Skip to content
dentedprinter

Legal

Privacy Policy

Cardlink — Last updated: July 31, 2026

What this extension is

Cardlink is an independent browser extension for Chrome and Firefox that turns the text you type into a styled image card, hosts a link-preview page for it, and hands you back a link to paste into a social media post. It currently supports Threads. It never posts on your behalf, and no content script ever runs on the platform's own site — it only talks to its own backend and, optionally, to the platform's own login flow. It is not made by, affiliated with, or endorsed by Meta Platforms, Inc.


What data is collected

You don't need an account to use the extension. Every time you use "Generate share link," the following is sent to our backend and stored so the link keeps working:

  • The text you typed into the card
  • The image generated from it (rendered entirely in your browser, on your device, before it's uploaded)

We also briefly use your IP address to enforce rate limits (capping how many cards one connection can generate per hour/day, to deter abuse) — it's used as a short-lived counter key and isn't stored as part of the post itself or kept beyond the rate-limit window.


If you connect your account (optional)

The extension offers an optional "Connect account" feature via the platform's own login (OAuth) — you're never asked to type a password into the extension. If you use it:

  • Your username and profile picture are fetched once and cached on our server, so cards you choose to include them on don't need to re-fetch them each time
  • Your access token is used once, immediately, to fetch that username/picture — it is not saved anywhere afterward, and is never used to post, like, comment, or take any other action on your behalf
  • A separate proof-of-ownership token is generated and stored only in your browser, so the extension can prove a later card really came from you before we'll stamp your name/photo onto it

Including your name/photo on a card is an explicit toggle, off by default until you connect, and it's yours to leave off per-post even once connected.


Generated pages are public links

Each card gets its own link (thread-preview.dentedprinter.workers.dev/p/<id>) — this is the whole point, so it can unfurl as a link preview when pasted into a social media post or elsewhere. Anyone who has or guesses that link can view the page. If you chose to include your name/photo on that card, the page's header links your username and photo out to your real, public profile on that platform, same as any other visible byline.


What the backend stores, and where

Unlike some of our other projects, this one doesn't run on our own server — it runs on Cloudflare Workers, with images in Cloudflare R2 and everything else (the post text, timestamps, rate-limit counters, and the cached username/photo described above) in Cloudflare KV. Dented Printer operates this Cloudflare account but the data itself lives on Cloudflare's infrastructure, not a server we host directly.

This data is never sold, shared with advertisers, or used to build an advertising profile of you.


Data retention & deletion

Generated cards are handled in two ways, depending on whether anyone's actually viewed the link:

  • A card that's never viewed (nobody opened the link, and no crawler ever fetched it to build the unfurl) is automatically deleted after 14 days — this is meant to clean up cards that were made but never actually posted anywhere
  • A card that has been viewed is kept as a working, permanent link — with one exception: everything is deleted after 420 days regardless, as a distant backstop in case the cleanup above ever misbehaves, not as an intended expiry for real posts

Your cached username/photo (if you've connected your account) doesn't expire on its own — it stays cached until you ask us to remove it. Disconnecting in the extension's popup removes the connection from your browser immediately, but by itself only affects your browser — it doesn't delete anything on the server, since your username/photo may still be attached to cards you've already created and shared.

To actually delete your data from our server, open the extension popup while connected and click Delete my data (next to Disconnect), then confirm. This is self-serve and immediate — no email required. It deletes your cached username/photo and every card you created while connected — the text and the image both, not just the byline. Links to those cards will stop working afterward. This is one-way and cannot be undone.

If you no longer have the extension installed, or run into any issue with the in-popup deletion, email dentedprinter@gmail.com and we'll help by hand — including deleting a specific card outright.


Contact

Questions about this policy: dentedprinter@gmail.com