Security and Privacy
Learn how Linkyhost protects accounts and hosted content, what link controls do, and which responsibilities remain with publishers.
Security model at a glance
Linkyhost combines account authentication, HTTPS delivery, private object storage, publication checks, and optional link controls. These measures reduce risk, but a normal published URL is still accessible to anyone who has it.
| Area | Current protection |
|---|---|
| Account sign-in | Google authentication or a one-time code sent by email |
| Data in transit | HTTPS/TLS for the app, uploads, and hosted links |
| File storage | Google Cloud Storage with provider-managed encryption at rest |
| Hosted-content isolation | User content is served from content subdomains or connected customer domains, separate from the main app origin |
| Link access | Optional Pro password gate for PDF and HTML |
| PDF controls | Optional Pro restricted viewer that hides common download and print actions |
| Publication safety | Automated file-type, content-policy, and archive checks before or during publication |
Account access
Linkyhost does not ask you to create a reusable account password. Sign in with Google or request a one-time code at your email address. Protect the connected Google or email account, because access to it can be used to sign in to Linkyhost.
For shared work, use Teams instead of sharing an account or sign-in code. Member removal takes effect through the team workspace's role checks.
Public, unlisted, and password-protected links
A standard link is unlisted, not private: it is not intended as a public directory entry, but anyone with the URL can open it. Do not rely on an unpredictable address for confidential material.
Pro password protection supports PDF and HTML links. The visitor must supply the password before Linkyhost serves the stored content. This protects the hosted URL; it does not add password encryption to a file after a viewer downloads it.
Use these practices:
- choose a unique password that is not used for another account;
- send the password through a different channel from the link;
- remove or rotate it if it may have been shared too widely; and
- set an expiry when access should end automatically.
PDF download controls
The Pro restricted PDF viewer removes the normal download and print buttons and blocks common browser save, copy, and right-click actions. It is a deterrent, not DRM. Screenshots, screen recording, photography, and determined extraction cannot be fully prevented.
Upload and content checks
Linkyhost verifies supported file types against their contents and checks uploads for prohibited or harmful material. Website archives are also inspected for a deployable static structure and unsafe archive behavior. Some workflows briefly show a processing page until publication checks finish.
Publishers remain responsible for having the rights to share their content and for complying with the Terms. Linkyhost can remove content or suspend accounts in response to policy violations, abuse reports, or valid legal requests.
Analytics and deletion
Visitor analytics store an anonymized network identifier along with available time, referrer, country, and compact browser/device information. See Analytics for interpretation limits.
Deleting a link removes its stored file or site assets and analytics. Deleting an account removes its personal content and account data; team-workspace content is governed by team ownership. These actions are permanent. See Storage and Retention.
Search and sharing considerations
Hosted user content is served with search-engine indexing restrictions by default, but no crawler directive is an access-control mechanism. A link can still be copied, forwarded, cached by a recipient, or captured after viewing.
Before publishing sensitive content:
- remove hidden metadata and information viewers do not need;
- confirm the recipient list and sharing channel;
- enable a password for PDF or HTML when appropriate;
- enable an expiry if access should be temporary;
- understand that download deterrence cannot stop screenshots; and
- keep your own secure backup.
Reports and compliance questions
Report suspected abuse through Report Abuse, send copyright notices through DMCA, or contact support@linkyhost.com.
Linkyhost does not document SAML/SSO, SCIM, or formal compliance certifications as current product features. Do not assume a certification or regulated-workload guarantee that is not stated in a signed agreement; contact support with your organization's requirements before uploading regulated data.