Privacy Policy
Linqyou · last updated 2026-09-04
Linqyou (“Linqyou”, “we”), [registered legal entity name and address — to be added once Linqyou completes business registration], provides LinkedIn analytics software for individuals and workspaces. This policy explains what personal data we process, why, on what legal basis, and what rights you have — under the EU General Data Protection Regulation (GDPR) and equivalent laws.
If you are an organization or agency customer — a workspace that tracks LinkedIn profiles belonging to people other than you — you and Linqyou typically act as independent controllers or as controller and processor for different parts of the data (see our Data Processing Agreement). This policy describes our practices as a controller for your own account data, and as a processor for the LinkedIn data you upload on behalf of the individuals it describes.
What we collect
Account data. Name, email, and billing details you provide when signing up, plus usage data needed to operate the service (login timestamps, plan tier, support requests).
LinkedIn export data. When you upload a LinkedIn data export, we parse a defined allowlist of files from it. We deliberately ingest only what the analytics require.
We parse, at most:
- Profile, positions, skills, education, certifications, languages
- Connections (company, role, and connection date only — see below)
- Posts you shared, and reactions, comments, and poll votes you gave. Comment text you wrote is stored with an opaque post id, never another member’s name or profile URL.
- Invitations sent and received, endorsements given and received
- LinkedIn’s own inferred credibility scores and ad-targeting categories about you
- The separate LinkedIn analytics export (impressions, engagement, follower and audience demographic data), if you provide it
We never open, parse, or store the following files, even though LinkedIn’s export includes them: your private messages, login and security-challenge history, phone numbers, email address book, and job-application screening answers. This exclusion is enforced in the software itself — these files are never read from the archive, not merely hidden from your view.
Connections are pseudonymised at the point of import. We store a one-way cryptographic hash of each connection’s profile identifier, plus their company and role, so we can compute network statistics (growth, industry mix, seniority mix). We do not store connection names, emails, or profile URLs in reversible form.
Why we process it, and on what basis
- To provide the service (Art. 6(1)(b) — performance of a contract): parsing your export, computing metrics, generating insights, running the AI chat feature.
- To bill you (Art. 6(1)(b) and (c)): processing payments and applicable tax via Stripe.
- Free-plan data exchange. Before a Free account can run its first analysis, we present a separate agreement explaining that benchmark-safe derived metrics will contribute to sector comparisons and generalized product guidance. This is a condition of that Free plan, not a hidden default. Ending it stops new Free-plan use; it never removes statutory privacy rights.
- Paid-plan benchmarking and product improvement (Art. 6(1)(f) — legitimate interests): we may use benchmark-safe derived metrics and non-reconstructive patterns to improve comparisons and generalized guidance. Paid users can object in the Privacy Centre without losing paid service access. We document and periodically review this balancing assessment.
- Retained analysis from unfinished sign-ups (Art. 6(1)(f) — legitimate interests): you can upload an export and see your analysis before creating an account. If you never confirm your email address, we erase the uploaded archive and the identifiers — your name, profile URL, contact email and the session token that could have reached the session — and keep the de-identified analysis computed from it for benchmarks, generalized guidance and product improvement. This is stated on the screen immediately before any file is uploaded, not discovered afterwards. Because nothing identifying is retained, we cannot look up such an analysis by name; if you want it excluded, tell us within the seven-day window and we will delete it outright.
- Security and abuse prevention (Art. 6(1)(f) — legitimate interest): rate limiting, fraud detection.
Data classes, anonymisation and generalized patterns
We distinguish raw uploads and original post content; user-specific metrics, reports, graphs and AI narratives; benchmark-safe derived features; and irreversibly anonymous cohort statistics. Replacing a name with a hash is pseudonymisation, not anonymisation. User-specific material remains personal data until it has passed our documented anonymisation controls.
Raw posts may be analysed to derive features, but are not placed directly in benchmark tables, sold as a standalone dataset, or reproduced in generalized tips. Numeric cohort results require at least 20 workspaces and 100 profiles, contribution caps, coarse cohort labels and suppression of extremes. Text-derived guidance requires at least 50 profiles, uses normalized features rather than source text, and is blocked if it overlaps source wording.
How AI is involved
See our dedicated AI Transparency Notice. In summary: an AI model is used to write plain-language interpretation of numbers that are always calculated by ordinary software first, never to calculate the numbers themselves. Written interpretation is not yet enabled in the product; when it is, it will run only on infrastructure that is EU-hosted under a zero-data-retention commitment — that is a requirement we build to, not a feature we’ll relax to launch sooner.
Retention
Account and analytics data is retained for as long as your account is active. If you delete your account or a subject workspace, it is soft-deleted immediately (hidden, no longer accessible) and permanently erased — including the underlying uploaded files in storage — 30 days later, except for de-identified aggregate statistics that can no longer be traced back to you. An erasure request under Art. 17 is honoured in full: we do not keep a de-identified per-person analysis of an account that asked to be deleted.
Uploads made before signing up. If you run the pre-signup flow and never confirm your email, the session becomes unclaimable after seven days. At that point we permanently delete the uploaded archive from storage, and erase your name, profile URL, contact email, the raw text and links of your posts, the LinkedIn identifiers of posts you engaged with, and the pseudonymous identifiers of your connections. What we keep is the derived analysis: metrics, insights, demographics, and non-reversible features such as topic and format labels, company, role and seniority mix. We describe that result as de-identified rather than anonymous, and treat it accordingly: it is not published, not sold, and not linked back to a person. It is retained indefinitely for benchmarks and product improvement.
Sessions abandoned before any upload. If you leave before giving us a LinkedIn profile, we keep only the shape of the visit — account type, the goals you picked, and how far you got. That record contains no name, email, profile URL, IP address or token.
Who we share data with
See our Sub-processors page for the complete, current list and what each one does. We do not sell identifiable personal data, and we do not share it with any party for their own marketing purposes.
If Linqyou is sold, merged, financed, or reorganized, active account data may transfer to a successor that continues the service, subject to this policy and applicable rights. Irreversibly anonymous statistics, generalized patterns, software, and methodology may transfer as company assets. This is not a sale of personal data to a data broker.
Your rights
Under GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for processing based on consent (such as benchmark participation). You can exercise most of these directly from your account’s privacy settings, or by contacting us at privacy@linqyou.com. We respond within one month of a verified request, extendable by a further two months for complex requests, in which case we will tell you why within the first month.
You also have the right to lodge a complaint with your local data protection authority. If you are in the Netherlands, that is the Autoriteit Persoonsgegevens; if you are elsewhere in the EU, your national equivalent.
International transfers
Our primary infrastructure is hosted in the EU. Where a sub-processor operates outside the EU (see the sub-processors list), we rely on the European Commission’s Standard Contractual Clauses or an equivalent adequacy mechanism.
Contact
General questions: support@linqyou.com. Data protection requests and rights exercises: privacy@linqyou.com.