← Back to Sirclink

Privacy Policy

Last updated: July 13, 2026

Sirclink (“we”, “our”, “the app”) is a private social network built around one idea: the likes and comments on your posts are visible only to you, the author. This policy explains what information we collect, why, and how you can control it — across the Sirclink website and the Sirclink Android app, which share the same account and data.

Information we collect

Account information. Email address, display name, and a password (stored only as a salted hash — we never see or store your plain-text password). Optionally, a bio and organization you choose to add to your profile.

Content you create. Posts, comments, likes, group names, and direct messages you send to friends. Post visibility is controlled by you (all friends, a specific group, or hand-picked recipients).

Connections. Friend requests and friendships, and which groups you organize friends into.

Messaging status. Whether a direct message has been read (“Seen”), and a short-lived signal used to show “typing…” to the person you’re chatting with. Typing status is not stored beyond a few seconds.

Automatically collected. Basic technical data needed to operate the service securely, such as IP address (used only for rate-limiting against abuse, e.g. brute-force login attempts) and timestamps on your activity.

The core privacy design

Likes and comments on a post are visible only to that post’s author. Someone who comments on your post cannot see whether anyone else liked or commented — including you replying to others. This rule is enforced on our server for every request, not just hidden in the app’s interface.

How we use your information

  • To create and secure your account, including email verification and password reset codes.
  • To operate core features: posting, commenting, liking, friending, grouping, and direct messaging.
  • To notify you of relevant activity (a friend request, a comment on your post, a new message).
  • To detect and prevent abuse, such as automated account creation or brute-force login attempts.

We do not sell your data, and we do not use it for advertising. Sirclink has no ads.

Who we share data with

We use a small number of service providers to operate Sirclink, each only for the specific job below:

  • Resend — sends verification and password-reset emails on our behalf.
  • Vercel — hosts the website and its backend.
  • Neon (PostgreSQL) — stores the application database.

None of these providers are permitted to use your data for their own purposes. We do not share your data with advertisers or data brokers.

Your controls

  • Edit or delete any post, comment, or message you’ve sent, at any time.
  • Remove a friend or leave a group whenever you choose.
  • Delete your account permanently from Profile → Delete Account. This immediately and irreversibly removes your posts, comments, likes, messages, friendships, and groups from our systems.

Data security

Passwords are hashed with bcrypt and never stored in plain text. All traffic between your device and Sirclink is encrypted (HTTPS/TLS). Access to the production database is restricted to the service itself.

Children’s privacy

Sirclink is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If we make material changes to this policy, we’ll update the date at the top of this page.

Contact

Questions about this policy or your data? Reach us at helpsirclink@gmail.com.