1. Who we are
GetLinky ("GetLinky", "we", "us", or "our") operates the email outreach platform available at getlinky.io. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to that information.
For privacy questions or data subject requests, contact us at support@getlinky.io.
2. What GetLinky does
GetLinky is a SaaS email-outreach platform. Users connect their Gmail account via Google OAuth 2.0, then use GetLinky to compose campaigns, schedule and send outreach emails from their own Gmail inbox, and view replies and engagement analytics — all routed through their own connected account.
GetLinky does not operate its own email servers. Every email is sent through the user's own Gmail account using the Gmail API.
3. Information we collect
3a. Information you give us directly
- Account registration details: name, email address, password (stored as a secure Argon2 hash), and organisation name.
- Campaign content you create: email templates, subject lines, and lead/prospect lists you upload.
- Support communications you send to us.
3b. Google user data obtained via OAuth
When you connect a Gmail account, GetLinky requests the following Google OAuth scopes:
https://www.googleapis.com/auth/gmail.send(Sensitive) — to send outreach emails from your Gmail account on your behalf, initiated by you inside GetLinky. We never send email without your explicit action.https://www.googleapis.com/auth/gmail.readonly(Restricted) — to read campaign reply threads so that replies can be displayed inside your GetLinky Inbox. We limit read operations by querying only threads that correspond to messages sent through GetLinky (tracked by Gmail Message ID). We do not access or store any other part of your inbox.https://www.googleapis.com/auth/gmail.settings.basic(Sensitive) — for reading Gmail signature and display name, appended to outreach emails. States that no Gmail settings are modified.openid,email,profile— to identify the Google account being connected and display it inside GetLinky.
For campaign-related reply threads, the specific data we may process and store includes:
- Gmail Message ID and Thread ID (to identify and de-duplicate replies)
- Sender and recipient email addresses of the reply
- Subject line and date/time of the reply
- Message body of the reply only
- A mapping linking the reply to the relevant GetLinky campaign
We do not build contact profiles from Gmail data, index your broader inbox, or store any message content beyond the campaign-reply fields listed above. OAuth refresh and access tokens are stored encrypted at rest.
3c. Usage and technical data
- Log data: IP address, browser type, pages visited, and timestamps.
- Campaign analytics: email sends, open events, reply detection, and bounce information.
4. How we use your data
We use information solely to provide and improve the GetLinky service features visible in the app. Specifically:
- gmail.send scope: used exclusively to send the outreach emails you compose and schedule inside GetLinky, from your own Gmail address. We do not send any email without your explicit initiation.
- gmail.readonly scope: used exclusively to detect replies to campaigns you sent via GetLinky and display those replies in your GetLinky Inbox. We query only threads linked to GetLinky-sent Message IDs.
- gmail.settings.basic scope: used exclusively to read your Gmail signature and display name so that outreach emails sent via GetLinky match your standard Gmail format. We do not modify any Gmail settings.
- Account data: to authenticate you, manage your organisation, and display campaign history and analytics.
- Analytics data: to provide campaign performance metrics (sends, opens, replies) in your GetLinky dashboard.
- Log data: for security monitoring, debugging, and service reliability.
Google Limited Use: GetLinky's use of information received from Google APIs complies with the Google API Services User Data Policy, including the requirements for Limited Use. We do not use Google user data for advertising, profiling, credit assessment, or any purpose other than delivering GetLinky's core outreach features that are visible and prominent in the app interface.
5. What we do not do with your data
- We do not sell, rent, or transfer your Google user data to any third party.
- We do not use your Google user data for advertising or retargeting.
- We do not use your Google user data to train AI or machine-learning models.
- We do not allow humans to read Gmail data unless: (1) you explicitly request support and affirmatively consent to our staff viewing specific messages or threads for troubleshooting; (2) it is necessary for security purposes such as investigating abuse; or (3) it is required by applicable law.
- We do not retain your Google OAuth tokens after you disconnect your Gmail account.
- We do not access your Gmail beyond threads corresponding to campaigns sent through GetLinky. We enforce this by querying the Gmail API using only the specific Message IDs of emails sent via the platform, not by scanning your inbox broadly.
6. When we share data
We share data only in the limited circumstances below:
- Infrastructure providers: We use hosting, database, and background-job providers that process data on our behalf under strict data processing agreements. These providers do not receive Google user data beyond what is technically necessary to operate the service.
- Legal compliance: We may disclose information where required by applicable law, court order, or lawful government request.
- Business transfers: In the event of a merger, acquisition, or sale of assets, user data may transfer to the successor entity. We will notify you and obtain your explicit prior consent before any Google user data is transferred in such a scenario.
- Security: We may disclose information to investigate or prevent abuse, fraud, or threats to platform security.
In all other cases, we do not share your data with third parties without your explicit prior consent.
7. Data retention
- Account data is retained for as long as your account is active. When you delete your account, we delete or anonymise your personal data within 30 days.
- Google OAuth tokens are deleted immediately when you disconnect your Gmail account from GetLinky, or when you delete your GetLinky account.
- Gmail-derived reply metadata (message/thread IDs, reply content, and campaign mappings) is retained only while your account is active and the Gmail connection is enabled. When you disconnect Gmail, OAuth tokens are deleted immediately and all cached Gmail-derived reply metadata is deleted within 7 days.
- Campaign and analytics data is retained for the life of your account. You may request deletion at any time by contacting us.
- Log data is retained for up to 90 days for security and debugging purposes.
8. Security
We take reasonable and appropriate technical and organisational measures to protect your data, including:
- Encryption of OAuth tokens at rest.
- Encrypted HTTPS connections for all data in transit.
- Password storage using the Argon2 hashing algorithm.
- Role-based access controls limiting internal access to user data.
- Background job isolation so Gmail API calls are scoped per user account and cannot access another user's data.
No method of internet transmission or electronic storage is 100% secure. We will notify affected users promptly in the event of a data breach as required by applicable law.
9. Your rights and choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you.
- Correction: request correction of inaccurate data.
- Deletion: request deletion of your account and personal data.
- Portability: request your data in a portable format.
- Withdraw consent: disconnect your Gmail account at any time within the app (Settings → Accounts → Disconnect). You may also revoke access directly in your Google Account permissions.
To exercise any of these rights, contact us at support@getlinky.io. We will respond within 30 days.
10. Children's privacy
GetLinky is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at support@getlinky.io and we will delete it promptly.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes — particularly changes to how we use Google user data — we will notify you by email and display a prominent notice within the app before the changes take effect. We will not use your Google user data in new ways without first obtaining your consent.
12. Contact us
For questions about this Privacy Policy or to exercise your data rights:
- Email: support@getlinky.io
- Website: getlinky.io

