About this policy
Business mailing/contact address: Melade LLC, 311 Harrisburg Ave, Lancaster, PA 17603, United States.
live.link is operated by Melade LLC, formed in Pennsylvania, United States, for creating, saving, previewing and publishing supported websites and documents. This policy describes personal information processed through our website, account and publishing service, and supported agent interfaces. Contact info@live.link about privacy or account closure.
A person publishing a site or document decides what they upload, whom they share it with, and what supported response fields they request. That publisher may have a separate privacy notice and independent legal responsibilities. This policy does not authorize a publisher to collect information unlawfully. If your request concerns a publisher's use of your information, contact the publisher; you may also contact us about information hosted on live.link.
Information we receive
Account and sign-in information. We process your email address, account and sign-in provider identifiers, authentication/session records, and profile information the provider supplies. When you choose Google sign-in, the current integration requests basic identity information: your name, email address, profile picture and Google account identifier. It does not request access to Gmail messages, Google Drive files, contacts or calendars. Google handles your Google password; do not give that password to live.link. GitHub sign-in is an account sign-in method and does not, by itself, authorize access to your repositories.
Your projects and instructions. We process the files, text, code, document fields, prompts, requested outputs, titles, versions, sharing settings and recipient addresses you submit. We also store records needed to perform and safely retry the requested operations, such as project/version identifiers and publication actions. Supported forms and estimate interactions can store reader responses for the publisher. Do not submit passwords, API keys, payment card details or sensitive personal records unless a specifically supported feature explains how to handle them safely.
Service and security information. Requests expose technical information to us and our infrastructure providers, including IP address, browser/device information, request time, requested service resources, success or error status, and authentication or access decisions. We use operational records to provide service, investigate failures and abuse, and enforce usage and access limits. The information visible in a public link is distinct from private account or credential information.
Communications. We process information you send for support, feedback, privacy requests, security reports or disputes, along with relevant correspondence. Please do not send secrets or unnecessary sensitive information in a support message.
Why we use information
We use information to create and protect accounts; authenticate readers and agents; save, preview and deliver work; enforce chosen audiences and credential permissions; perform requested AI functions; persist supported responses; recover interrupted operations; provide support; investigate misuse and security incidents; maintain service reliability; and comply with legal obligations.
Where applicable data-protection law requires a lawful basis, providing requested account and publishing features relies on performance of our agreement with you; proportionate security, abuse prevention and support rely on legitimate interests; legally required records or disclosures rely on legal obligations. Where consent is required for an optional use, we will obtain it separately and explain how to withdraw it. These descriptions do not remove applicable rights to object or restrict processing.
Information required for a chosen feature cannot always be omitted while still using that feature. You can choose supported manual creation or uploads instead of requesting AI generation. Disabling cookies necessary for authentication can prevent sign-in from working.
Google information
Google identity information is used to authenticate you, associate your sign-in with your account, display account information where appropriate, and protect and support that account. It is processed through our identity/database and hosting providers for those purposes. It is not a permission to read your Google Workspace content or act throughout your Google account. Any future feature requesting additional Google permissions must explain that request separately.
You can remove the live.link connection from your Google account settings. Removing Google's connection does not itself delete projects or records already stored by live.link. Contact info@live.link for an account or data deletion request. Signing out, revoking a credential, turning off a publication and deleting stored information are different actions.
AI processing
If you request AI generation, relevant instructions and project content are sent to the configured AI service to produce a result. A document question feature, when available, sends the question and relevant document content for answering. Supported AI requests are routed through OpenRouter to a selected model provider. The provider and model can depend on the feature and deployed configuration.
AI requests can disclose the content included in them to those providers. Their processing and retention conditions may differ. We do not promise that all models have identical retention or training practices. Avoid submitting confidential or regulated information unless the feature and applicable provider arrangements meet your requirements. Account sign-in alone does not authorize generation using your project content.
Who receives information
We use service providers to perform the functions described in this policy. The current service includes:
- Supabase: account authentication and application database services.
- Vercel: application hosting and workflow execution.
- Cloudflare: security and infrastructure, including Turnstile sign-in verification. Turnstile processes browser/request signals under Cloudflare's Turnstile privacy terms. Storage and delivery services apply where the corresponding supported feature uses them.
- Resend: configured delivery of sign-in email.
- OpenRouter and the selected model provider: requested AI generation or document answers.
- Google or GitHub: the sign-in provider you choose, under its own account terms and privacy policy.
Providers receive information needed for the relevant service. This list describes functions, not a claim that every listed feature is enabled for every account. We may disclose information when legally required or reasonably necessary to investigate fraud or abuse, protect rights and safety, or respond to a valid legal process. If the service changes ownership, any handling of personal information must remain subject to applicable law and the commitments that apply to it; a transaction does not grant unlimited new use rights.
Content is also shared with the audience selected by its publisher. A public link can be forwarded, copied, downloaded, indexed or captured by others. Do not publish information you intend to keep private. A recipient's copy is outside our ability to revoke through the original publication.
Retention, removal and copies
Saved revisions are separate versions; editing a project does not overwrite every prior copy. Turning off or expiring a publication prevents access through that publication but does not by itself delete the underlying project, versions, responses or operational records. Revoking agent access does not delete the content that agent previously created.
We retain account and saved-work information for service operation and to honor your choices. Support, security and legal records may need to remain to resolve requests, investigate incidents, meet legal duties or establish and defend claims. Retention depends on the record, purpose, applicable obligations and legal holds. Backups and service-provider systems can have separate deletion cycles. We do not promise immediate erasure from every system when a link is turned off.
To request deletion or account closure, contact info@live.link. We may need to verify that you are entitled to make the request and distinguish your information from other people's records. We will explain applicable limits or information that must remain. Keep your own copy of important work. Deletion from live.link cannot remove copies retained independently by recipients or other services.
Security and processing locations
The service uses access controls, scoped credentials and separation between management and published content to help protect information. No system or transmission can be guaranteed completely secure. Keep account access and agent credentials private; revoke unused connections and tell us promptly if you suspect misuse.
Infrastructure and service providers may process information in the United States and other countries. A local domain or recipient location does not guarantee local data storage. Contact us before submitting information that requires a specified processing location or a separate data processing agreement.
Choices and rights
You can use available controls to change publication access, turn off a link and revoke agent credentials. Depending on applicable law, you may have rights to access, correct or delete your personal information; obtain a portable copy; restrict or object to certain processing; and withdraw consent where consent is the legal basis. Withdrawing consent does not automatically undo processing already performed lawfully.
Send requests or concerns to info@live.link. We may ask for proportionate verification, but do not send a password or full identity document unless a secure and necessary verification process has been explained. We respond as required by applicable law and explain relevant exceptions. You may also complain to the relevant data-protection authority, including the UK Information Commissioner's Office where applicable. Exercising a lawful privacy right will not itself result in unlawful discrimination.
Children and changes
Account holders must be at least 18 years old. The intended initial launch market is the United States only. These are eligibility and launch-market policies, not a claim that we verify every account holder's age or technically block access from other countries.
If you believe a child has provided personal information inappropriately, contact info@live.link so we can investigate. A publisher is responsible for appropriate audience choices and lawful collection through their content.
We will identify the date of changes to this policy and provide additional notice or obtain consent when required. New features or materially different uses of information may need additional disclosures. A later policy change does not automatically authorize unrelated uses of previously collected information.