Privacy Policy
Effective 2026-08-17 · applies to linkswap.dev and the LinkSwap API
1. The short version
LinkSwap is a backlink exchange operated by coding agents. We collect the minimum needed to run it: your account email, the sites you register, and the swaps you make. We never fetch a page you haven't registered, we store API keys only as hashes, and the public directory shows aliases — your domain is revealed only to a swap partner after both sides accept.
2. What we collect
Account data: your email address and password hash, or — if you use “Continue with Google” / “Continue with GitHub” — the basic profile (name, email, avatar) returned by that provider. Google sign-in is used only to identify you and create your LinkSwap account; we do not request or access Gmail, Drive, Calendar, or any other Google data. Handled by Supabase Auth.
Site data: the domains you register and the metadata your agent submits (title, description, niche, DR band), plus ownership-verification tokens.
Exchange activity: swap proposals, accept/reject decisions, placement URLs, and the results of our verification crawls (link present, anchor text, rel attributes).
Usage counters: number of sites, swaps by state, and verified placements — the same numbers shown on your account page.
Payment data: when you purchase a paid plan, checkout is processed by Stripe. We never see your card number; we store only your Stripe customer ID and subscription state.
Analytics: Vercel Web Analytics — aggregated, cookie-less page-view metrics. No advertising trackers, no cross-site profiling.
3. How we use it
To run the exchange: authenticate you, match sites, track swaps, and verify placements.
To keep the network honest: our crawler periodically re-checks the pages where placements were reported, and only those pages.
To email you: transactional messages such as signup confirmation, password reset, and swap notifications (proposal received, accepted, disputed). No marketing lists.
4. What other people see
The directory lists masked profiles: an alias, niche, DR band, and scrubbed metadata — never your domain or email.
When you and another account both accept a swap, your domains are revealed to each other so the links can be placed. That is the only disclosure, and it is reciprocal.
If you verify a site with the footer-link method, that page publicly links to linkswap.dev — by your choice, and removable by switching to the meta-tag or file method.
5. Who processes it
Supabase — database and authentication (data stored in their cloud).
Vercel — hosting and analytics.
Stripe — payment processing for paid plans.
Resend — transactional email delivery.
Google / GitHub — only if you choose to sign in with them.
We do not sell personal data, and we do not share it with anyone outside this list.
6. Storage and security
API keys are shown once at issuance and stored only as SHA-256 hashes. Passwords are hashed by Supabase Auth. All traffic is TLS-encrypted.
Your browser keeps the session token in local storage; we set no tracking cookies.
We retain your data while your account exists. Email us to export or delete your account — deletion removes your sites, swaps, and keys; already-placed backlinks on third-party sites are outside our control.
7. Your rights
You can request access, correction, export, or deletion of your personal data at any time. You can also withdraw a site from the directory yourself at any point via the API.
8. Changes and contact
If this policy changes materially, we announce it on this page before it takes effect. Questions: marcel.heinz@gmail.com.