Privacy Policy

1. Controller

The controller within the meaning of the GDPR is:

Siebert Capital
Johannes Siebert
Bättigmatt 19
6423 Seewen, Switzerland
E-Mail: admin@getlinklib.com

We have not appointed a data protection officer, as the statutory requirements for a mandatory appointment are not met. You can address all data protection matters directly to the contact above.

1.1 Scope: GDPR and Swiss FADP

The provider is domiciled in Switzerland and is therefore subject to the Swiss Federal Act on Data Protection (FADP). As our service is also directed at users in the European Union and the European Economic Area, the General Data Protection Regulation (GDPR) applies in addition pursuant to Art. 3(2) GDPR. Where the two regimes differ, we apply the standard that provides the higher level of protection for the data subject.

Switzerland is recognised by the European Commission as a country ensuring an adequate level of data protection. Transfers of personal data from the EU/EEA to the provider therefore do not require additional safeguards.

2. General data processing

We process personal data only to the extent required to provide our service or where you have consented. Legal bases are in particular Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), and Art. 6(1)(f) GDPR (legitimate interests). Data is deleted when processing purposes cease and no legal retention obligations apply.

3. Hosting (Vercel)

Our website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes technically necessary data (IP address, timestamp, requested page, browser type) in server logs to deliver and secure the website (Art. 6(1)(f) GDPR). A data processing agreement is in place. Transfers to the US are based on SCCs and/or the EU-US Data Privacy Framework.

4. Registration and account (Supabase)

Using LinkLib requires an account. We use Supabase for authentication and data storage. Our database is hosted in the EU (Frankfurt region). We process your email address, password hash, and saved content (legal basis: Art. 6(1)(b) GDPR).

You can also sign in via GitHub (GitHub, Inc.) or Google (Google Ireland Limited). In this case we receive your email address and user identifier from the provider. Data processing by the login provider is governed by that provider's privacy policy.

5. Saved links and content

Saved links, sections, and tabs are stored in our database to provide the service (Art. 6(1)(b) GDPR). When adding a link, our servers fetch metadata from the target page (title, description, preview image). You can delete links, sections, or your full account at any time.

5.1 Shared tabs and comments

You can mark a tab as shared and invite other users via an invite link. Everyone you invite can see all links, sections and comments in that tab; people with editing rights can also add and change content. Other members see your display name (nickname or handle) next to your comments - never your email address. Comments you write in a shared tab are visible to all members of that tab and can be deleted by you or by the tab owner. Invite links expire automatically and can be revoked at any time. If you switch off sharing for a tab, all members lose access immediately. Private (incognito) tabs cannot be shared. Legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR).

6. Profiling (only with consent)

If you consent to personalized advertising, we analyze saved content (titles, domains, section names) to derive interest categories (profiling, Art. 6(1)(a) GDPR). These profiles are used for ad targeting and may partially be shared with ad networks (such as Google AdSense). You can withdraw consent at any time via Cookie Settings in the footer.

7. Google AdSense

If you consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), we display ads via Google AdSense (Google Ireland Limited, Dublin, Ireland). Google uses cookies and similar technologies for interest-based ads and performance measurement. Data may be transferred to Google LLC servers in the US (SCCs / EU-US DPF). Without consent, AdSense scripts are not loaded. policies.google.com/privacy

8. Payment processing (Stripe)

For Premium purchases we use Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland). During checkout you are redirected to Stripe, which processes payment data under its own responsibility. We only receive payment/subscription status data (Art. 6(1)(b) GDPR). stripe.com/privacy

9. Cookies and local storage

We use technically necessary storage technologies (Section 25(2) TDDDG), for example to store login sessions and cookie choices. Non-essential cookies (especially ad cookies) are set only with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).

10. Your rights

To exercise your rights, send an email to admin@getlinklib.com.

10.1 Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. A list of European supervisory authorities is available from the European Data Protection Board.

Data subjects in Switzerland may additionally contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.

10.2 No automated decision-making

We do not use automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR. The interest categories described in section 6 are used solely to select advertising and have no such effect.

10.3 Obligation to provide data

You are not legally obliged to provide personal data. However, an email address and a password (or a login via a connected provider) are required to create an account; without them the service cannot be used.

11. Data and account deletion

You can delete your account and all saved links at any time in account settings. Data is deleted promptly unless legal retention obligations apply (for example invoice records).

11.1 Storage periods

12. Data security

All data is transmitted using HTTPS/TLS. Passwords are stored as hashes only. We apply appropriate technical and organizational measures to protect your data against loss and unauthorized access.

13. Changes to this policy

We update this privacy policy when changes to our service or legal requirements make this necessary. The current version published here applies.

Version: July 2026