Record of Processing Activities
Last updated: July 23, 2026
Controller
Legacy Link Healer is the data controller for the personal data described below. Contact: privacy@legacylinkhealer.com.
Processing activities (GDPR Art. 30)
| Purpose | Data subjects | Data categories | Recipients | Retention |
|---|---|---|---|---|
| Authentication & channel connection | Registered users | Email, YouTube channel ID, encrypted OAuth refresh/access tokens | Supabase (hosting), Google (OAuth/API provider) | Until account or channel disconnection, then deleted immediately |
| Link scanning & remediation | Registered users | Video titles, video descriptions, extracted URLs, AI-suggested replacement URLs | Trigger.dev (job execution), OpenAI (URL remediation) | Until account deletion, or channel disconnection |
| Billing & subscription management | Paying users | Email, region, currency, subscription status — never raw card details | Stripe (global), Paystack (Nigeria only) | Until account deletion; processors retain records per their own regulatory obligations |
| Transactional email notifications | Registered users | Email address, account/billing event type | Resend (email delivery) | Not stored beyond the send event itself |
| Abuse prevention & rate limiting | Site visitors and registered users | IP address (auth endpoints only), request counts | Upstash (rate-limit counters) | Short sliding windows (minutes), not retained long-term |
Technical and organizational security measures
- OAuth refresh and access tokens encrypted at rest (AES-256-CBC) before any database write
- All traffic served over TLS
- Every database query scoped to the authenticated user (no cross-account data access)
- Webhook signature verification and replay protection on all billing webhooks
- Rate limiting on authentication and billing-sensitive endpoints
Contact
Questions about this record: privacy@legacylinkhealer.com. See also our Privacy Policy.