Lifetime launch - 23 of 100 spots at $99 · $149Claim your spot

Legal

Privacy Policy

Last updated September 2026

This Privacy Policy explains what personal data Link in Seconds collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. We have written it in plain language and kept every claim honest to how the product actually works. If something here is unclear, please write to us at support@linkinseconds.com.

This document is also the notice we are required to give you under Section 5 of the Digital Personal Data Protection Act, 2023 (India). Together with our Terms and Acceptable Use Policy, it forms the privacy policy required under Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Who runs Link in Seconds

Link in Seconds (linkinseconds.com) is operated by Radadiya Sunny Keshavbhai (Sole Proprietorship), GSTIN 24CADPR8542K2ZA, with its principal place of business at Bhaktinandan, Sector 4, S G Road, Mota Varachha, Surat, Gujarat 394101, India. For all data-protection matters, Radadiya Sunny Keshavbhai is the data fiduciary (under the DPDP Act) and the data controller (under the GDPR and UK GDPR). We are established in India and process the data of visitors in the EEA and UK under the extraterritorial scope of Article 3(2) of the GDPR / UK GDPR.

Contact: support@linkinseconds.com · +91 99090 97776. Our Grievance Officer is named in the Grievance Redressal page and again at the end of this policy.

What we collect

We keep data collection to what the service actually needs. We collect:

  • Your account email. When you sign in with Google (OAuth), we receive and store the email address associated with your Google account. We use it to create and authenticate your account and to send you service-related email.
  • Your files and links. The files you upload, and the public links and metadata you create from them (title, slug, view counts, settings such as password protection or expiry).
  • Link view analytics. When someone opens one of your public links, we record a SHA-256 hashed version of the visitor IP address (we never store the raw IP), the browser user-agent, and the referrer. This lets us show you view counts without keeping identifiable visitor addresses.
  • Abuse reports. If someone uses the Report button on a public page, we store the reason, any details provided, a hashed IP and the user-agent of the reporter (again, the reporter's raw IP is never stored).
  • Product analytics and session insights. We use Google Analytics 4 and Microsoft Clarity to understand how the site is used. Clarity records anonymised session replay and heatmaps (mouse movement, scrolling and clicks) so we can find and fix usability problems. It is still session recording, so it runs only with consent where consent is required. Sensitive on-screen text such as email addresses and filenames is masked before it leaves your browser.
  • Advertising. Some pages show Google AdSense ads, which use advertising cookies (including DoubleClick). See Cookies and consent below.
  • Billing details. If you buy Pro, our payments provider (Dodo Payments) handles the transaction. We receive your subscription status; we never see or store your full card details.

Why we process your data (lawful basis)

We only process personal data for the purpose we collected it for. Under the DPDP Act our basis is your consent for that specific purpose (Section 6) or a legitimate use (Section 7); under the GDPR the corresponding bases are in Article 6:

  • Account and sign-in (email): your consent / performance of the service you asked for.
  • Storing and serving your files and links: performance of the service you requested.
  • Hashed-IP view analytics, security, fraud prevention and content-safety review: our legitimate interest in running a safe, reliable service (balanced against your rights).
  • Non-essential cookies (analytics, session replay, ads): your consent, where consent is required.
  • Tax and financial records, and reporting unlawful content to authorities: compliance with a legal obligation.

Consent given for one purpose is not reused for another. You can withdraw consent at any time (see Your rights), and withdrawing it is as easy as giving it.

Automated content safety (please read)

To keep the service safe and lawful, files are scanned for unsafe content at the time you upload them. This means the content of your upload is transmitted to third-party content-safety providers, all located in the United States, solely so they can return an automated safety score:

  • OpenAI Moderation API receives extracted text (up to roughly the first 20,000 characters from documents, HTML and sites) and images.
  • Google Cloud Vision (SafeSearch) receives image bytes.
  • AWS Rekognition receives image bytes.
  • For video, we sample individual frames (using ffmpeg) and send those frames to the providers above as images.

This transmission happens on upload even though our moderation currently runs in shadow mode: it scans and logs results for review, and does not automatically block content today. Because these providers receive the content, they can technically read it. They receive it only to score its safety. Our scanning is a best-effort safety measure and is not a warranty that all content is lawful, and we do not pre-approve or exercise editorial control over user uploads.

We never train AI on your files. We do not use your uploaded files to train, fine-tune or improve any artificial-intelligence or machine-learning model, and the content-safety providers process your content solely to return a score for that upload. This is described further in our Terms and Child Safety Policy.

Who we share data with (sub-processors)

We do not sell your personal data. We share it only with the service providers below, each for the specific role described. Several are outside India (see International transfers).

  • Cloudflare R2 (United States / global): stores the raw file bytes in a private bucket, served through a signed same-origin proxy. Some older files are stored on Supabase Storage.
  • Supabase (United States / global): Postgres database (accounts, links, metadata) and authentication.
  • Dodo Payments (Merchant of Record): billing and payment processing. We never see or store full card details.
  • Resend: transactional and digest/reminder email.
  • Google Analytics 4, Microsoft Clarity and Google AdSense: product analytics, session insights and advertising.
  • OpenAI, Google Cloud Vision and AWS Rekognition (all United States): receive uploaded text, images and sampled video frames solely to return an automated content-safety score, as described above.

We may also disclose data where required by law, a court order, or a lawful request from an authorised government agency (see Legal requests).

Where data is stored and international transfers

Our infrastructure and providers are located outside India, mainly in the United States and other regions. Your files (Cloudflare R2, Supabase Storage), your account and link data (Supabase), your email delivery (Resend), analytics (Google, Microsoft) and content-safety scoring (OpenAI, Google Cloud Vision, AWS Rekognition) are all processed on that global infrastructure. We do not claim that your data stays in India, because it does not.

Under Section 16 of the DPDP Act, personal data may be transferred outside India except to countries restricted by the Central Government (no such restriction has been notified as of the date of this policy). For visitors in the EEA and UK, transfers of personal data and content to US-based providers are made under Standard Contractual Clauses and/or the providers' EU-US Data Privacy Framework certification (and its UK Extension), together with supplementary safeguards.

How long we keep data (retention)

  • Free links: a 5-day renewable TTL. A free link expires 5 days after it was last renewed unless you renew it or upgrade to Pro.
  • Pro links: kept until you delete them. Pro links do not expire on a timer.
  • Account data (your email and account): kept while your account exists, and deleted on request (see below). We retain user registration information for 180 days after cancellation where required by Rule 3(1)(g) of the IT Rules, 2021.
  • Hashed-IP analytics and abuse reports: kept for a limited period (generally up to 24 months) for security, abuse-handling and product analytics.
  • Financial and tax records: retained for as long as required by Indian tax law, handled by Dodo Payments as our Merchant of Record.
  • Reports of child sexual abuse material: preserved as required by law (see our Child Safety Policy).

Under Section 8(7) of the DPDP Act we erase personal data once the purpose is no longer served or when you withdraw consent, unless we are required by law to keep it.

Your rights

Under the DPDP Act, 2023 you (as a Data Principal) have the right to:

  • Access a summary of the personal data we hold about you and how we process it (Section 11).
  • Correct, complete, update and erase your personal data (Section 12).
  • Grievance redressal: raise a complaint with us (Section 13); see the Grievance Officer below.
  • Nominate another individual to exercise your rights in the event of your death or incapacity (Section 14).

For visitors in the EEA and UK, under the GDPR / UK GDPR you also have the rights of access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent, and the right to lodge a complaint with your local supervisory authority (your EU Data Protection Authority, or the UK ICO). We aim to respond to rights requests within one month.

To exercise any of these rights, email support@linkinseconds.com. You can also make a complaint to the Data Protection Board of India.

Your controls in the product

You are in control of your content and account:

  • Delete a project. You can delete any file and its link from your dashboard at any time.
  • Delete your account. Request account deletion by emailing support@linkinseconds.com. We will remove your account and associated data, subject to the retention periods required by law.

Cookies and consent

Cookies fall into two groups:

  • Essential cookies keep you signed in and keep the site working. These are always on.
  • Non-essential cookies power Google Analytics 4, Microsoft Clarity session replay and heatmaps, and Google AdSense / DoubleClick advertising.

For visitors in the EEA, UK and Switzerland, non-essential cookies are set only after you opt in through our cookie banner, and we honour Google Consent Mode v2 with signals defaulting to denied until you consent. You can change or withdraw your consent at any time. Microsoft Clarity records anonymised sessions with sensitive fields masked, but it is still session recording and runs only with consent where consent is required.

You can control ad personalisation in your Google Ad Settings and opt out of third-party advertising cookies at aboutads.info.

Security and what encryption we actually use

We protect your data with sensible technical measures, and we want to be honest about the limits:

  • Uploads and downloads are encrypted in transit (TLS).
  • Files are stored in a private bucket and served only through short-lived signed links, so there are no public raw storage URLs.
  • Visitor IP addresses are stored only as a SHA-256 hash, never in raw form.

Stored files are not end-to-end encrypted and not zero-knowledge. We, and our content-safety providers, can technically access file content. Please do not assume an uploaded file is unreadable to us. The one exception is our peer-to-peer Direct Send feature, which transfers files directly between devices, encrypted device-to-device, with nothing stored on our servers.

Public links are public. Anyone who has the URL can view the file, and no login is required to view it. Please do not upload sensitive or confidential personal information to a public link.

Children

You must be at least 18 years old to create an account or upload content. This service is not directed to, and is not intended for use by, children (persons under 18). Consistent with COPPA in the United States, it is also not directed to children under 13. We do not knowingly collect the personal data of children. If we become aware that we have collected a child's data without verifiable parental or guardian consent, we will delete it. We do not run behavioural tracking or targeted advertising directed at children.

Data breach notification

If a personal data breach occurs, we will notify each affected Data Principal and the Data Protection Board of India without undue delay, with the particulars required under the DPDP Act and its rules. Where applicable, we also meet our reporting duties to CERT-In under the directions issued on 28 April 2022, including reporting certain cyber incidents within six (6) hours of becoming aware of them and retaining logs as required. If you believe your data may have been affected, contact us at support@linkinseconds.com.

Legal requests and content safety

On receipt of a lawful order, we provide information or assistance to an authorised government agency as early as possible and in any event within seventy-two (72) hours, as required under Rule 3(1)(j) of the IT Rules, 2021. We remove or disable access to content on a valid court order or government notification within the timelines described in our Grievance Redressal page. Copyright complaints are handled through our copyright takedown channel, and child-safety matters through our Child Safety Policy.

Grievance Officer and contact

Grievance Officer: Radadiya Sunny Keshavbhai.

The Grievance Officer will acknowledge your complaint within twenty-four (24) hours and resolve it within fifteen (15) days of receipt, in accordance with Rule 3(2)(a) of the IT Rules, 2021. For the full grievance procedure, including timelines for non-consensual intimate imagery and appeals to the Grievance Appellate Committee, see our Grievance Redressal page.

Radadiya Sunny Keshavbhai · Sole Proprietorship · GSTIN 24CADPR8542K2ZA · Contact us.