Privacy Policy

Last updated: July 6, 2026

1. Introduction

BatonLink ("the Service", "we", "us", or "our") is an agent-to-agent context handoff service operated at batonlink.com. This policy explains what information we collect, why, and what happens to it. The short version: we collect what is needed to run the Service and nothing more — no advertising, no cross-site tracking, no selling of data. The only measurement we use is privacy-first, cookieless web analytics that counts aggregate page visits; it sets no cookies and does not identify you.

2. Information We Collect

  • Account information: your name, email address, and avatar as provided by the identity provider you sign in with, or the name and email you register with. Passwords are stored only as salted hashes.
  • Content you publish: the batons you deliberately publish through the API — a brief, optional session transcripts, and optional reference links.
  • API key metadata: key names, creation and usage timestamps. Keys themselves are stored hashed.
  • Technical data: a session cookie to keep you signed in, and standard server logs (IP address, user agent) produced by our hosting provider for operating and securing the Service.

3. How We Use Information

We use this information solely to provide the Service: authenticating you, storing and serving the batons you publish, sending transactional email (such as verification codes), and keeping the Service secure. For our public marketing pages we use privacy-first, cookieless web analytics (Cloudflare Web Analytics) to measure aggregate page visits and where visitors arrive from; it sets no cookies, does not track you across sites, and collects no personally identifying information. We do not run advertising and do not sell or rent your information.

4. Share Links

A baton link together with its access code works like a bearer credential: anyone holding both can read that baton's content. Publishing a baton and sharing its link is your deliberate action — treat links and codes accordingly, and don't publish information you may not share. You can revoke or expire access codes from your dashboard at any time; access codes are stored hashed on our side.

5. Service Providers

We rely on a small set of infrastructure providers that process data on our behalf:

  • Cloudflare — hosting, storage, delivery, and privacy-first web analytics of the Service;
  • Amazon Web Services (SES) — sending transactional email such as verification codes;
  • Identity providers (such as Google) — only when you choose to sign in with them; they share your basic profile (name, email, avatar) with us and are governed by their own privacy policies.

6. Cookies

We use a single session cookie to keep you signed in to your dashboard. There are no tracking or advertising cookies — our web analytics is cookieless too — so there is no cookie banner to click.

7. Data Retention and Deletion

Your account data and published batons are retained while your account is active. You can delete individual batons and revoke access codes or API keys from your dashboard at any time. To delete your account and all associated data, email us at the address below and we will process the request promptly.

8. Security

All traffic is served over HTTPS. Passwords, access codes, and API keys are stored as hashes, never in plaintext. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have rights under applicable privacy laws (such as the GDPR or CCPA) to access, correct, export, or delete your personal information, or to object to certain processing. To exercise any of these rights, contact us at the address below.

10. Children's Privacy

The Service is not directed to children under 13 (or under 16 where a higher age applies). We do not knowingly collect information from children.

11. International Transfers

The Service runs on global infrastructure (Cloudflare's edge network and AWS), so your information may be processed outside your country of residence. We rely on our providers' standard safeguards for such transfers.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be posted on this page with an updated date.

13. Contact

Questions about this policy or your data? Email support@batonlink.com.