Purl

Privacy Policy

What Purl collects when you save links, how it's used and stored, and how to delete your data.

Purl keeps the links you save and little else. This page explains what we collect, why, who helps us run Purl, and how to delete it all.

The short version: we collect what we need to run your account and your links. We don't sell it, show ads, or use it to train AI. You can delete everything from Settings at any time.

What we collect

  • Your account. Your name, email address and profile picture from Google or GitHub, and a username (we make one for you, and you can change it). We use them to sign you in and to show who you are, including on folders you share.
  • Sign-in details. The tokens your sign-in provider gives us to keep your account linked, and a record of each session: when it started, its IP address and browser. We use them to keep you signed in and your account secure.
  • Your links. The URL, and the title, description, icon and image we find on the page, plus its domain, its type (web, YouTube, PDF or audio) and when you saved it. This is the point of Purl: keeping your links in one place.
  • Your folders. Each folder's name, emoji, description and order, and whether it's shared. We use them to organize your links.
  • Preferences. Whether you see a list or a grid, and whether links show their folder. We use them to remember how you like Purl.
  • API keys and connected apps. The name of each API key and each app or assistant you connect, and when they were created. We use them to let you use the API and MCP, and to let you revoke access.
  • Feedback. What you write, with your name and email, sent to us as an email. We use it to read and reply to your feedback.
  • Usage and speed. Page views and how fast pages load, collected without cookies. We use them to see what works and what's slow.
  • Request counts. How many requests came recently from an IP address. We use them to keep Purl available for everyone and block abuse.

When you save a link, Purl's servers visit the page to read its title, description, icon and image. That request comes from Purl, not from you. We keep those details, not a copy of the page.

Icons and images are loaded from the original sites when you look at your links, so those sites can see the request, as they would if you visited them.

Sharing a folder

Folders are private. If you make a folder public, anyone with its link can see its name, emoji and description, every link in it, and your name, username and profile picture. We ask search engines not to index shared folders. Make the folder private again and its link stops working.

Browser extension

The Purl extension for Chrome adds one button. When you click it, the extension reads the address of the tab you're on and sends it to purl.live along with your signed-in session, which saves it as a link. That's all it sends.

It asks Chrome for two permissions: activeTab, which gives it access to the tab you click it on, and scripting, which it uses to show the "Saved with Purl" message on that page. It doesn't read what's on the pages you visit, it can't see your browsing history or your other tabs, and it only talks to purl.live.

We use what the extension sends only to save the link you clicked, and for nothing else. We don't sell it, share it for advertising or use it to build a profile of your browsing.

Who helps us run Purl

CompanyWhat it does for Purl
VercelHosts Purl, and measures page views and speed.
SupabaseStores your data, and keeps your devices in sync.
UpstashCounts requests to limit abuse.
ResendDelivers the feedback you send us.
Google and GitHubSign you in.

They handle your data to provide those services to us. Their servers are in several countries, so your data may be processed outside the one you live in.

Apps and assistants you connect through MCP or the API act with your permission and can read and change your links and folders. What they do with what they read is covered by their own policies.

What we don't do

  • We don't sell or rent your data.
  • We don't show ads or track you across other sites.
  • Purl has no AI features, and we don't use your links to train AI models.

Cookies and storage

Purl uses only what it needs: cookies that keep you signed in, a cookie that remembers whether you prefer a list or a grid on shared folders, and a few settings kept in your browser, such as your emoji skin tone and whether you've seen the landing page animation. If you install Purl as an app, your browser also keeps a copy of some app files so it works offline.

There are no advertising or tracking cookies.

Your choices

  • See your data: it's all in the app, and the API returns every link and folder you've saved.
  • Change it: edit or delete any link or folder, or change your username.
  • Revoke access: remove API keys and connected apps in Settings โ†’ Integrations.
  • Delete everything: choose Delete account in Settings โ†’ Account. It permanently deletes your account, links, folders, sessions and connected sign-ins. Copies in our database provider's backups are removed as those backups expire.

Depending on where you live, you may have legal rights over your data, such as access, correction, deletion and moving it elsewhere. Most of that you can do yourself as above. For anything else, send us feedback.

Children

Purl isn't meant for children under 13.

Changes

When we change this page, the date at the top changes too. If the change matters, we'll tell you in Purl.

Contact

Questions? Send Feedback from the account menu in Purl: it reaches us by email. You can also open an issue on GitHub (opens in a new tab). Purl is made by @nublson (opens in a new tab).

The rules for using Purl are in the Terms of Service.