LinkWell works entirely on your device. If you never sign in, every link you save stays in a database on your phone and we never see it. There is no server holding your library, so there is nothing for us to read, lose or hand over. The app does register an anonymous id for the device so we can count how many people use LinkWell, send notifications and stop abuse — never your links.
If you turn on Pro sync, your links, folders and tags are stored on our cloud so they reach your other devices. We do not read them, profile them, sell them, or use them to target advertising — and no analytics event we collect ever contains a URL, page title, note or tag.
We do collect some things. The free tier shows a Google advert, the app sends anonymous usage and crash data, and signing in records your email address. Analytics and crash reporting can both be switched off in Settings.
Who we are
LinkWell is made by AroraLabs, based in Australia. We are the data controller for the information described here, and you can reach us at support@aroralabs.org.
This policy covers the LinkWell mobile app, the browser extension and linkwell.aroralabs.org.
What stays on your device
Unless you sign in and have Pro, all of this stays on your phone and never reaches us:
- Your vault — links, folders, tags, notes, highlights, reading state, reminders and settings.
- Offline copies of the pages you opened, and their preview images.
- PDFs and ebooks you add, including the text extracted so you can search them. These are never uploaded, even on Pro.
- Reminders and the weekly catch-up, which your phone works out and delivers itself.
- Article summaries, written on the device. No artificial-intelligence service is involved.
- Anything you share. Sharing builds a bookmarks file and hands it to your phone's own share sheet — we never receive it, and nothing is given a public web address.
Using LinkWell without an account
You can use LinkWell without signing in, and most people start that way. Your vault still never leaves the phone. To count people honestly, deliver notifications and keep abuse out, the app gives the device an anonymous account of its own, and that account holds:
- A random id and the nickname the app shows you (for example "wittykeepkoala"). No email, no name, no photo — we have no way to work out who you are.
- Device and app details: model, operating system, app version, and when the app was last opened.
- The same feature counts as any other account — how often a feature was opened, never what you opened.
- A notification token, if you allow notifications.
When you sign up, that anonymous account becomes your account — the same one, so nothing you saved is lost. If you sign in to an account you already have, the anonymous one is deleted. Either way you can delete everything from Settings.
What we collect, and why
| What | Why | Legal basis (UK/EU) |
|---|---|---|
| Email address, name and profile photo Only if you sign in. The photo comes only from Google or Apple sign-in, as a link | To create your account, show you who is signed in, and let you sign back in | Performance of a contract |
| Your vault Only with Pro sync switched on | So your links reach your other devices | Performance of a contract |
| Anonymous guest account A random id, a nickname and the device details below. Created even if you never sign in | To count people once, deliver notifications, and keep abuse out | Legitimate interests |
| Device and app details Model, operating system, app version, notification token | To deliver notifications and diagnose faults | Legitimate interests |
| Usage events Which features get opened. Never a URL, title, note or tag | To learn which features are worth keeping | Legitimate interests — with an off switch in Settings |
| Crash reports | To find and fix the crash | Legitimate interests — with an off switch in Settings |
| Purchase records Which plan, and until when | To unlock what you paid for, and to keep tax records | Contract, and legal obligation |
| Advertising identifier Free tier only, and Android only — see below | To show the banner advert | Consent, where required |
| Emails you send us Support, feedback, waitlist | To reply to you | Legitimate interests |
We do not sell your data, and we do not make automated decisions that have a legal effect on you.
Signing in with Google or Apple
You can create your account with an email code, with Google, or with Apple. When you choose Google, Google sends us your name, your email address, a link to your profile photo and a Google account identifier — nothing else, and we ask for no other Google permissions. When you choose Apple, Apple sends your name (if you allow it) and either your email address or a private relay address that forwards to you.
We use these only to create your account, show you who is signed in, and let you sign back in. They are stored with your account in Google Firebase, deleted when you delete your account, never sold, never shared with anyone for their own purposes, and never used for advertising.
You can withdraw LinkWell's access at any time from your Google account permissions or your Apple ID, and delete your LinkWell account from Settings. LinkWell's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
The browser extension
The extension saves the page you are on into your cloud vault. It has no sign-in of its own: you pair it from the app, by typing a short code or by scanning a QR code and approving on your phone. Pairing gives that browser a random key, which is the only thing the extension stores. It never holds your password, your Google or Apple login, or any other credential.
What it reads: the page you are on, or a link you right-click — and only when you ask it to save. From the page you are on it takes the address, title, description, favicon and preview image. From a link you right-click it takes only the address and the words of the link itself; LinkWell does not open, load or visit that page. It never reads other tabs, your history, or anything in the background, and it cannot: it holds no permission that would let it. If you add a note when saving, the note goes into the same vault as everything else you save. What we keep about the pairing: the account it belongs to, a name for the browser (for example "Chrome on macOS"), and when it was paired and last used, so you can see and remove it in the app. Removing it, or leaving it unused for 90 days, ends its access.
Advertising
The free tier shows a single banner advert supplied by Google AdMob. To serve it, Google may use your device's advertising identifier. In the EEA and the UK you are asked for consent first, and you can change that choice at any time in Settings.
We never send Google anything from your vault, and any paid plan removes the advert entirely.
On iPhone we do not ask for permission to track you, so no advertising identifier is available to the advert there.
Who we share it with
We never sell your data, and we never hand your vault to anyone for their own purposes. We use a small number of service providers, who process data only on our instructions:
- Google — cloud infrastructure, sign-in, notifications, anonymous analytics, and the AdMob advert on the free tier.
- Apple and Google Play — the stores. They take every payment; we never see your card details.
- A subscription-management provider — to confirm which plan you are on.
- An error-reporting provider — to receive crash reports.
- An email provider — to send sign-in codes and answer support.
- A website host and content-delivery network — to serve this site.
We may also disclose data where the law requires it, or to protect our rights or someone's safety. If you want the name of any provider above, ask us and we will tell you.
Where it is stored
We are in Australia and our providers are largely in the United States and the European Union, so your data may be transferred outside your own country. Where it leaves the UK or the EEA we rely on the UK and EU Standard Contractual Clauses, or on an adequacy decision where one applies.
How long we keep it
| Data | Kept for |
|---|---|
| Your on-device vault | Until you delete it or uninstall the app. We hold no copy |
| Account and synced vault | Until you delete your account, then 30 days so you can undo it. Ask us and we will skip the 30 days |
| Sign-in codes | Minutes — removed once used or expired |
| Browser pairing codes | Ten minutes, or the moment they are used |
| Browser extension keys | Until you remove the browser in the app, or 90 days after it was last used |
| Usage events | Up to 14 months in our analytics tool. A running tally of the same counts — how many times a feature was opened, never what you opened — is kept on your account until you delete it |
| Crash reports | Up to 90 days |
| Purchase records | Up to 7 years, as Australian tax law requires |
| Support emails | Up to 3 years after the matter is closed |
| Waitlist email | Until the launch email is sent, or until you ask us to remove it |
After your account is deleted we may still keep a limited amount of information for a while — the records above that we are required to hold, and anything we genuinely need to deal with a dispute, a chargeback, a suspected fraud or abuse, or a legal claim. Copies also persist in routine backups and server logs for a short period before they cycle out. We keep no more than we need and only for as long as we need it, and none of it is used to rebuild your vault or to market to you.
You can delete your account from Settings → Delete account in the app, or by emailing us. Full instructions are on the delete account page.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct or delete it, or ask us to stop using it. You can also export your whole vault to a file from inside the app at any time, on every plan, without asking us. Email support@aroralabs.org and we will respond within 30 days. We will never treat you worse for asking.
UK and EEA. You also have the right to restrict or object to processing, the right to data portability, the right to withdraw consent at any time, and the right to complain to your data-protection authority — the Information Commissioner's Office in the UK, or your national authority in the EEA.
California. You may request the categories and specific pieces of personal information we have collected, and ask us to delete it. We do not sell or share personal information as the CCPA defines those terms.
Australia. You may access and correct your personal information, and complain to the Office of the Australian Information Commissioner if you are not satisfied with how we have handled it.
Security
Everything travels over HTTPS. Cloud data is protected by server-side rules that only ever let your own account read or write your vault, and access to our systems is limited and protected by multi-factor authentication. No system is perfectly secure, but if a breach affects you we will tell you and the relevant regulator as the law requires.
Data on your device is protected by your phone's own security. Use a passcode, and consider the app's folder lock for anything sensitive.
Children
LinkWell is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child has given us any, email us and we will delete it.
Changes & contact
If we change this policy we will update the date at the top of this page, and tell you in the app before any change that materially reduces your privacy takes effect.
Questions, requests or complaints: support@aroralabs.org.