Back to Home

Privacy Policy

Relinq is a Metedata product designed to limit the data it handles. This policy explains what Relinq and third-party providers or recipients process when you use the app, matching service, and website.

Relinq's Matching Service

Relinq 1.3 restored music-link conversion by routing preview and conversion requests through Relinq's matching service instead of placing the upstream Songlink/Odesli credential in the app. This proxy protects that credential, preserves existing license and trial state, and lets successful public music mappings be reused during upstream outages. No Relinq account is required. The service processes and retains only the categories described below; it does not intentionally retain raw IP addresses, raw license keys, or access tokens.

Data Relinq Processes

Relinq processes supported music URLs, the requested destination service, a two-letter country code used for catalog matching, and technical records needed to provide previews and conversions, count the five-conversion trial, validate lifetime licenses, prevent duplicate charges against the trial, enforce rate limits, and protect the service.

The app creates a random installation identifier and stores it, along with its Relinq access token, in the macOS Keychain. The matching service stores a keyed one-way fingerprint of the installation identifier and a one-way hash of the access token, rather than the raw values.

Cloudflare provides the connecting IP address to Relinq at the network edge. Relinq's application code uses the full IPv4 address (a /32) or truncates an IPv6 address to its /64 network prefix, then transiently derives a keyed one-way fingerprint for abuse controls. Relinq stores the fingerprint—not the raw address—in its D1 database and Durable Object quota records. Cloudflare still processes IP addresses and other request metadata while routing, securing, and logging requests under its privacy policy.

Clipboard Access

Relinq monitors your clipboard to detect music streaming URLs. This happens locally on your device. Clipboard contents are:

  • Ignored unless they match a supported music URL pattern
  • Sent to Relinq's matching service only for a preview or conversion
  • Never sent in full when the clipboard contains unrelated text

To recover a confirmed conversion after a crash or restart, the app stores a pending-redemption journal in the macOS Keychain. An entry can contain the supported source URL, selected destination, request and resolution identifiers, and, after a successful redemption, the converted URL and entitlement response. The app attempts to delete an entry after delivering the converted URL to the clipboard; the entry can remain if cleanup fails. If the app cannot read the journal, it preserves a recovery copy in the Keychain; that copy has no automatic expiry and may remain until it is manually removed.

Music Matching and Retention

Preview and conversion requests go to Relinq's service hosted on Cloudflare. If Relinq does not already have a match, it sends the canonical public music URL and country code to the SongLink/Odesli API. Relinq does not intentionally include your installation identifier, Relinq access token, license key, email address, or end-user IP address in that Odesli request. Odesli handles the request under its privacy policy.

When music previews are enabled, the app loads cover artwork directly from the HTTPS artwork URL returned in the matching metadata rather than through Relinq's matching service. The artwork host receives the request and standard network information, including your IP address, and the artwork URL may identify the song or album. Turning off Show Music Preview prevents the app from making this artwork request.

Successful normalized music mappings are stored in Cloudflare D1 without automatic expiry so they can be reused and served during upstream outages. A mapping can include a country code, an entity type (song or album), public service URLs and identifiers, a SongLink, AlbumLink, or Odesli page URL, and public metadata such as title, artist, artwork URL and, for songs when available, duration and ISRC. This shared catalog is not organized as a user profile.

Trial and entitlement records are pseudonymous but can still describe service use. A redemption record links an entitlement to a resolved catalog entry, requested destination, response, and idempotency identifier. The free-trial count and up to five successful free redemption records are retained without automatic expiry so reinstalling, retrying, or replacing a token does not replenish the same trial. Lifetime-license redemption responses become eligible for deletion after seven days and are deleted incrementally during later activity, so they may remain longer until cleanup occurs.

Pseudonymous installation and entitlement records, license and refund state, numeric Lemon Squeezy identifiers, and one-way webhook replay hashes currently have no automatic expiry. Relinq keeps them to preserve trial and lifetime-license state, apply refunds and revocations, reject replayed events, and maintain access across token replacement.

Cloudflare D1 Time Travel is always on. While Relinq uses Cloudflare Workers Free, Cloudflare keeps point-in-time database history for up to seven days. D1 data that Relinq changes or deletes can therefore remain recoverable by Cloudflare during that period. Cloudflare's published retention may change if its service or Relinq's hosting plan changes.

Security Records and Logs

Cloudflare Durable Objects store rolling counters, cooldowns, short-lived lookup leases, and pseudonymous installation, entitlement, and network fingerprints used for rate limits and upstream-capacity coordination. Data outside an active minute, hour, day, or seven-day window is ignored and replaced or cleaned as the service continues to receive traffic; some pseudonymous state rows may remain until later traffic or operational cleanup. Cloudflare retains point-in-time recovery for SQLite Durable Objects for 30 days, so changed or deleted Durable Object records may remain recoverable by Cloudflare during that period.

Relinq access tokens stop authorizing requests within 180 days and can be replaced automatically. Their stored hashes and the associated installation and entitlement records may remain after a token expires so Relinq can preserve trial and license state, investigate abuse, and issue a replacement.

Relinq's structured Worker logs contain a request identifier, route name, status, outcome, duration, and occasional aggregate quota milestones. Relinq does not intentionally put music URLs, request bodies, clipboard contents, license keys, access tokens, email addresses, raw IP addresses, or stored fingerprints in those custom log messages. Cloudflare also creates platform and invocation logs that may contain network and request metadata. While Relinq uses Cloudflare Workers Free, Workers Logs are retained by Cloudflare for three days; Cloudflare's published retention may change if its service or Relinq's hosting plan changes.

The app also writes operational messages to ~/relinq_debug.log and Apple's macOS unified logging system on your Mac. The file remains until you delete it; unified-log retention is controlled by macOS. Relinq is designed not to write music URLs, unrelated clipboard contents, license keys, access tokens, or email addresses to either log.

Software Updates

Relinq uses Sparkle to check for software updates automatically by default. Update checks retrieve Relinq's release feed from GitHub, and update files are downloaded from releases.relinq.app, which is hosted on Cloudflare R2. GitHub and Cloudflare receive standard network and request metadata, such as an IP address and request time, when serving those files.

License Validation

Purchases and license administration are handled by Lemon Squeezy. When you activate a new license, the app sends the license key and a device instance label—normally the Mac's platform UUID, with a random fallback—directly to Lemon Squeezy. The app stores the license key, purchaser email if Lemon Squeezy returns one, Lemon Squeezy activation-instance identifier, and validation dates in the macOS Keychain.

When an existing license is connected to or refreshed with Relinq's matching service, the raw key and activation-instance identifier are sent securely to Relinq and forwarded to Lemon Squeezy for validation. Relinq's database stores a keyed one-way fingerprint of the license key, the Lemon Squeezy activation-instance identifier associated with the pseudonymous installation, and numeric Lemon Squeezy license, order, store, and product identifiers. Lemon Squeezy validation responses and signed webhook events may contain customer details, but Relinq does not persist or intentionally log the raw license key, webhook body, customer name, or email address on the matching service. Relinq does not receive or store payment-card details.

Crash Reporting

Relinq uses Sentry to collect crash reports and error data. This helps us identify and fix bugs. When an error occurs, we collect:

  • Error message and stack trace
  • Device model and OS version
  • App version

Relinq does not intentionally attach music URLs, clipboard contents, license keys, or email addresses to crash reports. Sentry may process network and device information as described in its policy.

Please refer to Sentry's Privacy Policy for more information.

Website Analytics

Our website (relinq.app) uses Cloudflare Web Analytics for aggregate page-view and performance measurements. The activation page does not load the analytics beacon and supports placing the license key in the URL fragment so it is not sent in the web request. Older receipt links that place a key in the query string remain supported; opening one can send that query string to the hosting provider before the page removes it from the address bar.

The homepage loads the Playfair Display typeface from Google Fonts. Google receives standard request metadata when serving the stylesheet and font files, such as the visitor's IP address, requested URL, browser or operating-system information, and referrer.

Third-Party Providers and Recipients

Relinq uses Cloudflare for website delivery, API hosting, D1 storage, Durable Objects, security, analytics, update downloads, and short-term service logs; GitHub to serve the automatic-update feed; Google Fonts to serve the homepage typeface; SongLink/Odesli for uncached music matching; Lemon Squeezy as the independent merchant of record and for license administration; and Sentry for app crash and error reporting. Cover-art hosts also receive requests directly from the app when music previews are enabled. These recipients may process information under their own privacy policies. Relinq does not sell personal information or use matching-service records for behavioral advertising.

Your Choices and Rights

You can stop clipboard monitoring or stop using Relinq at any time. You may delete the local diagnostic log yourself. Subject to applicable law, you may ask to access, correct, or delete personal information associated with you, or object to or restrict certain processing, by emailing [email protected]. We may need information that reasonably verifies the installation or purchase connected to the request.

Some records cannot be linked back to a person without an installation or purchase identifier. Shared public catalog data is not deleted merely because one user requested the same song or album. We may also retain information needed to preserve a requested lifetime license, prevent repeated trial abuse, process refunds or disputes, meet legal obligations, and protect the service. We will explain any limitation that applies to a request.

Contact

If you have questions about this privacy policy, you can reach us at [email protected].

Last updated: August 21, 2026