BurnLink
Back
Legal

Privacy Policy

Effective date: June 29, 2026 ·  BurnLink

BurnLink is built on a single principle: your secrets are not our business. This policy explains, in plain language, exactly what we collect, what we do not collect, and how your data is protected. It is intentionally brief because our data practices are intentionally minimal.

1. Encryption & Security

All message content is protected with AES-256-GCM — the same cipher standard used by NATO, the NSA for Top Secret classification, and leading financial institutions. This is the highest commercially available encryption standard in existence.

All data in transit is protected by TLS 1.3 with forward secrecy. Communications cannot be intercepted or retroactively decrypted even if future keys are compromised.

Secrets are stored encrypted at rest. Once a secret reaches its view limit or expiry, it is permanently and irrecoverably deleted from our infrastructure — including all backups within the same TTL cycle.

2. No-Logs Policy

BurnLink operates a strict zero-logs policy with respect to secret content. Specifically, we do not log, store, or transmit:

  • The plaintext content of any message
  • Who sent a secret to whom
  • The identity of message recipients
  • Reading history or access patterns linked to individuals
  • Any data that could be used to reconstruct a secret after it is burned

Once a secret is burned, its content is gone. We cannot recover it, and no third party — including law enforcement — can compel us to produce data we do not possess.

3. Data We Collect

To operate the service, we temporarily process the following operational metadata only:

  • Secret metadata — view limit, expiry timestamp, whether a passphrase is set. Never the content itself.
  • IP addresses — recorded at creation and access time solely for abuse prevention and rate-limiting. Not linked to identity. Purged when the secret is destroyed.
  • User-agent strings — browser or device type, used for security analytics only.
  • Timestamps — when a secret was created and when it was accessed, retained only while the secret exists.

We do not collect names, email addresses, phone numbers, account data, cookies, or any form of persistent identifier unless you voluntarily contact us.

4. Data Retention & Deletion

Secrets are auto-deleted upon the earliest of: (a) reaching the configured view limit, (b) reaching the configured expiry time, or (c) manual deletion by the creator.

Associated metadata (IP, user-agent, timestamps) is deleted in the same operation. There is no archive, no cold storage, no soft-delete. Deletion is final, immediate, and irreversible.

5. Third Parties & Disclosure

We do not sell, rent, trade, or share your data with third parties for commercial purposes. Ever.

We may share aggregated, fully anonymised statistical data (e.g. “N secrets were created this month”) that contains no personal information whatsoever.

In the event of a lawful government request: because we hold no content and no persistent personal data, there is nothing to disclose. We are structurally incapable of cooperating with surveillance requests that target message content.

6. Contact

Questions about this policy or your data may be directed to the BurnLink team. As we collect no personal data, there is typically no “your data” to action — but we are happy to clarify anything.

We reserve the right to update this policy. Material changes will be reflected by an updated effective date above. Continued use of BurnLink after changes constitutes acceptance of the revised policy.

© 2026 BurnLink·Privacy Policy·Terms & Conditions