Privacy, plainly explained.
This page describes the beta at linksave.app, hosted on an OVHcloud server. Downloads are prepared on that server; QR codes are generated in your browser.
Links and temporary files
When you choose Download, LinkSave receives the submitted post link and contacts the source platform and its media servers. Those services receive our server’s network address and request details. Opening an original post yourself contacts the platform directly.
Media, temporary request files and ZIP archives are held in server memory, without swap to disk. The request file is removed after preparation ends. Prepared files remain available for 15 minutes, with cleanup after active transfers finish. They are lost when the server restarts and are excluded from disk backups. Files that you save to your device stay there until you remove them.
QR codes for original posts
Create QR generates PNG and SVG in your browser. This action does not send the destination to our download server, the source platform or an external QR service. Anyone with the code can read its destination. Scanning it opens the original post under the source platform’s access rules.
LinkSave does not count scans, operate a redirect or make private posts public. Saved QR images do not expire with prepared media files.
Clipboard and accounts
Clipboard access happens only when you choose Paste and your browser permits it. You can also paste directly. LinkSave does not request social passwords or import signed-in browser cookies. A source may issue anonymous cookies used in memory for one preparation.
Visitors do not need an account. Administration is restricted to a private SSH connection and requires a password. The admin uses an essential HttpOnly, SameSite session cookie, lasting up to eight hours and cleared server-side on backend restart.
Aggregate analytics
The browser sends page views, Save clicks, QR creations and QR export clicks to this server. Events contain a page name, platform, file-format label and broad browser, device and traffic-source categories. They do not contain the QR destination, clipboard, full referrer or a visitor identifier. There is no analytics cookie, fingerprint, scan counter or unique-user estimate.
Aggregate counts are retained for up to 397 days. Geographic reporting is not configured. Google Analytics, Meta Pixel and advertising scripts are not enabled, and submitted links are not sent to an advertising service.
Processed-link history
The owner can retain the cleaned source link, platform, time, result, file metadata, preparation duration and error category for troubleshooting. Tracking query parameters are removed; usernames that are part of a source address can remain. The history is not linked to visitor addresses. Creating a QR alone does not add its destination to this history.
History is kept for seven days by default, with a maximum of 10,000 records. The owner can choose 30 days or disable and delete it. Expired records are cleaned about once a minute while the service runs and on startup. Aggregate counts remain separate. Server disk backups can retain earlier database snapshots under the hosting provider’s backup cycle.
Network protection and monitoring
Your IP address necessarily reaches our HTTPS server. The download API uses it temporarily in memory to limit repeated requests and simultaneous work. Request-rate records expire after two minutes of inactivity; jobs and transfers retain a keyed identifier until they end. People sharing an address can share a limit.
Application access logs are disabled. Seven-day operational counters contain totals and error categories, without source links, visitor IP addresses, post IDs or titles. System and certificate-management logs are size-limited and retained for up to seven days; the hosting provider may independently process infrastructure and security information.
Contact and email correspondence
For support or a question about how your data is handled, email hello@linksave.app.
If you email us, your email address, message and any attachments are processed through OVHcloud Zimbra and your email provider. Correspondence is separate from download history: the 15-minute media expiry and seven-day history cleanup do not delete emails.
The operator’s identification is still being completed for this beta.
Updated September 6, 2026.