Privacy Policy
Last updated: 19 September 2026
This page covers everything called Linkcroft: the website (linkcroft.com), the app (app.linkcroft.com), the browser extension, and the mobile apps we are building.
1. Who is responsible for your data
The controller — the party that decides why and how your personal data is used — is Total Management Control, a sole proprietorship under Dutch law trading as Linkcroft,Appeldijk 24, 4161 BH Heukelum, The Netherlands, registered with the Dutch Chamber of Commerce under 09109749.
Questions, requests or complaints: info@linkcroft.com, or the form at linkcroft.com/support. We answer every message ourselves.
Linkcroft is small enough that the law does not require a data protection officer, and we have not appointed one. The address above reaches the person who makes these decisions.
2. What we collect, why, and how long we keep it
3. The links you save
Your links are yours and they are private. Linkcroft publishes nothing you save, and there is no way for another user to see your collection.
Links that carry their own key. Some web addresses open a file all by themselves — a SharePoint or OneDrive share link, a Google Drive link, a Dropbox link with an rlkey, a WeTransfer or Figma link, or an address with a token or key in it. Whoever holds such an address can open what is behind it, without signing in.
When you save one, we say so once and you choose: keep the key, so the link keeps working exactly as it does now, or save it without the key, which leaves only the address of the page — it will then open only for someone who already has access. Where the key is part of the address itself, there is nothing to strip and we tell you that instead.
If you keep the key, the whole address is stored like every other link you save: encrypted at rest, readable only inside your own account. Our servers never open such a link and never fetch the file behind it, so the file itself never reaches us. But the address is in your account, so anyone who gets into your account can use it — which is exactly why we ask.
Linkcroft is not a password manager. Do not store passwords, API keys or recovery codes here.
4. Pages we never read
Some pages are nobody’s business but yours. Linkcroft keeps a blocklist, and on a page that is on it the text is never stored, never sent to the AI step, and no picture is taken:
- Online banking and payment services.
- Webmail — Gmail, Outlook, Proton, iCloud and the rest.
- Government portals — DigiD, MijnOverheid, the Dutch tax authority.
- Social networks and messaging.
- Microsoft 365 — SharePoint, OneDrive, Teams, Microsoft 365 on the web, and Copilot. A conversation with an AI assistant is, by definition, what you typed yourself.
- The sign-in, account, password and checkout pages of any other website, even one that is otherwise perfectly ordinary.
Part of this block sits inside the extension itself, so on those sites the page text does not even leave your browser. The other part sits on our server, so a link that arrives by any other route is stopped there too. If we cannot read an address well enough to judge it, we treat it as blocked and store nothing.
Saving the link still works. You keep the bookmark; we skip the contents.
Google Drive and Google Docs are deliberately not on this list, because genuinely public documents live there too. Those fall under the warning in section 3 instead.
Our servers only open what a browser can open without consequences. An address that would do something by being opened — confirm, unsubscribe, accept an invitation, activate, reset a password, pay, check out — is never fetched by us, and neither is an address that carries an access key. We store it; we do not visit it.
5. The browser extension
- It reads a page only when you click save. It does not watch you browse and runs no background collection.
- What it sends at that moment: the web address, the title, and the page text described above — to your own Linkcroft account, over an encrypted connection.
- It also reports which fields it managed to find — the field names and a hash of each value, never the values themselves — so that reading pages keeps getting better.
- Limited use: our use of information received from the extension follows the Chrome Web Store User Data Policy, including the Limited Use requirements. We use that data to build your cards and nothing else: no transfer to third parties except the processors named in section 8, no advertising, no selling, and no human reading it except where you ask us to help with a problem.
6. Pictures and icons on your cards
Our server fetches the picture on a card once, shrinks it, and stores it in our own storage. Your browser only ever asks us, so the website the picture came from never sees your IP address or learns which advert you kept. The same goes for the little site icons: they come from us, not from a Google service, so Google never sees which websites are in your collection.
Two honest details:
- If the original website refuses our server, the card falls back to showing the picture from that website, and then it does see your IP address — the same as any other image on the web. Pages on the blocklist in section 4 never get a picture at all.
- The stored picture sits at an address that contains two random identifiers. It cannot be guessed, and nothing links to it except your own account, but it is not behind a sign-in. Treat it the way you would treat any picture that was already published on the web, because that is where it came from.
7. How AI is used
Most cards are filled in without AI: the details come from what the website itself publishes about the page, and the suggested spot for a link comes from your own earlier links and the words on the page. Only for the small share of pages where that is not enough do we send the web address, the title and that slice of page text to Anthropic, our AI provider, and get structured details back.
You can also ask for the AI yourself. Some buttons in the app — such as the one that writes a description for a link — send that one page to Anthropic when you press them, and only then. That is your choice each time; nothing happens until you press. And a switch in your account turns the automatic part off altogether, so that the AI only ever works when you ask it to.
- Your data is not used to train anyone’s models. Anthropic’s own terms for business customers like us forbid it.
- Anthropic deletes what we send within 30 days. If one of their safety systems flags something, they may keep it for up to two years to investigate it — that is their published policy, and it applies to us as to everyone.
- Pages on the blocklist in section 4 never go through this step.
- Your email address, your account, and anything else about you never go with it.
- For a blocked site the AI may still suggest where to file the link, using only the title and the web address — never the contents of the page.
- AI gets things wrong. A price, a date or a description on a card is our best reading of someone else’s page, not a fact. Check the original before you act on it.
There is no automated decision-making that produces legal effects for you or similarly significantly affects you, in the sense of Article 22 of the GDPR. The AI fills in fields on a card. It decides nothing about you.
8. Who processes data for us
They process data on our instructions only and may not use it for their own purposes. We have a data processing agreement with each of them — the standard agreement each provider publishes, which applies from the moment we opened the account. If we add a provider, this table changes and the date at the top of the page moves.
One exception, and we would rather say it than bury it. For the bot check, Cloudflare is our processor when it tells us whether a visitor looks like a bot — but it also uses those same signals to improve its own bot detection, and for that it acts on its own account, not ours. What it receives when the check runs is your IP address, some technical characteristics of your browser, and which of our pages you were on. Cloudflare states that the purpose is to detect and block bots, not to identify, profile or target individuals.
Three sources that are not processors. Some widgets show information from outside: the weather from MET Norway (api.met.no, the Norwegian Meteorological Institute), currency rates from open.er-api.com, and the coordinates of a place you pick from Nominatim (OpenStreetMap).
Your browser never contacts these three. Our server asks them and stores the answer, so the next person asking about the same city gets the stored answer. This matters more than it sounds: all three keep server logs of who asked them what, and because we sit in between, what they log is our address, not yours. They never see your IP address and never learn that it was you who asked. MET Norway requires every request to carry a contact address — that is ours, not yours.
What does reach them is the substance of the question: the name or the coordinates of a place somebody put in a weather widget, and a currency code. Never attached to an account, a name or an email address.
9. Sending data outside the European Union
Your account and everything in it is stored in the European Union — the database is in Paris. But storage is not the whole story, and some processing happens elsewhere. Here is the honest picture, provider by provider.
The Standard Contractual Clauses are the European Commission’s own model contract for sending personal data to a country that the EU has not declared adequate. They are part of the data processing agreement we have with each provider. Where a provider is also certified under the Data Privacy Framework, both apply — so if the Framework were ever struck down, as its predecessor was, the Clauses would still stand.
You have the right to ask us for a copy of the safeguards that apply. Write to info@linkcroft.com.
10. Cookies
We use one cookie.
That is it. It is strictly necessary to deliver a service you asked for, so there is no consent banner — and there is nothing for a banner to ask about.
We run no analytics, no advertising trackers and no third-party scripts that follow you. There is no Google Analytics, no Tag Manager, no Plausible, no Meta pixel, nothing of the kind, on the website or in the app.
The bot check on the sign-in, sign-up and password-reset screens does not set a cookie — we have deliberately not switched on the Cloudflare option that would. Loading it does contact Cloudflare, which is described at the end of section 8.
Your browser also stores a few of your own preferences locally — which view you last used, for instance. That never leaves your machine and never reaches us.
11. Security
- Everything is encrypted in transit, and the database is encrypted at rest.
- Each account can only reach its own rows; that is enforced by the database itself, not only by the application.
- Sign-in attempts are rate-limited, passwords are checked against known breaches, and there is a bot check on the sign-in screens.
- We are told automatically when something looks wrong, and there is a written procedure for a data breach: we assess it, and where the law requires it we report it to the Dutch Data Protection Authority within 72 hours and tell you as well.
Who at Linkcroft can see your content. Linkcroft is run by a small team. Nobody on it reads your links. Access to the database happens for a specific reason — fixing a fault, investigating abuse, answering a support request you sent, or a legal obligation — and not otherwise. We tell you honestly: this is a promise about how we work, not a technical impossibility. If that is not good enough for a particular document, do not keep it here.
We do not hand data to law enforcement voluntarily. We respond to a valid legal order, and we will tell you it happened unless we are forbidden to.
12. Deleting your account
Open the app, go to your account page, and choose to delete it. It happens on the spot: your links, notes, tags, pages, device keys and sign-in details are removed. You do not have to email us and ask for permission. If you would rather we did it for you, write to info@linkcroft.com and we will.
There is no waiting period and no shadow copy. Copies held in our provider’s routine backups disappear as those backups are overwritten, within 90 days at the outside, and those backups can only be used to restore the service after an incident.
Export what you want to keep before you press the button.
13. Your rights
Under the GDPR, the European Union’s data protection law, you can ask us to (the article numbers below refer to that law):
- Give you a copy of your personal data, and tell you what we do with it (Article 15).
- Correct anything that is wrong (Article 16).
- Delete it (Article 17) — or do it yourself, which is faster; see section 12.
- Restrict what we do with it while something is in dispute (Article 18).
- Hand it over in a portable file, to you or to another service (Article 20).
- Object to anything we do on the basis of a legitimate interest (Article 21).
- Withdraw your consent, for the things in section 2 that rest on it. That does not undo what was lawful before you withdrew it.
Email info@linkcroft.com and we will handle it within one month. If a request is complicated we may take up to two more months, and we will tell you within the first month if that happens.
If you think we got it wrong, tell us first — we would rather fix it. You also have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl, or to the supervisory authority in the EU country where you live.
14. Age
Linkcroft is built for adults and older teenagers, so we ask that you be 16 or over. That is not a judgement about younger readers: European privacy law says a child under 16 cannot agree to this on their own — a parent has to — and we have deliberately not built the parental-consent machinery that would require. If a younger child has given us data, tell us at info@linkcroft.com and we will remove it.
15. Changes to this page
As Linkcroft grows we will update this page. The date at the top shows the last change, and for anything that materially affects you we will say so in the app as well, at least 30 days before it takes effect. Every previous version is kept; ask us at info@linkcroft.com and we will send you the one that applied on any given day.
16. Contact
Total Management Control, trading as Linkcroft · Appeldijk 24, 4161 BH Heukelum, The Netherlands · info@linkcroft.com · KVK 09109749
Full details are on the company details page.