Security

Last updated: February 17, 2026

At LinkMinds, security is foundational to everything we build. Your bookmarks, data, and privacy are our top priority. This page outlines the measures we take to keep your information safe.

1. Infrastructure & Hosting

Our infrastructure is built on industry-leading platforms:

  • Supabase: Our backend runs on Supabase with PostgreSQL databases, providing enterprise-grade reliability and security.
  • Encrypted connections: All data in transit is protected with TLS 1.2+ encryption.
  • Data at rest: All stored data is encrypted using AES-256 encryption.
  • Regular backups: Automated database backups ensure data durability and disaster recovery.

2. Authentication & Access Control

We use multiple layers to protect your account:

  • Passwordless authentication: Magic link and OTP-based login eliminates the risk of weak or reused passwords.
  • OAuth providers: Sign in securely with Google or Apple using industry-standard OAuth 2.0 protocols.
  • Session management: Secure, short-lived JWT tokens with automatic refresh ensure sessions stay protected.
  • Row Level Security (RLS): PostgreSQL RLS policies ensure that every database query is scoped to the authenticated user. Your data is never accessible to other users, even at the database level.

3. Data Isolation & Privacy

Your data is strictly isolated:

  • Per-user data isolation: Every bookmark, collection, summary, and embedding is tied to your user ID and protected by RLS policies.
  • No cross-user data access: There is no mechanism for one user to read, modify, or delete another user's data.
  • Minimal data sharing: We only send the minimum necessary data to third-party AI services for processing, and we do not store your content on third-party servers beyond what is needed for processing.

4. AI Processing Security

When we use AI to process your bookmarks:

  • Server-side only: All AI processing happens on our secure edge functions, not in your browser or on your device.
  • No training on your data: Your bookmarks and content are never used to train AI models.
  • Ephemeral processing: Content sent to AI providers is processed and discarded; it is not retained by third-party services.
  • API key protection: All API keys for third-party services are stored as encrypted secrets and are never exposed to the client.

5. Application Security

Our applications follow security best practices:

  • Input validation: All user input is validated and sanitized on both client and server sides.
  • CORS policies: Strict Cross-Origin Resource Sharing policies prevent unauthorized API access.
  • Content Security Policy: CSP headers protect against XSS and code injection attacks.
  • Dependency management: We regularly audit and update dependencies to patch known vulnerabilities.
  • No advertising trackers: We use PostHog for product analytics and error reporting inside the app, to understand which features work. We do not use advertising trackers.

6. Browser Extension Security

Our Chrome extension is built with security in mind:

  • Manifest V3: Built on Chrome's latest extension platform with improved security and privacy controls.
  • Minimal permissions: We only request the permissions strictly necessary for bookmark saving functionality.
  • No background data collection: The extension only activates when you explicitly choose to save a bookmark.

7. Payment Security

All payment processing is handled by RevenueCat and the respective app store platforms (Apple App Store, Google Play Store, Stripe). We never store credit card numbers, CVVs, or other sensitive payment information on our servers. Payment data is handled entirely by PCI DSS-compliant payment processors.

8. Data Deletion & Portability

You are always in control of your data:

  • Account deletion: You can delete your account at any time, which permanently removes all your data within 30 days.
  • Data export: Export your bookmarks and data at any time in standard formats.
  • Right to be forgotten: Upon account deletion, all personal data, bookmarks, AI-generated summaries, and embeddings are permanently removed.

9. Incident Response

In the unlikely event of a security incident, we are committed to transparency and swift action. We will notify affected users promptly, investigate the root cause, implement fixes, and publish a post-incident report. We continuously monitor our systems for anomalies and potential threats.

10. Responsible Disclosure

If you discover a security vulnerability in LinkMinds, we encourage responsible disclosure. Please report any security concerns to security@linkminds.app. We appreciate the security research community and will acknowledge valid reports.