Privacy Policy
LinkScout handles two very different kinds of personal data: our own customers', and the data of the people our customers choose to contact. The rules are different for each, and this explains both.
1Who is responsible
Dimitrije Pavlovic
Fischerweg 4
4222 Zwingen
Switzerland
Privacy questions and requests: support@linkscout.io. A person reads them.
We are not required to appoint a data protection officer and have not appointed one. The address above is the contact point for every request under this policy.
2Two roles - read this first
The rest of this policy only makes sense once this distinction is clear.
For your account, we are the controller
Your name, your email address, your billing details, which websites you added, what you did in the app. We decide why and how that data is used, so we are the controller of it and answer to you for it directly.
For the people you contact, we are your processor
The contacts LinkScout finds for you, the emails sent to them, and the replies that come back are personal data of people who never signed up with us. You choose the keywords, you choose the targets, you approve the prospects, and the email leaves your mailbox in your name. You are the controller of that data. We act on your instruction as your processor, on the terms in the Data Processing Agreement.
Practically, this means we do not decide who is contacted and we do not use prospect data for our own purposes. It also means the obligations that attach to that data - having a lawful basis for the outreach, and telling people where their data came from under Article 14 GDPR - are yours, not ours. Clause 6 of the Terms says the same thing.
If you are someone who received an email sent through LinkScout and you want your data removed, see clause 9. You can reach us directly and we will act, but the controller is the business that wrote to you.
3Data we hold as controller, and why
| What | Why | Legal basis |
|---|---|---|
| Name, email address, account identifier | To create and run your account, and to contact you about it | Performance of the contract |
| Postal address | It appears in outreach you send, because several jurisdictions require a physical address in commercial email | Performance of the contract; legal obligation |
| Timezone, notification preferences, settings | To send things at sensible hours and only when you asked | Performance of the contract |
| Subscription status, plan, price, payment outcome. We never see or store your card number | To bill you and to give you the plan you paid for | Performance of the contract; legal obligation for the records |
| Mailbox credentials for the inbox you connect, encrypted at rest and never shown back to you | To send and read the mail you asked us to send and read | Performance of the contract |
| Usage and cost events - searches run, model calls made, emails sent, jobs that failed | To operate the service, enforce plan limits, understand what the service costs us, and investigate faults | Legitimate interest in running a viable and reliable service |
| API keys you create, stored only as a hash | To authenticate requests from tools you connect | Performance of the contract |
We do not sell personal data, we do not share it with advertisers, and we do not use it to train our own models.
4Data we hold as your processor
On your instruction, LinkScout collects and stores:
- Contacts - the name, email address and role of a likely person at a website you targeted, found from the site’s own public pages and from a contact data provider;
- Messages - the subject and full body of outreach sent from your mailbox, and of replies received, so that follow-ups can be threaded correctly and replies matched to the right prospect;
- Prospects and links - the websites found, their status, and the links that resulted.
We handle this only to provide the service to you. We do not use it for our own purposes, we do not sell it, we do not use it to train models, and - with the two exceptions in clause 5 - we do not make one customer’s data available to another.
Gmail data
When you connect Gmail, LinkScout checks the sender, subject, thread ID and reply headers of new Inbox messages to find replies to outreach sent through LinkScout. It reads and stores the full body only after a message matches a LinkScout campaign. That content is used to display the conversation, match the reply, stop follow-ups where appropriate, classify the reply and prepare an editable reply draft.
Reply content and the relevant campaign conversation are sent to Anthropic only to provide those classification and drafting features. They are not used to train models. LinkScout does not use Gmail data for advertising, does not sell it, and does not allow people to read it except when you specifically authorise help with a named conversation, or where access is required for security or legal compliance.
LinkScout’s use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5The two things shared across customers
Clause 4 says we do not reuse your data for other customers. There are exactly two exceptions and we would rather name them than leave them buried.
The search cache
When LinkScout runs a search, the results are cached for a week and reused for anyone who searches the same phrase. The cache is keyed on the search phrase alone - never on a customer, a website or an account - and it holds only public search results: page titles, URLs and positions. It contains no contact data and nothing that identifies who ran the search. It exists so two customers researching the same topic are not billed for the same query twice.
The suppression list
When someone unsubscribes, replies asking not to be contacted, or their address hard bounces, that email address goes on a suppression list that is shared across every account on the platform, and no customer can send to it again through LinkScout.
This is deliberate and we think it is the right trade. The alternative - a suppression list per customer - would mean a person who asked one customer to stop could be contacted the next week by another, through the same product. A request to be left alone should be honoured by the platform that carried the message, not just by the sender who provoked it.
The list holds the email address, the reason, and the date. Our legal basis is our legitimate interest, and yours, in not contacting people who have said no - an interest the recipient plainly shares. It is kept indefinitely; see clause 8.
6Who we share data with
We use a small number of providers to run the service. Each receives only what it needs. The full list, with what each one gets and where it is located, is at Sub-processors, which forms part of this policy.
In summary: providers for hosting and the database, sign-in, payments, transactional email, search data, contact data, language models, and product analytics.
Some of these are outside Switzerland and the EEA, including in the United States. Where that is so, transfers are covered by the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the Federal Data Protection and Information Commissioner, or by an adequacy decision, together with the additional measures required of us.
We may also disclose data where the law requires it, to establish or defend a legal claim, or to a buyer in connection with a sale or reorganisation of the business - in which case we will tell you.
7Automated processing
LinkScout uses large language models to write outreach, classify replies and draft guest posts, and automated scoring to rank the websites it finds. This is automated processing of personal data, and we would rather say so plainly.
It does not produce decisions with legal or similarly significant effects on anyone within the meaning of Article 22 GDPR: the output is text and a ranking, a human can review every message before it is sent, and nothing here decides anyone’s access to a service, employment or credit.
Content sent to our model provider is not used to train their models. We do not train models on customer or prospect data.
8How long we keep things
While your account is active, we run two deletion rules so data does not accumulate for no reason:
- a prospect that was never approved and never contacted is deleted after six months - there is no reason to hold an editor’s address for years because a search once surfaced it and nothing came of it;
- when you reject a prospect, the contact record is deleted immediately and only the domain is kept, on your blocklist, so the same site is not suggested again.
After your account closes, prospects, contacts, messages, drafts and links are deleted twelve months later. The delay lets us restore an account reopened by mistake and deal with a dispute if one arises.
Delete a mailbox and its stored conversations. After disconnecting a mailbox, you can permanently delete it from Inboxes. This immediately deletes the stored messages and reply drafts associated with that mailbox from the live service.
Two things outlive the account. Billing records are kept for ten years because Swiss law requires it - Art. 958f of the Code of Obligations - and that obligation stands regardless of a deletion request. Suppression records are kept indefinitely, because an opt-out has to outlive the account that caused it: if closing and reopening an account wiped the list, everyone who had asked to be left alone would become contactable again.
Deletion is scheduled, not instantaneous. Requests are actioned on our next deletion cycle rather than the moment they arrive. Backups are kept on their own rotation and expire on that schedule; we do not surgically edit backups, and we will not promise erasure from them at a particular moment. Data in a backup is not restored into the live service except to recover from a failure, and if that happens the deletion is re-applied.
9Your rights
Under Swiss and, where it applies, European data protection law you can ask us for access to your data, correction of it, deletion of it, a copy in a portable format, and restriction of or objection to our processing of it. Where we rely on consent you can withdraw it at any time, without affecting what we did beforehand.
Write to support@linkscout.io. We answer within 30 days. We may need to confirm who you are first - not to obstruct you, but because handing someone else’s data to whoever asks would be the larger failure.
If you received an email sent through LinkScout
Your data is held on behalf of the business that wrote to you, and they are the controller. Ask them, or ask us and we will pass it on and help. Regardless of that, you can always tell us directly at support@linkscout.io that you do not want to be contacted, and we will add you to the platform-wide suppression list in clause 5, which stops every customer of LinkScout from writing to you again.
You can also complain to a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner; in the EEA or the UK, your local authority.
10Security
Mailbox credentials are encrypted at rest with a key we hold separately from the database, and are never displayed back to you or to us. API keys are stored only as a hash, so a copy of our database contains nothing that can call our API. Access to production data is limited to those who need it. Traffic is encrypted in transit.
No system is perfectly secure. If a breach occurs that is likely to result in a high risk to anyone affected, we will notify the people concerned and the competent authority within the time the law allows.
11Cookies and analytics
We use strictly necessary cookies to keep you signed in. Without them the app cannot work, and no consent is required for them.
For product analytics we use providers that do not set advertising cookies and do not track you across other websites. We measure page views, referrers and rough location at country level, and we count visits by AI crawlers. We do not build advertising profiles and we do not sell what we measure.
Because we set no advertising or tracking cookies, there is no cookie banner on this site. That is a deliberate choice, not an oversight.
12Children
LinkScout is sold to businesses and is not intended for anyone under 16. We do not knowingly collect their data. If you believe we hold data about a child, tell us and we will delete it.
13Changes to this policy
We will update this page when the service changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell you by email before it takes effect.