Skip to content

What leaves your device

Linkgarden makes network requests in four situations.

Your bookmarks, folders, and tags are mirrored into your own iCloud private database. This is the only place your library is stored outside the device, and it belongs to you, not to Linkgarden.

See How sync works for what travels and what stays local.

When a bookmark has an address but no name, Linkgarden requests that page and reads its <title> to fill in the name for you.

  • The request goes to the site you bookmarked, and nowhere else.
  • It stops after 128 KB, or as soon as the closing </title> tag arrives.
  • It gives up after 8 seconds.
  • Non-HTML responses are ignored.

This happens when you add a bookmark with an address and leave the name empty, and when you open such a bookmark’s details. It is attempted once per bookmark per session.

When a bookmark with an address is shown and has no icon yet, Linkgarden requests that page, looks for its declared icons, and downloads the best one.

  • The requests go to the site you bookmarked and to whatever icon URL that site declares.
  • The page read stops after 128 KB; the icon must be 100 KB or less.
  • At most three icon candidates are tried, and no more than six of these look-ups run at once.
  • A look-up that finds nothing is not retried while the app is open.

The downloaded icon is stored on the bookmark, so it syncs with the rest of your library and is not fetched again on your other devices.

Both fetches contact the site itself. A site can therefore observe that someone requested it, the same way it would if you loaded the page in a browser — but with no page content sent, no referrer from your library, and nothing identifying which of your bookmarks it was.

Neither fetch happens for anything other than an http or https address.

Linkgarden sends anonymous product analytics to PostHog, hosted in the EU.

What is captured is the shape of an action, never its content. For example, saving a bookmark records that a bookmark was saved, whether it had an address, whether it was a favourite, whether it had a note, how many characters long its name was, and where it was saved from. It does not record the name, the address, or the note.

Across every event, the properties Linkgarden sets are counts, booleans, colour values, and fixed labels like list or safari_extension. No bookmark name, web address, note body, folder name, tag name, or search query text is sent. Search records the length of the query, not the query.

PostHog also attaches an approximate location to every event, estimated from the network address the event arrives from: country, region, city, postal code, time zone, and coordinates accurate to about 10 km. The address itself is discarded, not stored.

This data exists to see which features are actually used, so Linkgarden can be improved — it is never used for advertising, and never sold.

Share Anonymous Usage Data, in Settings under Privacy, is on by default and turns this off immediately, with no relaunch needed. See Settings reference for where it lives.

Saves made from the Safari extension queue their event locally and are sent by the app the next time it runs — the extension itself has no analytics code and makes no network requests of its own.

Linkgarden has no server, no account system, and no other outbound connection. It does not phone home for updates, does not fetch remote configuration, and does not send your library anywhere but your own iCloud account.