At insert.link, we are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website and services, including when our services are accessed or used through third-party AI assistants and Model Context Protocol (MCP) connectors, in compliance with the General Data Protection Regulation (GDPR) and other applicable laws.

By accessing or using insert.link, you consent to the practices described in this policy. We may update this Privacy Policy from time to time. Continued use of insert.link after these updates will imply your acceptance of the changes unless legally required to obtain explicit consent.

1. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), We are the data controller of your personal information.

2. What is insert.link?

Insert.link is a platform that facilitates inserting links into existing content on websites partnered with us. The services are intended for SEO specialists and link builders working in-house or at agencies. By using insert.link, you agree to the terms and conditions specified here and in our Terms of Use. Our services may also be accessed indirectly through supported AI assistants via an MCP connector; use through such a connector is subject to this Privacy Policy in the same way as direct use of our website or API.

3. Information We Collect

We collect the following types of personal information in compliance with GDPR:

  • Personal Identification Information:
    • Name
    • Nickname
    • Email address
    • Telephone number
    • Social media profile links (e.g., Telegram, WhatsApp, Facebook)
  • Account Registration Information:
    • Email address (required)
    • Password (required)
  • Behavioral and Technical Information:
    • IP address
    • Browser type and version
    • Device type and operating system
    • Pages visited, time spent on each page, and other browsing behavior
  • AI Assistant / MCP Integration Information:
    • Requests and parameters sent to our service by an AI assistant on your behalf
    • Authentication tokens or API keys used to connect your account to the AI assistant
    • Tool call inputs and outputs (i.e., the data exchanged between the AI assistant and our servers) necessary to fulfil your request
  • Direct API Access Information (see Section 11 for details):
    • API keys and related account/project identifiers used to authenticate API requests
    • Request parameters and payloads you or your systems send to our API
    • Request metadata such as timestamp, IP address, and endpoint called 

We may also collect aggregate information such as site visit frequency or page popularity, anonymously, to better understand user behavior and improve services.

4. Legal Basis for Processing

We collect and process personal data on the following legal grounds, as permitted by GDPR:

  • Consent – You have provided explicit consent for the processing of your personal data for one or more specific purposes.
  • Contract – Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract.
  • Legitimate Interests – Processing is necessary for the purposes of the legitimate interests pursued by insert.link, such as improving our services, marketing, and ensuring security.
  • Legal Obligation – Processing is necessary for compliance with a legal obligation to which insert.link is subject.

5. Why We Collect Information

Insert.link collects and processes personal information for the following purposes:

  • To provide relevant services and fulfill contractual obligations.
  • To personalize and enhance your platform experience.
  • To generate statistical reports for market research and analysis.
  • To process transactions and provide customer support.
  • To communicate updates, services, and offers (you may opt out of marketing communications).
  • To improve the platform’s functionality, security, and usability.
  • To conduct anonymized market research and analysis.
  • To enable and support the use of our services through connected AI assistants (MCP connectors), including authenticating requests and returning the results of tool calls.
  • To authenticate and process requests made directly through our API, and to maintain the security, rate-limiting, and reliability of the API. 

If the purposes of data processing change, we will notify you and request your consent if required.

6. Sharing Your Information

We do not sell or rent your personal information. However, we may share your data with third-party service providers to support the platform, including:

  • Service Providers – Google Tag Manager, Google Search Console, Google Analytics, Hotjar, Facebook (via pixel), Reddit (via pixel), and payment processors. These providers may access and process data based on their own privacy policies.
  • AI Assistant Platforms – When you choose to use our services through a supported AI assistant (e.g., Claude by Anthropic) via an MCP connector, the data necessary to process your request is transmitted through that platform’s infrastructure. We only send the data required to fulfil the specific request; we do not grant the AI platform standing access to your full account data.
  • International Transfers – Your personal information may be processed in non-EU countries, such as the USA or Ukraine. When transferring data outside the European Economic Area (EEA), we ensure it is adequately protected by using standard contractual clauses approved by the European Commission, or through other lawful transfer mechanisms.
  • Your Own Integrators – If you use our API to build your own product or workflow, and you in turn share data collected through that product with your own users or customers, you act as the data controller for that downstream sharing, and this Privacy Policy does not extend to it. You are responsible for your own privacy disclosures to your end users 

In addition, we may disclose your personal information to comply with legal obligations or respond to government authorities.

7. Data Retention

We will retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including providing our services, complying with legal obligations, resolving disputes, and enforcing our agreements. In particular:

  • Account and profile data is retained for as long as your account remains active, and deleted within 30 days of account closure, unless a longer period is required by law.
  • Server, API, and MCP tool-call logs (including requests routed through connected AI assistants) are retained for up to 90 days for security, debugging, and abuse-prevention purposes, after which they are deleted or anonymized.
  • Billing records are retained for the period required by applicable tax and accounting law.

If you request the deletion of your account, we will terminate the processing of your personal data, unless legal obligations require otherwise.

8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of Access – You have the right to request access to the personal data we hold about you, along with information about how we use it.
  • Right to Rectification – You have the right to request that we correct inaccurate or incomplete personal data.
  • Right to Erasure (“Right to be Forgotten”) – You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected or where you have withdrawn consent.
  • Right to Restrict Processing – You have the right to request a restriction on the processing of your data in certain circumstances, such as if you contest the accuracy of the data.
  • Right to Data Portability – You have the right to request that your personal data be provided to you in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
  • Right to Object – You have the right to object to the processing of your personal data, including for direct marketing purposes.
  • Right to Withdraw Consent – You have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to Lodge a Complaint – You have the right to lodge a complaint with a supervisory authority if you believe that we are processing your personal data in violation of the GDPR.

To exercise these rights, please contact us at [email protected].

9. Security of Your Information

We take appropriate technical and organizational measures to ensure the security of your data, protecting it from unauthorized access, loss, or damage. This includes encrypting data in transit using TLS and encrypting sensitive data at rest, restricting access to personal data on a need-to-know basis, and applying the same safeguards to data exchanged through connected AI assistants (MCP connectors) as to data submitted directly through our website or API. However, no method of transmission over the Internet or electronic storage is 100% secure, so we cannot guarantee absolute security.

10. AI Assistant (MCP) Integration

This section applies when our services are accessed through a Model Context Protocol (MCP) connector inside a supported AI assistant, such as Claude by Anthropic. It supplements the rest of this Privacy Policy – Sections 4, 7, 8, and 9 apply to this type of use in the same way as to direct use of our website or API.

10.1 Information We Receive

When you initiate an action through our MCP connector, the AI assistant transmits to us:

Request Parameters – the information needed to perform the action you asked for, such as the link or content data to be processed.

Authentication Credential – the credential issued when you connected your insert.link account.

Technical Metadata – limited request information such as timestamp and IP address.

We do not receive or retain your conversation history, chat transcripts, stored memory, or any other content from your session with the AI assistant — only the inputs necessary to execute the specific tool call you initiated.

10.2 Why We Process This Information

We process this information only to authenticate your request, execute the requested action and return the result to the AI assistant, and maintain the security and reliability of our services. The first two purposes rely on Contract as the legal basis, the third on Legitimate Interests, as described in Section 4.

We do not use this information for advertising or marketing, and we do not use it to train or develop artificial intelligence or machine learning models.

10.3 Storage and Retention

This information is stored on the infrastructure described in Section 9 and protected by the measures set out in that section. Authentication credentials are stored in encrypted form. Records of tool-call requests and responses are kept in our server logs for the period stated in Section 7, after which they are deleted or anonymized.

10.4 Sharing With the AI Assistant Provider

As described in Section 6, the provider of the AI assistant acts as the transmission channel between you and our services and processes data under its own privacy policy and terms, which we do not control. We disclose to the provider only what is necessary to return the result of your request. Connecting the connector does not give the provider general or ongoing access to your account data.

10.5 Your Choices

You can disconnect the MCP connector at any time. Disconnection revokes the associated credential immediately and prevents further access to your insert.link account through that channel. The rights described in Section 8 apply to information processed under this section, including deletion of MCP-related log records, subject to the retention periods in Section 7.

11. Direct API Access

This section applies when you or your systems access insert.link directly through our API, rather than through the website or an AI assistant connector. It supplements the rest of this Privacy Policy – Sections 4, 7, 8, and 9 apply to this type of use in the same way as to other forms of access.

11.1 Information We Receive

When you make a request to our API, you or your systems transmit to us:

  • API Key – the credential issued to your account or project that authenticates the request.
  • Request Parameters and Payloads – the data needed to perform the requested action, such as the link or content data to be processed.
  • Technical Metadata – request information such as timestamp, IP address, and the endpoint called.

11.2 Why We Process This Information

We process this information to authenticate the request, execute the requested action and return a response, enforce rate limits and usage quotas, and maintain the security and reliability of the API. The first two purposes rely on Contract as the legal basis, the remaining purposes on Legitimate Interests, as described in Section 4.

11.3 Storage and Retention

This information is stored on the infrastructure described in Section 9 and protected by the measures set out in that section. API keys are stored in encrypted or hashed form. Records of API requests and responses are kept in our server logs for the period stated in Section 7, after which they are deleted or anonymized.

11.4 Sharing

We do not share data submitted through the API with third parties except as described in Section 6 (service providers, legal compliance, or where you have configured your own integration to send data elsewhere). If you integrate our API into your own product and share resulting data with your end users, Section 6 (“Your Own Integrators”) applies to that sharing, not this Privacy Policy.

11.5 Your Choices

You can revoke or rotate an API key at any time from your account settings; revocation takes effect immediately and prevents further use of that key. The rights described in Section 8 apply to information processed under this section, including deletion of API log records, subject to the retention periods in Section 7 

12. Cookies

Cookies are small text files that enhance your experience on insert.link. They are used to track user behavior, tailor content, and help us understand how visitors use the website.

For more information, please refer to our Cookies Policy.

13. Third-Party Links and Services

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We recommend reviewing the privacy policies of any third-party sites you visit.

14. Age Restrictions

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we discover that we have collected personal data from a minor, we will take steps to delete it.

15. International Data Transfers

By using insert.link, you consent to the transfer and processing of your data outside your country of residence, including to countries where data protection laws may differ from those in your country. However, we ensure that appropriate safeguards, such as standard contractual clauses, are in place to protect your data.

16. Changes to This Privacy Policy

We may revise this Privacy Policy from time to time. We will notify you of any significant changes through your account or email. By continuing to use insert.link after being notified, you accept the changes.

17. Contact Us

For any questions regarding this Privacy Policy or to exercise your rights, please contact us at:

Email:[email protected]

Your Insert.link team.