Privacy Policy
Last updated: July 12, 2026
LincSpider (https://lincspider.kwverdit.com) is a link-building assistant delivered as a Chrome extension and web account. This policy explains what data we collect, how we use it, and what control you have. It applies to the extension, our API, and the website.
What LincSpider does
LincSpider helps you discover backlink opportunities, generate AI-suggested comment and outreach email drafts, and optionally prefill comment forms on pages you choose. It does not auto-post comments, auto-send emails, or browse the web outside tasks you start.
Chrome extension permissions
The extension requests only the permissions needed for the features above:
- storage — save your settings, task checkpoints, recent task history (up to 10 entries), guest preview state, and sign-in session data locally in Chrome.
- tabs — open target pages during a task, switch to a page when you choose to review or prefill, and close background tabs created for processing.
- scripting — during user-started tasks, read Google SERP pages and target pages (title, URL, visible text, public contact emails on the page, comment-form fields) to assess fit, generate drafts, and prefill forms you approve. A lightweight content script is registered so the background worker can request this data on demand; it stays idle until messaged.
- alarms — resume paused tasks at the time you configure (for example after a cooldown or when you return).
- identity — sign in with Google through a secure OAuth flow tied to your LincSpider account.
- host_permissions (<all_urls>) — open and process pages only while you run a task or guest preview against blogs, SERP results, or URLs you provide. A passive content script may load to enable on-demand communication during those pages. We do not read unrelated browsing activity.
Account and billing data
- Email address and authentication identifiers from Google sign-in (stored via Supabase Auth).
- Credit balance, subscription status, and credit transaction history on our servers.
- Payment and invoice metadata from Creem (we do not store full card numbers).
- Task session metadata sent to our API: target URLs, page titles, outreach settings you enter, AI step types, credit usage per step, and generated draft text needed for billing and task recovery.
- Guest preview (no sign-in required): a random install ID stored locally, a preview session ID, and page excerpts (URL, title, visible text) sent to our API for AI draft generation and server-side rate limiting.
Data stored locally in your browser
The extension keeps configuration, a random install ID for guest preview limits, up to 10 recent tasks (including guest previews), pause checkpoints, page-analysis cache for in-progress work, outreach-domain cache, and a cached credit balance for faster UI updates. This data stays on your device unless you start a signed-in task that syncs metadata to our API.
AI processing
When you run a signed-in task or guest preview, page excerpts (URL, title, and relevant visible text; and public contact emails on the page when suggesting outreach) are sent to our API and forwarded to DeepSeek for inference. Guest preview sends an install ID and preview session ID for abuse prevention. We use results to suggest comments or outreach emails and to deduct credits for successful AI steps when signed in. Cached AI outputs may be reused within the same task to save credits. Server-side task content used for inference is deleted after the task completes, per our retention rules.
Website analytics
The marketing site (https://lincspider.kwverdit.com) uses Google Analytics 4 and Microsoft Clarity in production to understand traffic and improve the site. The Chrome extension does not include these analytics SDKs.
What we do not do
- We do not sell your personal data.
- We do not auto-submit comments or send emails on your behalf.
- We do not collect passwords for third-party blogs or email providers.
- We do not read or transmit page content except when you run a signed-in task or guest preview. A passive content script may load in the browser to enable on-demand communication during those tasks.
- We do not use your target URLs, competitor lists, or outreach targets for cross-user analytics, ad targeting, or resale to third parties.
- We do not embed website analytics or ad-tracking SDKs (such as GA or Clarity) in the Chrome extension.
Retention and deletion
Account and billing records are kept while your account is active and as required for payments and support. You may sign out in the extension at any time. To request account or data deletion, email us at support@kwverdit.com.
Third-party services
- Supabase — authentication and account database.
- Creem — subscription and one-time credit pack payments.
- DeepSeek — AI inference for drafts and page analysis.
- Google — OAuth sign-in and (on the website) analytics.
- Microsoft Clarity — website session analytics (production site only).
- Vercel — hosting for the website and API infrastructure.
Your choices
You can use guest preview (up to 3 drafts) without signing in. Signed-in features require Google authentication. You control whether to copy, edit, prefill, or publish any suggested content.
Changes to this policy
We may update this policy when our product or legal requirements change. The date at the top will be revised accordingly.
Contact
support@kwverdit.com