Every person who gives a business their phone number is trusting somebody they have never met. This page says exactly what Your Brand does with that trust — including the parts we have not finished.
Keys, and who holds them
Most platforms encrypt customer data at rest with a key the platform holds for everybody at once. That protects against somebody walking off with a disk. It does not protect against anything else, because the operator can read every customer’s data by design.
Your Brand generates a separate AES-256 encryption key for each workspace. That key is itself encrypted before it is stored. One customer’s data is not readable with another customer’s key, and a copy of the database on its own is not enough.
What is encrypted today — and what is not
We would rather be exact than impressive. Right now, on Plus and above, contact notes and organisation are encrypted field by field with the workspace key.
Phone numbers and email addresses are not yet. They are how Your Brand finds the right contact when a message arrives — and an encrypted value cannot be looked up, so encrypting them today would mean every incoming message started a new conversation instead of joining the existing one. Doing it without that side effect needs a searchable index built alongside the encryption. That work is in progress and this page will change when it lands.
If a security page tells you everything is encrypted, ask which fields and how lookups still work. It is a fair question and it has a real answer.
A record of who did what
Every action that touches contact data is recorded: who, when, from which address, and whether it succeeded. Sign-ins are recorded separately with device and location. Retention runs from 30 days on the free plan to unlimited on Enterprise.
The log records the action and the identifiers — never the contents. An audit trail that quietly becomes a second copy of your customers’ messages is a liability, not a control.
Getting data out is the risky moment
An export is the entire list in one file, and it is the single most valuable thing that can walk out of a door. Your Brand lets a workspace require a password before an export runs, limit exports to admins, and watermark each one so a leaked file can be traced back to the download it came from.
Deletion you can check
When a record is destroyed, Your Brand can issue a signed certificate: a fingerprint of the data that was deleted, the time, and an ID. The certificate holds no personal data — only the fingerprint — and anybody can check one at studio.linxi.app/verify-deletion without an account.
“We deleted it” is a claim. This is a record the person who asked can verify for themselves, and that stands up if a regulator ever asks.
What we will not do
- We will not sell contact data.
- We will not use your contacts to train any AI model, ours or anybody else’s.
- We will not share contact data with advertising platforms.
- We will tell you about a breach affecting your data within 72 hours of confirming it.
The sub-processors we do use are named in the Privacy Policy, by name, with what each one receives.
Not built yet, and said so
Zero-knowledge encryption — where the key never leaves your browser and Your Brand cannot decrypt your data under any circumstances — is on the Enterprise plan and is not yet available to switch on. SOC 2 Type II is not certified; we have not started the audit. There is no bug bounty programme yet.
Each of those is a real thing to want and none of them is true today, so none of them is claimed above.
Reporting something
If you have found a security problem in Your Brand, write to team@linxi.app with enough detail to reproduce it. We will confirm receipt and tell you what we are doing about it.
Last updated 1 September 2026.