Privacy Policy (Datenschutzerklärung)

Last Updated: December 2, 2025

1. Data Controller

Responsible for data processing on this website and application within the meaning of the General Data Protection Regulation (GDPR) is:

Nderim Topalli

Falterer Berg 32

84307 Eggenfelden, Germany

Email: support@linkedmemo.com

2. What Data We Collect

We collect data to provide the LinkedMemo service:

  • Identity Data: Email address, name, and profile picture (via Clerk).
  • Content Data: The text of notes you write, the LinkedIn Profile IDs you associate them with, and tags.
  • Usage Data: Logs of when you log in, feature usage, and subscription status.
  • Technical Data: IP address, browser type (via PostHog/Supabase).

3. How We Process Your Data (The Tech Stack)

We use third-party processors to provide the service. We have concluded Data Processing Agreements (DPA / AV-Vertrag) with these providers where necessary.

3.1 Hosting & Database (Supabase)

Our database and backend are hosted by Supabase Inc. We have selected the EU (Frankfurt, Germany) region for our database. This ensures your primary data (notes) resides within the European Union. Download DPA.

3.2 Authentication (Clerk)

We use Clerk (Clerk, Inc., USA) for user management. When you sign up, your email and identity data are processed by Clerk in the USA. Clerk operates under standard contractual clauses to ensure GDPR compliance.

3.3 Payments (Stripe)

For Pro subscriptions, payment data is processed directly by Stripe (Stripe Payments Europe, Ltd.). We do not store your credit card details. We only store a Customer ID and Subscription Status. Download DPA.

3.4 Artificial Intelligence (OpenRouter)

If you use AI features (e.g., "Auto-Tagging"), the text content of your specific note is sent to OpenRouter (and its underlying models, e.g., OpenAI or Google).

  • Privacy Guard: We do not send your entire database. Only the specific text you are analyzing is transmitted.
  • No Training: We utilize APIs that generally do not use your data for model training, but we recommend not putting highly sensitive personal secrets (e.g., health data) into the AI analysis fields.

3.5 Analytics (PostHog)

We use PostHog to understand how users interact with our app. PostHog captures usage data (e.g., "User created a note"). We have configured PostHog to anonymize IP addresses where possible.

4. Chrome Extension Permissions

The LinkedMemo Chrome Extension requires specific permissions:

  • activeTab or Host Permissions for linkedin.com: This is strictly required to display the sidebar overlay on LinkedIn. We do not read your LinkedIn messages, browse history, or other tabs.

5. Cookies

  • Essential Cookies: Required for Clerk authentication (to keep you logged in).
  • Analytics Cookies: Used by PostHog. You have the right to opt-out of these via our Cookie Banner settings.

6. Your Rights (GDPR)

You have the right to:

  • Access: Request a copy of the data we store about you.
  • Rectification: Correct wrong data.
  • Deletion: Request the deletion of your account and all associated notes ("Right to be Forgotten"). You can usually do this directly inside the App settings.
  • Data Portability: Export your notes (we provide a CSV/JSON export feature).

To exercise these rights, please contact us at the email provided in Section 1.