LinkGuardian
Privacy Policy
LinkGuardian analyses URLs to protect you from phishing, malicious redirects, and privacy-invading trackers. This policy explains exactly what data is processed when you scan a link, and how we protect your privacy.
1. Who We Are
LinkGuardian is developed and maintained by Cyber Analyst Academy, an independent cybersecurity education platform.
2. What Data We Process and Why
LinkGuardian's core function is URL analysis. The table below describes every category of data involved:
| Data Type | Purpose | Storage Location | Retention |
|---|---|---|---|
| URL submitted for analysis | Threat lookup against safe-browsing databases | Not stored — analysed in transit and discarded | None (transient only) |
| Analysis result (safe / suspicious / malicious) | Shown to you, optionally saved to history | On-device only (never our servers) | Until you clear history or delete app |
| App preferences (theme, default actions) | Personalised experience | On-device only (iOS UserDefaults) | Until you reset or delete app |
| Aggregate, anonymous error logs | App stability and crash detection | Apple's crash reporting (anonymous) | Per Apple's data retention policy |
We do not collect: name, email, device identifier, advertising ID (IDFA), precise location, contacts, photos, or any other personal data.
3. How URL Analysis Works
When you submit a URL for analysis, LinkGuardian performs the following steps:
- Domain extraction: The domain (e.g.,
example.com) is extracted from the URL locally on your device. - Hash-based lookup: The domain is hashed (SHA-256) and the first portion of the hash (a prefix) is sent to our threat intelligence lookup service. This is the same privacy-preserving technique used by Google Safe Browsing — the full domain is never transmitted.
- Result returned: Matching hash entries are returned to the app and evaluated locally. We do not receive which specific URL you checked.
- No log of your query: No IP address, timestamp, or URL is stored on our servers in association with any lookup request.
4. Third-Party Threat Intelligence Services
LinkGuardian uses the following third-party services to perform URL safety checks:
- Google Safe Browsing API (hash-prefix protocol): Queries use hash prefixes only — Google does not receive the full URL. Governed by Google's Privacy Policy.
- PhishTank community database: Checks the URL domain against the PhishTank open-source phishing database. Lookups are anonymous. Governed by PhishTank's Privacy Policy.
These services may receive: a hash prefix of the domain you submit. They do not receive your identity, full URL, or device identifiers from LinkGuardian.
5. Tracker Detection (On-Device)
LinkGuardian's tracker-stripping feature analyses URL query parameters (e.g., utm_source, fbclid) entirely on-device using a locally bundled tracker database. No URL or parameter data is transmitted to any server for this feature. The cleaned URL is returned to you without logging.
6. iOS Share Sheet Integration
When you use the iOS Share Sheet to send a URL to LinkGuardian, the URL is processed within the app's sandboxed extension. No data leaves this sandbox except for the hash-prefix lookup described in Section 3. The source app that shared the URL is not recorded.
7. Permissions Requested
- Network access: Required to perform hash-prefix threat lookups (Section 3). The app makes no other outbound requests.
- No camera, microphone, location, or contacts access.
- No advertising identifier (IDFA) access. LinkGuardian does not serve ads and does not participate in ad networks.
8. Your Link History
If you enable Link History in settings, previously scanned URLs and their results are saved locally to your device using iOS Core Data. This data:
- Never leaves your device
- Is protected by your device's lock screen encryption
- Can be deleted at any time from Settings → LinkGuardian → Clear History
- Is not backed up to iCloud unless you have enabled iCloud backup for app data in iOS Settings
9. Children's Privacy
LinkGuardian is not directed at children under 13. We do not knowingly collect personal data from children. Because we collect no personal identifiers from any user, no special risk exists for minors.
10. International Users and GDPR
LinkGuardian is available globally. For users in the European Economic Area (EEA):
- Our legal basis for processing URL hash-prefix lookups is legitimate interest — providing the threat detection service you explicitly requested.
- Because we do not retain personal data linked to you, there is no data subject access request (DSAR) to fulfil. We can confirm in writing that no data linked to you is held.
- You have the right to object to processing at any time by not using the URL analysis feature or by deleting the app.
11. Security
All network communications between LinkGuardian and threat intelligence services use TLS 1.3 encryption. On-device data is protected by iOS sandboxing and device encryption. We do not operate servers that store user data, so there is no server-side database to breach.
12. Changes to This Policy
If we materially change how LinkGuardian processes data — for example, by adding a new feature that requires additional lookups — we will:
- Update this page with a new effective date
- Display an in-app notice before the change takes effect
- Publish release notes in the App Store describing the change
We will never apply a more permissive data use policy retroactively.
<