Back to Home

Privacy Policy

Relinq is a Metedata product designed to limit the data it handles. This policy explains what Relinq and third-party providers or recipients process when you use the Mac app, iOS app and Share extension, including TestFlight builds, matching service, and website. Platform-specific features and recipients are identified below.

Relinq's Matching Service

Relinq 1.3 restored music-link conversion by routing preview and conversion requests through Relinq's matching service instead of placing the upstream Songlink/Odesli credential in the app. This proxy protects that credential, preserves existing license and trial state, and lets successful public music mappings be reused during upstream outages. No Relinq account is required. The service processes and retains only the categories described below; it does not intentionally retain raw IP addresses, raw license keys, or access tokens.

Data Relinq Processes

Relinq processes supported music URLs, the requested destination service, a two-letter country code used for catalog matching, and technical records needed to provide previews and conversions, count the five-conversion trial, validate Mac licenses and iOS subscriptions, prevent duplicate charges against the trial, enforce rate limits, and protect the service. Relinq also uses installation, conversion, entitlement and subscription records to produce the first-party usage statistics described below.

The app creates a random installation identifier and stores it, along with its Relinq access token, in the platform Keychain. On iOS, the app and Share extension use a shared Keychain access group; the item also contains the recorded free-use count and, when applicable, an access-refresh credential. The matching service stores a keyed one-way fingerprint of the installation identifier and one-way hashes of access and refresh tokens, rather than the raw values. These records are pseudonymous, not anonymous: an installation can be linked to its conversions and purchase entitlement.

Cloudflare provides the connecting IP address to Relinq at the network edge. Relinq's application code uses the full IPv4 address (a /32) or truncates an IPv6 address to its /64 network prefix, then transiently derives a keyed one-way fingerprint for abuse controls. Relinq stores the fingerprint—not the raw address—in its D1 database and Durable Object quota records. Cloudflare still processes IP addresses and other request metadata while routing, securing, and logging requests under its privacy policy.

Clipboard Access

On Mac, Relinq checks the clipboard for supported music links while clipboard monitoring is enabled. On iOS, you can use Paste or share a link from another app; you can also opt in to checking clipboard text when Relinq opens. iOS may ask for paste permission. When automatic checks are off, the iOS app can ask the system whether the clipboard appears to contain a URL without reading its text, to offer a paste hint. Link detection happens locally on your device. Clipboard contents are:

  • Ignored unless they match a supported music URL pattern
  • Limited to the supported music link when sent for a preview, conversion, or the direct iOS source-metadata requests described below
  • Never sent in full when the clipboard contains unrelated text

To recover a confirmed conversion after a crash or restart, the app stores a pending-redemption journal in the macOS Keychain. An entry can contain the supported source URL, selected destination, request and resolution identifiers, and, after a successful redemption, the converted URL and entitlement response. The app attempts to delete an entry after delivering the converted URL to the clipboard; the entry can remain if cleanup fails. If the app cannot read the journal, it preserves a recovery copy in the Keychain; that copy has no automatic expiry and may remain until it is manually removed.

iOS Shared Local Storage

The iOS app and Share extension share an App Group container. It holds destination and catalog-region preferences, whether destination setup is complete, the clipboard-check preference, a pending conversion, access state, local engagement counters and saved converted links. It also stores a local clipboard receipt containing the last converted URL Relinq copied, the clipboard change counter, and the write time, so the app can avoid treating its own copied link as new input. A pending or saved record can contain the source URL, selected destination, requested country, public title and artist metadata, artwork URL, converted URL, creation time, and identifiers used to recover the same conversion without counting it twice. Saved links have no automatic expiry or count limit; repeating the same source, destination and catalog region updates its saved entry.

Local engagement counters help decide when to offer feedback and review prompts. Relinq does not upload those counters or the local history database for usage statistics or prompt scheduling. Saved links use an indexed local database; migration from the earlier history file retains that file as a recovery backup.

Installation and access credentials use a non-synchronizing, device-only Keychain item, accessible after the device's first unlock. App Group storage is separate from those credentials and is not explicitly excluded from operating-system backups. Backup and restore behavior is controlled by iOS and your settings. Removing or reinstalling the app does not guarantee removal of Keychain or server records and does not reset an existing server-side trial.

Music Matching and Retention

Preview and conversion requests go to Relinq's service hosted on Cloudflare. If Relinq does not already have a match, it sends the canonical public music URL and country code to the SongLink/Odesli API. Relinq does not intentionally include your installation identifier, Relinq access token, license key, email address, or end-user IP address in that Odesli request. Odesli handles the request under its privacy policy.

When the configured album-matching fallback is needed, Relinq's server also requests album metadata from Spotify using the public Spotify album identifier and requested catalog region, and checks Apple's iTunes lookup service using the album product code (UPC) and region. These requests originate from Relinq's server; Relinq does not intentionally forward your installation identifier, access credentials, or end-user IP address to these services. This fallback depends on server configuration and an available matching catalog entry.

To display song details sooner on iOS, the app or Share extension can request public source metadata directly from Spotify's embed endpoint at open.spotify.com, Apple's iTunes lookup at itunes.apple.com, YouTube's oEmbed endpoint at www.youtube.com, or SoundCloud's oEmbed endpoint at soundcloud.com. These providers receive the canonical public music identifier or URL, and Apple lookup also receives the selected catalog country. Because the requests originate on your device, recipients also receive your IP address and standard network information. The requests do not include Relinq access credentials, your music-account credentials, cookies, or unrelated share text, and do not follow redirects.

This source metadata is used to display the public title, artist and available artwork, independently of conversion. The app keeps at most 64 source-metadata entries in process memory and does not use a disk cache for these requests. This limit does not describe providers' own retention. Spotify, Apple, YouTube and SoundCloud process requests under their respective privacy policies. A title supplied by the sharing app may also appear locally; Relinq does not send arbitrary share-sheet titles to these metadata endpoints.

The apps can load cover artwork directly from the HTTPS artwork URL returned in matching metadata rather than through Relinq's matching service. The artwork host receives the request and standard network information, including your IP address, and the artwork URL may identify the song or album. On Mac, turning off Show Music Preview prevents this artwork request. The current iOS app displays available artwork as part of the conversion flow and does not have that Mac preference. Its artwork requests are restricted to supported artwork hosts and do not include Relinq access credentials or cookies.

For a recognized shortened music link on iOS, Relinq may contact the music service's public link hosts to follow a bounded chain of HTTPS redirects. Those hosts receive the requested link and standard network information, including your IP address. Relinq does not send its API access credentials or cookies with those requests, collect the response page body, or use arbitrary websites as redirect destinations.

Successful normalized music mappings are stored in Cloudflare D1 without automatic expiry so they can be reused and served during upstream outages. A mapping can include a country code, an entity type (song or album), public service URLs and identifiers, a SongLink, AlbumLink, or Odesli page URL, and public metadata such as title, artist, artwork URL and, for songs when available, duration and ISRC. This shared catalog is not organized as a user profile.

Trial and entitlement records are pseudonymous but can still describe service use. A redemption record links an entitlement to a resolved catalog entry, requested destination, response, and idempotency identifier. The free-trial count and up to five successful free redemption records are retained without automatic expiry so reinstalling, retrying, or replacing a token does not replenish the same trial. Paid-access redemption responses become eligible for deletion after seven days and are deleted incrementally during later activity, so they may remain longer until cleanup occurs.

Pseudonymous installation and entitlement records, license and refund state, numeric Lemon Squeezy identifiers, and one-way webhook replay hashes currently have no automatic expiry. Relinq keeps them to preserve trial and lifetime-license state, apply refunds and revocations, reject replayed events, and maintain access across token replacement.

Cloudflare D1 Time Travel is always on. While Relinq uses Cloudflare Workers Free, Cloudflare keeps point-in-time database history for up to seven days. D1 data that Relinq changes or deletes can therefore remain recoverable by Cloudflare during that period. Cloudflare's published retention may change if its service or Relinq's hosting plan changes.

First-Party Usage Statistics

Relinq uses its existing Cloudflare-hosted matching service and database to count service registrations, successful free conversions, confirmed conversions that reach the five-use trial cap, first observed active iOS subscriptions and verified subscription lifecycle notifications. These measurements help us understand service use and improve the product. They do not require a new analytics SDK, tracking service or additional telemetry from the app.

The statistics store daily totals by UTC date, measurement type and purchase environment where known, with subscription notifications grouped by their type and subtype. They do not store a separate event history, installation or purchase identifiers, music URLs, IP addresses or network fingerprints. Access is restricted to authorized service administrators; there is no public statistics endpoint. Aggregate counts have no automatic expiry and begin when collection is enabled, rather than reconstructing a complete history of past use.

The underlying operational records remain pseudonymous and linked to installations, conversions and entitlements as described above. Relinq uses those links to avoid counting the same registration, successful trial conversion or subscription subject repeatedly, and records when a subscription subject is first counted. Aggregate reporting does not make the source records anonymous or change their retention. A registration is not necessarily a unique person or App Store download; a first observed subscription can include a restore or Family Sharing access, and a lifecycle notification is not a count of paying customers or revenue.

Security Records and Logs

Cloudflare Durable Objects store rolling counters, cooldowns, short-lived lookup leases, and pseudonymous installation, entitlement, and network fingerprints used for rate limits and upstream-capacity coordination. Data outside an active minute, hour, day, or seven-day window is ignored and replaced or cleaned as the service continues to receive traffic; some pseudonymous state rows may remain until later traffic or operational cleanup. Cloudflare retains point-in-time recovery for SQLite Durable Objects for 30 days, so changed or deleted Durable Object records may remain recoverable by Cloudflare during that period.

Free-trial and Mac-license access tokens stop authorizing requests within 180 days and can be replaced automatically. iOS subscription access tokens expire at the earlier of ten minutes and the end of the verified paid period or eligible billing grace period. Their installation-bound refresh credentials expire after a fixed 180 days and can be replaced by a verified purchase or restore. A refresh credential does not extend an expired subscription. Expiry stops authorization, but does not delete stored token hashes, installation records, or entitlement history. Those records may remain to preserve trial and purchase state, investigate abuse, and issue a replacement.

Relinq's structured Worker logs contain a request identifier, route name, status, outcome, duration, and occasional aggregate quota milestones. Relinq does not intentionally put music URLs, request bodies, clipboard contents, license keys, access tokens, email addresses, raw IP addresses, or stored fingerprints in those custom log messages. Cloudflare also creates platform and invocation logs that may contain network and request metadata. While Relinq uses Cloudflare Workers Free, Workers Logs are retained by Cloudflare for three days; Cloudflare's published retention may change if its service or Relinq's hosting plan changes.

The Mac app also writes operational messages to ~/relinq_debug.log and Apple's macOS unified logging system on your Mac. The file remains until you delete it; unified-log retention is controlled by macOS. Relinq is designed not to write music URLs, unrelated clipboard contents, license keys, access tokens, or email addresses to either log. The iOS app does not create this Mac diagnostic file.

Software Updates

The Mac app uses Sparkle to check for software updates automatically by default. Update checks retrieve Relinq's release feed from GitHub, and update files are downloaded from releases.relinq.app, which is hosted on Cloudflare R2. GitHub and Cloudflare receive standard network and request metadata, such as an IP address and request time, when serving those files. The iOS app uses Apple's App Store distribution and does not include Sparkle.

Mac License Validation

Purchases and license administration are handled by Lemon Squeezy. When you activate a new license, the app sends the license key and a device instance label—normally the Mac's platform UUID, with a random fallback—directly to Lemon Squeezy. The app stores the license key, purchaser email if Lemon Squeezy returns one, Lemon Squeezy activation-instance identifier, and validation dates in the macOS Keychain.

When an existing license is connected to or refreshed with Relinq's matching service, the raw key and activation-instance identifier are sent securely to Relinq and forwarded to Lemon Squeezy for validation. Relinq's database stores a keyed one-way fingerprint of the license key, the Lemon Squeezy activation-instance identifier associated with the pseudonymous installation, and numeric Lemon Squeezy license, order, store, and product identifiers. Lemon Squeezy validation responses and signed webhook events may contain customer details, but Relinq does not persist or intentionally log the raw license key, webhook body, customer name, or email address on the matching service. Relinq does not receive or store payment-card details.

iOS App Store Purchases

Apple handles the separate monthly and yearly iOS subscriptions, restore, and eligible Family Sharing through StoreKit, under Apple's privacy policy. Relinq passes its random installation UUID to StoreKit as an app-account token to associate the purchase with that installation; it is not your Apple Account name. Relinq does not request your Apple Account password or receive payment-card details through this integration. The iOS app does not send a Mac license key to Lemon Squeezy.

To enable access after a purchase or restore, the app sends a verified signed transaction, its installation identifier, and recorded free-use count to Relinq's service. Later access refreshes send the installation identifier and an opaque refresh credential. Relinq verifies Apple's signed transaction and renewal evidence and checks current subscription status with Apple before granting access. This processes subscription periods, expiration, renewal settings, billing grace periods when applicable, and revocation information. Apple's App Store Server Notifications also inform Relinq of subscription, refund, reversal, and Family Sharing access changes. Restoring or sharing an eligible subscription can associate more than one installation with an entitlement.

Relinq stores Apple app-transaction, transaction, and original-transaction identifiers; product and environment; purchased or family-shared ownership; signed dates; revocation state; the current access-validity timestamp; and the binding to a pseudonymous installation and hashed refresh credential. It also stores notification identifiers, type, dates, and a payload hash to reject duplicate events. Signed purchase, renewal, or notification bodies are verified during processing and are not intentionally persisted or logged on the server. Apple transaction and notification records, including revocation evidence, currently have no automatic expiry. These records support restore, current access checks, refunds, and protection against replayed or stale purchases.

Subscribing preserves the original free-use count and successful trial redemption history. Relinq does not reset an existing trial when a subscription expires or access is revoked. Purchase records are processed through Relinq's Cloudflare-hosted service and database; the hosting, backup, security-record, and deletion limitations described above also apply to them.

Voluntary Feedback and Support

On iOS, Send feedback opens an editable draft in your email app addressed to [email protected]. Relinq adds its app version and build, iOS version and generic device model. It does not attach your device name, installation identifier, clipboard, saved links, purchase evidence or logs. You choose what to write and whether to send; your email app supplies its configured sender information and processes the message.

We use messages you send to provide support and use product suggestions and accompanying app context to improve Relinq. You may contact us about a feedback or support message using the rights process below; your email service controls its own copy. Older iOS builds can send a voluntary feedback form to Relinq's service, where those records remain in Cloudflare D1 without automatic expiry. Changing the current app to an email draft does not delete earlier submissions. Please avoid including passwords, access credentials or unrelated personal information in feedback.

Crash Reporting

The Mac app uses Sentry to collect crash reports and error data. This helps us identify and fix bugs. The current iOS app and Share extension do not include Sentry or a third-party analytics SDK. When a Mac error occurs, we collect:

  • Error message and stack trace
  • Device model and OS version
  • App version

Relinq does not intentionally attach music URLs, clipboard contents, license keys, or email addresses to crash reports. Sentry may process network and device information as described in its policy.

Please refer to Sentry's Privacy Policy for more information.

Website Analytics

Our website (relinq.app) uses Cloudflare Web Analytics for aggregate page-view and performance measurements. The activation page does not load the analytics beacon and supports placing the license key in the URL fragment so it is not sent in the web request. Older receipt links that place a key in the query string remain supported; opening one can send that query string to the hosting provider before the page removes it from the address bar.

The homepage loads the Playfair Display typeface from Google Fonts. Google receives standard request metadata when serving the stylesheet and font files, such as the visitor's IP address, requested URL, browser or operating-system information, and referrer.

Third-Party Providers and Recipients

Relinq uses Cloudflare for website delivery, API hosting, D1 storage, Durable Objects, security, first-party usage statistics, website analytics, Mac update downloads, and short-term service logs; GitHub for the Mac automatic-update feed; Google Fonts for the homepage typeface; SongLink/Odesli for uncached music matching; Spotify and Apple's iTunes lookup for configured server-side album matching; Lemon Squeezy for Mac purchases and license administration; Sentry for Mac crash and error reporting; and Apple for iOS distribution, subscriptions, and purchase verification. Spotify, Apple, YouTube and SoundCloud metadata endpoints, artwork hosts, and supported music-link redirect hosts can receive the direct iOS requests described above. These recipients may process information under their own privacy policies. Relinq does not sell personal information or use matching-service records for behavioral advertising.

Your Choices and Rights

You can stop Mac clipboard monitoring or turn off iOS clipboard checks in Settings. Paste and the iOS share sheet remain available when automatic checks are off. You may delete the Mac diagnostic log yourself. Subject to applicable law, you may ask to access, correct, or delete personal information associated with you, or object to or restrict certain processing, by emailing [email protected]. We may need information that reasonably verifies the installation or purchase connected to the request. Never send an Apple Account password, access token, or refresh token in a support message.

Some records cannot be linked back to a person without an installation or purchase identifier. Shared public catalog data is not deleted merely because one user requested the same song or album. We may also retain information needed to preserve a requested Mac license or iOS subscription record, prevent repeated trial abuse, process refunds or disputes, meet legal obligations, and protect the service. We will explain any limitation that applies to a request.

Contact

If you have questions about this privacy policy, you can reach us at [email protected].

Relinq support

Last updated: September 10, 2026