Privacy Policy
Updated September 4, 2026
Short version: visitors are recorded as a one-way hash and never as an address, we run no advertising trackers, and the only thing any partner learns about you is on the survey step. The detail is below.
1Who we are
Linktain operates linktain.com from the United States. Send anything about this policy to info@linktain.com, including a request to see, correct or delete what we hold about you. Telegram at @LinksWithAndrew and Discord at @andrewworks are faster for a question, but a formal request should go to the address so there is a record of when you asked.
2If you visit a locked link
You need no account and we never ask your name. Per visit we store a one-way salted hash of your IP address, your browser's user agent string, the referring page, and the country, region and city the address resolves to. The address itself is never stored, and the hash cannot be turned back into it.
3Why a hash instead of an address
The hash answers one question: is this the same visitor as an hour ago. That is what stops one person being paid for a hundred times, and it is the only reason the field exists. Storing the address would answer the same question and would also identify a person, which we have no use for. Same answer, less data, so we take the less.
4If you have a creator account
We store your email and name, and either a hash of your password or your Google or Telegram account id depending on how you sign in. We never see or store a Google or Telegram password. We record when you last signed in and by which method, so you can tell your own session from somebody else's. We keep your application answers: where your traffic comes from, your Telegram or Discord handle, and your own estimates of earnings and daily volume.
5If you request a payout
We store the method and destination you give us, a PayPal email, a wallet address or bank details. We need it to send money and we keep it as the record of where a payment went. It goes to nobody except the provider actually moving the funds.
6If you buy a pass
Stripe handles payment end to end. Your card number never reaches our servers and we could not store it if we tried. We keep your email, what you paid, which pass, and when it expires. The email is what lets you restore a pass after clearing your browser, which is why we ask for it before payment rather than after.
7What we do not do
We do not sell your personal information and we never have. We do not share it with advertisers or data brokers. There is no Google Analytics, no Facebook pixel, no tag manager and no third-party analytics anywhere on this site. We build no advertising profiles and we follow nobody around the web. One exception, and we would rather state it than bury it: press the button on a survey step and we set a session cookie, then hand the survey company a name built from it, so they can tell you are the same browser during that session. That happens on the survey step only, it lasts until you close your browser, and the cookie policy explains it in full.
8The sponsored steps
A gate step sends you to a partner's own website, and from that moment their privacy policy applies instead of ours. We pass a click identifier so a completed offer is credited to the right creator, and we receive back whether it completed and what it paid. We do not receive your name, your address, or anything you typed on their site, and we cannot read cookies they set.
9Who else touches it
Stripe processes payments. Resend delivers our email. Our advertising partners receive a click identifier plus the country and device type a gate was opened from, which is what decides whether an offer can be shown at all. A survey partner additionally receives a name for your browser, described in section 7 and in the cookie policy, because their service refuses to run without one. Hosting is netcup. None of them may use any of it for their own purposes.
10Where it is stored
Our servers are in Vienna, Austria. We are a United States company, so data collected here is held in the European Union and accessed from the United States. If you are in the EU or UK, that transfer is covered by the standard contractual clauses our providers operate under.
11How long we keep it
Visit records are kept while they are needed to run and audit payments, in practice the current financial year and the one before it. Account data is kept while the account exists. Records of money that actually moved, payouts and conversions, are kept seven years because tax law requires it, and a deletion request cannot override that.
12Your rights
Wherever you live, you can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to info@linktain.com and we answer within 30 days. We delete what we are not required to keep and tell you plainly what we kept and why. We will never charge you, deny you service, or pay you less for asking.
13California
Under the CCPA and CPRA you may request the categories and specific pieces of personal information we have collected, the sources, the purpose, and who we shared it with. You may request deletion and correction. We do not share personal information for cross-context behavioural advertising. We are paid by a survey partner who receives a name for your browser, so if you would rather that did not happen, do not use the survey step: every other way through a gate sends them nothing, and you can also block the lt_sid cookie or write to us and we will act on it. You may use an authorised agent, and we will not discriminate against you for exercising any of this.
14Europe and the United Kingdom
If you are in the EEA or UK, the GDPR applies to you and you additionally have the right to object to processing, to restrict it, to data portability, and to complain to your national supervisory authority. Our lawful bases are: contract, for running your account and paying you; legitimate interest, for hashing addresses to prevent duplicate payment and fraud, which is the least identifying method we found; and legal obligation, for financial records.
15Children
Linktain is not for anyone under 18 and we do not knowingly collect information from children. If we learn that an account belongs to a child we close it and delete what we hold.
16Security
Passwords are hashed, never stored in a readable form. Sessions are signed and their cookies are HttpOnly and Secure. Traffic is encrypted in transit. No system is perfectly secure, and if a breach ever affects your data we will tell you rather than wait to be asked.
17Changes
If we change what we collect or why, this page changes and so does the date at the top. If the change is material we email account holders instead of expecting anybody to re-read a page they already read.