← Back to home

Privacy Policy

This policy covers both this website and the browser extension that feeds it. It explains what is collected, why, where it goes — and, just as importantly, what is never done with it.

Last updated: 26 July 2026

Who this policy covers

Post Analytics is self-hosted software. This page describes the specific instance you are visiting now, run by the individual who operates it — not a company, and not a shared service holding other people’s data alongside yours.

The browser extension sends data to exactly one place: the instance address its user types into the extension’s own settings. Nothing is routed through the developer, and there is no central server. If the extension is pointed at a different instance, that instance’s operator is responsible for what is sent there.

What is collected

Two kinds of information are held here:

  • Account data — your username, your password (stored hashed, never in readable form), your language preference, your session, and any API tokens you create for the extension.
  • Captured post data — the text and metadata of the LinkedIn posts you choose to capture, along with the names, headlines, profile links and connection degree of the people who reacted to, commented on or reposted them.

The extension reads only what is already on screen in a tab you have open, and only at the moment you press one of its capture buttons. It does not run in the background, does not browse on your behalf, and contains no analytics or telemetry of its own.

Information about other people

Engagement data is, unavoidably, information about other people — those who interacted publicly with a post. It is read from what LinkedIn had already shown to the account holder, and it is stored only on this instance.

It is never sold, never shared with advertisers, and never combined with data from outside sources. It is not used to build a profile of anyone for any purpose beyond the account holder’s own view of their own posts.

If you believe this instance holds information about you and you would like it removed, write to the address at the bottom of this page and it will be deleted.

What is never done

  • Your data is never sold, rented or licensed to anyone.
  • It is never used for advertising, ad targeting or audience building.
  • This site runs no third-party analytics, no tracking pixels and no advertising code. The extension carries none either.
  • Nothing is transferred to any third party, except where the operator is compelled to by law.
  • Nothing is used to assess creditworthiness or for lending decisions.

Cookies

Two cookies are used. The session cookie keeps you signed in: it carries no tracking identifier and is discarded when you sign out, and it lasts up to 30 days from your last visit, so that signing in once does not have to be repeated on every visit. The language cookie records which of the site's two languages you picked, so the choice survives to your next visit; it holds nothing but a language code, is set only if you use the language switcher, and is never set at all while you are signed in — your account setting is used then instead. Both are strictly necessary to provide what you asked for, and neither is shared with anyone. There are no advertising or analytics cookies to consent to, because there is no advertising or analytics — which is also why this site asks for no cookie consent: EU law exempts strictly necessary cookies of this kind from it.

How it is protected

The site requires a username and password. Passwords are stored as salted PBKDF2-SHA256 hashes, never in readable form, so they cannot be recovered from the database.

API tokens are stored hashed for verification and, additionally, encrypted at rest so that a token you created earlier can be shown to you again on the settings page. That means a token is recoverable by this instance, unlike a password — so treat one like a password, and revoke it from the settings page if it is ever exposed.

Traffic between your browser and this site is served over HTTPS.

How long it is kept

Captured data is kept until it is deleted. You can remove posts and people from the interface at any time; the operator can remove anything else, including an entire account. Deleting an account also removes its sessions and its API tokens.

There is no automatic expiry — nothing is quietly deleted behind your back, and nothing is quietly kept after you delete it.

Your rights

You can ask what is held about you, ask for it to be corrected, ask for a copy of it, or ask for it to be deleted. Requests go to the contact address below and do not need to be in any particular form.

If you are in the EU or EEA, you also have the right to complain to your national data protection authority. For Italy, that is the Garante per la protezione dei dati personali.

Changes to this policy

If this policy changes, the date at the top of the page changes with it. Material changes affecting data already held will be raised with account holders directly rather than only posted here.

Contact

Questions about this policy, or about data held on this instance: ale.impe@gmail.com