Legal

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: June 4, 2026

Privacy First: We respect your privacy and are committed to protecting your personal data. We do not sell your information to third parties, period.

1. Introduction

Welcome to Upvote.link ("we," "our," or "us"). This privacy policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services. By using Upvote.link, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, username, and password when you create an account
  • Profile Information: Optional avatar, bio, and other profile details
  • Content: URLs you share, comments you post, and upvotes you give
  • Communications: Messages you send to us or other users

2.2 Information Collected Automatically

  • Usage Data: Pages visited, links clicked, time spent on site, referral sources
  • Device Information: IP address, browser type, operating system, device identifiers
  • Cookies: Session cookies for authentication and preferences (see Section 5)
  • Analytics: We use Middleware.io for performance monitoring and error tracking

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: Providing and maintaining our platform functionality
  • Account Management: Creating and managing your user account
  • Content Processing: Processing your shares, comments, upvotes, and engagement
  • Gamification: Calculating points, credits, streak rewards, and leaderboard rankings
  • User Statistics: Displaying public leaderboards and aggregate statistics
  • Notifications: Sending important account-related notifications and updates
  • Improvement: Analyzing usage patterns to improve our services and user experience
  • Security: Detecting and preventing spam, abuse, fraud, and security issues
  • Legal Compliance: Complying with legal obligations and responding to lawful requests

4. Information Sharing and Disclosure

We do not sell your personal information. We may share information in the following limited circumstances:

  • Public Content: Your username, shared URLs, comments, and upvotes are publicly visible to other users. This is core to our service functionality.
  • Service Providers: We use trusted third-party services:
    • Cloudflare (CDN and DDoS protection)
    • Middleware.io (Performance monitoring and error tracking)
    • Hosting providers for infrastructure
  • Legal Requirements: When required by law, court order, subpoena, or government regulation
  • Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets (you will be notified)
  • Safety and Security: To protect our rights, users' safety, investigate fraud, or enforce our Terms of Service
  • With Your Consent: Any other disclosure will be made with your explicit consent

5. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience:

  • Essential Cookies: Required for session management, authentication, and security (cannot be disabled)
  • Functional Cookies: Remember your preferences, settings, and previous actions
  • Analytics Cookies: Help us understand how you use our site through Middleware.io RUM (Real User Monitoring)

Cookie Control: You can control cookies through your browser settings. However, disabling essential cookies may limit site functionality and prevent you from logging in.

For more details, see our Cookie Policy.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: HTTPS/TLS encryption for all connections and data transmission
  • Password Security: Passwords are hashed using secure algorithms (bcrypt/Argon2)
  • CSRF Protection: Cross-Site Request Forgery protection on all forms
  • SQL Injection Prevention: Prepared statements and parameterized queries
  • Rate Limiting: Protection against brute force attacks and abuse
  • Regular Updates: Security patches and monitoring for vulnerabilities
  • Access Controls: Limited employee access to personal data on a need-to-know basis

Important: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

7. Your Privacy Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data we hold
  • Correction: Update inaccurate or incomplete information in your profile
  • Deletion: Request deletion of your account and associated data (see Data Retention)
  • Objection: Object to certain data processing activities
  • Portability: Receive your data in a structured, machine-readable format (JSON/CSV)
  • Withdrawal of Consent: Withdraw consent for optional data processing at any time

How to Exercise Your Rights: Contact us at [email protected] with your request. We will respond within 30 days.

8. Data Retention

We retain your data for the following periods:

  • Active Accounts: Data retained as long as your account remains active
  • Deleted Accounts: Personal data anonymized within 30 days of deletion request
  • Public Content: Shared URLs and comments remain publicly visible but are anonymized (username changed to "Deleted User") after account deletion
  • Server Logs: Access logs and error logs retained for 90 days for security and debugging
  • Database Backups: Automated backups retained for 7 days (may contain deleted data during retention period)
  • Legal Holds: Data may be retained longer if required for legal proceedings or compliance

9. Children's Privacy

Upvote.link is not intended for users under 13 years of age (16 in the EU). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected]. We will take steps to delete such information promptly.

10. Third-Party Links

Our platform contains user-shared links to external websites and services. We are not responsible for the privacy practices, content, or security of these third-party sites. We encourage you to review the privacy policies of any external sites you visit. Clicking on external links is at your own risk.

11. International Users and Data Transfers

Our services are hosted in the United States. If you access Upvote.link from outside the US, your information will be transferred to, stored, and processed in the United States, which may have different data protection laws than your country of residence.

EU Users: By using our services, you consent to the transfer of your data to the United States. We implement appropriate safeguards for international data transfers.

12. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request disclosure of data collection and sharing practices
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: We do not sell personal information, so no opt-out is necessary
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise these rights, email [email protected] with "CCPA Request" in the subject line.

13. GDPR Compliance (EU Users)

For users in the European Union, we comply with the General Data Protection Regulation (GDPR):

  • Legal Basis for Processing: Consent, contract performance, legitimate interests, legal compliance
  • Data Protection Officer: For GDPR inquiries, contact [email protected]
  • Right to Lodge a Complaint: You may file a complaint with your local data protection authority

14. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Post a notice on our homepage for 30 days
  • Send an email notification to registered users (for significant changes)

Your continued use of our services after changes are posted constitutes acceptance of the updated policy. We encourage you to review this policy periodically.

15. Contact Us

If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

We aim to respond to all privacy inquiries within 30 days.