Privacy Policy
What we collect, what we do not, who else sees it, and how long we keep it.
Last updated 23 August 2026. Linkrra, contact weare@linkrra.com.
The short version
We collect the minimum needed to run an account and bill it: your email and name from Google, what you buy, and how many tokens you use. We do not sell your data, we do not use your prompts to train models, and we do not hand your content to advertisers.
What we store
Account: the email address, name and profile picture Google returns when you sign in. Nothing else from your Google account. We never see or store a password.
Billing: which plan you are on, what you were charged, and Stripe's reference for it. Card numbers are handled by Stripe and never reach our servers.
Usage: per-request token counts, the model used and the timestamp, so we can bill correctly and show you where your credits went.
Sessions: an opaque cookie token, stored only as a hash, so a copy of our database cannot be replayed as a login.
Your prompts and answers
Requests are forwarded to a serving node, answered, and the token count is recorded. We do not retain prompt or completion text for API requests, and we do not use it to train anything. Conversations you save in the site chat are stored in your account so you can return to them, and you can delete them.
The models are served on machines contributed by independent operators. We require operators not to retain request content, but we cannot audit every machine, so treat the service as you would any third-party cloud: do not send secrets, credentials, or data you are contractually barred from sending to a processor.
If a message is blocked by our safety filter or reported by another user, a short excerpt (up to 120 characters) is kept in a moderation log so we can review and tune the filter. It is keyed to a hashed identifier, not your account, and this applies even to visitors who are not signed in.
Who else sees anything
Stripe — payments, and it holds your card and billing details under its own policy.
Google — only to sign you in.
When our own capacity is short, a request may be served by a commercial upstream provider. Every request we send one is restricted, per request in our code and not just by account setting, to providers offering zero data retention — a provider able to store the request is refused before it can run one. We do not share your identity with them; they see the request, not who sent it. For a subset of models, API callers can additionally request "confidential": true, which restricts the request to a provider running it inside an attested GPU Trusted Execution Environment — the operator cannot read it even with root access to the machine, not merely a policy promise not to look; see the docs for which models support it.
We disclose data to authorities only where a valid legal order requires it.
How long we keep it
Account and billing records: as long as the account exists, and afterwards for as long as tax and accounting law requires us to keep proof of a transaction. Usage records: kept up to 24 months for billing history. Moderation log excerpts: reviewed periodically and cleared once no longer needed for filter tuning. Session tokens: 30 days, then they expire.
Your choices
You can see your data on the account page, cancel a plan yourself, and ask us to delete your account by writing to weare@linkrra.com. We delete what we are not legally required to keep, and we tell you what is left and why. If you are in the EU or UK you have the usual rights of access, correction, portability and erasure, and these are them.
Cookies
One cookie, for your session, so you stay signed in. Local storage remembers your theme and sidebar preference. No advertising or cross-site tracking cookies.
Children
Linkrra is not for anyone under 16. We do not knowingly hold data about children, and we delete it if we learn we have.