Legal

Privacy Policy

Last updated 1 September 2026

1. Who we are

LinkIntel is a LinkedIn analytics product operated by DevRel Bridge Ltd, a company registered in England and Wales (company number 15979110), whose registered office is at 128 City Road, London, United Kingdom, EC1V 2NX. DevRel Bridge Ltd is the data controller for the personal data described in this policy.

Responsibility for privacy compliance sits with the company’s director. We are not required to appoint a statutory Data Protection Officer, and we have not appointed one. Privacy questions and data subject requests are handled directly, at support@getlinkintel.com.

2. LinkedIn data accessed with your permission

This section describes the part of LinkIntel that connects to LinkedIn directly, and it is the most important part of this policy to understand.

2.1 What we are permitted to do

When you connect your LinkedIn account, you are asked to grant a single permission, r_member_postAnalytics. This permission is read-only and applies to your own account only. Concretely:

  • We can read performance metrics for posts you have published on your own profile.
  • We cannot publish posts, comments or reactions on your behalf. We do not request any write permission.
  • We cannot read anyone else’s posts, your connections, your messages, your feed, or any company Page you administer.

2.2 What we read

We call LinkedIn’s Member Post Analytics API (memberCreatorPostAnalytics) to retrieve the following metrics, both in aggregate for your account and for individual posts you have published: impressions, members reached, reactions, comments, reshares, post saves, post sends, and link clicks. We refresh these daily and keep roughly 90 days of history, which is the window LinkedIn makes available.

LinkedIn’s API can measure a post only if we can name it, and it cannot list your posts for us. So we also store the LinkedIn share identifier, the post URL, the publication date and a short excerpt of the text for each post you register with LinkIntel, which is what lets metrics be attributed to the right post and grouped by theme. Section 3 explains where that list of posts comes from.

2.3 How it is used

These metrics are used for one purpose: to show you the performance of your own content. That includes summaries over a period, day-by-day trends, period-over-period comparisons, identification of unusually strong or weak days, and rankings of your own posts.

  • Your LinkedIn data is visible only to you.
  • We do not sell, rent or trade it.
  • We do not share it with third parties for their own purposes.
  • We do not use it to train machine learning or AI models.
  • We do not aggregate it with other members’ data to produce benchmarks or industry reports.

2.4 Access through AI assistants

LinkIntel can be connected to an AI assistant using the Model Context Protocol, so that you can ask questions about your analytics in natural language. When you choose to do this, the answers to your questions are sent to whichever AI assistant you have connected, because that assistant is the interface you are reading them in. That assistant is operated by a separate company under its own terms and privacy policy, and your data is subject to those terms once it reaches it. We do not send your data to any AI provider except in response to a request you have made from a client you connected yourself.

2.5 Withdrawing access

You can revoke LinkIntel’s access at any time from LinkedIn’s permitted services settings, without going through us. Revoking access stops all further collection immediately. To also delete the metrics we have already stored, email us at support@getlinkintel.com and we will delete them within 30 days of your request.

3. Telling us which posts are yours

Because LinkedIn will measure a post but will not list your posts, you have to give LinkIntel that list once. There are two ways to do it, and you choose which.

3.1 The analytics file LinkedIn gives you

You can download your own creator analytics export from LinkedIn, as a spreadsheet, and give it to us on the setup page. We read it in memory, take the post identifiers, URLs and dates out of it, and register those posts so they can be measured. We do not keep the file. It is never written to disk or to our database: all we record afterwards is its name, so the setup page can tell you which file you last used. The older Shares.csv from LinkedIn’s full data archive is also accepted and is handled the same way.

3.2 A scheduling tool you already use

If you publish through Typefully or Postiz, you can connect it instead, by giving us an API key from that tool. We use the key to read the LinkedIn posts you published through it, and take the same fields: identifier, URL, date and a short excerpt. We never read anything from those tools other than your own published posts, and we never write to them.

That API key is stored, rather than hashed, because it has to be replayed against the provider each time an import runs: a key we could not read back could never be sent. It is held in a column that our own web application does not query, and that our database refuses to return to any browser session. Only our server-side service role can read it, and only immediately before an outbound call to that provider. It is never displayed back to you and never appears in a page we render.

You can remove a connected source at any time from the setup page. Disconnecting deletes the stored key. Posts already imported are left in place, because they are measurements about your own content rather than something belonging to the tool you imported them from. If you want those deleted too, ask us and we will delete them.

3.3 A webhook from any other tool

If you publish through a tool we do not integrate with directly, you can create a webhook on the setup page and point that tool at it. Each call registers the posts it describes: the LinkedIn share identifier, the URL, the date and a short excerpt, the same fields as above. The webhook secret is ours rather than a third party’s, so it is stored only as a SHA-256 hash and used solely to check that a call is genuine; it is shown to you once, when you create it. Deleting the webhook on the setup page deletes the hash and stops further calls being accepted.

4. Other information we collect

4.1 Information you provide

  • Your email address. It is the whole of your account. You sign in with a one-time link sent to it, so we hold no password for you, and we do not ask for your name.
  • Payment information. Polar acts as merchant of record and takes the payment. Your card details go to Polar and never reach us. We receive confirmation that a subscription is active, and the identifiers needed to keep it in step with your account.
  • Access credentials for connected services. Your LinkedIn authorisation token, and any API key you give us for Typefully or Postiz, as described in sections 2 and 3.
  • Correspondence. Messages you send us for support.

4.2 Information collected automatically

  • Usage data: which features are used, to understand what to improve. For MCP requests, this means the name of the tool your assistant chose, whether it succeeded, how long it took, and a small set of non-content parameters such as metric and time period. Your assistant sends your natural-language question to its own provider, not to us, so LinkIntel never receives it. We do not put tool responses, post text, post URLs, LinkedIn identifiers, API keys or access tokens into product analytics.
  • Technical data: IP address, browser and device information.
  • Error logs: diagnostic information when something fails.

5. Legal bases for processing

  • Consent: for accessing your LinkedIn analytics. You give it through LinkedIn’s authorisation screen and can withdraw it at any time.
  • Performance of a contract: to provide the service you signed up for, manage your account and take payment.
  • Legitimate interests: to keep the service secure, prevent abuse, and improve the product.
  • Legal obligation: to meet accounting, tax and other legal requirements.

6. Who we share data with

We do not sell, rent or trade personal information. We use a small number of service providers who process data on our behalf, under contract and only on our instructions:

  • Supabase, for the database and for sending your sign-in links.
  • Vercel, for application hosting.
  • Polar, for the subscription. Polar is the merchant of record and processes the card itself, so it is a controller in its own right for the payment, under its own privacy policy.
  • PostHog, for product analytics.

Beyond those, we disclose personal data only:

  • when required by law, a court order, or to establish or defend legal claims;
  • in connection with a merger, acquisition or sale of assets, with equivalent protections in place;
  • where you have asked us to.

7. Where data is stored and transferred

We run no servers of our own. Your data is held on cloud infrastructure operated by the providers listed in section 6, some of which operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK or EEA, we rely on UK International Data Transfer Agreements, standard contractual clauses, or an adequacy decision, as applicable. If you want to know the current hosting region for your data, ask us and we will tell you.

8. How long we keep it

  • LinkedIn analytics: kept while your account is active, and deleted within 30 days of you closing your account or asking us to delete it.
  • LinkedIn access tokens: deleted when you revoke access or close your account.
  • API keys for Typefully or Postiz: kept until you disconnect that source or close your account, then deleted.
  • The analytics file you give us: not kept at all. It is read once, in memory, and discarded.
  • Account and billing records: kept for as long as required by UK accounting and tax law, currently six years.
  • Error logs: kept for a short operational period and then discarded.
  • MCP tool usage: kept for 90 days, then deleted automatically.

9. Security

We take a deliberately small-surface approach to security, and describe here only what we actually do:

  • All data is encrypted in transit and at rest by our hosting providers.
  • Access tokens for the LinkedIn API are stored server-side and are never exposed to the browser.
  • The access key you use to connect LinkIntel to an AI assistant is stored only as a one-way SHA-256 hash, so it cannot be recovered from our database. You are shown it once, and you can revoke it at any time.
  • API keys for Typefully or Postiz have to be replayed against those services, so they cannot be hashed. They are stored instead in a column that only our server-side service role can read, with database access rules that refuse the request for every other role, including your own signed-in session.
  • Database access is restricted by row-level security, so one customer’s records cannot be read by another.
  • Administrative access is limited to the company’s director.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the ICO as required by law.

10. Your rights

Under UK and EU data protection law you have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive it in a portable format, and to withdraw consent where processing relies on it. Exercising these rights is free, and we will respond within one month.

To make a request, email support@getlinkintel.com.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office. We would appreciate the chance to put it right first.

11. Cookies

We use cookies to keep you signed in, to remember your preferences, to secure the sign-in process, and to measure product usage. You can control cookies through your browser, though disabling them will stop parts of the product working.

12. Children

LinkIntel is a paid product for adults. Our terms of service require you to be at least 18, and we do not knowingly collect personal data from anyone younger. If we learn that we have, we will delete it.

13. Changes to this policy

We may update this policy to reflect changes to the product, the law, or our providers. The date at the top always shows the current version, and we will tell you by email before any change that materially affects your rights takes effect.

14. Contact

  • Controller: DevRel Bridge Ltd, company number 15979110
  • Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
  • Privacy, data requests and everything else: support@getlinkintel.com

Ask

Questions about this policy?

Ask anything about what we hold, why we hold it, or how to get rid of it.

Contact us about privacy