Privacy policy
LinkJar saves your links in your own AT Protocol account. Private links are encrypted on your device before they leave it. This page explains what LinkJar handles, when and why, and what you control.
The short version
- Public links are public. Public links, boards, comments, reactions and follows are records on the open AT Protocol network. Anyone can read them, including other apps.
- Private links are encrypted on your device. Their addresses, titles, notes and tags are encrypted before upload. Your settings, reading progress and highlights are always encrypted. LinkJar and your account host store this data but cannot read it.
- Some features send data when you use them. Link previews, snapshots and AI features send a link or article text to a LinkJar service. For private links, these features are off by default or ask each time. On iPhone, some of them start on; see Features that use our servers.
- No ads, no selling. We don't sell personal data, show ads, or track you across other apps and websites.
- Limited analytics. The web app and website use analytics that never include your links. The browser extension and the iPhone and Mac apps have none.
- Who runs LinkJar
- Your account
- Public and private links
- Your Private Jar keys
- Features that use our servers
- Sync and notifications
- The public index
- LinkJar accounts
- Website and waitlist
- Analytics
- Data on your devices
- Service providers
- How long we keep data
- Your choices and rights
- Changes and contact
Who runs LinkJar
LinkJar is operated by Uros Karic, Mise Vujica 1, Belgrade, Serbia, the controller of the personal data described here. Email hello@linkjar.io with any privacy question or request.
Your account
LinkJar runs on AT Protocol, the open network that Bluesky also uses. Your links are records in your AT Protocol account, also called your repository. An account host stores it:
- If you sign in with Bluesky or another provider, that provider hosts your account, and its privacy policy covers the account itself. LinkJar signs in through OAuth. Your sign-in session stays on your device; LinkJar's servers never receive your password or your session.
- If you create a LinkJar account, we host it. See LinkJar accounts.
When an app uses a LinkJar service, your host issues it a short-lived token that proves which account is asking. The token identifies your account by its DID, the permanent identifier every AT Protocol account has.
Public and private links
Public
A public link's address, title, note, tags and summary are published with your account, as are public boards and their items, comments, reactions and follows. Anyone can read them. Other services on the network, such as relays and apps, can keep copies. When you delete a public record, it leaves your repository and LinkJar's index; we can't remove copies that others hold.
Private
For a private link, the address, title, note, tags and boards are encrypted on your device. Settings, reading progress, highlights and saved summaries are always encrypted, whatever the link's visibility. Snapshots (offline copies of articles) are encrypted before upload.
Encryption doesn't hide everything. For private records, your host and the network can still see when each record was created, its approximate size, that it is private, how many images a snapshot has and their sizes, and a keyed marker that shows whether two of your private links point to the same address. Encrypted records travel through the network like public ones, so others can hold copies of the encrypted data.
Your Private Jar keys
- Private data is encrypted with keys derived from your Recovery Seed, which your device creates. The seed never goes to LinkJar in readable form.
- Your Recovery Kit (a code or 24 words) restores access. We can't reset it or recover your private data without it. Anyone who has it can read your private data, so keep it safe.
- With a passkey, your repository keeps a copy of the seed that only that passkey can unlock.
- The iPhone and Mac apps can keep a copy of the seed in iCloud Keychain so your other Apple devices can unlock. This is on by default. Turn it off in Settings with Sync with iCloud Keychain. Apple encrypts iCloud Keychain end to end.
- In the web app, your Recovery Kit stays in the browser's local storage until you set up a passkey.
Features that use our servers
These features send data to a LinkJar service when you use them. The service uses it for that one request unless the table says otherwise. Where a feature would send a private link's content, it is off by default or asks you first, except where the iPhone row says otherwise.
| Feature | What is sent | Default | Kept |
|---|---|---|---|
| Link previews (web app) | The link's address. Our server loads the page to read its title, description and image, so the website sees a request from LinkJar. | Public links: on. Private links: off, or ask for each link. | The preview, by address, for up to 1 hour. |
| Link previews (iPhone) | Nothing to LinkJar. Your phone loads the page and its images directly. | On, including Previews for private links. | On your phone. |
| Snapshots | The browser extension copies the page you have open, with no server involved. The web app can ask our server to load the page; the server sees the article text while it prepares the copy. Your device then encrypts the copy and stores it in your repository. | Private links: asks every time. On iPhone, your phone loads pages itself, and Snapshot when saving and Snapshot for Read Later are on. | Not on our servers. |
| AI suggestions (tags, summary, board) | Title, description, site and language. For public links, also the address. Processed by Cloudflare Workers AI (currently Llama 3.3). | Off. For private links, asks every time. | Public-link results for 30 days, without your identity. Private: not kept. A count of your requests, for usage limits. |
| Cloud summaries | The article's title and text, up to about 48 KB per request. Processed by Cloudflare Workers AI (currently Mistral Small 3.1), with request logging off. | Off. Asks for each article. | Not kept. A count of your requests, for usage limits. |
Some features stay on your device. Summaries from Apple Intelligence on iPhone and Mac run locally, as does the Labs search feature. Some features download files when you ask: the listening voice pack (about 116 MB) and the Labs search model come from Hugging Face, which sees your IP address.
Images and site icons shown with your saved links load directly from the websites that host them, so those websites see your IP address.
Sync and notifications
- Live sync. While an app is open, our events service relays changes in your repository to your other devices. It holds up to your last 1,000 changes (public content, and private records still encrypted) and deletes them when your last device disconnects. To receive changes quickly, it tells Bluesky's Jetstream service which accounts are connected, by DID.
- iPhone notifications. We store your device's push token, app details, notification preferences and pending alert counts. They stay until you sign out, turn notifications off, or Apple reports the token as invalid. Sync notifications contain no content. Social alerts contain the type of activity, counts, the DIDs of up to eight people involved and a reference to the link. Apple delivers them.
- Web reminders. We store your browser's push subscription and your reminder times under random IDs. A reminder notification carries only its ID. We remember sent reminders for 7 days.
The public index
LinkJar's index (indexer.linkjar.io) reads public LinkJar records from the network. It powers Following, Discover, public jar pages, people search, comments and notifications. It stores public links (address, title, note, site, tags and summary), boards, follows, comments and reactions, the notifications derived from them, and a cache of account handles. It never stores private records.
Your notifications are visible only to you: the index answers only the account they belong to. When you delete a public record or make it private, we remove it from the index. When your host reports that your account was deleted, suspended or deactivated, we remove what it published. If anything remains, email us and we'll remove it. The index also checks whether saved public links still load, which contacts those websites.
LinkJar accounts
LinkJar accounts open during the private alpha. This section describes how they work; we'll update it if anything changes when they open. When you create a LinkJar account on our account server (pds.linkjar.social), we store:
- Your email address and whether you've verified it.
- Your password as a hash. If you sign in with Apple, Google or GitHub instead, we store the link to that account.
- Your handle and DID.
- Your devices' sessions and the apps you've connected.
- IP addresses and times of sign-ins and sign-ups, for security and to prevent abuse.
- Your repository and files: records on our server in Nuremberg, Germany (Hetzner), and files in Cloudflare R2.
Sign-up is protected by hCaptcha, which receives your IP address and browser details. We send account emails through Cloudflare Email Service, from accounts@linkjar.io. From the day accounts open, backups of account databases are kept for 7 days, and daily snapshots of encryption keys and server configuration for 30 days.
You can manage or delete your account on your account page (in Settings, open Sign-in methods), or email us. Deleting the account removes your repository from our server. Public records that others copied before you deleted them remain with them.
Website and waitlist
- Waitlist. We store your email address, the time you joined and whether our email reached you. We send the email through Resend. We keep your entry until you ask us to delete it. To limit repeated sign-ups, we briefly store a hash of your IP address combined with the current hour; it can't be linked across hours and is deleted with the next sign-up after that hour.
- Extension uninstall form. If you fill it in, we store your reason, any comment, the extension version, your browser and a hash of your IP address.
- Fonts. The website and web app load fonts from Google Fonts, which receives your IP address.
Analytics
We use PostHog, hosted in the EU, to understand how LinkJar is used.
- Web app. We record which screen you open (as a route, such as the Read Later screen, never the link itself) and events such as "link saved", "highlight created" or "AI suggestion accepted". Events never include addresses, titles, notes or article text. They are linked to your account's DID, not your handle. There is no automatic click tracking and no session recording. Analytics stays off when your browser sends Do Not Track or Global Privacy Control, and uses local storage rather than cookies.
- Website. We record page views and clicks, without session recordings, and honor Do Not Track. Nothing is stored in your browser, so we can't recognize repeat visits. Cloudflare Web Analytics also counts visits, without cookies.
- Browser extension, iPhone and Mac apps. No analytics. No LinkJar app uses crash reporting.
Data on your devices
- Web app. Your records are cached in the browser, encrypted with a key derived from your seed. Your handle and some preferences sit in local storage. Signing out removes your keys, the decrypted data and the local database.
- Browser extension. To show that a page is already in your Jar without asking a server, the extension keeps an index of your saved links. Public links are stored as they are. Private links are stored encrypted, with only a keyed hash of each address, so the index reveals nothing about them without your keys. Your seed stays in memory for the browser session.
- iPhone. The app stores your records decrypted in its own storage, protected by your device's data protection. Saves waiting to sync, including page content from the share sheet, are stored the same way until they sync.
- Mac. The app's local database is encrypted.
Service providers
We share data only as this policy describes, with these providers:
- Cloudflare: hosts LinkJar's services and website, runs the AI features, sends LinkJar account email, resolves handles over DNS, and provides web analytics.
- PostHog (EU): analytics.
- Resend: waitlist email.
- Apple: push notifications, iCloud Keychain and Sign in with Apple.
- Google: fonts, and Google sign-in for LinkJar accounts.
- GitHub: GitHub sign-in for LinkJar accounts.
- hCaptcha: sign-up protection for LinkJar accounts.
- Hetzner: the LinkJar account server.
- Hugging Face: downloads you request.
- Bluesky: Jetstream (sync), its AppView (profiles and people search) and, by default, handle lookups through bsky.social.
- PLC directory (plc.directory): account identity lookups.
We don't sell personal data or share it for advertising. We disclose data when the law requires it.
How long we keep data
| Data | Kept |
|---|---|
| Link previews | Up to 1 hour |
| AI results for public links | 30 days |
| Live sync buffer | Until your last device disconnects |
| iPhone push registration | Until you sign out or turn notifications off |
| Sent web reminders | 7 days |
| Public index entries | Until you delete the record, make it private or ask us to remove it |
| LinkJar account | Until you delete it |
| LinkJar account backups | Databases 7 days; key and configuration snapshots 30 days (from the day accounts open) |
| Waitlist entry | Until you ask us to delete it |
| Waitlist sign-up limit (hashed IP and hour) | Until the next sign-up after that hour |
| Service logs | Short-term operational logs with event names; some error logs include a DID |
Your choices and rights
- Settings. Choose each link's visibility, and turn previews, snapshots, AI features and notifications on or off.
- Export. In Settings, use Your data on the web or Export links on iPhone. The export file is created on your device and not sent to LinkJar.
- Delete. Deleting a link removes it from your repository and from our index. In the web app, its snapshots, highlights and board entries go with it. A saved article summary stays in your repository, encrypted. Your host may keep a deleted snapshot's encrypted file until it cleans up unused files.
- Your rights. Depending on where you live, you can ask to access, correct, delete, restrict or transfer your data, or object to how we use it. Email hello@linkjar.io; we reply within one month. You can also complain to your data protection authority.
- Legal bases. We process data to provide the features you use, with your consent for features that ask first, and for our legitimate interests in security, abuse prevention and limited analytics.
- Children. LinkJar is not for children under 16.
Changes and contact
When this policy changes, we update the date at the top. We announce significant changes in the app or by email. Questions and requests: hello@linkjar.io.