user-agent strings in our own database, except once when a viewer introduces themselves on a share link: that introduction record keeps the browser type with the IP address, language setting and referring site for 90 days (see Reader profiles). The only third-party analytics we use is Vercel Web Analytics, which counts page visits in aggregate without cookies (see section 4.2).
2.3 Information from Third Parties
- Google: Your email, name, account identifier, and profile picture URL when you sign in.
- Stripe: Transaction and subscription status, billing period dates, and invoice availability needed to run your plan.
- Google Drive, if you connect it: Your Google account's email address and identifier, and the names, types, owners and dates of the Drive files you or your agent search for, and the contents of the files you or your agent choose to import. See Google Drive in section 4.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Store, process, and display your documents, including sending document text and page images to our AI provider to generate summaries, key points, and version comparisons
- Show you who viewed your shared documents and how they engaged with them, including page by page, and write visit briefs and reader summaries about that reading with our AI provider, and reader profiles of readers who introduce themselves
- Post workspace activity, visit briefs and reader summaries to a Slack channel, if your workspace connects one
- Find and import the Google Drive files you or your agent ask for, if you connect your Google Drive
- Create and manage your account, workspaces, memberships, and settings
- Generate share links and enforce the access controls you set on them
- Meter credits, process payments, and manage subscriptions
- Send service emails: workspace invitations; document activity notifications and digests, which are on by default and which you can turn off at any time in your settings (view notifications can also be turned off from the email itself); visit briefs, the written account of a viewer's visit, which follow the same rule; and download-request and approval messages
- Detect, prevent, and address technical issues, abuse, and security threats, including rate limiting
- Comply with legal obligations and enforce our Terms of Service
Notification change, effective September 16, 2026: document activity emails now include view notifications, which tell workspace members that someone opened a shared document. They are on by default, so this section no longer describes activity emails as ones you have opted into.
We do not use your information for advertising, and we do not sell it.
5. If Someone Shared a Document With You
This section is for people who open a LinkDrop share link. You do not need an account to do so, but the document owner can see how you interacted with what they shared.
When you open a share link we record the following. Everything except your IP address is shown to the document owner:
- That the document was opened, which pages you viewed, in what order, how long you spent on each page, and how many times you returned to a page. From this we sort the pages of each visit into the ones you came back to, spent time on (15 seconds or more), skimmed (3 to 15 seconds), passed through, and never opened.
- Whether you downloaded the PDF, if the owner enabled downloads
- Your IP address, which we keep for security and abuse prevention. It is not shown to the document owner. If you introduce yourself, an approximate location derived from it may be (see Reader profiles).
- Your name and email address, only if you choose to enter them when the viewer asks you to introduce yourself. You can decline. If you are signed in to LinkDrop, your account identity is used instead.
The "document owner" here means the workspace that shared the link: every member of that workspace can see this information, including people who join it later. If the document is in a private (locked) project, only that project's members can see your visits and the briefs about them. What the workspace sees does not depend on its plan. On every plan, if you are signed in to LinkDrop the workspace sees your account name and email address; otherwise it sees the name and email address you typed in, if you gave them. On every plan the workspace also sees each of your visits page by page, all of them since your first, the visit briefs written about them, and, if you are one of its contacts, your reading history across its documents.
The document owner and members of their workspace may be emailed when you open it, and that email can include the details above that are shown to the owner.
Visit briefs, effective September 23, 2026: a few minutes after you stop reading, the details above (pages, time on each page, returns, downloads, and your name if you gave one) may be summarised by automated processing into a short written account of your visit for the document owner and their workspace. The brief is emailed to the workspace's members and may be posted to a Slack channel the workspace connected.
Page-level briefs and reader summaries, effective September 30, 2026: a visit brief now says which pages you came back to, spent time on, skimmed and skipped. To write it, our AI provider receives the record of your visit, the heading and first words of the pages involved, and the text of the pages that held you longest or that you came back to. It receives your name and email address when the workspace sees them, as described above. No content you typed is sent to the AI provider other than a name and email address you chose to give. A workspace on any plan can also have a reader summary written about you: an automated account of your reading across all your visits to its documents, which is stored with your contact record in that workspace, shown to its members, quoted in brief emails and posted in Slack. From October 2, 2026, the reader summary is replaced by the reader profile described below.
Reader profiles
Reader profiles, effective October 2, 2026: if you introduce yourself on a share link or project link by typing your name and email address, and then confirm that address with the link in the email we send you, the workspace that shared it can have LinkDrop put together a short profile of you. The profile helps them know who is reading and follow up with what is relevant to you. Research runs after you confirm your email address; until then, nothing is looked up about you automatically. Readers who do not introduce themselves are never profiled, and being signed in to LinkDrop does not on its own lead to a profile. If your browser sends a Global Privacy Control signal when you introduce yourself, we do not profile you.
A reader profile can include:
- Public professional details: your name, your role or job title, your company or employer and what it does, and your professional background. We look these up from publicly available sources, such as company websites, public professional profiles and news articles, using your name and the company domain of the email address you gave. We never search the web for your email address itself. If the workspace uses the Advanced level, the profile can also include your public career history (earlier roles and companies) and recent public news or activity about you from the last 12 months, such as talks, articles or company announcements. We do not look up sensitive information such as health, religion, political views or family.
- Your general location: an approximate city, region and country, estimated from the approximate location our hosting provider, Vercel, derives from your IP address, from the language setting your browser sends, and from the time zone the share page reports from your device when you introduce yourself. It can also use the city of your workplace when a public page states it as where you work, such as your company's office or headquarters. We never look up or show where you live. The workspace sees the estimate and how it was worked out. It never sees your IP address itself.
- Relevance to the document: an automated assessment of how relevant you are likely to be to the document you opened. It is an inference, not a statement of fact about you.
- Your history with the workspace: your earlier visits and return visits, and the workspace's other documents you have opened, as described above.
How it is made: the profile is written by automated processing after you confirm your email address, a few minutes after you introduce yourself or as soon as you confirm, whichever is later. Its record of your visits is updated after later visits, and the public details may be looked up again when you come back after 30 days or when the workspace asks, so it can change over time. OpenAI (see section 4.2) runs the search of the public web and writes the profile. It receives your name and your email address's domain (never the full address), your approximate location (which also localises the search), your browser's language and time zone, and the titles and stored summaries of the documents you opened, plus what the search found (the search step receives the documents' summaries only once your address is confirmed); it never receives the documents' text, your IP address, your browser type or the site you came from. The search uses public web pages only: it never signs in to a site, and LinkedIn, other sites behind a login and people-search sites are never used as a source. The profile notes whether you have confirmed your email address; a workspace owner can ask for a profile before you confirm, and the profile then says the address is not confirmed. Public sources can be out of date, or can be about someone else with the same name, so a profile can be wrong.
Who sees it: only the workspace that shared the document. That means the same members who can see your visits, as described above, including the rule that only a private (locked) project's members see visits to its documents. The profile is shown in LinkDrop only: it is never included in the workspace's emails or posted to a Slack channel it connected, which carry visit briefs, not profiles. It is never shown on the share page, never shown to another workspace, and never visible to LinkDrop's administrators. As with all your information, we do not sell it and we do not use it for advertising.
How long it is kept: each workspace has one profile per reader, stored with your contact record and replaced when it is refreshed. It is deleted when you ask us to delete it, when your contact record is removed from that workspace, when the workspace resets its data, and when the workspace is purged. The record kept when you introduced yourself (your IP address, browser type and language, the site you came from, and the approximate network location) is deleted after 90 days.
Your choices: you can always read a share link without introducing yourself. Changing or clearing your introduction from "Viewing as" in the viewer's toolbar stops your browser sending it again; it does not remove a profile already made. To have a reader profile about you deleted, or to object to one being made, email support@lnkdrp.com (hi@lnkdrp.com reaches us too) from the address you introduced yourself with, or tell us which document you opened. We record your objection against your address in any variation (letter case, a +tag, and dots or googlemail.com for Gmail) and against your name together with your address's company domain, both as one-way keyed hashes rather than in readable form, so a different spelling of your address does not lead to a new profile. We act on it without asking the document owner first, and we will confirm when it is done.
Legal basis: for readers in the EEA and UK, we make reader profiles on the basis of legitimate interests (GDPR Article 6(1)(f)). For the workspace that shared the document, that interest is knowing who is reading what it sent and following up with them. For LinkDrop, it is providing that feature. We weighed these interests against yours. A profile is made only after you choose to introduce yourself and confirm your address, uses professional details that are already public, is visible only to the workspace whose document you opened, and can be deleted on request. You can object at any time at support@lnkdrp.com.
To tell repeat visits apart we store a random identifier in your browser's local storage. On our side we keep only a keyed hash of it, and the key is different for each workspace, so the same browser leaves unrelated identifiers in different owners' workspaces and the identifier is not linked across different owners' documents. A browser a workspace had already recorded before September 30, 2026 keeps its earlier identifier in that workspace, so a returning reader is not counted twice. It is not shared with anyone else. Clearing your browser storage removes it.
If the owner has not enabled downloads, you can request one by entering your email address. We email the owner to ask for approval; if they approve, we email you a link, and you must sign in with Google to receive the file. The file you receive is a copy of the document as it was when the owner approved; we keep that copy only for a short period, never more than 7 days (or until the owner takes the approval back), and the email and the download page say until when; then we delete it. A copy you save to your own LinkDrop account is yours and stays. Your email address is stored with that request.
Password protection on a share link is set by the owner. When you enter a correct password we set a cookie so you do not have to re-enter it for 14 days on that browser.
6. AI Processing
We use OpenAI's API to generate summaries, key points, and version comparisons. When an AI feature runs, we send the extracted text of the document and, for some features, images of its pages, together with our instructions. For version comparisons we send page images from both versions.
- A summary is generated automatically when a document finishes uploading. Comparisons run when you or someone in your workspace asks for them.
- For shared documents, a visit brief is generated automatically a few minutes after a viewer stops reading, unless the workspace turns automatic briefs off. Since October 1, 2026, workspaces on every plan get a brief for every qualifying visit; on Free each brief is paid for with the workspace's credits, except the first, which is free. A brief is written from the record of the visit (pages, time per page, reading order, returns, which pages the viewer came back to, spent time on, skimmed or skipped, downloads, earlier visits on the same link, and the viewer's name and email address when the workspace sees them), the heading and first words of the pages involved, and the full text of the pages that held the viewer longest or that they came back to. Nothing else the viewer typed is sent.
- On every plan, a reader summary of one contact's reading across all their visits is generated when a workspace member asks for it, or automatically after each visit brief about that contact while the workspace has that switched on (on by default; it can be turned off). It is written from that contact's visits, the page lists and headings for each, and the briefs already written about them, and never from visits inside a private (locked) project. It is stored until it is refreshed, shown to every member of the workspace, quoted in visit brief emails, and posted in Slack as a reply under the brief. Agents connected with an API key can read a stored reader summary but cannot generate one.
- From October 2, 2026, on every plan, a reader profile is made after a viewer introduces themselves by typing a name and email address and confirms that address, while the workspace has that switched on (on by default; it can be turned off), or when a workspace owner asks for one. It uses OpenAI's web search tool and is described in section 5. It replaces the reader summary.
- AI output is stored with the document or, for reader summaries and reader profiles, with the contact, and shown to you; summaries and key points are also shown to viewers of the share link. Visit briefs, reader summaries and reader profiles are never shown to the viewer they describe.
- New AI runs do not store the prompt or the response. For each run we keep a record of its facts (kind, model, timing, token counts, cost, status and a short error description if it failed) for 30 days to meter credits and investigate failures, and then delete it automatically. Records of runs made before September 30, 2026 may still hold the prompt and response, and they are deleted automatically within 30 days of that date. Nobody at LinkDrop can read your documents' text or the AI output through that record.
- We do not train AI models. Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models. We have not opted in to any data-sharing program.
- AI output is provided for informational purposes only and can be inaccurate. It is not professional advice.
Uploading a document means its content will be processed this way. If you do not want a document sent to our AI provider, do not upload it.
7. Data Security
We implement technical measures to protect your information, including:
- Encryption of data in transit (HTTPS/TLS)
- Sign-in delegated to Google; no passwords are stored by us
- Share passwords stored as salted hashes, together with an encrypted copy so the link's owner can look the password up again in the app or through their connected agent
- Invitation, download, and request tokens stored as hashes; where the owner's app shows a link again (workspace invitations and document replacement links), an encrypted copy is kept for that purpose only
- Anonymous-identity secrets stored as hashes, and viewer identifiers hashed with a separate key for each workspace
- Files stored at unlisted addresses, with access through the app controlled by the owner's share settings
- Role-based access to workspaces and rate limiting on public endpoints
- Automatic redaction of secrets from error logs
What our administrators can see. LinkDrop's administrators can see account and file metadata: document and project titles and descriptions, who owns them, dates, file sizes, activity counts, and billing records. They use it to operate, secure and support the Service. They cannot see the contents of your documents: not the files, their text, their page images, or the AI summaries and briefs written about them. Nor can they see what was sent to our AI provider or what it wrote back, or who read your documents: a reader's name, IP address and account are never shown to them, and a reader's email address appears only masked, as its first letter and domain.
No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Data Retention and Deletion
We retain your information for as long as your account exists and as needed to provide the Service, unless a longer period is required by law. LinkDrop is not a long-term archive: keep your own copies of anything you need to keep. Specifically:
- Deleting a document removes it from the app and disables its share links immediately. 30 days after deletion it is permanently purged, together with its files and its AI output.
- Deleting a project or a workspace removes it from the app and disables its share links immediately. 30 days after deletion it is permanently purged, together with its share links, the visits and activity of the people you shared it with, and, for a workspace, its members, invitations, contacts, documents and files. Documents in a deleted project are not deleted with it; they stay in the workspace. Billing records of a deleted workspace are kept, without the name of the person who made them, as described below.
- Resetting a workspace: a workspace's owner can reset it, and so can our support team, at the owner's request or when the workspace is used for an app review, testing or a demo. A reset permanently removes the workspace's documents, links, analytics and history immediately, with no 30-day window, while keeping the account, its members and its billing records. As with other permanent deletions, we keep a metadata record of what was removed.
- Recently deleted: a deleted document, project or workspace is kept for 30 days. Within that window its owner can restore it from Recently deleted in the app, or our support team can restore it on request. After 30 days it is permanently removed and can no longer be restored.
- Viewer activity (visits, time per page, project views and clicks), the visit briefs written about it, and the workspace activity feed are kept for two years and then deleted automatically, or sooner when the related document or workspace is purged. Documents, links and their total counts stay: each link keeps one record per reader (who opened it, how often and when last), which its totals are counted from, for as long as the link exists.
- Archived documents are moved to Recently deleted one year after they were archived. From there their owner can restore them for 30 days; after that they are permanently removed.
- Inactive Free workspaces: if no member of a workspace that has never had a paid plan or bought credits signs in for two years, we email its owner. If nobody signs in within 30 days of that email, we permanently remove the workspace's documents, links, analytics and history, as a reset does, and keep the account and the workspace. A workspace with any billing history is never removed for inactivity.
- Inactive accounts: if an account that has never paid is not signed in to for three years, we email it. If nobody signs in within 30 days of that email, we delete the account as described below and email a receipt when the deletion has run. Signing in once cancels either countdown, and we send each warning only once.
- Reader summaries are kept, one per contact, until they are rewritten. A summary is deleted when a document it was written from is purged, and when its workspace is purged.
- Reader profiles are kept, one per reader per workspace, and replaced when refreshed. A profile is deleted on request (support@lnkdrp.com or hi@lnkdrp.com), when that contact is removed from the workspace, when the workspace resets its data, and when its workspace is purged. The introduction record behind it (IP address, browser type and language, referring site, network location) is deleted after 90 days. A record of what was removed keeps counts only, never a profile's content.
- Error records are deleted automatically after 14 days. Rate-limit records expire after their window.
- Deletion receipts. When an account is deleted we keep a receipt that the deletion happened: when it was asked for and by whom, when it ran, and what it removed (workspace names, document titles and sizes, counts of files and links, and the subscriptions it cancelled), never the documents themselves. We email you a copy when you ask to delete your account and again when the deletion has run. The receipt keeps your email address for 90 days after the deletion runs, so we can answer questions about it, and then the address is removed. When our support team deletes an account, the receipt also records why, and the email we send you after the deletion says so; any explanation or note our team wrote about it is removed together with the address.
- Records of what was removed. When something is permanently removed (an account, a workspace, a project or a document) we keep a record of what was removed: titles, descriptions, sizes, counts, dates and the owner. It never includes the files, their text, AI output or who read them. For an account, the record is part of its deletion receipt, and the name and email address in it are removed after 90 days, like the receipt's address.
- Email delivery records (the address an email went to, the kind of email and, where it names one, the document title; never the subject line as sent) are deleted automatically after 90 days.
- AI run records (the facts about each run, without prompts or responses) are deleted automatically after 30 days.
- Billing records are kept as required for tax and accounting purposes.
- Backups of our database expire on a rolling schedule; the longest-kept snapshots are deleted after one year. Something purged from the live service can remain in a backup until that backup expires.
You can delete your account yourself, from your dashboard. Your account stops working immediately and the deletion takes effect 30 days later; within that window you can change your mind by emailing hi@lnkdrp.com. After it takes effect, your account is purged, together with the workspaces you are the only member of, any workspace you owned and had already deleted, and the documents, files and activity in them. A workspace that still has other members keeps its documents, including any you added to it; only your membership is removed. We do not yet offer self-service data export: to receive a copy of your data, or to delete specific information without closing your account, email hi@lnkdrp.com and we will handle it manually.
9. Your Rights and Choices
Depending on your location, you may have rights regarding your personal information, including:
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a portable format
- Objection: Object to certain processing of your information
- Restriction: Request restriction of processing in certain circumstances
To exercise these rights, contact us at hi@lnkdrp.com. We will respond within a reasonable timeframe and in accordance with applicable law. If you were a viewer of someone else's document, we may need to confirm the request with the document owner. A request about a reader profile is the exception: we delete it, or stop making one, without asking the document owner first.
In the app you can change your display name, leave workspaces, remove members from workspaces you administer, delete documents, and turn document activity emails off, to a daily digest, or to immediate in your notification settings. Workspace owners and admins can turn automatic visit briefs off, and automatic reader profiles on or off, on the workspace's Automations tab.
10. Children's Privacy
The Service is not intended for individuals under the age of 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at hi@lnkdrp.com, and we will take steps to delete such information.
11. International Data Transfers
The Service is operated from the United States, and our service providers listed in section 4.2 process data in the United States and other countries. If you are located elsewhere, your information will be transferred to, stored, and processed in those locations, which may have different data protection laws than your country of residence.
By using the Service, you consent to these transfers.
12. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect, use, and disclose
- The right to delete your personal information (subject to certain exceptions)
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at hi@lnkdrp.com. To have a reader profile about you deleted, email support@lnkdrp.com from the address you introduced yourself with; we delete it in every workspace without asking the document owner first.
13. European Privacy Rights
If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including:
- The right to access, rectify, or erase your personal data
- The right to restrict or object to processing
- The right to data portability
- The right to withdraw consent at any time
- The right to lodge a complaint with a supervisory authority
Our legal bases for processing are: performance of our contract with you (providing the Service you signed up for), our legitimate interests (securing the Service, preventing abuse, understanding how features are used, and showing document owners how their shared documents are viewed and, for readers who introduced themselves, preparing reader profiles for the sharing workspace), compliance with legal obligations, and your consent where you give it, for example by entering your name and email as a viewer.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last updated" date
- Emailing account holders about significant changes
Your continued use of the Service after such modifications constitutes your acceptance of the updated Privacy Policy. If you do not agree to the modified Privacy Policy, you must stop using the Service.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: hi@lnkdrp.com
We will respond to your inquiry within a reasonable timeframe. Our Terms of Service describe the rules for using the Service.