Skip to main content
Link’d DMR

Legal

Privacy Policy

Last updated: August 12, 2026

Scope

This policy covers linkddmr.com, LinkdDMR accounts, the Android beta app, private groups, and the account-authorized cellular push-to-talk public beta.

What we collect

We store the email address, textual Linkd ID, server-assigned numeric Linkd Radio ID, optional RF DMR ID, display name, password hash, account and email-verification status, registered-device identifiers and names, reported and attested device-type/capability labels, session identifiers, private-group membership and roles, invitations, blocks or bans, hashed one-time verification/reset token state, and limited security audit events needed to run accounts safely. Radio features also store the latest per-device group-presence lease, short-lived call-alert sender/recipient state, current Cellular floor authority, and reasoned manager-action receipts. When cellular PTT is enabled, the service transiently processes participant, device, group, floor-control, and network metadata needed to authorize and route a live call. The download counter stores an HMAC-authenticated random-browser credential only as a separate server-held HMAC digest, grouped by release and UTC day; it does not store the browser value, IP address, or user agent in the counter. The account database uses separate IP-derived one-way hashes for rate limiting, including a coarse anti-inflation limit on counted download starts; the web server and reverse proxy may also process raw IP addresses in ordinary access and security logs. A diagnostic support submission stores only the small, sanitized preview you explicitly approve, not the selected source file. Contact and beta forms contain the details you choose to submit. We do not use advertising trackers.

How information is used

Account data is used to authenticate you and manage the private groups and devices you control. When transactional delivery is configured, one-time links can verify mailbox ownership or reset a password. Email-verification status does not currently gate sign-in, private groups, or cellular PTT. In the cellular beta, current group membership, account session, and registered Android device status control access to that group's live audio room. Cloud groups do not authorize RF bridging. Data is not sold or shared for advertising.

Transactional email

A configured transactional email provider receives the destination address and verification or password-reset message, including its short-lived one-time link, solely to deliver that message. LinkdDMR stores the token hash, bounded expiry, generation, and delivered/consumed/revoked state. To keep public reset requests from revealing whether an account exists, the normalized destination is briefly held in an authenticated-encrypted request queue and looked up by a background worker. While a message awaits delivery, its one-time token is likewise held in an authenticated-encrypted outbox. The web service can encrypt with a public key but cannot decrypt these rows; the matching private key is available only to the isolated delivery worker and stays outside the database. Plaintext links are not written to application logs. Provider delivery, retention, bounce, complaint, and subprocessor terms must be reviewed before production activation. If delivery is not configured, the site says so and does not claim that an email was sent.

Voice and radio information

The account database does not store DMR Enhanced Privacy keys or ARC4 material. In the public cellular beta, a self-hosted LiveKit selective-forwarding server transiently receives, processes, and routes live audio to authorized room participants. One owner-authorized CJ-1 may archive its incoming cellular and decoded RF receptions only while Android displays a dedicated system recording notification. Cellular archives are sender-floor correlated; RF archives are bound to the exact signed-in CJ-1 owner/device and current private group. All archive audio is encrypted with a dedicated AES-256-GCM key before database storage and expires after at most 30 days; every other account and device receives no archive permission. For that exact owner workflow, a separate isolated delivery worker may send the encrypted archive after decryption to the owner's configured Telegram chat. Telegram then processes and retains that delivered copy under its own account and retention controls; deleting the website database copy does not delete a copy already delivered to Telegram. Transport encryption protects cellular audio in transit, but this cellular path is not end-to-end encrypted; the service and receiving devices can process the audio, and participants may capture it. A talkgroup room is limited to 64 concurrent participants, and restrictive networks may fail because the beta has no TURN/TLS fallback. Anything transmitted over real DMR or analog radio is broadcast RF and may be received by compatible radio equipment.

Security and retention

Passwords are stored only as salted, memory-hard hashes. Login tokens are stored as one-way hashes. Verification and password-reset tokens are one-way hashed for validation, expire, and use only short-lived authenticated-encrypted queue material for asynchronous delivery. Verification/reset token and associated outbox records are removed 30 days after expiry. Finalized reset-request queue records are removed after two days, with a 30-day hard limit for any abandoned request record. Expired sessions are removed, expired invitation records are removed after 30 days, diagnostic support summaries expire after 30 days, and rate-limit records after two days. Per-day download-counter digests are removed after two days; the random HttpOnly browser credential used only for deduplication expires after one year. A presence table holds only the latest heartbeat for each group/device and expired rows are removed after one day; call-alert records are also removed one day after expiry. Routine security audit events are removed after 90 days. Reasoned group manager-action receipts are immutable during their one-year security retention and are then removed only by an age-gated operator cleanup. Server access and security logs are rotated and retained only for a limited operational period. Account and active membership records remain while the account is active.

Access and deletion

You can remove registered devices, leave groups, manage your blocked-user list, download your account data—including your Radio IDs, device labels, latest presence, call alerts, redacted blocked-user and group-ban records, and manager-action records involving you—or permanently delete your account from the account dashboard. Export uses one consistent database snapshot and rechecks the exact active session. Deletion verifies the current password and exact session together, and removes active account, block, ban, presence, and call-alert data. Pseudonymous manager-action receipts containing actor/target UUIDs, an idempotency UUID and integrity fingerprint, action, reason, and result remain for the balance of their one-year security period; limited copies may also remain in rotating security backups until those backups expire.

Changes

Material changes will be reflected on this page with a new last-updated date.