← home

Privacy Policy

# Privacy Policy — link-preview

> ⚠️ TEMPLATE DRAFT. Not legal advice. Placeholders in [BRACKETS].

Effective date: [DATE]. Operator: [ERIC / ENTITY NAME, CONTACT EMAIL].

## What we collect

- **Signup data:** your email address and chosen plan (when paid tiers launch).
- **Usage metadata:** timestamp, API key name, request path, response status,
  and latency for each API call.
- **Server logs:** request method and path (query strings are stripped before
  logging), response status, timing.

## What we do NOT collect or store

- **User-submitted content (e.g. query parameters) is never persisted.** It
  exists in memory only for the duration of the request. No query strings or
  request bodies appear in any log we keep.
- No advertising or analytics trackers. No cookies on API endpoints.

## Retention

- Usage metadata: 90 days, then deleted (aggregates may be kept).
- Server logs: 30 days (hosting-provider log drain).

## Third parties (subprocessors)

- **DigitalOcean** — application hosting.
- **Stripe** — billing only, when paid tiers launch (we never see card numbers).

## Your rights

You may request access to, or deletion of, your account and usage data at any
time via [CONTACT EMAIL]. We do not sell data, ever.

## Roles under GDPR/CCPA

For content you submit, **you are the data controller and we act as a
transient processor**. For your account data, we are the controller.

## Changes

Material changes to this policy will be announced 14 days in advance.