Legal Documentation
Privacy Policy
Effective Date: January 1, 2025 ? Last Revised: May 2026 ? Operator: DigiMktg Co. LLC, Illinois, USA
Introduction & Privacy Philosophy
Plain language summary: PhantomLink is built around one principle — the less we know about you, the better. We designed the entire platform to avoid collecting your information in the first place. This Privacy Policy explains exactly what that means in practice.
1.1 This Privacy Policy describes how DigiMktg Co. LLC ("we," "us," "our," or the "Operator"), operating PhantomLink.app (the "Service"), collects, uses, stores, and discloses information in connection with your use of the Service. This Policy applies to all visitors, users, and others who access the Service.
1.2 This Privacy Policy is incorporated by reference into the PhantomLink Terms of Service located at PhantomLink.app/legal. Capitalized terms not defined herein have the meanings given to them in the Terms of Service.
1.3 Privacy by Design. PhantomLink is constructed on a privacy-by-design architecture. The Service was engineered to minimize data collection as a foundational technical constraint, not as an afterthought. The result is a platform that functionally cannot produce most categories of user-identifiable data even if legally compelled to do so.
1.4 Apple App Store Compliance. This Privacy Policy serves as the required privacy disclosure for PhantomLink's mobile application(s) distributed through the Apple App Store and Google Play Store. The data practices described herein reflect the complete and accurate data handling of all platform versions, including mobile applications.
What We Do Not Collect
2.1 The following categories of data are not collected, stored, logged, or retained by DigiMktg Co. LLC at any point in connection with the Service:
- Permanent message content — Message text is encrypted at rest while active and destroyed per sender-configured settings. The Service decrypts message content only as needed to display it to an authorized recipient while the message is active.
- Sender identity — No name, username, email address, phone number, or other identifier is required from or collected from message senders.
- Recipient identity — No identity information is collected from or about message recipients.
- IP addresses linked to message events — IP addresses are not stored in the PhantomLink application database in association with message creation or link access events by the Operator.
- Device fingerprints linked to message events — No persistent device fingerprinting is conducted by the Operator in connection with message creation or access.
- Geolocation data — The Service does not request, collect, or store geolocation data.
- User account data — The current Service requires no account creation. No user accounts, profile data, or login credentials are created or stored for message senders or recipients.
- User passwords — Message passwords set by senders are not stored in plaintext or accessible to the Operator. A password hash may be temporarily stored only to verify access while the message exists, then deleted with the message row.
- Optional name fields — Sender-entered optional name fields are stored only inside the temporary message row while the message exists and are destroyed with the message. They are not used to create a user profile.
- Behavioral profiles — The Operator does not create, maintain, or sell behavioral profiles of individual users.
What We Do Collect
3.1 In the course of operating the Service, the following limited categories of information are collected or generated:
- Aggregate analytics data — Google Analytics collects anonymized, aggregate traffic data including page views, session duration, general geographic region (country/region level, not precise location), device type, and browser type. This data is not linked to individual message events or user identities by the Operator.
- Bot mitigation data — The Service uses rotating mathematical challenge questions and rotating math challenges and Cloudflare network protections to prevent automated abuse. Responses to these challenges are evaluated in real time and are not stored persistently by the Operator.
- Cloudflare network data — Cloudflare, Inc. processes all traffic to the Service through its edge network and independently maintains network-level logs pursuant to its own privacy policy. This data is not controlled by or accessible to the Operator.
- Legal contact submissions — Information voluntarily submitted to [email protected] for legal or compliance purposes is retained solely for the purpose of responding to that inquiry.
- Abuse reports — Information included in abuse reports submitted by users is retained for the purpose of investigating reported conduct and is not used for any other purpose.
SMS Messaging and Privacy
We value your privacy. Mobile numbers collected for the purpose of sending transactional account notifications, security alerts, and system updates will not be shared, sold, or rented to third parties or affiliates for marketing or promotional purposes. Your SMS opt-in data and consent are strictly confidential and used solely to deliver the services you request.
Transactional Email Delivery
When a sender chooses to deliver a PhantomLink by email, the recipient email address and delivery details are processed by our transactional email provider, Brevo, solely for the purpose of sending the requested message link. PhantomLink does not sell, rent, or share recipient email addresses for marketing or promotional purposes.
Email delivery may include the sender name if provided, Trust Clue if provided, password and password hint if provided, the PhantomLink URL, and related delivery metadata. The secret message content itself is not included in the email and remains accessible only through the PhantomLink page while the link is active.
Data Collection Reference Table
| Data Type | Collected by Operator? | Notes |
|---|---|---|
| Message content | TEMPORARY | Encrypted at rest while active; destroyed per timer/trigger; not used for profiling |
| Sender identity | ✗ NO | Not required; optional name field destroyed with message |
| Recipient identity | ✗ NO | Not collected at any point |
| IP addresses (message events) | ✗ NO | Not logged by Operator; Cloudflare may log independently |
| Geolocation | ✗ NO | Not requested or stored |
| Message passwords | HASH ONLY | Plaintext password is not stored; temporary hash is deleted with the message |
| Device fingerprints | ✗ NO | Not collected by Operator for message events |
| User accounts / profiles | ✗ NO | Free tier requires no registration |
| Aggregate analytics | ✓ YES | Via Google Analytics; anonymized; not linked to message events |
| Cloudflare network logs | ✓ THIRD PARTY | Maintained by Cloudflare per their privacy policy; not accessible to Operator |
| Legal/abuse correspondence | ✓ YES | Retained only for purpose of responding to inquiry |
How We Use Information
5.1 The limited information collected by the Operator is used exclusively for the following purposes:
- Operating, maintaining, and improving the technical functionality of the Service
- Detecting, preventing, and mitigating automated bot activity and abuse of the Service
- Measuring aggregate, anonymized traffic patterns for Service improvement purposes via Google Analytics
- Responding to legal correspondence, law enforcement inquiries, and abuse reports
- Enforcing the Terms of Service and investigating reported violations
- Complying with applicable legal obligations
5.2 No Secondary Use. The Operator does not use collected information for advertising profiling, sale to data brokers, cross-platform tracking, or any purpose beyond those enumerated in §5.1.
Third-Party Services Overview
6.1 The Service integrates with the following categories of third-party services, each of which operates under its own independent privacy policy:
- Cloudflare, Inc. — Network proxy, DDoS protection, rate limiting, TLS termination
- Google LLC (Google Analytics) — Aggregate traffic analytics
- Web hosting providers — Server infrastructure for Service delivery
- Payment processors (future) — Payment processing for paid tier features upon launch
6.2 The Operator does not control the data practices of third-party services and is not responsible for their privacy practices. Users are encouraged to review the privacy policies of applicable third parties.
Cloudflare & Infrastructure Providers
7.1 All traffic to PhantomLink.app is routed through Cloudflare's global edge network. Cloudflare independently processes and may log network-level data including IP addresses, request headers, and connection metadata pursuant to Cloudflare's Privacy Policy available at cloudflare.com/privacypolicy.
7.2 This Cloudflare-maintained data is not accessible to, controlled by, or retrievable by DigiMktg Co. LLC. Law enforcement seeking network-level data should direct legal process to Cloudflare directly.
7.3 Web hosting providers utilized by the Service may independently maintain server access logs pursuant to their own data retention policies. The Operator does not direct or control such logging.
Third-Party Advertising Networks
8.1 The Service may load third-party advertising network scripts or ad placement code, including HilltopAds or Monetag placements.
8.2 The Operator does not intentionally share message content, sender identity, or recipient identity with advertising partners. Advertising partners may process browser, device, referrer, and ad interaction data under their own policies.
Google Analytics
9.1 The Service uses Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses first-party cookies and similar technologies to collect anonymized usage data including page views, session duration, general geographic region, device type, and traffic source.
9.2 The Operator has configured Google Analytics to anonymize IP addresses prior to collection. The Operator does not use Google Analytics User-ID features or any configuration that would link analytics data to individual message events or user identities.
9.3 Google Analytics data is processed pursuant to Google's Privacy Policy at policies.google.com/privacy and Google Analytics Terms of Service at marketingplatform.google.com/about/analytics/terms.
9.4 Opt-Out. Users may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.
Data Sharing & Sale
10.1 No Sale of Personal Data. DigiMktg Co. LLC does not sell personal information to third parties. The Operator does not engage in the sale of user data as defined under the California Consumer Privacy Act (CCPA) or any comparable state privacy law.
10.2 No Data Broker Activity. The Operator does not share user data with data brokers, list vendors, or marketing aggregators.
10.3 Limited Disclosure. The Operator may disclose information in the following limited circumstances only: (a) as required by applicable law or valid legal process, subject to the zero-retention limitations described in the Terms of Service §12; (b) to protect the rights, property, or safety of the Operator, users, or the public; (c) in connection with a merger, acquisition, or sale of all or substantially all of the Operator's assets, with advance notice to users; or (d) with your express prior consent.
Data Retention
11.1 Message Data. Message content and associated temporary operational fields are deleted from the active PhantomLink application database upon satisfaction of the applicable destruction trigger, including timer expiration, read-window expiration, or manual destruction. Third-party infrastructure logs, hosting backups, database snapshots, or provider-level records may be governed by the independent policies of those providers.
11.2 Analytics Data. Aggregate analytics data maintained by Google Analytics is subject to Google's standard data retention settings, configurable by the Operator. The Operator does not retain identifiable analytics records beyond the minimum necessary for aggregate traffic analysis.
11.3 Legal Correspondence. Information submitted in connection with legal inquiries or abuse reports is retained for the period necessary to respond to and resolve the matter, and for such additional period as required by applicable law or prudent legal record-keeping practice.
11.4 No Obligation to Retain. The Operator has no legal obligation under currently applicable federal law to retain logs of user communications or message metadata for any specified period. The zero-retention architecture is legally compliant as of the effective date of this Policy.
Your Privacy Rights
12.1 Access & Portability. Because the Operator does not collect personally identifiable information from message senders or recipients in the ordinary course of Service operation, there is generally no personal data held by the Operator subject to access or portability requests. Requests may be submitted to [email protected] and will be responded to within a commercially reasonable time.
12.2 Deletion. Message content is automatically and permanently deleted per the applicable destruction trigger. No additional deletion request is required or available for message data. For any other data you believe the Operator may hold, deletion requests may be submitted to [email protected].
12.3 Correction. Requests to correct inaccurate personal information held by the Operator may be submitted to [email protected].
12.4 Opt-Out of Analytics. See §9.4 for Google Analytics opt-out instructions. See §8.3 for advertising opt-out options.
California Consumer Privacy Act (CCPA) Disclosure
13.1 This section applies to California residents and is provided pursuant to the California Consumer Privacy Act of 2018 (CCPA) and the California Privacy Rights Act (CPRA).
13.2 Categories of Personal Information Collected. As described in this Policy, the Operator collects only aggregate, anonymized analytics data and information voluntarily submitted in legal correspondence. The Operator does not collect the following CCPA-defined categories of personal information in connection with normal Service use: identifiers; commercial information; biometric information; internet or network activity linked to an individual; geolocation data; sensory data; professional or employment information; or sensitive personal information.
13.3 Do Not Sell or Share. The Operator does not sell or share personal information as those terms are defined under the CCPA/CPRA. No opt-out mechanism for sale of personal information is required because no such sale occurs.
13.4 Your CCPA Rights. California residents have the right to: know what personal information is collected; request deletion of personal information; opt out of the sale or sharing of personal information (not applicable here); and non-discrimination for exercising CCPA rights. Requests may be submitted to [email protected].
GDPR & International Users
14.1 PhantomLink.app is operated from the United States. If you are accessing the Service from the European Union, European Economic Area, United Kingdom, or other jurisdiction with data protection laws that differ from U.S. law, please be aware that you are transferring information to the United States.
14.2 Legal Basis. To the extent GDPR applies to any data processed by the Operator, the lawful basis for processing is: (a) performance of a contract (delivery of the Service); (b) legitimate interests (security, fraud prevention, aggregate analytics); and (c) compliance with legal obligations.
14.3 GDPR Rights. EU/EEA/UK residents may have rights of access, rectification, erasure, restriction of processing, data portability, and objection under applicable data protection law. Given the minimal data collection practices of the Service, most GDPR rights requests will result in a confirmation that no personal data is held. Requests may be submitted to [email protected].
14.4 Data Controller. For purposes of applicable data protection law, DigiMktg Co. LLC is the data controller for any personal information processed in connection with the Service.
Children's Privacy
15.1 The Service is not directed to, and is not intended for use by, persons under the age of eighteen (18). The Operator does not knowingly collect any personal information from persons under the age of eighteen.
15.2 Given the Service's zero-collection architecture, the Operator does not have technical means to verify user age. If the Operator becomes aware that a person under eighteen (18) has used the Service in violation of the Terms of Service, the Operator will take appropriate action consistent with applicable law including the Children's Online Privacy Protection Act (COPPA).
15.3 If you believe a minor has used this Service, please contact us at [email protected].
Security Measures
16.1 The Operator employs the following technical and organizational security measures in connection with the Service:
- AES-256 or equivalent encryption of message content at rest
- TLS 1.2+ encryption for all data in transit, enforced via Cloudflare's edge network
- Cloudflare DDoS protection and Web Application Firewall (WAF)
- Rate limiting at the infrastructure level to mitigate brute force attacks
- Rotating mathematical challenge questions for bot mitigation on message creation and access
- No plaintext storage of message passwords
- Automatic and irreversible message destruction upon satisfaction of destruction conditions
16.2 No security system is impenetrable. The Operator does not guarantee that the Service is free from unauthorized access or security breaches. In the event of a security incident that affects user data (to the extent any such data exists), the Operator will provide notice as required by applicable law.
Changes to This Privacy Policy
17.1 The Operator reserves the right to modify this Privacy Policy at any time. Material changes will be communicated through a prominent notice on the Service website. The "Last Revised" date at the top of this Policy will be updated to reflect the date of any modification.
17.2 Your continued use of the Service after the effective date of any modification constitutes acceptance of the revised Privacy Policy. If you do not agree to the revised Policy, you must discontinue use of the Service.
17.3 The Operator will not retroactively apply materially less protective privacy practices to information collected prior to the effective date of any modification without your express consent.
Contact & Privacy Requests
18.1 All privacy-related inquiries, data subject requests, and legal correspondence regarding this Privacy Policy should be directed to:
DigiMktg Co. LLC — Privacy
Operating: PhantomLink.app
Privacy Inquiries: [email protected]
Subject Line: "PRIVACY REQUEST — [Nature of Request]"
State of Incorporation: Illinois, USA
18.2 The Operator endeavors to respond to all privacy requests within thirty (30) days of receipt. Response times may vary based on the complexity and volume of requests. For requests that cannot be fulfilled within thirty (30) days, the Operator will provide written notice of the expected completion date.