privacy
last updated 16 september 2026
lynxr is run by lynxr LLC (“we”, “us”), a Massachusetts limited liability company and a partner company of Lynx Media Group LLC. this page covers everything at lynxr.io — the public site, the creator app, and the internal agency tool. it says what we collect, why, who else can see it, how long we keep it, and how to make us delete it.
it is written to be read. where something might reasonably surprise you, we have said so plainly rather than burying it.
the short version
- the wait list is used for launch news and occasional updates. nothing else, and one click stops it.
- what you make in lynxr is yours. other creators cannot see it, and that is enforced by the database rather than by the interface.
- we can see the video links you paste. not your notes, your companies, or your scripts.
- we do not sell data, we do not run ads, and there is no analytics or tracking on this site.
- you can delete your account yourself, instantly, from settings.
the wait list
if you enter your email on the wait list page we store three things: your email address, the date and time you entered it, and a short label for the link you arrived from — for example a campaign tag, or the site that referred you. for referrals we keep only the hostname (“tiktok.com”), never the full referring address, because a full address can carry search terms or private path segments that are none of our business.
we also record the exact wording you agreed to at the time, so that if we ever change what we promise, we can tell who agreed to what.
we use it to tell you when lynxr launches, and to send the occasional update on what we are building. that is all. we do not sell it, rent it, or share it outside the processors listed below, and we will not add you to any other list. every email carries a one-click unsubscribe, and unsubscribing stops all of it.
people who joined before 17 august 2026 agreed to a narrower promise — a launch email only — and we hold them to it: they will not get product updates unless they tell us they want them. that is why we store which version of this promise each person agreed to.
lawful basis: your consent, which you can withdraw at any time by unsubscribing or emailing us.
your account
if you have a lynxr account we store the email address you signed up with, and optionally a display name, a contact email and the niches you work in, if you choose to fill those in.
passwords are handled by our authentication provider and stored hashed. we never see them, cannot recover them, and could not tell you your password if you asked.
if you choose to sign in with google instead of a password, we receive your email address from them and nothing else — we do not ask for, receive or store your contacts, your calendar, your photos or anything you do on their services. we never see your google password.
if the address you sign in with already has a lynxr account, it is the same account — signing in with google does not make a second one.
lawful basis: performance of a contract — we cannot run an account for you without it.
what you create in lynxr
when you use the app we store what you put into it: the companies you add, the video links you paste, any notes you write, and the scripts produced from them.
this is yours. other creators using lynxr cannot see any of it. that separation is enforced by row-level security in the database, so it holds even if the interface has a bug — a request for someone else's data returns nothing rather than returning theirs.
what our staff can see: the video links you paste are recorded on our side, so we can learn which formats are performing across the creators we work with. your notes, your companies and your scripts are not used this way. we are telling you because you would reasonably assume otherwise, and because that shared source library is part of what makes lynxr better for everyone using it.
lawful basis: performance of a contract, for storing and producing your work; our legitimate interest in understanding which video formats perform, for the link collection.
videos we collect from public platforms
lynxr is built on a database of thousands of publicly posted videos from TikTok, Instagram and YouTube. for each one we hold the link, the account handle that posted it, the caption, public engagement numbers, and a machine-generated transcript and shot list.
if you are a creator whose public video is in there: it is used only to understand format — structure, pacing, how a hook is built. the database is never published, never resold, and is not visible to anyone outside our staff. we do not republish your video or your words as content. if you would rather not be in it, email us and we will remove you; you do not have to explain why.
lawful basis: our legitimate interest in analysing publicly available content to understand video formats, weighed against the limited, internal use described above.
how we use AI
producing a script means sending material to an AI provider: the video's transcript and caption, and the text of a company's website when you add that company. speech is transcribed by software we run ourselves rather than sent to a transcription service, on a server we rent from Fly.io.
our AI provider processes this in order to return a result to us, and does not use it to train their models. nothing here makes an automated decision with a legal or similarly significant effect — it writes a draft script, and what you do with it is yours to decide.
who else processes your data
we use these services to run lynxr. they act on our instructions and for no other purpose:
- Supabase — the database, and sign-in
- Anthropic — the AI that reads a video and writes the script
- Fly.io — the machine that downloads a video, transcribes it and runs the pipeline
- Resend — sends our emails
- Apify — collecting publicly posted video data
- Google — sign-in, if you choose it; and a copy of the wait list is mirrored into a private spreadsheet, so that signups land somewhere we actually look
- GitHub — hosts this site and keeps standard server logs, which include visitors' IP addresses
- Cloudflare — sits in front of this site, so every visitor’s request reaches it before GitHub, including their IP address
to read a video’s title and caption at the moment you paste it, your browser asks a public relay service (allorigins.win, or codetabs.com if the first is down) to fetch the page for it, because the platforms do not allow us to fetch it directly. that relay sees the link you pasted and your IP address. we have no contract with them and they are not storing it for us — if you would rather that did not happen, the title simply does not load, and everything else about the script still works.
we do not sell personal information, and we do not share it with anyone for advertising.
where your data is held
our providers are US-based, so your data is stored and processed in the United States. if you are in the UK or EU, that means it is transferred outside your home jurisdiction; our providers offer standard contractual clauses covering those transfers.
how long we keep it
wait list addresses are deleted once we have launched and emailed you, or sooner if you ask.
account data is kept for as long as your account is open. you can close it yourself at any time — settings → delete account — and it happens immediately: the account and everything in it goes, your companies, saved links and scripts included. we cannot undo it for you. if you would rather we did it, email us and we will action it within 30 days.
one thing survives, and we want to be straight about it: the link you pasted, and what we extracted from that public video — its transcript, shot list and structure — stay in our shared library of video formats. that record is filed under the video’s own address, not under you: it carries no name, no email and no account id, and after you delete your account nothing connects it to you. your companies, your notes and your scripts all go.
a single still frame from each video you paste is also stored, on a public address worked out from the video’s own link, so that the video has a thumbnail. it is the same frame for everyone who pastes that video and it is not filed under you either.
feedback you send us is kept, but is detached from your account when you delete it — the note survives, the link to you does not.
after deletion, copies can persist in encrypted backups for a short period before they age out.
how we protect it
everything travels over an encrypted connection. passwords are hashed by our authentication provider. access between accounts is enforced by the database itself rather than by the interface, so one creator cannot reach another's data even if a page has a bug. only staff accounts can reach agency data, and that is enforced the same way.
no system is perfect. if there is ever a breach affecting your data we will tell you, and any regulator we are required to tell, without undue delay.
your rights
wherever you live, you can ask us to:
- tell you what we hold about you, and give you a copy
- correct anything that is wrong
- delete it
- stop using it for a particular purpose, or withdraw your consent
- send you a portable copy of what you have put into lynxr
email hello@lynxr.io. you do not need to give a reason, it costs nothing, and we will respond within 30 days. we will not treat you differently for asking.
if you are in the UK or EU you also have the right to complain to your data protection authority.
if you are in california
you have the right to know what we collect and why, to request deletion, to request a copy, and not to be discriminated against for exercising any of them. the categories we collect are set out above. we do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the past twelve months.
cookies and local storage
we do not use tracking or advertising cookies, and there is no analytics on this site — we cannot tell you how many people have visited this page.
the app stores two things in your browser: a sign-in token, so you are not asked to log in on every page, and a cached copy of your own work, so it loads instantly. both are required for the app to function, neither is used to track you, and both are cleared when you sign out.
children
lynxr is for adults. you must be 18 or older to use it, and we do not knowingly collect data from anyone under 18. if you believe someone under 18 has given us information, email us and we will delete it and close the account.
changes to this policy
if we change it we will update the date at the top. if a change materially affects how we use data you have already given us — the wait list in particular — we will email you rather than quietly editing this page.
contact
lynxr LLC
15 Farrington Ave, Allston MA 02134, USA
hello@lynxr.io