Privacy
Last updated October 2026
This describes what Ferret Media does with data in Linker. It is written to be checkable: almost everything below is a consequence of how the product is built rather than a promise about how we behave.
Public pages set no cookies
A Linker page — linker.cool/@someone — contains no JavaScript, no cookies, no local storage and no third-party resources. There is nothing in the page capable of tracking a visitor, which is why there is no consent banner on one.
What we count, and how
Page views are recorded on our servers as the page is rendered, not by anything running in your browser. For each view we store a count, and derive an identifier so the same person is not counted twice in a day.
That identifier is deliberately built so it cannot become a history:
- It is a 128-bit HMAC of the current day, the page's account identifier, the IP address and the user agent. The IP address itself is not stored — only the hash it contributed to.
- The day is part of the message, so the same visitor produces a different identifier tomorrow. Two days of records cannot be joined into a profile.
- The page's account is part of it too, so someone who visits two Linker pages appears as two unrelated identifiers.
- Referrers are reduced to a hostname before storage. Paths are discarded.
Alongside each view we keep a few coarse totals, each one a count per page per day rather than a record of a visit: the visitor's country (as our hosting provider reports it), the kind of device, browser and operating system (read roughly from the user agent), and a campaign tag if the page address carried one, such as ?ref= orutm_source. None of these is joined to the identifier above.
What we count when a link is pressed
Each link on a page carries a standard HTML ping attribute. When a visitor presses one, their browser follows the link as normal and separately tells us which link it was. The link itself is not routed through us, so the address a visitor copies and the site they arrive at are exactly what the page's owner put there.
For a press we store a count per link per day, with the link's label so the owner can still recognise it after renaming or deleting it. We do not store the visitor's IP address or any identifier for them. Some browsers and privacy tools turn pings off, and nothing is counted for those visitors.
Requests we believe came from bots and link-preview fetchers are discarded rather than counted, for both views and presses.
Your links are not in our database
Links, and the profile and theme attached to them, are stored as records in your own atproto repository — the same repository your Bluesky posts live in. Linker reads them to render your page. They are public by the nature of the protocol, they remain yours, and if you stop using Linker they are unaffected.
What we do store
- Your account. Authentication is handled by Clerk, which holds your email address and sign-in credentials on our behalf.
- Your connection to an atproto account, so we know whose repository to read.
- A claimed short name, if you have one, and which account it points at.
- Subscription status, which comes from our payment provider. We never see your card details.
- Aggregate view and click counts, as described above.
Accounts on our own server
If you open an atproto account hosted by Linker, we run the server that holds that repository — your posts, your records and your blobs. It is a standard atproto Personal Data Server, and the account can be migrated away to another provider, at which point we no longer hold it.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete your account. Deleting your Linker account does not delete your atproto repository, because that was never ours — if it is hosted elsewhere it is untouched, and if it is hosted by us you can migrate it away first.
Write to hello@linker.cool and we will answer.