Airlinkr
Home Terms Privacy Disclaimer Blog Open Studio →
🛡️ Zero Third-Party Data Sharing

Privacy Policy & Security Standards

At Airlinkr, we hold your trust and digital security to the highest standard. We never monetize, rent, or share your proprietary website data with third parties.

📅 Effective Date: September 29, 2026
🔒 Encryption Standard: AES-256-GCM at Rest
🛡️ Strict In-Memory Decryption for Search APIs
Table of Contents
1. Our Core Privacy Guarantee 2. Bank-Grade Encryption 3. Information We Collect 4. What We Do NOT Collect 5. How Your Data Is Used 6. Search Engine APIs & Keys 7. Storage & Data Retention 8. Right to Deletion 9. Cookies & Local Storage 10. Contact Us

1. Our Core Privacy Guarantee: No Third-Party Data Sharing

Strict Non-Sharing Commitment: We DO NOT sell, rent, license, exchange, or share your website sitemaps, articles, crawled pages, topic clusters, or search engine credentials with any third-party advertisers, data brokers, or marketing networks under any circumstance.

Your website structure, draft articles, internal link strategies, and API credentials belong exclusively to you. Airlinkr operates strictly as a private processing tool to serve your optimization and indexing needs.

2. Bank-Grade Encryption Standards (AES-256-GCM)

We adhere to uncompromising security standards to protect your sensitive service accounts, API keys, and website inventories:

🔒 AES-256-GCM at Rest All Google Cloud Service Account JSON credentials are encrypted at rest using Galois/Counter Mode authenticated encryption before touching disk or database storage.
⚡ In-Memory Decryption Only Private keys are never held unencrypted. Decryption occurs strictly in-memory right before constructing the RS256 JWT assertion to contact Google.
🛡️ Zero Wire Exposure Endpoints returning key status never transmit private keys back to the browser. Only safe verification metadata (e.g. client email) is returned.
🔑 Isolated Secret Vaults All Gemini AI, Cloudinary, Flutterwave, and Paystack master secrets are masked with bullets (••••••••) and isolated from client-facing payloads.

3. Information We Collect

To provide our SEO automation and indexing capabilities, we collect only necessary operational data:

  • Account Credentials: Email address and cryptographically salted and hashed passwords (via bcrypt). We never store plaintext passwords.
  • Sitemap & Website Inventory Data: Public URLs, page titles, meta descriptions, and page text extracted from your sitemaps. This data is used exclusively to build the semantic search graph and calculate topic clusters for your workspace.
  • Article Optimization Drafts: Text submitted to the Studio for internal linking and rephrasing. Text is processed ephemerally and saved only within your private session or domain vault.
  • Search Engine Verification Keys:
    • IndexNow Keys: Random hexadecimal tokens generated client-side to verify domain ownership with Bing and Yandex.
    • Google Cloud Service Account JSON: Encrypted credentials containing client email, project ID, and private key used solely for official Web Search Indexing API calls.
  • Payment Transaction Records: Reference IDs, timestamps, and credit amounts associated with Flutterwave or Paystack transactions.

4. What We Do NOT Collect

Zero Financial & Personal Tracking Footprint:
  • No Credit Card or Bank Account Storage: All payments are processed directly by certified PCI-DSS Level 1 payment processors (Flutterwave & Paystack). We never see or store your credit card numbers, CVVs, or bank PINs.
  • No Visitor Tracking: We do not track or collect data from visitors to your website. Airlinkr only crawls the public HTML of your URLs to discover context for internal links.
  • No Advertising Pixels: We do not deploy third-party trackers, Facebook pixels, or advertising beacons on our platform.

5. How Your Data Is Used

Your information is used strictly to fulfill core system functionality:

  1. Internal Linking Engine: Processing your article drafts against your sitemap repository to recommend contextual anchors and preserve PageRank balance.
  2. Neural AI Rephrasing: Transmitting target sentence context to Google Gemini to write natural anchor integrations that respect surrounding grammar and structure.
  3. Search Engine Dispatch: Forwarding your chosen public URLs to Google Indexing API and IndexNow endpoints at your express command.
  4. Account Administration: Managing your login sessions, credit wallet balance, and domain workspaces.

6. Search Engine APIs & Google Cloud Credentials

When you configure FastIndex Turbo Mode, you provide a Google Cloud Service Account JSON key. Here is our unequivocal promise regarding this key:

  • Sole Purpose: Your key is used solely and exclusively to request an OAuth 2.0 access token with the https://www.googleapis.com/auth/indexing scope and submit your specific URLs to Google.
  • No Broad Permissions: The Service Account requires access only to the Web Search Indexing API and does not require administrative or billing access to your Google Cloud project.
  • Immediate Removal: You can click "Remove Key" in the FastIndex modal at any time to instantly delete the key from both local memory and encrypted database storage.

7. Storage, Security & Data Retention

All platform data is hosted on secure servers with TLS 1.3 encryption in transit and AES-256 encryption at rest.

We retain your domain records, sitemap entries, and wallet transaction history as long as your account remains active. If your account remains inactive for over 12 consecutive months or upon your explicit request, all associated domain inventories and keys are permanently purged.

8. Your Rights & Permanent Data Deletion (GDPR & CCPA Compliance)

Regardless of your location, we honor universal privacy rights:

  • Right to Access: You can export your indexed pages, internal link recommendations, and articles at any time.
  • Right to Rectification: You can update or replace your sitemaps, active domains, and API keys instantly via the interface.
  • Right to Erasure (Be Forgotten): You have the right to request complete deletion of your account, website inventories, encrypted credentials, and transaction logs. Upon receiving a deletion request, all data is purged within 48 hours.

9. Cookies & Local Storage

Airlinkr uses minimal, essential client-side storage technologies:

  • Authentication Tokens: Secure JWT tokens stored in your browser session to maintain your logged-in state.
  • UI Preferences: Local storage flags to remember your theme preference (Dark or Light mode) and active domain context.
  • Zero Tracking Cookies: We do not use third-party analytics cookies or ad-tracking scripts.

10. Contact Us Regarding Privacy

If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact our team:

Airlinkr Security & Privacy Desk:
Email: obi.irozuru@gmail.com
Platform: Airlinkr — Autonomous AI SEO & FastIndex Studio
Response Time: Inquiries are addressed within 24 to 48 business hours.
Airlinkr © 2026 Airlinkr. All rights reserved.
Terms of Use Privacy Policy Disclaimer Studio