Privacy Policy
What stays on your device, what reaches our servers, who else touches it, and how to have it deleted.
What this policy covers
Linsa is a messenger with a built-in assistant, team Spaces, agents and a wallet. This policy covers the Linsa app for iOS, currently distributed through TestFlight, and this website.
Linsa is in external testing. This document describes how the product works today. When the product changes, this page changes with it.
What we do not do
These are not promises about the future. They are statements about the build you can install today, and they are verifiable: the app ships an Apple privacy manifest that declares no tracking at all.
- We do not track you across other companies’ apps or websites.
- We do not embed advertising, attribution, crash-reporting or analytics SDKs. There are none in the app.
- We do not ask for the advertising identifier and we do not show ads.
- We do not sell your data and we do not share it for anyone else’s marketing.
- We do not build a profile of you for targeting.
What stays on your device
Linsa is built local-first. Your chats, notes, tasks and files are written to your device first and work with no connection. Servers exist to synchronize your devices with each other and to hold an encrypted copy so that reinstalling the app does not mean starting over.
- Your device key is generated on the device and stays there. We never receive it.
- Your 12-word recovery phrase is shown to you once and never leaves the device. We do not store it and cannot restore it for you.
- Face ID and Touch ID are handled by iOS. The app is told yes or no; your biometric data never reaches us.
- Diagnostic timings the app measures for itself (how long a screen took to draw, how long a query ran) stay on the device and are not transmitted.
What we collect, and why
Everything below leaves the device because the messenger cannot work otherwise: a message has to reach the person you sent it to. All of it is tied to your account, all of it is used to run the product, and none of it is used for tracking.
- Email address. Sign-up and sign-in are an email plus a six-digit code, or Sign in with Apple. We store it to identify the account.
- Name and handle. Your first and last name and your public username, shown to the people you talk to.
- Account identifier. The account’s internal identifier, which every synchronized record is keyed by. No device identifier is collected.
- Messages. Message bodies are synchronized so they reach the recipient and survive a reinstall.
- Photos and videos. Image and video attachments and your avatar.
- Other content you create. Notes and their attachments, tasks, non-media files, and your profile bio.
- Activity signals. Presence, last seen and read state. What other people can see is controlled by you in the app’s settings. This is not analytics: we run none.
Calls
Voice and video calls run through LiveKit, a media server we operate. Call audio and video are relayed between participants in real time and are not recorded and not stored. Because nothing is kept, call media is deliberately absent from the list above.
Lin, the assistant
Lin answers, summarizes and drafts using Anthropic’s Claude models, with a fallback provider when the primary one is unavailable. That means the material you hand to Lin is sent to that provider to produce an answer.
- Lin reads only what your own permissions already allow. It does not gain access to chats, Spaces or files that you cannot open yourself.
- What goes to the model is what a request needs: your prompt and the context you pointed it at. Your whole archive is not uploaded.
- We do not use your content to train models, and we do not permit our providers to train on it.
Agents
An agent you create or install acts inside the permissions you grant it, and never beyond them. Permissions are confirmed explicitly, agent actions are written to an audit log you can read, and revoking a permission takes effect immediately. An agent published to the marketplace by someone else runs under the same rules.
Who else touches your data
The list is short on purpose. There is no advertising network, no data broker and no analytics vendor on it.
- Our own servers. Edge servers close to users and a global core that reconciles regions. We run them ourselves, so we control where data physically sits.
- Jazz. The local-first synchronization engine and its sync server, which holds the encrypted replica of your data.
- LiveKit. Real-time relay for calls. Nothing is stored there.
- Anthropic, and a fallback model provider. Only what you send to Lin, and only when you send it.
- Apple. TestFlight delivers the app; Sign in with Apple is optional; push notifications travel through Apple’s notification service.
We may also disclose data when the law requires it. If that ever happens and we are allowed to tell you, we will.
Device permissions the app asks for
- Photo library. To attach an image or a video, and to set an avatar. The picker runs inside the app; nothing is read without you choosing it.
- Camera. To shoot a photo or a video for a chat, and for video calls.
- Microphone. For voice messages and calls.
- Notifications. To tell you about a new message. You can decline and keep using the app.
How long we keep it, and how to have it deleted
We keep account data for as long as the account exists, because the product needs it to work. Deleting a message or a note deletes it from your devices and from the synchronized copy.
To delete the whole account and everything listed above, write to hello@linsa.io from the address the account is registered to. We will delete it and confirm when it is done. During the testing period this is the deletion path; an in-app control is coming before the public release.
Deleted data can persist for a short time in server backups until those backups rotate out. It is not used for anything in the meantime.
How we protect it
- Traffic between the app and our servers is encrypted in transit.
- The synchronized replica of your data is stored encrypted.
- The device key never leaves the device, and confirmations can be gated behind Face ID or Touch ID.
- Chats can hold optional encrypted regions for the parts that need them.
- Account and agent actions are written to audit logs.
What we will not claim: Linsa is not end-to-end encrypted across the board today. Encryption is applied where it is described above, and we would rather say that plainly than write a sentence that sounds stronger than the product is.
Children
Linsa is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to hello@linsa.io and we will remove it.
This website
This site is a set of static files. It sets no cookies, runs no analytics, loads no fonts, scripts or images from anyone else’s domain, and carries no tracking pixels. Our hosting provider keeps ordinary server logs, which include the requesting address, for security and diagnostics.
Changes to this policy
When the product changes in a way that changes this document, we update this page. If a change materially affects what we collect or who we send it to, we will say so in the app rather than quietly editing the text.
Contact
Questions about privacy, requests for deletion, or a report of something that looks wrong: hello@linsa.io.