Privacy Policy
Last updated: August 28, 2026
LydLynk ("LydLynk", "we", "us", or "our") provides investor outreach and fundraising support services for startups and growth companies. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to lydlynk.com, related subdomains, and our application (collectively, the "Service").
1. Information we collect
- Account information — name, email address, company, role, and authentication identifiers when you sign up or log in.
- Onboarding & campaign materials — pitch deck, one-pager, company description, fundraising stage, target investor criteria, and outreach copy you submit.
- Connected account data — tokens and identifiers required to send outreach on your behalf via your connected Google (Gmail) and LinkedIn accounts.
- Outreach activity — messages sent, replies, status, timestamps, and recipient metadata used to manage your campaigns.
- Technical data — IP address, device, browser, and usage logs collected automatically for security and reliability.
2. Google API Services & Limited Use
When you connect your Google account, LydLynk requests a single Gmail scope: https://www.googleapis.com/auth/gmail.send ("Send email on your behalf"). We use this scope solely to send investor outreach messages and follow-ups that you have composed and explicitly authorized from within the LydLynk dashboard, sent from your own connected Gmail address.
In addition, we request the standard sign-in scopes openid, userinfo.email, and userinfo.profile to identify the connected Google account and display your name and email in the app.
We do not read, list, download, modify, label, archive, or delete any messages, drafts, threads, attachments, or other content in your Gmail mailbox. We do not access your inbox or sent folder. The gmail.send scope is the minimum scope required to send mail from your address on your behalf, and it is the only Gmail scope we request.
LydLynk's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we:
- Only use Google user data to provide or improve user-facing features that are prominent in LydLynk's interface.
- Do not transfer Google user data to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- Do not use Google user data for serving advertisements, including retargeted, personalized, or interest-based advertising.
- Do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in accordance with applicable privacy laws.
3. How we use information
- To provide, operate, and maintain the Service.
- To send investor outreach and follow-up messages on your behalf.
- To personalize messaging and target relevant investors.
- To communicate with you about your account, billing, and support.
- To secure the Service, prevent abuse, and meet legal obligations.
4. Sharing of information
We do not sell personal information. We share information only with:
- Service providers processing data on our behalf (hosting, database, email infrastructure, analytics, payment processing) under appropriate contractual safeguards.
- Recipients of your outreach — messages you author and authorize are delivered through your connected accounts.
- Legal & safety — when required by law, legal process, or to protect rights, property, or safety.
5. LynkBot Chrome extension & LinkedIn session data
The LynkBot Chrome extension lets LydLynk send LinkedIn connection requests and messages on your behalf as part of the outreach campaigns you configure. To do this, the extension captures a limited set of LinkedIn session data and your LydLynk account authentication token. This section explains exactly what is involved.
What we collect
When you connect LinkedIn through LynkBot, we collect the following LinkedIn session cookies: li_at, li_rm, bcookie, bscookie, liap, JSESSIONID, li_mc, and li_gc, along with your LydLynk account authentication token. We never collect or store your LinkedIn password or your LydLynk password.
Why we collect it
These session cookies let LydLynk act as the authenticated you when sending connection requests and messages on LinkedIn on your behalf, as part of the outreach campaigns you have configured in your LydLynk dashboard. Without them, LydLynk could not perform the LinkedIn outreach you authorized.
Where it is sent and stored
Session data is transmitted from the extension to LydLynk's servers over HTTPS and stored securely, associated with your client account. It is not sold. It is used only to operate the platform for you and is not shared with any third party outside of what is needed to run the Service.
Support access
Our support team may access your session data only when necessary to diagnose and resolve a technical issue you have reported. Access is limited to what is required to resolve the issue.
How to revoke access
- You can disconnect your LinkedIn session at any time from your LydLynk dashboard. This stops any further use of the stored session cookies for outreach.
- Logging out of LinkedIn, or changing your LinkedIn password, invalidates the stored session on LinkedIn's end regardless of LydLynk.
- You can request deletion of your stored session data at any time by contacting us at support@lydlynk.com.
Data retention
Session data is kept while your account is active. When your account goes inactive (for example, outreach is paused or your subscription is deactivated), the stored cookies are no longer used for outreach. If your client record is permanently deleted, your LinkedIn session data is removed automatically. You can request deletion at any time (see "How to revoke access" above).
6. Data retention
We retain account information and campaign data for as long as your account is active or as needed to provide the Service. Google tokens are retained while your account is connected and revoked upon disconnection or account deletion. You may request deletion at any time (see Section 10).
7. Security
We use industry-standard administrative, technical, and physical safeguards. Access tokens are stored encrypted at rest and transmitted over TLS. No method of transmission or storage is 100% secure.
8. International transfers
We may process data in countries other than your own. Where required, we use appropriate transfer mechanisms.
9. Your rights & choices
- Disconnect Google access at any time from your dashboard, or revoke access at myaccount.google.com/permissions.
- Access, correct, or delete your personal information by emailing us at the address below.
- Cancel your subscription at any time prior to the next billing cycle.
10. Children
The Service is not directed to children under 16.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email.
12. Contact
Questions or requests regarding this policy or your data: privacy@lydlynk.com.