Your library, safely organized.
This page is maintained by LinkSafe to answer common security, privacy, AI, and compliance questions about the Service. It is not an independent certification and is not audited by a third party. Security is a shared responsibility — LinkSafe operates the platform, our hosting provider operates the infrastructure, and you protect your credentials and the content you choose to make public.
AI responsibility
LinkSafe uses AI to help you organize and search your library, and lets you connect the library to compatible external AI assistants. We take a conservative approach and want you to understand exactly what that means.
- AI assists, you decide. AI-suggested categories, tags, and descriptions are always editable and never applied silently to your account.
- What we send during enrichment. AI enrichment sends the URL and its public page metadata (title, description, OpenGraph image) to a large language model. We do not send your notes, tags, other items, account data, or the contents of your private boards.
- MCP access. When you connect LinkSafe to an external AI client through MCP, that client — acting as you — can call the tools listed on the AI access page. Any resources it retrieves are sent to that AI provider to answer your question and processed under their terms, not LinkSafe's. You can disconnect the client at any time.
- No model training on your content. Our AI provider processes prompts to generate a response and does not use them to train third-party models. LinkSafe does not train its own models on your saved data.
- Best-effort accuracy. AI output can be wrong. We never claim AI results are authoritative, and dead-link checks, duplicate detection, and enrichment can all produce false positives or negatives.
- You control usage. Every internal AI action (auto-fill, intent search) costs one credit against your monthly quota; you can see remaining credits in the app.
What we do not do
- We do not sell personal data — to anyone, ever.
- We do not run ad networks, tracking pixels, or third-party ad cookies.
- We do not send marketing emails, newsletters, or promotional campaigns. See Email preferences.
- We do not store copies of the pages you save — only your references, titles, and notes.
- We do not read the contents of your private boards for advertising, model training, or profiling.
- We do not claim SOC 2, ISO, HIPAA, or PCI certification. We do rely on hosting providers who hold those certifications for the infrastructure layer.
Public boards and moderation
You choose whether a board is private (only you and invited collaborators) or public (anyone with the link). Public boards may be indexed by search engines until you unpublish them.
- Public boards must comply with our acceptable-use rules — no unlawful, infringing, harassing, or malware-linking content.
- To report abusive content on a public board, use the contact form and pick "Other" or "Privacy". Include the board URL and a short description.
- Verified reports lead to unpublishing the board, removing the offending item, or — for repeat abuse — account suspension.
- DMCA / copyright complaints: use the contact form, pick "Other", and include the material identified, the URL on LinkSafe, your contact info, a good-faith statement, and a signature (electronic is fine). See the DMCA section of our Terms.
False-positive appeal (blocked by a DNS or web filter?)
LinkSafe is a legitimate bookmark manager operated at linksafe.io. Some web filters, DNS blocklists, or corporate proxies may misclassify us as a "link shortener" or "user-generated content" risk because we host public boards. If your organization's filter blocks LinkSafe, please share the following with your IT or security team:
- Category: personal productivity / bookmark manager
- Primary domain:
linksafe.io(withwww.linksafe.io) - Security policy: /.well-known/security.txt
- Company / abuse contact: contact form
If you are a filter operator and want to remove a false positive, please reach out via the contact form with category "Security".
Report a vulnerability
We welcome coordinated disclosure. Please submit findings via the contact form (category "Security") or refer to our machine-readable security.txt.
- Please avoid testing against other users' data — use your own test account.
- Give us reasonable time to respond and remediate before public disclosure.
- We do not currently run a paid bug-bounty program, but we credit researchers who follow this policy.
Compliance and certifications
LinkSafe itself does not hold SOC 2, ISO 27001, HIPAA, or PCI certifications. We rely on hosting and payment providers who do:
- Lovable Cloud (Supabase) — SOC 2 Type II reports available under NDA from Supabase.
- Stripe — PCI DSS Level 1 for payment processing; card data never touches our servers.
- Cloudflare (Workers) — SOC 2 Type II and ISO 27001 for the edge runtime.
Reach us via the contact form, or read the full legal texts: Terms, Privacy, DPA, Cookies.