Legal
Privacy Policy
Last updated August 9, 2026
What LinkedIn Voice Builder collects, why, who we share it with, and how to get it back or delete it. In short: we store what the product needs to work, we do not sell your data, and we do not train AI models on your writing.
1. Who controls your data
[Legal entity name — set NEXT_PUBLIC_COMPANY_LEGAL_NAME], [Registered address — set NEXT_PUBLIC_COMPANY_ADDRESS], is the data controller for the personal data described here. You can reach us at hello@linkedinvoicebuilder.com.
2. What we collect and why
We collect only what the product needs. Everything below is either provided by you or generated by your use of the Service.
Account
Name, email address, profile image, and — if you sign up with a password — a bcrypt hash of that password. We never store your password itself.
Why — To create and secure your account, and to contact you about the service.
Sign-in
Session records, OAuth provider identifiers and tokens (Google or LinkedIn, if you use them), and short-lived email verification and password-reset tokens.
Why — To keep you signed in and to verify it is really you.
Writing profile
Tone and voice attributes, industry, target audience, recurring topics, your sample posts, banned phrases, preferred length, and structure notes.
Why — This is the core of the product — it shapes every draft we generate for you.
Generations
The topic you submitted, the angle, the draft variants produced, which variant you selected, the research sources cited, the model used, and token counts.
Why — To show your post history, enforce plan limits, and bill accurately.
Billing
Stripe customer and subscription identifiers, subscription status, and plan. Card details go directly to Stripe and never touch our servers.
Why — To operate subscriptions and process payments.
LinkedIn (optional)
Only if you connect LinkedIn: your LinkedIn identifier, headline, industry, current role, profile URL, granted scopes, imported posts, scheduled posts, and post analytics.
Why — To personalise your writing profile and, where you schedule it, to publish on your behalf.
Usage and security
Monthly generation counts, rate-limiting counters, and an audit log of significant actions (including administrative actions taken on an account).
Why — To enforce plan limits, prevent abuse, and maintain an accountability trail.
Analytics
Page views and feature usage. Only collected through third-party analytics if you consent to analytics cookies.
Why — To understand what to fix and what to build.
We do not intentionally collect special category data (such as health, political opinions, or biometric data). Please do not put such information into your writing profile or topics.
3. Legal bases for processing
Where data protection law such as the UK/EU GDPR applies, we rely on:
- Performance of a contract — to provide the Service you signed up for: your account, writing profile, generations, and billing.
- Legitimate interests — to keep the Service secure, prevent abuse, maintain an audit trail, and improve the product. We balance these against your rights.
- Consent — for optional analytics and marketing cookies, and for connecting a LinkedIn account. You can withdraw consent at any time.
- Legal obligation — to keep financial records and respond to lawful requests.
4. AI processing and model training
To generate a draft, we send your writing profile, the topic you entered, and retrieved research context to our AI provider. This is what makes voice matching work.
- We do not use your writing profile, sample posts, topics, or generations to train any AI model.
- Our AI provider does not train its models on data submitted through its API.
- We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
- Our team does not read the contents of your generations, except where you explicitly ask us to as part of a support request, or where we must investigate a security incident or a serious policy breach.
5. Who we share data with
We share personal data only with service providers who process it on our behalf under contract, and only as needed. The current list — including what each one receives — is on our subprocessors page.
Analytics we host ourselves: Umami, self-hosted on our own infrastructure. It is cookieless, records no cross-site identifiers, and no data leaves our servers.
We may also disclose data where legally required, to enforce our terms, or as part of a merger or acquisition — in which case we will notify you and this policy will continue to apply until replaced.
6. International transfers
Some of our providers are based outside your country, including in the United States. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. Contact us for details of the safeguards for a specific transfer.
7. How long we keep it
- Account, writing profile, and generations — for as long as your account is open.
- Deleted accounts — soft-deleted immediately, then permanently erased after a 30-day grace period that lets you recover from an accidental deletion.
- Cached research results — 24 hours. These are keyed to the search query, not to you.
- Backups — retained for 30 days, after which deleted data ages out of them too.
- Audit logs and billing records — retained longer where we need them for security, accounting, or legal obligations.
8. Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access and portability — download everything we hold as JSON from your account page.
- Correction — edit your account details and writing profile directly in the product.
- Deletion — delete your account from the account page. This cascades to your writing profile, generations, and connected sign-in providers.
- Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it.
- Withdraw consent — change cookie choices any time from your cookie preferences, or disconnect LinkedIn from your profile settings.
- Complain — to your local data protection authority. In the UK that is the Information Commissioner's Office.
To exercise a right we cannot handle in-product, email hello@linkedinvoicebuilder.com. We respond within one month. We will not discriminate against you for exercising your rights.
9. Cookies
We use strictly necessary cookies to sign you in and remember your consent choices. Analytics and marketing categories are off by default until you opt in, and we honour the Sec-GPC Global Privacy Control signal. Full detail is in our Cookies Policy.
10. Security
- All traffic is encrypted in transit with TLS, and HSTS is enforced.
- Passwords are stored only as bcrypt hashes; most accounts use OAuth or email links and have no password at all.
- Access to production data is limited to personnel who need it, and privileged actions are recorded in an audit log.
- Rate limiting and standard security headers are applied across the application.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to hello@linkedinvoicebuilder.com rather than disclosing it publicly. Where a breach is likely to result in a high risk to you, we will notify you and the relevant regulator as required by law.
11. Children
The Service is not directed at anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes to this policy
We will update the date at the top of this page when this policy changes, and we will notify you of material changes by email or in the product before they take effect.
13. Contact
Questions, or want to exercise a right? Email hello@linkedinvoicebuilder.com or use our contact form.
[Legal entity name — set NEXT_PUBLIC_COMPANY_LEGAL_NAME], [Registered address — set NEXT_PUBLIC_COMPANY_ADDRESS].