Trust

Security and trust

Last updated: October 4, 2026

Overview

LinkDrop is operated by LNKDRP Technologies LLC. People trust us with documents they have not made public and with the record of who read them, so this page sets out how we protect both: where the service runs, what we protect and how, who can change production, how we back up and delete data, which providers process it, and where we stand on certifications. It describes what the product does today, including one limit you should know about. The Privacy Policy and Terms of Service are the binding documents and take precedence over this page.

Infrastructure

  • Web app, API, scheduled jobs and file storage: Vercel. Our application servers run in Vercel's US East region.
  • Database: MongoDB Atlas, on AWS in the US East (us-east-1) region.
  • Agent (MCP) server and live-update server: Fly.io, in its US East region.
  • Encrypted in transit: every connection to lnkdrp.com and to our agent and live-update servers uses HTTPS (TLS), and plain HTTP is redirected to HTTPS. Our servers connect to the database over TLS.

Data protection

  • Sign-in is through Google only. We do not store account passwords.
  • Share-link passwords are stored as salted hashes (scrypt), together with an encrypted copy so the link's owner can look the password up again. Wrong guesses are rate-limited per link and per address.
  • Agent API keys are shown once and stored only as a hash. Invitation, download and request tokens are stored as hashes too.
  • A Slack connection's bot token is encrypted (AES-256-GCM, with a key derived for that purpose alone) before it is stored. It is never logged or returned by our API, and it is used only to post to the channels a workspace chose. We never read your Slack.
  • Repeat-visit identifiers for readers are hashed with a separate key for each workspace, so they cannot be linked across different owners' documents.
  • Secrets are redacted automatically from our error logs.
  • Our administrators can see account and file metadata (titles, owners, dates, sizes, counts and billing records) to run and support the service. They cannot see the contents of your documents, their text or page images, the AI output written about them, or who read them.
  • Share pages tell search engines not to index them, and our robots rules tell crawlers not to fetch them.

File addresses

Uploaded files and page images are stored at addresses that include a long random part, are not listed anywhere, and cannot be worked out from a document or link. A share page checks the link's settings (disabled, expired, password, archived) every time it is opened.

One limit to know about: the file storage itself does not check those settings. Turning a link off stops its share page from opening, but someone who already copied the direct address of a file out of it could keep opening that one file. If a document must be withdrawn completely, delete it: its stored files are removed when it is purged 30 days later, or sooner if you ask us.

Access and change control

  • Our source code is kept in private repositories. Our automated checks fail if a code repository is ever made public.
  • Every change is scanned for leaked credentials before it can be released. Credentials live only in our hosting providers' environment settings, never in source code.
  • Changes reach production only through a release step. It requires the automated test run to have passed, runs the type check, lint and full test suite again on that exact version in a clean checkout, and needs the owner's explicit go-ahead.
  • Preview builds receive neither production credentials nor access to the production database.
  • Only the web application writes to the production database. The agent (MCP) server has no database access and goes through the same API, with the same permission checks, as everyone else. The live-update server reads through a read-only database account. Our test and script tooling is blocked from writing to a real database.

Backups

  • The production database has continuous cloud backup with point-in-time restore: we can restore it to any moment in the last 7 days.
  • Snapshots are also taken every 6 hours and daily (kept 7 days), weekly (kept 4 weeks), monthly (kept 12 months) and yearly (kept one year). The cluster has termination protection on.
  • Restores are tested. On September 29, 2026 we restored production to a point in time in a separate cluster and checked that every collection's record count matched; the test cluster was then deleted. Restores always go to a separate cluster first, never straight over production.
  • These backups cover the database. Uploaded files are kept in Vercel's file storage, separately from them.

Retention

We keep your information while your account exists and as needed to provide the service. Some records expire on their own:

  • Error records: deleted automatically after 14 days.
  • AI run records (the facts of each run, never the prompt or response): 30 days.
  • Email delivery records: 90 days.
  • Rate-limit records: expire at the end of their window.
  • Viewer activity, the activity feed and visit briefs: two years, then deleted automatically. Each link keeps one record per reader, which its totals are counted from, as long as the link exists.
  • Archived documents: moved to Recently deleted after one year, restorable for 30 days.
  • Inactive Free workspaces (two years) and never-paid accounts (three years): a warning email, then removal 30 days later unless someone signs in.
  • Database backups: on a rolling schedule; the longest-kept snapshots are deleted after one year.
  • Billing records: as long as tax and accounting law requires.

The full list is in the Privacy Policy, section 8.

Deletion

  • Account owners can delete their account themselves from the dashboard. Anyone can ask us to delete their data by emailing hi@lnkdrp.com; if you were a reader of someone else's document, we may need to confirm the request with its owner.
  • A deleted account, workspace, project or document is removed from the app and its share links stop working immediately. It stays restorable for 30 days in case the deletion was a mistake.
  • A workspace's owner can instead reset it, which permanently removes its documents, links, analytics and history at once, with no 30-day window, while keeping the account, its members and its billing records. Our support team can do the same at the owner's request, or for a workspace used for an app review, testing or a demo. See the Privacy Policy.
  • After 30 days an automated job, which runs every day, permanently deletes it: the files in storage, the database records, share links, viewer activity, contacts and members. Active subscriptions are cancelled first.
  • We keep a receipt that the deletion happened (never the documents themselves) and the billing records the law requires, without the person's name. Something purged can remain in a database backup until that backup expires.
  • Disconnecting Slack in LinkDrop deletes the stored connection and its encrypted token at once. Removing the LinkDrop app in Slack does the same: Slack notifies us, and we delete every connection to that Slack workspace and its token.

Step by step: Privacy and security in How LinkDrop Works.

Subprocessors

These providers operate parts of the service, each receiving only what its role needs. This is the list in Privacy Policy section 4.2.

  • Google · Google LLC

    Google Safety Center

    Sign-in, and Google Drive for members who connect it. Receives your sign-in requests, and the Drive searches and imports you or your agent ask for.

  • Vercel · Vercel Inc.

    Vercel security

    Hosting, request logs, scheduled jobs and file storage (PDFs, page images, previews, extracted text, workspace icons).

  • Vercel Web Analytics · Vercel Inc.

    Web Analytics privacy

    Counts page visits in aggregate, without cookies. Page addresses are stripped of anything that grants access before they are sent; it never receives document contents.

  • MongoDB Atlas · MongoDB, Inc.

    MongoDB Atlas Trust Center

    Database: account, workspace, document text, AI output, viewer activity, billing and log records.

  • OpenAI · OpenAI, L.L.C.

    OpenAI Trust Portal

    AI processing: summaries, version comparisons, visit briefs, and reader profiles, including a web search for public professional information about a reader who introduced themselves and confirmed their email (see AI processing below).

  • Stripe · Stripe, Inc.

    Stripe security

    Payments and subscriptions. Card details are entered on Stripe's checkout page; we never see the full card number.

  • Resend · Resend, Inc.

    Resend security

    Transactional email. Receives each recipient address and message.

  • Fly.io · Fly.io, Inc.

    Fly.io security

    Hosting for the agent (MCP) server and the live-update server. Live updates are passed on, not stored.

  • Customer support chat and email. Receives your name, email address and the messages you send support.

  • Slack · Slack Technologies, LLC

    Slack Trust Center

    Only if a workspace connects it: receives the activity messages we post to the channels that workspace chose. Reader profiles are never posted. We never read your Slack.

AI processing

We use OpenAI's API. What it receives, and when:

  • Summaries and key points: when a document finishes uploading, its extracted text and, for some features, images of its pages.
  • Version comparisons: when someone in your workspace asks for one, page images from both versions.
  • Visit briefs: a few minutes after a reader stops reading, the record of the visit, the heading and first words of the pages involved, and the text of the pages that held the reader. The reader's name and email go only when the workspace may see them. Workspace owners and admins can turn automatic briefs off.
  • Reader profiles: after a reader introduces themselves on a link by typing a name and email address and confirms that address, OpenAI runs a web search for public professional information about them and writes the profile. It receives the name they gave and their email address's domain (never the full address, which is never searched for), their approximate location, browser language and time zone, and the titles and stored summaries of the documents they opened; never the documents' text, their IP address or browser type. Only the workspace that shared the document sees the profile, in LinkDrop: it is never posted to Slack or included in emails. Readers who do not introduce themselves are never profiled, and workspace owners and admins can turn profiles off.

We do not train AI models. Under OpenAI's API data usage policy, content sent through the API is not used to train OpenAI's models, and we have not opted in to any data-sharing programme. AI runs no longer store the prompt or the response: we keep only the facts of each run (kind, model, timing, tokens, cost, status) for 30 days. Records of runs made before September 30, 2026 may still hold them and are deleted automatically within 30 days of that date. If you do not want a document processed this way, do not upload it. We never read your Slack, so no Slack content is sent to OpenAI or anywhere else.

Details: Privacy Policy section 6.

Compliance

Where we stand today, stated plainly.

  • GDPR (EU and UK)

    Rights honoured

    Access, correction, deletion, portability, restriction and objection are honoured on request by email. Our legal bases and your rights are set out in the Privacy Policy, sections 9 and 13.

  • CCPA (California)

    Rights honoured

    We do not sell personal information. See Privacy Policy section 12.

  • International transfers

    By consent

    The Service is operated from the United States. We are not certified under the EU-US Data Privacy Framework; transfers are described in Privacy Policy section 11.

  • COPPA (children)

    Not for under-13s

    LinkDrop is a business tool. You must be at least 13 to use it, we do not knowingly collect children's information, and we will take steps to delete it if you tell us we have. See Privacy Policy section 10.

  • HIPAA

    Not supported

    We do not sign Business Associate Agreements. Do not upload protected health information; the Terms of Service prohibit it.

  • SOC 2, ISO 27001

    Not certified

    We do not hold SOC 2 or ISO 27001 certification today. If your organisation needs a security questionnaire answered, email hi@lnkdrp.com.

Reporting a vulnerability

If you believe you have found a security problem in LinkDrop, email hi@lnkdrp.com with “Security” in the subject. Please include what you found, the steps to reproduce it, and the page or endpoint involved.

  • Use only accounts and documents you own or have permission to test with.
  • Do not read, change or keep other people's data beyond what is needed to show the problem.
  • Do not run denial-of-service tests, send spam, or try social engineering.
  • Give us a reasonable time to fix the problem before you disclose it publicly.

We aim to reply within 3 business days, and we will tell you what we are doing about it. We do not run a bug bounty programme.

Machine-readable contact details are in /.well-known/security.txt.

Trust and Security - LinkDrop