Last updated: September 10, 2026
Who we are
BacklinkGPT is operated by FMD Labs GmbH, Ernst-Haeckel-Platz 5/6, 07745 Jena, Germany, registered with the Commercial Register at the Local Court of Jena, HRB 523255 (the "controller" for the processing described here, except where noted otherwise). Contact details are at the end of this policy.
BacklinkGPT is an AI-assisted link-building agent for businesses: it finds pages that could link to a customer's website, identifies a relevant business contact for each page, drafts outreach messages, and (with the customer's approval, or on the customer's autopilot setting) sends and manages that outreach from the customer's own connected accounts. Because of what the product does, this policy covers two very different groups of people: our customers and the outreach recipients (prospects) our customers' agents contact. Both are addressed below.
1. Data we process about customers
When you create and use a BacklinkGPT workspace, we process:
- Account data: name, email address, sign-in identifiers (Google sign-in or magic-link email), workspace and organization details.
- Workspace content: your domain, product and positioning descriptions, playbook rules, guidance you give the agent, and everything the agent produces for you (prospect lists, drafts, conversation history).
- Billing data: handled by our payment provider acting as merchant of record. We never see or store full card numbers; we receive subscription status, plan, and invoicing metadata.
- Usage and diagnostics: product analytics events, log and error data, and device/browser metadata, used to operate, secure, and improve the service.
- Support and communication: emails you exchange with us, in-app notifications, and (if you opt in) product update emails. Non-essential email types can be switched off in your notification settings at any time.
Legal bases: performance of the contract (Art. 6(1)(b) GDPR) for account, workspace, and billing data; legitimate interest (Art. 6(1)(f) GDPR) in operating and improving a secure service for usage and diagnostics data; consent (Art. 6(1)(a) GDPR) where we ask for it.
2. Connected mailboxes and LinkedIn accounts
If you connect a sending account (Google, Microsoft, IMAP, or LinkedIn), the connection is established through our messaging integration provider (Unipile). We then process, on your behalf: the account's display name and address, the outreach messages the agent sends from it, and the replies those messages receive, so the agent can run conversations, detect replies, and stop sequences.
We access connected accounts only to operate your outreach. The sign-in credentials for a connected account are held by the integration provider, not by us: on our side we store only the account identifier and the message data described above, and that link is removed when you disconnect the account. Incoming messages on a connected account are checked to decide whether they belong to an outreach conversation the agent is part of; messages that do not match are discarded rather than stored, and your mailbox is never used for anything beyond running your outreach.
3. Prospect data (people our customers' agents contact)
This is the product's largest category of personal data, and if you received an email or LinkedIn message sent through BacklinkGPT, this section is about you.
What we process: name, role/title, company, business email address, public LinkedIn profile URL, the page and website the outreach relates to, publicly available site metrics, and the ensuing conversation (your replies).
Where it comes from: public web pages (the page we are writing about, its site, public author and imprint pages), public search results, public professional profiles, and licensed business-contact and site-metrics data providers. We also verify email addresses through a verification provider before sending. This data is not collected from the data subject directly; this policy serves as the information under Art. 14 GDPR and is publicly available at backlinkgpt.com/legal/privacy.
Why and on what legal basis: legitimate interest (Art. 6(1)(f) GDPR) of our customers and us in relevant, low-volume business-to-business outreach about a specific page the recipient is responsible for. The agent is built to keep that interest proportionate: prospects are filtered for topical relevance before anyone is contacted, sending is capped and paced per sender, sequences are short and stop at the first reply or sign of disinterest.
Opt-out and suppression: every outreach email carries a one-click unsubscribe (RFC 8058 List-Unsubscribe). An opt-out is recorded in a suppression list and cascades: the contact and their address are excluded from all future sequences, and we keep the minimal suppression record itself so the opt-out stays effective. You can also object informally: replying "no" stops the sequence.
Your rights as a prospect: you can request access, rectification, or erasure, and object to processing at any time using the contact details below. Erasure requests are honored across the workspace that contacted you and our systems, except for the suppression record needed to prevent renewed contact.
4. Free tools and website visitors
Our free tools (for example the authority checker and opportunity finder) process the domain you enter and, where you request emailed results, your email address, used to deliver the result and, only with your consent, for product emails. Visiting the website itself is measured with product analytics (see section 5); we do not run third-party advertising trackers on the application.
5. Service providers (sub-processors)
We use a small set of providers, each bound by data-processing agreements:
- Hosting: Hetzner Online GmbH, Germany (application and databases run on servers in Germany).
- Payments / merchant of record: Polar (subscription billing; card data never touches our systems).
- Transactional and product email: Resend.
- Mailbox and LinkedIn connectivity: Unipile.
- Prospect page content: Firecrawl (fetches the public pages the agent evaluates and writes about).
- Contact discovery: Apify (finds publicly listed employees and roles for prospect companies).
- AI models: Google (Gemini). Page content, workspace context, and drafts are processed to generate verdicts and copy; our paid API terms prohibit use of this data to train the provider's models.
- Product analytics: PostHog.
- Error monitoring: Sentry.
- Customer lifecycle email: Loops.
- Site and backlink metrics: Ahrefs (domain-level metrics; not personal data in most cases).
- Email verification: a verification provider that checks deliverability of prospect addresses before sending.
Where a provider processes data outside the EU/EEA, transfers rest on an adequacy decision (including the EU-U.S. Data Privacy Framework where certified) or EU Standard Contractual Clauses.
6. Retention
- Customer account and workspace data: for the duration of the contract, then deleted or anonymized unless statutory retention periods (commercial and tax law) require longer storage of specific records.
- Connected-account tokens: until you disconnect the account or delete the workspace.
- Prospect data: kept while the related engagement and its conversation are active and for a limited period afterwards for deduplication (so the same person is not re-contacted as new); deleted on request at any time.
- Suppression records: kept permanently, because they exist to prevent renewed contact.
- Logs and diagnostics: short rotation periods measured in days to months.
7. Security
Data is encrypted in transit (TLS) and at rest. Search Console tokens are additionally encrypted at the application level (AES-256-GCM; see the Google section below). Access to production systems is restricted, logged, and limited to what operating the service requires.
8. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interest (Art. 21), as well as the right to withdraw consent at any time with effect for the future. To exercise any of these, contact us using the details below.
You also have the right to lodge a complaint with a supervisory authority, in particular the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI), which is the authority responsible for our registered seat.
Google API Services (Search Console)
BacklinkGPT lets you optionally connect your Google Search Console account. If you do, we access your Search Console data in read-only mode (clicks, impressions, rankings, queries, and pages of your own verified website) to display your search performance in your dashboard, measure the impact of acquired backlinks, and suggest relevant keywords for your link-building campaigns.
BacklinkGPT's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use your Search Console data to provide and improve the features described above, which are visible in your own account.
- We do not transfer, sell, or share this data with third parties, and we do not use it for advertising purposes.
- We do not allow humans to read this data unless we have your explicit consent, it is necessary for security purposes, or we are required to do so by law.
- OAuth tokens are stored encrypted (AES-256-GCM) and are deleted when you disconnect the integration.
You can revoke access at any time by disconnecting Search Console in the app (Connected Accounts), which also revokes the grant at Google, or via your Google account security settings.
Changes to the Privacy Policy
We update this policy when the service or the legal situation changes. Material changes are announced to customers by email and published here with an updated date.
Responsible Party
The responsible party for data processing is:
If you have any questions about data protection, or want to exercise any of the rights above (as a customer or as an outreach recipient), you can contact us at any time.