Legal
Privacy Policy
Last updated 1 September 2026 · effective from the same date
We collect the minimum we need to run Linqtab: your email address, your login handle, a hashed password, whatever you put into your projects, and basic technical logs. There are no advertising cookies, no tracking pixels and no third party analytics, and we never sell or share your data for advertising. Your data lives on servers in Finland, inside the EU. Three companies help us run the service: our host, our email sender, and our crash reporter. The optional AI assistant never sends your API key to us, because it stays in your own browser. If you want a copy of your data, a correction, or deletion, write to support@linqtab.com and we answer within 30 days.
1. Who is responsible for your data
The controller of the personal data described here is [COMPANY], operator of Linqtab at linqtab.com. This policy covers the website, the web application and the public REST API. For any privacy question, write to support@linqtab.com. Formal legal notices go to [CONTACT].
Linqtab is a shared workspace. When you post an issue, a comment or a document in an organisation, its members and administrators can see it according to their roles. This policy describes what we do with data, not what your teammates do with it.
Our Terms of Service cover the rest of the agreement.
2. What we collect, why, and on what legal basis
We collect only what the product needs. The legal bases below refer to Article 6(1) of the GDPR.
| What we collect | Why | Legal basis |
|---|---|---|
| Account data: email address, public login handle, password stored only as a bcrypt hash | Create your account, sign you in, contact you about the service | Performance of a contract, Art. 6(1)(b) |
| Optional profile data: first, middle and last name, avatar image | Let teammates recognise you in issues, comments and boards | Consent, Art. 6(1)(a). You add it yourself and can remove it at any time |
| Email verification records and one time tokens | Confirm the address is real before the account becomes usable, and block throwaway sign-ups | Contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f) |
| Session data: short lived access token, rotating refresh session in an HttpOnly cookie, session timestamps | Keep you signed in and let us invalidate a stolen session | Contract, Art. 6(1)(b) |
| Your content: issues, comments, documents including co-editing history, uploaded files and images, board objects, assets, day plans, meetings, milestones | Provide the product you asked for | Contract, Art. 6(1)(b) |
| Organisation data: name, memberships, roles and permissions, invitations, quota usage | Access control, collaboration, enforcing per-organisation quotas | Contract, Art. 6(1)(b) |
| Public API data: OAuth2 client id, hashed client secret, scopes | Authenticate your integrations and limit what they can reach | Contract, Art. 6(1)(b) |
| Server logs: IP address, timestamp, request path and method, status code, user agent | Keep the service running, debug problems, rate limiting, stop abuse | Legitimate interests in a secure, working service, Art. 6(1)(f) |
| Error and crash reports, which may incidentally include an IP address, a user id and request metadata | Find and fix bugs before they hit more people | Legitimate interests, Art. 6(1)(f) |
| Transactional email data: your address and message metadata | Send verification, invitation and password reset messages | Contract, Art. 6(1)(b) |
| Support correspondence you send us | Answer you and keep a record of what was asked | Contract and legitimate interests, Art. 6(1)(b) and (f) |
What we never collect: payment or card data of any kind. Linqtab is a free public beta with no paid plans and no payment processing, so there is nothing to charge and nothing to store. We also do not ask for special category data such as health, religion or political views, and ask you not to put it into the product.
3. Cookies and browser storage
Linqtab sets one cookie: the HttpOnly refresh session cookie that keeps you signed in and lets sessions rotate safely. It is strictly necessary for authentication, so it needs no consent and there is no cookie banner.
We do not use advertising cookies, tracking pixels, third party analytics, fingerprinting or ad networks. We do not sell or share personal data for advertising, and build no advertising profiles.
The application also uses your browser's local storage for interface preferences such as theme and layout, and sessionStorage for the optional AI assistant key described below. That data stays in your browser and never reaches us.
4. Sub-processors and third parties
Three companies process personal data on our behalf. This is the complete list.
| Provider | What they do for us | What they can see | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosting: the servers that run the application, the database and the backups | All data at rest on the servers, as our infrastructure provider | Finland, EU |
| Resend | Delivery of transactional email: verification, invitations, password resets | Your email address and the content of those messages | May process outside the EEA, under standard contractual clauses |
| Sentry | Error and crash reporting | Error details, and incidentally an IP address, a user id and request metadata | May process outside the EEA, under standard contractual clauses |
No other third party processes your personal data. If that changes, we will update this table and the date on this page before the new provider starts.
We may also disclose data if the law requires it, for example a valid order from a competent authority, or where necessary to defend legal claims. If we are allowed to tell you, we will.
5. Where your data is stored
Linqtab runs on servers in Finland, inside the European Union, rented from Hetzner. The database, uploaded files and backups live there. Uploaded files sit outside the public web root and are served only through the application's access checks.
The only routine transfers outside the EEA are the ones in the table above, for email and crash reporting, covered by standard contractual clauses. Ask us for details at support@linqtab.com.
6. How long we keep things
- Unverified accounts are deleted automatically after a short retention window, 7 days by default.
- Your account and content are kept while the account exists. When you ask us to delete the account, we delete it and its content from the live system.
- Backups. We take daily database backups, encrypted at rest on disk and retained for a limited period. Content you delete, including a deleted account, can still exist in those backups until that period rolls over. We restore from them only for disaster recovery.
- Server logs are kept for a short period for security and debugging, then rotated away.
- Error reports are kept for the retention window configured with Sentry, then deleted there.
- Support emails are kept as long as needed to handle the request.
Where the law requires us to keep something longer, we keep it only while that obligation lasts.
7. Security
What we do: passwords are stored only as bcrypt hashes. Traffic runs over HTTPS. Authentication uses a short lived access token plus a rotating refresh session in an HttpOnly cookie, so a stolen token has a short life. Uploads sit outside the web root, requests are rate limited, backups are encrypted at rest on disk, and access to production is limited to the people who need it.
The honest part: Linqtab is a small operation and a public beta. No system is perfectly secure and we will not pretend otherwise. If a breach happens that is likely to affect your rights, we will notify the competent supervisory authority within 72 hours where the GDPR requires it, and tell affected users plainly.
Please use a strong, unique password and treat your API credentials like passwords.
8. Your rights
If you are in the EU or EEA, the GDPR gives you the rights below. We apply them to everyone, wherever you live.
- Access: ask what personal data we hold about you and get a copy.
- Correction: have inaccurate or incomplete data fixed.
- Deletion: ask us to erase your data, subject to the backup window above.
- Portability: receive an export of the data you gave us, machine readable.
- Restriction and objection: ask us to pause processing, or object to processing based on legitimate interests.
- Withdraw consent: where processing rests on consent, such as optional profile details, withdraw it at any time. That does not affect processing done before you withdrew.
To use them, write to support@linqtab.com. We reply within 30 days, normally free of charge. We may need to confirm the request really comes from you first.
You can also do a lot yourself. Content you create can be edited or deleted directly, and profile details and avatars changed in your settings. Account deletion is currently manual, by request, because during beta we would rather do it carefully than automate it badly.
We make no automated decisions with legal or similarly significant effects about you, and we do not profile you.
If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a data protection supervisory authority, normally the one in the EU or EEA country where you live or work, or your local regulator if you are elsewhere.
9. Children
Linqtab is not intended for anyone under 16, or under the age of digital consent in your country if that is higher. We do not knowingly collect personal data from children. If we learn that an account belongs to a child, we delete it and its data. A parent or guardian who believes a child has created an account can write to support@linqtab.com.
10. The AI assistant and where its data goes
Linqtab includes an optional, experimental AI assistant. It is off unless you switch it on, and works on a bring your own key basis.
You supply an API key for a third party model provider (Anthropic, OpenAI, OpenRouter or Google), or point the assistant at a model running locally on your own machine. The key is held in your browser's sessionStorage, so it disappears when the tab closes. Requests travel from your browser directly to the provider you chose. We do not receive your key, we do not store it, and that traffic does not pass through our servers.
The consequence is worth stating clearly: whatever you send to the model, such as issue text or the contents of a document, leaves Linqtab and is handled by that provider under their own terms and privacy policy. Read their policy before sending anything sensitive, and remember that project content can contain your teammates' personal data as well as your own.
There is also an optional bridge program you can download and run on your own computer. It keeps the model connection local, we do not receive that traffic either, and you run it at your own risk.
We do not train any AI model on your content, and no sub-processor may do so.
11. Changes to this policy
We will update this policy as the product changes or the law does. The date at the top of the page shows the current version. If a change materially affects how we handle your personal data, we will tell you in the product or by email before it takes effect.
12. Contact
Privacy requests, questions and complaints: support@linqtab.com. We answer within 30 days.
Formal legal notices: [CONTACT], addressed to [COMPANY]. A registered address will be published here once the company is incorporated in [JURISDICTION].
See also our Terms of Service.