This policy explains how Kajodex handles personal data when you use the LinkIt applications, account service, cloud features, AI processing, collection sharing, and subscriptions. The Kajodex website has a separate website privacy notice.
Controller: Kajodex, Helsinki, Finland. Privacy contact: privacy@kajodex.com.
The short version
- LinkIt uses a product-specific Firebase account. It is not shared with a Kajodex website account or another Kajodex product.
- The native app keeps an account-scoped local library on your device. Cloud processing and synchronization send the relevant library records to the LinkIt API.
- When you ask LinkIt to process a saved page with AI, the saved URL and extracted page text are sent through OpenRouter to the selected AI model provider.
- LinkIt does not use personal data for advertising. Release builds on supported Apple and Android platforms use Firebase Crashlytics for diagnostics, and the API records limited operational and cost metrics.
Account and authentication data
Firebase Authentication, provided by Google, handles LinkIt sign-in. Depending on the method you choose and the methods available in your build, Google, Apple, or Microsoft may also process the sign-in request under its own privacy terms.
- Firebase processes your email address, password credential or provider identity, display name if supplied, Firebase user identifier, email-verification state, and authentication security metadata.
- The LinkIt API receives a Firebase identity token containing your user identifier, email address, and verification state. It does not receive your password or a provider password.
- Your Firebase user identifier separates your records in the LinkIt database and is also used for subscription entitlement and crash-diagnostic records.
Purpose and legal basis: creating and securing your account and performing our contract with you. Preventing abuse and protecting the service are also our legitimate interests.
Saved links and cloud library data
When you use cloud processing or synchronization, LinkIt stores the records needed to provide your library across signed-in devices.
- Saved URLs, titles, summaries, detected language, provider, category, tags, content type, read-time estimate, favorite and archive state, created, updated, and opened times, and synchronization state.
- Collections, collection names and descriptions, collection membership, and records needed to deliver collections shared with or by you.
- Generated translations, rich-preview and embed metadata, favicon references, and deletion tombstones needed to synchronize changes.
- Subscription entitlement records associated with your Firebase user identifier.
Cloud library records are stored in Microsoft Azure Cosmos DB in the United States. Small cached site icons are stored in Azure Blob Storage. Access is authenticated and records are partitioned by the Firebase user identifier.
Data stored on your device
- The native app stores an account-scoped local copy of saved links, collections, categories, providers, and synchronization state in an encrypted Realm database.
- Local settings, search history, notification preferences, and interface preferences stay on the device unless a specific setting is later described as synchronized.
- The operating system may retain shared URLs, notifications, browser history, or app backups according to your device and cloud-backup settings.
Deleting the server account cannot remotely erase local files or operating-system backups. Remove LinkIt or clear its app data on each device if you also want to remove local copies.
Saved-page retrieval and AI processing
To prepare a saved link, the LinkIt API requests the public URL, follows redirects, and extracts a bounded amount of page text and metadata. It may retrieve a favicon and ask the LinkIt embed resolver on Cloudflare for supported media metadata. The source website and relevant media provider receive ordinary network information from those requests, such as the requested URL and service IP address.
When AI processing is enabled for a save, LinkIt sends the URL, extracted page text, requested translation language, and a bounded list of preferred category names to OpenRouter. OpenRouter routes the request to the configured model provider. The returned title, summary, category, tags, language, and optional translation are stored with the link.
- Do not save a private or access-controlled URL with AI enabled unless you are comfortable sending the URL and extracted content to these processors.
- If you disable AI for a save, LinkIt uses user-entered and extracted metadata instead. The service may still request the URL to build the basic link record and preview.
- Opening a source page or an inline media preview may connect your device directly to that third party, which may process your IP address, cookies, or account information under its own privacy notice.
Purpose and legal basis: processing the saved page you ask us to process and performing the LinkIt service. Reliability, rate limiting, and abuse prevention are our legitimate interests.
Collection sharing
When you share a collection, LinkIt looks up the recipient email address in Firebase. The recipient must already have a LinkIt account. LinkIt stores the recipient user identifier with the collection and a small share record in the recipient account.
- A recipient can see the collection name, description, a read-only snapshot of the included links, and the owner email address and display name where available.
- The owner can see the recipient email address and display name where available.
- Revoking a share removes access through LinkIt, but it cannot erase information a recipient already opened, copied, or saved outside LinkIt.
Purpose and legal basis: carrying out your request to share the collection. Share only material you have the right to disclose to the chosen recipient.
Subscriptions and purchase data
RevenueCat validates and synchronizes LinkIt Pro entitlements. Apple App Store or Google Play processes a purchase made through its storefront. Kajodex does not receive your full payment-card details.
- LinkIt supplies your Firebase user identifier to RevenueCat as the App User ID.
- RevenueCat and the storefront process purchase and entitlement information such as product, receipt or purchase token, subscription state, renewal state, and access-period dates, together with limited device and SDK information needed to provide the service.
- The LinkIt API stores the product and entitlement state, relevant period dates, provider identifiers, and update times needed to grant cloud access.
Purpose and legal basis: performing the paid-service contract, restoring access, preventing purchase fraud, and meeting accounting, tax, and consumer-protection obligations where they apply.
Diagnostics, logs, and operational metrics
- On Android, iOS, and macOS release builds, Firebase Crashlytics receives crash stack traces, diagnostic information, installation identifiers, and the Firebase user identifier so we can identify and fix failures. Collection is disabled in debug builds and is not enabled by LinkIt on web, Windows, or Linux.
- The LinkIt API logs request method, route, status, duration, and Firebase user identifier. Production application logs are configured with a 30-day retention period.
- Upstash stores the Firebase user identifier, email address, first- and last-seen times, counts of submitted links and rate-limit events, AI tier and cooldown state, estimated AI cost, and Azure database request-unit totals for service operation and the private owner dashboard.
- Hosting, authentication, and security providers necessarily process network information such as IP address, user agent, and request time to deliver and protect their services.
Purpose and legal basis: our legitimate interests in diagnosing failures, securing the service, controlling abuse and cost, and maintaining availability. These records are not used for advertising.
Service providers and recipients
- Google provides Firebase Authentication and Firebase Crashlytics. Google, Apple, and Microsoft may also provide federated sign-in when you select an available sign-in method.
- Microsoft Azure hosts the API, cloud database, logs, and cached icon storage in United States regions.
- OpenRouter and the selected AI model provider process AI inputs and outputs. Cloudflare runs the embed resolver used for supported rich previews.
- Upstash processes operational metrics. RevenueCat validates entitlements, and Apple App Store and Google Play process storefront purchases, receipts, refunds, and subscription management.
- Source websites and media providers receive requests needed to retrieve a saved page or display content. Email and support providers process information you choose to send us.
- Personal data may also be disclosed where law requires it or where necessary to establish, exercise, or defend legal claims.
Legal bases
- Contract: authentication, local and cloud library functions, synchronization, saved-page processing, sharing, subscription delivery, and support you request.
- Legitimate interests: service security, fraud and abuse prevention, rate limiting, diagnostics, reliability, capacity and cost control, and the defence of legal claims.
- Legal obligation: tax, accounting, consumer-protection, lawful-request, and data-protection duties where they apply.
- Consent: only where a device permission or applicable law specifically requires it. You may withdraw consent through the relevant setting without affecting earlier lawful processing.
International data transfers
LinkIt intentionally uses Microsoft Azure in United States regions. Firebase Authentication runs in the United States, while Firebase Crashlytics uses Google’s global infrastructure. Other international providers may also process data outside Finland or the European Economic Area. Where applicable law requires a transfer safeguard, we use the mechanism available under the relevant provider agreement, such as an adequacy decision or approved standard contractual clauses. Provider privacy notices describe their processing locations in more detail.
Retention and deletion
- Firebase account data and active cloud library, collection, share, and entitlement records are kept while the LinkIt account exists or until you delete the relevant item, subject to synchronization and legal requirements.
- A deleted-link synchronization tombstone is configured to expire after 30 days. Production API logs are configured for 30 days. Processor-held crash, authentication, purchase, and transaction records follow the applicable provider settings, agreements, and legal retention duties.
- Support correspondence is kept only as long as reasonably needed to handle the request, protect the parties, or meet a legal duty.
- Automated in-app account deletion removes the Firebase identity, the records in the account’s Azure Cosmos DB partition, and account-linked Upstash operational metrics and private-dashboard profile. It does not cancel a storefront subscription or itself clear every local or processor-held copy, shared cached favicon, purchase record, log, diagnostic record, support message, or legally required transaction record.
- For a complete verified deletion request, email privacy@kajodex.com from the address associated with the account. We use the verified request to identify remaining account-linked records and processor requests, and will explain if a specific record must be retained for a legal or security reason.
Security
LinkIt uses authenticated access, account-partitioned cloud records, encrypted local Realm storage, managed secrets, HTTPS, and restricted administrative access. No system is perfectly secure. Protect your device and sign-in account, avoid saving secret URLs, and contact support@kajodex.com if you suspect unauthorized access.
Your data-protection rights
Under the EU General Data Protection Regulation, where applicable, you may request access to and correction or erasure of your personal data, restriction of processing, object to processing based on legitimate interests, and receive data you provided in a portable form. You may also withdraw consent where processing relies on consent.
Email privacy@kajodex.com from the address associated with your LinkIt account. We may need to verify account ownership before acting. You may complain to a supervisory authority; in Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).
Changes and contact
We may update this policy when LinkIt, its providers, or applicable law changes. We will give any notice required by law when a change materially affects your rights. Privacy requests: privacy@kajodex.com. Product support: support@kajodex.com.

