Privacy Policy

Effective 8 August 2026 · Last updated 8 August 2026
LinkEdge is operated by Osiris Tech (“we”, “us”). Osiris Tech is the Data Fiduciary for the personal data described below under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the data controller for users in the EU/UK under the GDPR.

1. The unusual part, stated first

When you upload a LinkedIn data export, most of what it contains is not about you. It is about your connections — their names, employers, job titles and profile URLs. Those people are not our users and have not agreed to anything.

We take that seriously, and it shapes every choice below: that data is used only to show you your own network, it is never sold, never pooled across accounts, never used to build a cross-user profile database, and you can erase all of it at any moment. You are responsible for uploading only your own export and using it only for your own professional networking.

2. What we collect and why

DataPurposeLawful basis
Email address, password hash (scrypt), optional display name, sign-in timestamps Create and secure your account Performance of contract
From Connections.csv: each connection's name, LinkedIn profile URL, employer, job title, connection date, and email address only where that person chose to make it visible Classify and display your own network to you Legitimate interest of the user in managing their own professional contacts
From the rest of the export: your own profile, schools and past positions Personalise the message drafts shown to you Performance of contract
Tags, notes, message drafts, outreach statuses you create Provide the outreach tracking feature Performance of contract

Uploaded files are parsed in memory and are never written to disk. Only the parsed rows are stored. We do not collect payment details, and we do not knowingly collect data from anyone under 18.

3. What we never do

4. Who else can access it

We use one processor: Railway (Google Cloud, us-west1), which provides the servers and storage the application runs on. They process data only on our instructions. We do not transfer personal data to any other third party except where required by law, and we will resist overbroad requests.

If our hosting is located outside India or the EEA, that constitutes a cross-border transfer. It is made on the basis of the provider's standard contractual clauses and equivalent safeguards.

5. How long we keep it

Your data is kept while your account is active. If an account is inactive for 12 months — no sign-in during that period — the uploaded connection data, tags, notes and outreach records are automatically and permanently deleted. This is enforced automatically by the software, not by manual review.

You may delete your data sooner at any time, and deletion is immediate rather than a soft flag. Backups, where taken, are overwritten on a rolling basis and are not used to restore deleted accounts.

6. Your rights

You have the right to access, correct, and erase your personal data, to withdraw consent, and to complain to a supervisory authority. Most of these are self-service and immediate from your Account page:

Under the DPDP Act you may also nominate another individual to exercise these rights on your behalf in the event of death or incapacity; contact us to do so.

If you are not a user of LinkEdge and believe your details appear in data someone else uploaded, write to us at the address in section 8. We will locate and delete those records. Note that we cannot identify you in our systems from an email address alone unless it appears in an upload, so please include the LinkedIn profile URL you are asking about.

7. Security

Passwords are hashed with scrypt and are never stored or logged in readable form. Session tokens are stored only as SHA-256 hashes, so a database disclosure does not yield usable sessions. Session cookies are HttpOnly, SameSite=Lax and Secure. All traffic is served over HTTPS. Sign-in attempts are rate-limited. Every database query is scoped to a single account.

No system is perfectly secure. In the event of a personal data breach we will notify the Data Protection Board of India, and affected individuals, without undue delay and within the timelines required by law.

8. Contact and grievances

Data Fiduciary: Osiris Tech
Grievance Officer: Ashish Bangar
Email: ashish.bangar.iiitm@gmail.com

We aim to acknowledge requests within 72 hours and to resolve them within 30 days. If you are unsatisfied with our response, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the EU/UK.

9. Changes to this policy

If we make a material change we will update the date at the top of this page and notify signed-in users by email before it takes effect. Continued use after that date constitutes acceptance.