Linkloom is operated by Timothy Crabtree, doing business as Paleonyx ("Paleonyx," "we," "us"). This policy explains what information Linkloom collects, why, and what you can do about it.
Account information. Your email address and a hashed version of your password (we never store your password itself - it's run through PBKDF2 and only the hash is kept). If you sign in with Google instead, we receive your email address and Google account ID, nothing else.
Content you create. Notes, tasks, links, tags, attachments, and the connections you draw between them on the board. This is the core of the service - we store it so you can access it, and we don't read it beyond what's needed to run the app or respond to a support request you send us.
Optional Google Calendar access. If you connect Google Calendar, we request access to create, update, and delete calendar events so we can sync tasks with due dates. We don't request access to your other calendars or non-task-related events, and disconnecting revokes this access immediately.
Optional AI features. AI features are off by default. If you turn on on-device AI, nothing leaves your browser. If you turn on cloud AI, the specific note, task, or item you tap "suggest" or "parse" on is sent to Google's Gemini API using your own API key, which we store so you don't have to re-enter it. Content is only sent when you actively trigger a suggestion - not automatically or in the background.
Technical data. We log IP addresses briefly for rate limiting and bot protection on sign-up and sign-in - this is used to prevent abuse, not to track you, and isn't linked to your account or content. We use one HttpOnly session cookie to keep you signed in; we don't use advertising or third-party tracking cookies today.
We don't sell your data. A few outside services help us run Linkloom, and each only sees what it needs to do its job:
If a page you capture has a URL, we fetch that page's own metadata (title, preview image) to build your capture - the site you're capturing from may see that request, the same as if you'd visited it yourself.
Linkloom is not directed at children under 13, and we don't knowingly collect information from anyone under 13. If you believe a child has created an account, contact us and we'll remove it.
Passwords are hashed, not stored in plain text. Sessions use HttpOnly cookies. We follow standard practices for a service this size, but no method of storage or transmission is perfectly secure, and we can't guarantee absolute security.
If we make material changes, we'll update the date at the top of this page. Continued use of Linkloom after a change means you accept the update.
Questions about this policy or your data: support@paleonyx.com.