linkport
How it worksHumans and agentsTerminalPricingDocs
Sign in Get a link

Privacy

What linkport stores, and why.

This service gets access to machines people care about. The least it owes you is a plain list of what it keeps.

Last updated 29 August 2026

Who operates this service

The service at https://linkport.cloud is operated under the brand linkport. For anything on this page, write to [email protected] or [email protected].

What we collect

When you create an account:

  • Your email address, and a hash of your password (argon2id — we never store the password).
  • Whether the address is confirmed. Confirmation and password-reset messages are sent to that address when mail is configured.
  • If you enable two-factor authentication, your TOTP secret.
  • API tokens you create, stored as hashes.
  • If you sign the desktop terminal in, a device-authorization request (a short code and its outcome) is stored for ten minutes. The session token the app then receives is the same kind as the cabinet session; we do not keep a second copy of it on the server beyond the ordinary session store.

When you connect a machine, the agent reports:

  • Its hostname, operating system, kernel version and architecture.
  • The public IP address it connects from.
  • The local addresses you chose to publish, and the links issued for them.
  • Bytes transferred, for usage metering.

When a link is used:

  • The time, the link, and the IP address of whoever opened it, in the audit log.
  • If you switched session recording on for that machine, either the command lines entered or a full terminal recording as an asciinema cast. This is off by default and it is per-machine — you decide, and the setting is visible in the dashboard.

When you pay for a plan:

  • The plan, period, USD amount, Heleket invoice id and order id, and payment status.
  • We send Heleket your email so they can show it on the invoice (payer_email). We do not receive your wallet keys or seed phrases.

What passes through us but is not stored

Tunnel traffic is relayed, not retained. By default the edge terminates TLS, which means that in principle it can see the contents of a session — that is the same place the command policy and the recorder run, and we would rather state it than imply otherwise. If you enable end-to-end encryption on a machine, the key is generated there and never leaves it, and the tunnel payload is opaque to us; in that mode the browser terminal and the HTTP proxy are switched off. Note that MCP commands and file transfers still cross the edge in the clear even then, because they ride the agent control channel rather than the tunnel.

Why we keep it

To run your account and your tunnels, to take payment, to enforce plan limits, to give you an audit trail of who reached your machines, and to investigate abuse of the service. We do not sell any of it, we do not use it to train anything, and we do not share it with advertisers.

How long

  • Account data: until you delete your account.
  • Machines, links and their settings: until you delete them.
  • Audit log entries: until you delete the account.
  • Session recordings: until you delete them, or the machine they belong to.
  • Traffic counters: aggregated per month.
  • Payment records: kept with the account so we can see what was paid and until when; they go when the account is deleted, unless we must retain a row to resolve a charge dispute.

Deleting your account removes the above. Write to [email protected] and we will confirm when it is done.

Who else touches it

  • The hosting provider that runs the servers for this hosted instance.
  • Heleket, which handles cryptocurrency checkout. They receive the amount, currency, order id, return URLs and your email. They do not get your machines, links or session recordings. Their privacy policy applies to that checkout.
  • Postal, when transactional mail is enabled, to send confirmation and password-reset messages.
  • Google and Apple, if you choose to sign in with them. They see that you are signing into this service and may share a verified email address.
  • Cloudflare Turnstile, when the operator enables it on sign-in, registration and password-reset request. Cloudflare then receives the challenge token and the visitor IP; it does not get your password. Their privacy policy applies to that check.
  • There is no analytics vendor, no ad network and no third-party session replay.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it, by writing to [email protected]. If you are in the EU or the UK, you also have the right to complain to your data protection authority.

Cookies

The site sets no tracking cookies. Signing in stores a session token in your browser so that you stay signed in; that is functional and there is no way to use the dashboard without it.

Changes

If this page changes in a way that matters, we will say so on the site rather than quietly editing the date.

linkport

Secure access to machines behind NAT, through one link. SSH, TCP, UDP and HTTP, for people and for agents.

Product

  • How it works
  • Humans and agents
  • Desktop terminal
  • Pricing

Build

  • Documentation
  • MCP server
  • Security model
  • FAQ

Account

  • Sign in
  • Create an account
  • Dashboard

Legal

  • Public offer
  • Privacy
  • Security
  • [email protected]
  • Report a vulnerability
© 2026 linkport Beta · [email protected]