LinkeeperLinkeeper

Privacy Policy

Last updated: October 11, 2026

Linkeeper (App Store: “Linkeeper - Read Later”, bundle ID com.vanthuongdao.linkeep) is a local-first bookmark-saving app: every link, tag, and collection is stored in an embedded SQLite database right on your device.

The short version: your data stays on your device by default. Signing in with Apple or Google is optional and only enables cross-device sync. The only other thing that ever reaches us is feedback you choose to send from the app (see “Feedback you send us”). Separately, the app sends anonymous usage statistics and crash reports to Google (Firebase) — these are always on and cannot be switched off in the app — and, only when you watch an ad or buy Linkeeper Unlimited, the data described below reaches Google AdMob or RevenueCat. None of these ever receive your links, titles, notes or tags.

Local, on-device data

While signed out, every link, tag, collection, read/favorite state, and hidden-vault item is stored in a WatermelonDB (SQLite) database on your device. We operate no server that receives or reads this data in that state, and none of it leaves your device. What does leave the device is listed in the sections below — anonymous usage statistics and crash reports, ad and purchase data when you choose to watch an ad or buy, and feedback you choose to send — and none of it includes your library.

The hidden vault is locked with a PIN you set yourself, unlockable with Face ID/Touch ID via your device's Keychain. We never store or receive this PIN.

Optional sync (Sign in with Apple/Google)

If you choose to sign in with Apple or Google, that sign-in is exchanged for a Supabase session, and the following is two-way synced to our Supabase (Postgres) server:

  • Email address and User ID from your sign-in provider.
  • User-generated content (links, tags, collections) — “Other User Content”.
  • Display name, if provided by your sign-in provider.

This data is used only to sync across your own devices. You can sign out any time (local data remains), or permanently delete your account and all server-side data via Settings → Delete account.

Anonymous usage statistics

Linkeeper uses Google Analytics for Firebase (Google) to understand which features get used most — for example, app opens, screens viewed, and generic events like “saved a link” or “changed the theme”. This data:

  • Is tied to a random per-install identifier, never your name or email.
  • Never includes links, titles, notes, tags, text you type, or anything stored in the hidden vault.
  • Is never used for advertising or sold to third parties. The app uses no IDFA and shows no App Tracking Transparency prompt.

Usage statistics are always on in the App Store version of Linkeeper; there is no setting to turn them off.

Google's privacy policy governs how it processes this data: policies.google.com/privacy.

Crash reports

When the app crashes or hits a serious error, Firebase Crashlytics (Google) receives a crash report so we can find and fix the bug. A report contains:

  • The error and where in the app's code it happened (stack trace).
  • Your device model, iOS version, app version, whether the app was in the foreground, free memory and disk space, and the time of the crash.
  • A random Crashlytics installation identifier — not your name, email or any account.

Crash reports never include your links, titles, notes, tags, text you type or your PIN: web addresses and quoted text are removed from error messages before a report is sent. They are not linked to your identity and are never used for advertising or tracking.

Crash reporting is always on in the App Store version of Linkeeper; there is no setting to turn it off.

Google's terms for Firebase: firebase.google.com/support/privacy.

Device permissions

Linkeeper only requests a permission when you use the feature that needs it:

  • Face ID — only to unlock the hidden vault biometrically, instead of re-typing your PIN.
  • Notifications — to send the daily read reminder, which you can toggle in Settings.

You can decline or revoke any of these in your device Settings; the related feature simply won't be available.

In-app browser

The in-app browser loads the web pages you visit directly from your device to that site; those sites are governed by their own privacy policies.

Backup & restore

You can export your whole link/tag library to a JSON file (saved to your own Files/iCloud) any time, independent of whether you're signed in. This file is entirely under your control — we never receive a copy.

Ads (only when you choose to watch)

The free version offers rewarded ads that you choose to watch when you reach a free limit (import, collections, hidden vault). There are no banners or pop-up ads. Linkeeper Unlimited has no ads.

Ads are served by Google AdMob. When you choose to watch one, AdMob receives an SDK-generated device identifier, ad interaction data, diagnostic data and an approximate location derived from your IP address, to show and measure the ad. Linkeeper requests non-personalized ads only, uses no IDFA and shows no App Tracking Transparency prompt. Your links, notes, tags and library content are never sent to AdMob. Google's policy: https://policies.google.com/technologies/ads

Purchases (Linkeeper Unlimited)

Linkeeper Unlimited is a one-time in-app purchase. Payment is handled entirely by Apple; we never see your card or Apple ID.

Purchases are verified through RevenueCat, which receives an anonymous app user ID generated by the app, your purchase history for Linkeeper (from Apple's receipt), and basic device data (app version, iOS version, country/currency), so that Unlimited is unlocked and can be restored. RevenueCat never receives your name, email, links or library content. RevenueCat's policy: https://www.revenuecat.com/privacy

Feedback you send us

Linkeeper has an optional “Feedback & bug report” form. Nothing is sent unless you open it and tap Send — the app never sends feedback on its own.

When you tap Send, we receive:

  • The message you type.
  • Your email address, only if you enter one — used only to reply to you.
  • Your app version, iOS version, device type (iPhone or iPad) and app language.
  • A random install identifier generated by the app. It is not linked to your Apple ID or any account, and is used only to limit spam.

Feedback is stored on our own backend, hosted by Supabase in Singapore (ap-southeast-1), and a notification with your message is forwarded to the developer's private Telegram chat. Your network IP address is kept only as a one-way hash, for at most one hour, to rate-limit submissions.

Feedback is never used for tracking, advertising or analytics, never sold or shared, and not linked to your identity.

We keep feedback until the issue is handled, then delete it. To have anything you sent deleted, email vanthuong.dao2004@gmail.com with roughly when you sent it and what it said (or the email address you used).

Children

Linkeeper is not directed to children and we do not knowingly collect data from them.

Changes

We may update this policy; the date at the top will change accordingly.

Questions or support requests? Email vanthuong.dao2004@gmail.com.