← home
Privacy Policy
# Privacy Policy — link-preview
> ⚠️ TEMPLATE DRAFT. Not legal advice. Placeholders in [BRACKETS].
Effective date: [DATE]. Operator: [ERIC / ENTITY NAME, CONTACT EMAIL].
## What we collect
- **Signup data:** your email address and chosen plan (when paid tiers launch).
- **Usage metadata:** timestamp, API key name, request path, response status,
and latency for each API call.
- **Server logs:** request method and path (query strings are stripped before
logging), response status, timing.
## What we do NOT collect or store
- **User-submitted content (e.g. query parameters) is never persisted.** It
exists in memory only for the duration of the request. No query strings or
request bodies appear in any log we keep.
- No advertising or analytics trackers. No cookies on API endpoints.
## Retention
- Usage metadata: 90 days, then deleted (aggregates may be kept).
- Server logs: 30 days (hosting-provider log drain).
## Third parties (subprocessors)
- **DigitalOcean** — application hosting.
- **Stripe** — billing only, when paid tiers launch (we never see card numbers).
## Your rights
You may request access to, or deletion of, your account and usage data at any
time via [CONTACT EMAIL]. We do not sell data, ever.
## Roles under GDPR/CCPA
For content you submit, **you are the data controller and we act as a
transient processor**. For your account data, we are the controller.
## Changes
Material changes to this policy will be announced 14 days in advance.