Privacy Updated 1 October 2026

Privacy policy

LinkJar saves your links in your own AT Protocol account. Private links are encrypted on your device before they leave it. This page explains what LinkJar handles, when and why, and what you control.

The short version

  • Public links are public. Public links, boards, comments, reactions and follows are records on the open AT Protocol network. Anyone can read them, including other apps.
  • Private links are encrypted on your device. Their addresses, titles, notes and tags are encrypted before upload. Your settings, reading progress and highlights are always encrypted. LinkJar and your account host store this data but cannot read it.
  • Some features send data when you use them. Link previews, snapshots and AI features send a link or article text to a LinkJar service. For private links, these features are off by default or ask each time. On iPhone, some of them start on; see Features that use our servers.
  • No ads, no selling. We don't sell personal data, show ads, or track you across other apps and websites.
  • Limited analytics. The web app and website use analytics that never include your links. The browser extension and the iPhone and Mac apps have none.
  1. Who runs LinkJar
  2. Your account
  3. Public and private links
  4. Your Private Jar keys
  5. Features that use our servers
  6. Sync and notifications
  7. The public index
  8. LinkJar accounts
  9. Website and waitlist
  10. Analytics
  11. Data on your devices
  12. Service providers
  13. How long we keep data
  14. Your choices and rights
  15. Changes and contact

Who runs LinkJar

LinkJar is operated by Uros Karic, Mise Vujica 1, Belgrade, Serbia, the controller of the personal data described here. Email hello@linkjar.io with any privacy question or request.

Your account

LinkJar runs on AT Protocol, the open network that Bluesky also uses. Your links are records in your AT Protocol account, also called your repository. An account host stores it:

When an app uses a LinkJar service, your host issues it a short-lived token that proves which account is asking. The token identifies your account by its DID, the permanent identifier every AT Protocol account has.

Public and private links

Public

A public link's address, title, note, tags and summary are published with your account, as are public boards and their items, comments, reactions and follows. Anyone can read them. Other services on the network, such as relays and apps, can keep copies. When you delete a public record, it leaves your repository and LinkJar's index; we can't remove copies that others hold.

Private

For a private link, the address, title, note, tags and boards are encrypted on your device. Settings, reading progress, highlights and saved summaries are always encrypted, whatever the link's visibility. Snapshots (offline copies of articles) are encrypted before upload.

Encryption doesn't hide everything. For private records, your host and the network can still see when each record was created, its approximate size, that it is private, how many images a snapshot has and their sizes, and a keyed marker that shows whether two of your private links point to the same address. Encrypted records travel through the network like public ones, so others can hold copies of the encrypted data.

Your Private Jar keys

Features that use our servers

These features send data to a LinkJar service when you use them. The service uses it for that one request unless the table says otherwise. Where a feature would send a private link's content, it is off by default or asks you first, except where the iPhone row says otherwise.

FeatureWhat is sentDefaultKept
Link previews (web app) The link's address. Our server loads the page to read its title, description and image, so the website sees a request from LinkJar. Public links: on. Private links: off, or ask for each link. The preview, by address, for up to 1 hour.
Link previews (iPhone) Nothing to LinkJar. Your phone loads the page and its images directly. On, including Previews for private links. On your phone.
Snapshots The browser extension copies the page you have open, with no server involved. The web app can ask our server to load the page; the server sees the article text while it prepares the copy. Your device then encrypts the copy and stores it in your repository. Private links: asks every time. On iPhone, your phone loads pages itself, and Snapshot when saving and Snapshot for Read Later are on. Not on our servers.
AI suggestions (tags, summary, board) Title, description, site and language. For public links, also the address. Processed by Cloudflare Workers AI (currently Llama 3.3). Off. For private links, asks every time. Public-link results for 30 days, without your identity. Private: not kept. A count of your requests, for usage limits.
Cloud summaries The article's title and text, up to about 48 KB per request. Processed by Cloudflare Workers AI (currently Mistral Small 3.1), with request logging off. Off. Asks for each article. Not kept. A count of your requests, for usage limits.

Some features stay on your device. Summaries from Apple Intelligence on iPhone and Mac run locally, as does the Labs search feature. Some features download files when you ask: the listening voice pack (about 116 MB) and the Labs search model come from Hugging Face, which sees your IP address.

Images and site icons shown with your saved links load directly from the websites that host them, so those websites see your IP address.

Sync and notifications

The public index

LinkJar's index (indexer.linkjar.io) reads public LinkJar records from the network. It powers Following, Discover, public jar pages, people search, comments and notifications. It stores public links (address, title, note, site, tags and summary), boards, follows, comments and reactions, the notifications derived from them, and a cache of account handles. It never stores private records.

Your notifications are visible only to you: the index answers only the account they belong to. When you delete a public record or make it private, we remove it from the index. When your host reports that your account was deleted, suspended or deactivated, we remove what it published. If anything remains, email us and we'll remove it. The index also checks whether saved public links still load, which contacts those websites.

LinkJar accounts

LinkJar accounts open during the private alpha. This section describes how they work; we'll update it if anything changes when they open. When you create a LinkJar account on our account server (pds.linkjar.social), we store:

Sign-up is protected by hCaptcha, which receives your IP address and browser details. We send account emails through Cloudflare Email Service, from accounts@linkjar.io. From the day accounts open, backups of account databases are kept for 7 days, and daily snapshots of encryption keys and server configuration for 30 days.

You can manage or delete your account on your account page (in Settings, open Sign-in methods), or email us. Deleting the account removes your repository from our server. Public records that others copied before you deleted them remain with them.

Website and waitlist

Analytics

We use PostHog, hosted in the EU, to understand how LinkJar is used.

Data on your devices

Service providers

We share data only as this policy describes, with these providers:

We don't sell personal data or share it for advertising. We disclose data when the law requires it.

How long we keep data

DataKept
Link previewsUp to 1 hour
AI results for public links30 days
Live sync bufferUntil your last device disconnects
iPhone push registrationUntil you sign out or turn notifications off
Sent web reminders7 days
Public index entriesUntil you delete the record, make it private or ask us to remove it
LinkJar accountUntil you delete it
LinkJar account backupsDatabases 7 days; key and configuration snapshots 30 days (from the day accounts open)
Waitlist entryUntil you ask us to delete it
Waitlist sign-up limit (hashed IP and hour)Until the next sign-up after that hour
Service logsShort-term operational logs with event names; some error logs include a DID

Your choices and rights

Changes and contact

When this policy changes, we update the date at the top. We announce significant changes in the app or by email. Questions and requests: hello@linkjar.io.