Privacy Policy
How LinkMe collects, uses, stores and protects information — and what stays on your device.
Effective: August 1, 2026 | Last updated: August 1, 2026
support@dashapi.ai1. Scope and who this covers
This Privacy Policy explains how DashAPI, Inc. (a Delaware corporation) handles personal information in connection with LinkMe, our relationship intelligence application for iOS, and its supporting services (the Service).
It covers three groups of people, whose position differs:
- Users — people with a LinkMe account. We are the controller of your account data and the processor of the records you create.
- Contacts — people whose details a User records in the app. The User is the controller of that information; we process it for them. See clause 14.
- Recipients — people who receive a shared card or open a claimable profile without installing the app.
The DashAPI platform has a separate policy — see theDashAPI Privacy Policy.
2. Who we are and how to reach us
All privacy enquiries are handled by email. We do not publish a postal address.
EU and UK enquiries. Individuals in the EEA and the UK may contact us directly atsupport@dashapi.ai, and we will route the matter to our appointed representative where one is required.
3. On-device processing
LinkMe is built on-device first. Using Apple's on-device model frameworks, the following happen on your iPhone and are not transmitted to us:
- transcription of voice capture and extraction of structured fields from it;
- construction and maintenance of your relationship graph;
- generation of just-in-time briefings from records held locally;
- classification and summarisation of contact records; and
- drafting of follow-ups from local context.
Data leaves your device only where:
- you enable cloud sync or backup;
- you use a feature that inherently requires our servers — sharing a card with a Recipient, claimable profiles, enrichment, or syncing to a DashAPI workspace;
- you consent to cloud AI processing for a specific action; or
- you send us a support request or diagnostic report.
The app indicates whether an operation runs on-device or in the cloud, and you can withdraw consent for cloud processing in the app's privacy settings at any time without losing core functionality.
4. Information we collect
4.1 Information you provide
- Account details — name, email address, and optionally phone number, job title and employer.
- Your profile — what you choose to put on the card you share, including biography, links and contact details.
- Contact records — the names, employers, roles, context, follow-ups and personal details you record about people you meet.
- Voice capture — audio you dictate, and the transcript produced from it. See clause 6.
- Correspondence — support requests, bug reports and feedback.
- Purchases — subscription status. Apple bills you; we receive confirmation of entitlement, not your payment card details.
4.2 Information collected automatically
- Device information — device model, iOS version, app version, language and region, and an app-generated identifier.
- Usage and diagnostics — feature usage events, capture and share counts, session timing, crash and error logs. Used in aggregate to improve the app.
- Exchange events — the fact and time of a card exchange by NameDrop, NFC, QR or link, and the details exchanged.
4.3 Information from other sources
Where you use enrichment, we send a limited identifier — such as a name, email address or company — to third-party business data providers and receive matching professional records in return. We also receive information about a Contact if they claim their profile and update it.
5. Device permissions
| Permission | Why we ask | What happens to the data |
|---|---|---|
| Microphone | Voice capture of notes after a meeting | Transcribed on-device; audio is not sent to us unless you enable a cloud feature that needs it |
| Contacts | Matching people you already know, and saving new contacts you capture | Read on-device; not uploaded unless you enable sync |
| Calendar | Surfacing a briefing before an upcoming meeting | Read on-device to identify participants and timing; not uploaded without your separate consent |
| Notifications | Proactive nudges and follow-up reminders | Delivered via Apple Push Notification service; content is minimised |
| NFC and camera | Tap and QR exchange of cards | Processed on-device at the moment of capture |
Every permission is optional and can be revoked in iOS Settings. Revoking one disables the feature that depends on it and nothing else.
6. Voice capture and recordings
LinkMe is designed for you to dictate your own note after a conversation, not to record the conversation itself. Where any audio you capture includes another person's voice, additional obligations apply to you.
Consent is your responsibility. Many jurisdictions require the consent of every party to a conversation before it may be recorded, and before that recording may be shared with a third party such as us or a transcription provider. Obtain that consent before you record. See clause 9 of theTerms of Service and theAcceptable Use Policy.
Audio is transcribed on-device and, by default, the audio is discarded once the transcript is produced. Where you enable a cloud feature that requires audio or a transcript to leave the device, we retain it only as long as needed to deliver that feature, and in any event no longer than your subscription term plus 30 days, unless the law requires otherwise.
Do not capture special-category information — health, religious or political views, or similar — about other people. If a recording happens to contain it, we process it under the same protections and delete it on request.
7. How and why we use information
| Purpose | Examples | GDPR legal basis |
|---|---|---|
| Providing the Service | Accounts, capture and transcription, briefings, card exchange and web cards, claimable profiles, sync | Performance of a contract |
| Cloud AI features | Enrichment, cloud-assisted drafting where you enable it | Consent, withdrawable at any time |
| Support | Answering questions, diagnosing crashes, restoring data | Performance of a contract; legitimate interests |
| Product improvement | Aggregate, de-identified usage analysis. We do not read your relationship content for this. | Legitimate interests |
| Security and abuse prevention | Authentication, fraud and abuse detection, enforcing our terms | Legitimate interests; legal obligation |
| Communications | Transactional notices about your account; product updates where you opt in | Performance of a contract; consent |
| Legal compliance | Responding to lawful requests; establishing or defending claims | Legal obligation; legitimate interests |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use your relationship data for advertising targeting.
8. AI processing
- On-device models process your content locally. That content is not sent to us or to Apple.
- Where you enable a cloud AI feature, only the context required for that request is sent to the provider listed on our Sub-processors page.
- Our cloud model providers are contractually prohibited from training on your content, and we do not use your content to train our own general-purpose models.
- AI output is probabilistic and may be inaccurate, including about real people. Review it before relying on it.
- We do not use AI to make decisions with legal or similarly significant effects about individuals.
10. Storage, security and retention
On device. Local data is protected by iOS device encryption and whatever passcode, Face ID or Touch ID you have configured. We cannot access it. If you lose the device without a backup, that data is not recoverable by us.
In the cloud. Where you enable sync or use a server-side feature, data travels over TLS and is stored encrypted at rest on servers in the United States, protected by the measures described in our Security Overview.
| Data | Retention |
|---|---|
| Synced records and profile | While your account is active; deleted within 30 days of account deletion, allowing recovery from accidental deletion |
| Audio retained for a cloud feature | No longer than needed for that feature, and never longer than your subscription term plus 30 days |
| Shared web cards | Until you revoke the share or delete your account |
| Support correspondence | Up to 3 years from the last interaction |
| Security and abuse logs | Typically 12 months, longer for an open investigation |
| Purchase and tax records | Up to 7 years, as required by law |
No system is perfectly secure. We use commercially reasonable measures but cannot guarantee absolute security.
11. International transfers
We are based in the United States and our servers are located there, though the app is available worldwide. Where personal data is transferred out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and on transfer risk assessments where required. Emailsupport@dashapi.ai for details of the safeguards applying to a specific transfer.
12. Your rights
Depending on where you live, you may have the right to access your personal information, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out.
Much of this is available directly in the app: view and edit your records, export your data, revoke a shared card, turn off cloud processing, and delete your account. For anything else, emailsupport@dashapi.ai. We verify identity before acting and respond within the period the law requires — one month under the GDPR and UK GDPR, and 45 days under most US state laws.
You may also complain to your supervisory authority — in the EEA, the authority where you live or work; in the UK, the Information Commissioner's Office. We would like the chance to put things right first.
13. US state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia have rights under their state privacy laws, including rights to know, access, delete, correct, obtain a portable copy, and not be discriminated against for exercising them.
The categories we collect are identifiers, professional and employment information, commercial information about your subscription, internet and device activity, and — where you use voice capture — audio data. Sources, purposes and recipients are described in clauses 4, 7 and 9.
We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out of sale or sharing to offer. We use audio and any other sensitive personal information only to provide the Service, to maintain security and to comply with law — never to infer characteristics — so we do not offer a separate "limit the use of sensitive personal information" control.
Make a request, including through an authorised agent, atsupport@dashapi.ai. If we decline, residents of states with an appeal right may appeal by replying to our decision; we respond within 45 days and will tell you how to reach your state attorney general.
14. If you are a Contact, not a user
You may appear in LinkMe because someone you met recorded your details, or because our enrichment feature matched business information about you.
Where a User recorded information about you, that User is the controller and we process it for them. We will forward your access, correction or deletion request to the relevant User and support them in responding, but we cannot act on it unilaterally. Tell us the name or email address of the person or organisation concerned so we can route it.
Enrichment opt-out. Email support@dashapi.ai with the email address or domain you want suppressed. We will stop enriching information about you and keep only the minimum identifier needed to honour that suppression, used for no other purpose. This does not remove your details from the third-party data providers themselves, who are independent controllers — contact them separately.
If you received a shared card or claimed a profile, you can update or remove the details on that profile, or ask us to delete it, at any time.
15. Organisation accounts and DashAPI sync
If your account is provided by an organisation, or you enable synchronisation with a DashAPI workspace, the records you sync become available to that organisation and its administrators, who can access, export, retain and delete them under their own policies. That processing is governed by theDashAPI Privacy Policy and your organisation's own policy. Records you keep only on your device are not affected.
16. Children's privacy
LinkMe is for professional use by people aged 18 and over. We do not knowingly collect personal information from children, and Users must not record information about children in the app. If you believe a child's information has reached us, emailsupport@dashapi.ai and we will delete it.
17. Data breach notification
If we become aware of a personal data breach we will investigate, contain it and assess the risk. Where required by law we will notify the relevant supervisory authority — within 72 hours under the GDPR and UK GDPR where feasible — and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, by email, in-app notice or other reasonable means.
18. Changes to this policy
We may update this policy. Material changes will be notified in the app or by email at least 14 days before they take effect. The "last updated" date at the top always shows the current version. Continuing to use the Service after that date means you accept the update.
19. Complaints and contact
For any privacy question, request or complaint, contact us. We aim to acknowledge within 5 business days and resolve complaints within 30 days, telling you if we need longer.