Privacy Policy
The short version: Linkvue stores what it needs to run your page, to show a creator who opened their links, and to answer the people who write to a creator’s bot or report a page. We sell none of it to anybody and we run no advertising of our own. Anyone can register. If you are on the waitlist, we hold your email until we invite you or you ask us to stop.
Who processes your data
The controller (prevádzkovateľ) under the GDPR is Penev, spol. s r.o. The same company runs other projects, but Linkvue is a separate service with its own database. What you give us here goes nowhere else and is not linked to any other account.
We have not appointed a data protection officer, because the law does not require us to. Write to us directly.
- Company name
- Penev, spol. s r.o.
- Registered office
- Záhradní 35, 080 01 Prešov, Slovenská republika
- Legal form
- Limited liability company (spoločnosť s ručením obmedzeným)
- Company ID (IČO)
- 31 677 622
- Tax ID (DIČ)
- 2020497985
- VAT ID (IČ DPH)
- SK2020497985
- Registration
- Commercial Register (Obchodný register), Okresný súd Prešov, section Sro, insert No. 12671/P
- contact@linkvue.uk
What we process
Three kinds of people meet Linkvue: creators who have an account, people who open a creator’s page or tap a link on it, and people who write to a creator’s Instagram or Facebook bot or report a page. Each section below says what we hold about you in that role. Registration is open, so you can create an account directly; the waitlist is optional.
The waitlist
If you leave your email on the landing page, we store the address, the handle you would like, the address of a page you want us to import if you gave one, and the date and time. We use it to send you one invitation from our operator console; the form itself sends nothing. When we invite you, an internal audit record of that action keeps the address as well.
Legal basis: your consent under Article 6(1)(a) GDPR. Withdraw it at any time and we take you off the list.
Your account
When you register we store your email address and your password as a hash (scrypt), never in readable form, and we ask you to verify the address before the account works. Before we accept a new password we check it against the Have I Been Pwned list of leaked passwords. Only the first five characters of a SHA-1 hash of the password leave our server, so the password itself never does.
If you turn on two-factor sign-in, we store the TOTP secret and your backup codes, and a marker for any device you tick as trusted. If you add a passkey, we store its public key, credential id, a counter and the name you give it. The private key, and any fingerprint or face used to unlock it, stays on your device and never reaches us.
Each sign-in creates a session record that includes the network address you signed in from (an IPv6 address is shortened to its /64 prefix). Sign-in attempts are also counted per address to slow down password guessing, and repeated failures lock the email address for a while.
Legal basis: performance of contract under Article 6(1)(b) GDPR for the account itself; our legitimate interest under Article 6(1)(f) in keeping accounts from being taken over for the sign-in records.
Your page and what you put on it
Links, bio, display name, tabs, social icons, appearance settings, the hours you set on the “available now” badge, and the photos you upload. Photos are stored on Cloudflare R2 and served from cdn.linkvue.uk. Anyone who holds an image’s address can open it; that is how a browser, or Instagram, fetches it. Link destinations never appear in your page’s HTML; every tap goes through our server, which resolves the destination and records the click.
If your translation scope allows it, your bio and your public link titles are sent to Cloudflare Workers AI (a Llama model run by Cloudflare) each time you save them, and the translations are cached with your page. Your display name and handle are not sent, and nothing a fan writes is ever sent. The auto-translate switch only decides whether a translation is shown; setting the scope to “none” is what stops the text being sent. Translations you paste yourself are never sent anywhere.
If you connect a custom domain, we store the domain and its verification state and register it with Vercel. Checking it sends DNS and RDAP lookups of the domain name to Google DNS, Cloudflare and rdap.org. If you connect your DNS provider, we store its API token encrypted so we can write the records for you; you can disconnect it at any time.
Legal basis: performance of contract under Article 6(1)(b) GDPR.
Subscriptions and payment
Paid tiers (Minimum, Basic, Advanced and Pro, monthly or quarterly) are billed through Stripe. Checkout happens on Stripe’s own page, so your card number never reaches us. We send Stripe your email address and your account id, and we keep the Stripe customer id, the subscription id, its status, the tier and price, and the end of the current period. We hold no card data and no invoices; Stripe issues and keeps the invoices, which we access for our accounts.
Legal basis: performance of contract under Article 6(1)(b) GDPR, and for accounting records the legal obligation under Article 6(1)(c) and the Slovak Accounting Act.
Visitors of a creator’s page
When you open a creator’s page or tap a link on it, we record one row per view and per click for that creator’s dashboard: what was opened and when, your country, region and city and the approximate coordinates our hosting provider derives from your address (no geolocation service is called), the category of your device, browser and operating system, the site you came from (its host only), the source tag if the link carried one, and which of two designs you were shown if the creator is running an A/B test.
We do not store your IP address or your full browser string in that row. In their place we store a visitor key: a hash of the day’s secret, your address and your browser string. The secret changes at midnight UTC, so a returning visitor is counted once per day but cannot be recognised across days or traced back to an address. If you gave the creator your email (see below), your later taps on that page are linked to that entry.
These rows are not turned into aggregates. They stay as they are until the creator deletes a day or all of their analytics, or deletes their account. The creator sees them in their dashboard, and through an AI assistant if they connected one. The creator’s own visits are marked and left out.
Two more things happen on a page without any record of you. If you arrive in an in-app browser (Instagram, Facebook, TikTok and similar), we recognise it from the browser string and offer to open the page in your system browser; we record only which app it was and when. If a page or a link asks you to confirm you are over 18, your tap sets the lv_adult_ok cookie for 24 hours and no other record is made.
Legal basis: legitimate interest under Article 6(1)(f) GDPR, the creator’s in seeing which links work and ours in running the service.
Protection against bots and copying
Every request to a creator’s page passes through our shield. It reads your browser string, a few request headers, your address, its network (the ASN) and your country, and decides whether you are a browser or a crawler. Crawlers get an empty page, and a creator may block whole countries. For a normal visit nothing is stored beyond the row described above.
Pages carry hidden tripwires, links a person never sees. If something opens one, we store the browser string, a salted hash of the address, the network number, the path and a fingerprint (a hash of the browser string, a few headers and the network), and we count that fingerprint across all pages so a known scraper is refused everywhere. These records are kept without a time limit.
Pages with adult links, or with the human gate switched on, load Cloudflare Turnstile in your browser. Cloudflare then sees your address and browser environment directly. When you pass, our server sends your address to Cloudflare once to confirm the result and does not store it; you then get the lv_hum cookie for 30 minutes. Nothing about the challenge is written to our database.
Legal basis: our legitimate interest under Article 6(1)(f) GDPR in protecting creators’ pages from scraping and abuse.
Leaving your email on a creator’s page
Some creators show a box where you can leave your email address. It is sent only when you tick the consent box. We store the address, the exact consent sentence you saw, the network address you sent it from as proof of that consent, your country, the source tag and the time. The creator sees the list in their dashboard and can export it (without the network address). They write to you with their own tools; Linkvue never emails you. For a year the lv_fan cookie links your later taps on that page to your entry, so the creator can see that you came back. To be removed, write to the creator or to us; the creator can delete you in one click.
Some pages also have an anonymous message box. The text goes to the creator with no name, address or identifier attached.
Legal basis: your consent under Article 6(1)(a) GDPR.
The Instagram and Facebook bot
If you are a creator and you turn on the Instagram or Facebook bot, we also process data about the people who write to the account you connected:
- Your fan’s platform identifier (an Instagram-scoped ID or a Facebook Page-scoped ID). Meta hands us this number with every message or comment. On its own it carries no name, phone number or email.
- The text of the message or comment that reached your bot, cut off at 500 characters. We keep it so the activity log in your dashboard can show you what happened and why the bot did or did not reply. No AI model reads it: the replies are texts you wrote, chosen by a keyword match.
- The connected account’s access token, encrypted at rest, for as long as the connection stays active. It is what lets the bot send a reply back through Meta on your behalf; we never see it as plain text once it is written to the database.
Whether a fan follows the account is asked from Meta at the moment the bot needs it and is not stored. No conversation history and no follower list is kept.
Legal basis: our legitimate interest under Article 6(1)(f) GDPR in running the reply a fan’s own message asked for, and the creator’s in running the bot they switched on. We do not use any of this for advertising, and we build no profile of a fan across conversations or accounts.
Reporting a page
Anyone can report a page at /report without signing in. We store the reported handle, the reason you picked, your description, your email address if you gave one, and a hash of your network address that slows down repeat reports. Your email is used only to answer you about that report and is never shown to the creator.
Legal basis: our legitimate interest under Article 6(1)(f) GDPR in keeping the service free of abuse.
Connecting an AI assistant
You can connect an AI assistant (an MCP client) to your account through a consent screen. Once connected, it can read your page, its analytics and your bot settings, and change your links, bio, theme, domain and bot configuration. What it reads is passed to the assistant’s own provider under that provider’s terms, which we do not control. You can end the connection at any time on the assistant’s side, or write to us and we revoke its access.
Our operators use a separate, key-protected interface for administration. Through it an operator’s assistant can list creators, the waitlist and platform-wide analytics.
Emails we send you
Only account emails: verification, password reset, confirmation of an email change, the 30-day notice when you ask for deletion, a waitlist invitation, an alert when a link on your page stops responding or a scraper trips a tripwire, and a monthly protection summary that you can turn off in the dashboard and that is skipped when there is nothing to report. There is no newsletter and no marketing email. We never email fans.
How long we keep it
- The waitlist: until you create an account or ask us to remove you. The internal record of an invitation we sent stays in our audit log.
- Your account and page: for as long as the account is active. After a deletion request we keep everything for a 30-day grace period, during which you can undo it, then the daily purge removes the account and what hangs off it: links, analytics rows, your fan list, bot data, the subscription record, and every photo you uploaded, which is deleted from storage before the account itself goes.
- Sign-in records: a session lasts up to 7 days, or 60 days on a device you marked as trusted. The records, including the address you signed in from, are deleted with the account.
- Analytics rows about visitors: no time limit. The creator can delete a day or all of them at any time, and they go with the creator’s account.
- Tripwire and fingerprint records: no time limit.
- Bot activity log (a fan’s platform identifier and the message or comment text): 7 days, then deleted, not merely hidden. Duplicate-delivery records, which stop the bot answering the same message twice: 48 hours. A connected account’s access token: until you disconnect it, then deleted straight away, not on the next cleanup.
- Your email left on a creator’s page: until the creator deletes it, you ask for that, or the creator’s account is purged.
- Abuse reports: we do not currently apply a fixed period. A closed report, including a reporter’s email, stays until we delete it by hand.
- Subscription record: with the account. The Stripe event ids we log stay without your account id. Stripe keeps the invoices for the 10 years the Slovak Accounting Act requires.
- Cached translations: until you change the text or delete the account.
- Custom domains: a domain that never finishes connecting is removed after 5 days. A DNS provider token stays until you disconnect it or delete the account.
- Meta deletion receipts: no time limit. They hold only a confirmation code and a count.
- Error reports at Sentry and request logs at Vercel: for the period each of them sets. We do not control it, and we keep no raw request logs ourselves.
Who we give it to
We sell it to nobody and we do not swap it with any other project the same company runs. The Linkvue database is separate.
The creator whose page you use is the first recipient. The analytics rows about visits to their page, and your email if you left it there, are theirs to see.
If you use the Instagram or Facebook bot, Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) is involved on both ends of that data, and not because we chose to send it anything: a fan’s message reaches us through Meta’s systems in the first place, and the bot’s reply is delivered back to them the same way. Meta processes what passes through its own platform under its own terms, not ours; see facebook.com/privacy/policy.
Beyond that, these suppliers receive your data, each only as far as it needs it:
- Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA): hosting, run in its Dublin region; the registration of custom domains; and Vercel Analytics, which counts page views on every page without a cookie or an identifier.
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA): the network and attack protection (CDN/WAF) every request passes through; R2, the storage that holds uploaded photos, which is not pinned to an EU location; Turnstile, the human check; Workers AI, which translates bios and link titles; and its DNS API when a creator connects a Cloudflare domain.
- Supabase: the database that holds everything described above. The project runs in an EU region (Ireland).
- Sentry (Functional Software, Inc., 45 Fremont Street, San Francisco, CA 94105, USA): error and performance monitoring, so a page that breaks gets found and fixed. Our account ingests in Sentry’s European region (Germany). When something fails it records the technical detail of that request: the IP address, the browser and device, and the address of the page; cookies, request bodies and headers are switched off at the source. It also records one in ten sessions, and every session with an error, as a replay, so we can see what led to a crash. In those replays all text and all images are masked before they leave your browser, so what remains is the shape of the page and where you clicked, not what it said.
- Resend, Inc. (2261 Market Street #5039, San Francisco, CA 94114, USA): sending the account emails listed above. Processes your email address and the content of those messages.
- Stripe Payments Europe, Limited (Dublin, Ireland): subscription payments. Receives your email address and account id, and holds your card details and invoices under its own privacy terms.
- Have I Been Pwned: receives the first five characters of a password hash when you set a password, and no other data.
- Google DNS, Cloudflare DNS and rdap.org: receive the name of a custom domain when we check it, and no other data.
A creator may add their own Meta Pixel or Google Analytics 4 (GA4) tag to their page. On that page Meta or Google then receives your visit and sets its own cookies (such as _fbp and _ga), under the creator’s responsibility and those tools’ terms. Linkvue’s own pages carry no such tags.
We have data processing terms with each supplier that holds personal data, and for those in the USA we rely on the standard contractual clauses approved by the European Commission.
Note: when we add another supplier that reaches your data, it appears here first.
Cookies and browser storage
Linkvue sets no advertising cookies and does not follow you across other sites. Vercel Analytics counts page views without a cookie. Every cookie below is ours; the only exception is a Meta Pixel or GA4 tag a creator added to their own page, described above.
lv_lang: whether you chose English or Slovak, so the site comes back in your language. Written only when you use the switch. One year.- Sign-in cookies, all named with the prefix
better-auth(and__Secure-in production):session_tokenkeeps you signed in for up to 7 days;dont_remembershortens that to the browser session when you leave “remember me” off;two_factorlives 10 minutes between your password and your code;trust_devicelives 60 days when you tick “trust this device”;better-auth-passkeylives 5 minutes during a passkey sign-in. lv_profile: which of your pages the dashboard has open. Signed-in users only. One year.lv_ig_stateandlv_fb_state: 10 minutes while you connect Instagram or Facebook, so nobody can forge that connection.lv_fb_pick: 10 minutes, encrypted, holds the connection while you choose which Facebook Page to use.lv_src: if you opened a creator page through a link tagged with?src=, the tag is held for 30 minutes so the click can be attributed to it. It holds the tag, nothing about you.lv_ab: which of two designs you were shown on a page running an A/B test, so it stays the same when you come back. 30 days.lv_adult_ok: your confirmation that you are over 18. 24 hours.lv_hum: a signed proof that you passed the human check. 30 minutes.lv_fan: the id of the email entry you left on a creator’s page. One year.
Two things live in sessionStorage, which the browser clears when the tab closes, and are never sent to us: lv_esc, so the offer to leave an in-app browser shows once per session, and lv:drafts, unsaved dashboard edits kept for a signed-in creator whose session expired mid-edit.
Your rights
You have the right to:
- know what data we hold about you, and get a copy of it,
- have it corrected if it is wrong,
- have it deleted,
- restrict the processing, or object to it,
- take your data elsewhere,
- withdraw any consent you gave us, at any time.
Write to us and we will deal with it within one month. It costs you nothing. If you left your email on a creator’s page, you can also write to that creator directly. Contact: contact@linkvue.uk.
Deleting an Instagram or Facebook connection
If you are the creator who connected the bot, disconnecting it from the Linkvue dashboard removes the stored access token immediately. Removing Linkvue’s access in your own Instagram or Facebook settings does the same: Meta tells us automatically the moment you do, we delete the connection and the bot activity log belonging to your page, and Meta shows you a confirmation code together with a link where you can check exactly what got deleted.
If you are a fan who wrote to a bot running on Linkvue, you never gave Linkvue access to your account, so there is nothing on your side to disconnect. What we hold about you is the activity-log entry described above, your platform identifier and the text of your message, and it is deleted automatically within 7 days. If you want it gone sooner, write to us and we will delete it by hand; tell us which creator you wrote to and roughly when, because your Instagram or Facebook identifier is not something we can look up from an email address. Contact: contact@linkvue.uk.
Complaints
If you think we handle your data badly, you can complain to the supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27
https://dataprotection.gov.sk
Automated decisions
The shield decides on its own whether a request comes from a browser or a bot and whether a creator has blocked your country, and an A/B test picks one of two designs at random. None of that has a legal or similarly significant effect on you. We do no profiling for advertising.
Age
Linkvue is a service for adults. Do not create an account or leave your email on a page if you are under 18. We do not knowingly keep data about anyone under 18 and we delete it when we learn of it.
Changes
When we change this page, we change the date at the top as well. If the change is a substantial one and we have your email, we will tell you.