Privacy policy
Last updated 3 October 2026
LinkGuard is a Chrome extension and a website (linkguard-one.vercel.app) that check where a link goes before you open it. This page says exactly what is sent, what our server does with it, and what is kept.
What the extension sends
When you rest the pointer on a link to another site, move keyboard focus to it, click it, or use “Check this link” from the right-click menu, the extension sends our API:
- the link’s full address, including anything after “?” in it;
- the link’s visible text (or its label, for image links);
- the title of the page you are on, with email addresses and long numbers removed first.
A pointer that only passes over a link doesn’t send it. Links to other pages on the same host as the page you’re on aren’t sent, unless they carry another site’s address (like /url?q=…). “Check this link” sends only the link. Nothing else from the page is sent, and the extension never reads form fields, passwords, cookies or your browsing history.
What the website and the phone app send
When you paste one link into the checker on this site, it sends our API that link, plus the link’s text and the message it came in if you fill in those optional boxes.
When you paste a whole message, or share one to LinkGuard from another app on your phone, the page picks out the web addresses on your device and sends only those (up to 8), without the rest of the message. Our server never reads or keeps the rest of the message. Each address is checked as described below, which can include our server visiting it.
Sharing works on Android once LinkGuard is on your home screen. On Android, LinkGuard sets up a small helper in your browser when you visit this site (a service worker that only handles shared messages). It receives what you share on your phone and hands it to the page through this site’s storage in your browser. The page deletes it as soon as it has read it; a share left unopened is ignored after 10 minutes and deleted with the next one. If the helper isn’t running (for example, just after you clear your browser’s data for this site), the shared message reaches our server instead: the server doesn’t read or keep it, and opens the page so you can paste the message.
“Paste and check” reads your clipboard only when you tap it, and your browser may ask you to allow that first.
What our server does
- It may visit the link’s address. To find where a link really goes, our server requests the address (usually a HEAD request, which asks for headers only) and follows up to four redirects. The site you link to sees a request from our server, not from you; it identifies itself as an ordinary browser so scam sites can’t show it a cleaner page than they show people.
- It checks public phishing and malware lists. Our server downloads public lists of known phishing and malware links (OpenPhish, PhishTank and URLhaus) about once an hour while LinkGuard is in use, and at least once a day, and keeps them on our server. Links are looked up there: nothing about you or the link is sent to the list providers.
- It may look up when the site was registered. For sites that aren’t widely known, our server asks the public registration database for that domain ending (RDAP, the successor to WHOIS) when the domain was registered. Only the domain name (for example “example.com”) is sent: never the full link, its text, the page title or anything about you. Answers are kept for up to 7 days.
- It asks Jev. The address, where it redirects, the link text and the first 120 characters of the page title (both with emails and long numbers removed) are sent to Jev, TypeSafe AI’s model, through TypeSafe AI’s own API. Text that tries to tell the checker what to answer is removed before it reaches the model.
- It returns a verdict (Safe, Suspicious or Scam), scores and reasons. A link on one of the public lists is answered from the list, without visiting it or asking Jev.
What is kept, and for how long
- Verdicts are cached on our server so repeat checks are fast: 10 minutes for threat-list matches and for Jev’s answers about links that don’t redirect, 60 seconds for everything else. A cached verdict includes the link, its text and the cleaned page title; it’s looked up by a one-way hash of the request.
- The extension keeps recent verdicts in your browser for the current browsing session and a list of the links checked in each tab (shown in the toolbar popup). Both are cleared when you close the browser.
- Your settings (whether to ask before opening likely scams, and sites where checks are off) are saved in Chrome’s sync storage.
- Our host, Vercel, keeps standard request logs and privacy-friendly page analytics for the website under its own terms. The analytics record which page was opened, without anything after “?” or “#” in its address except campaign tags (utm_…).
There are no accounts. We don’t sell or share data, and we don’t use it for advertising.
Permissions the extension asks for
- “Read and change your data on all websites” (Chrome’s wording for running on every page): used only to find the link you point at, draw the tag under it, and ask before a likely scam opens.
- Storage: for your settings and the short-lived verdict cache.
- Context menus: for “Check this link with LinkGuard”.
- Active tab: so the toolbar popup can show which site you’re on when you open it.
Limits
LinkGuard can be wrong in both directions. Some links show a grey “Check first” instead of Safe even when no scam signs are found: pages on free site builders, shared documents and other places where anyone can publish, sites that use a brand’s name without being its site, and sites the registry says were registered in the last 30 days. When it can’t get an answer from Jev, only well-known sites are called Safe; others show “Couldn’t fully check” or “Check first”, or a warning if the quick check finds red flags in the link, its text or the page title. Keep your browser’s own Safe Browsing protection switched on.
Who runs LinkGuard
LinkGuard is built and run by an independent developer.