← Back to Plinker

Privacy Policy

Plinker  ·  Last updated: 16 September 2026

Privacy is not an afterthought at Plinker. It is part of the product. This policy explains, in plain language, what we collect, why, and the control you keep over it.

1. Who we are (data controller)

The data controller is Plinker Limited, a company registered in Ireland, company number 823045, registered office FF Fintech Pro, Engineering House, Unit 79, Block 5, Western Parkway Business Park, Dublin 12, D12 NRY2, Ireland.

Plinker Limited was incorporated on 7 August 2026. Before that date, in the earliest phase of the service, the controller was Sukhmani Khanna acting as an individual ahead of incorporation. Controllership and all member data transferred to Plinker Limited on incorporation, and this policy was updated to name the company. We told our founding members directly when this happened.

Our privacy lead and contact point for any privacy question is Sukhmani Khanna, at privacy@plinker.app.

2. What Plinker is, and what the other member sees

Plinker is an invitation-only introductions service for senior professionals, to promote learning, support growth and open doors. You share your career background; we draft a "trajectory" and introduce you to one other member at a time. There is no public profile, no search, no feed, and we never show ads.

Your name and your photograph stay hidden until you both choose to connect. They are the two things people ask about most, so we say them first. But they are not the only things held back, and the rest of your profile is not held back, so here is the whole picture rather than a summary of it.

Before either of you has said yes, the other member sees: your current role and company; your level, function and industry; your general location; your career path and previous roles; your education; where you can help; what you value; your weekend interests; your answer to "If not this, then what?"; and, where you have chosen to have them drafted, your personality traits, top strengths and working style.

Only once you have both said yes do they see: your name; your photograph; your headline; your proof points; your LinkedIn link; and when you usually meet.

Nobody else ever sees: your destination, your private note about what you are really after this season, or your gender.

3. What we collect, why, and our lawful basis

Under the GDPR we rely on the following bases for each type of information:

  • What we read from a CV or LinkedIn screenshots you give us: your roles, employers, dates and education, and a first draft of your headline, your proof points and where you can help. The file itself is never kept: see section 4. Lawful basis: your consent to the reading, then our contract with you to run the service (Art. 6(1)(a), then 6(1)(b)).
  • The profile you write or confirm: your headline, proof points, where you can help, what you value, your weekend interests, and your answer to "If not this, then what?". You review and confirm everything, and can edit or remove any of it at any time. Most of it is shown to members you are introduced to: section 2 says exactly which. Lawful basis: our contract with you (Art. 6(1)(b)).
  • A description of how you work, but only if you ask for one: personality traits, top strengths, and a working-style reading on four of the Big Five traits, described in words. It is drafted from the same CV or screenshots, and it is a separate choice: when you hand over the file you can have your roles read without it, and that choice is offered before the file leaves your phone. Section 5 explains what it is and what it is not. Lawful basis: your consent (Art. 6(1)(a)), given separately from the consent to read your roles, and withdrawable at any time by clearing it in Profile → details.
  • Your destination, and your private note about what you are really after this season. Neither is ever shown to another member, in your words or at all. We use them to choose your introductions, and your concierge may describe why two people fit in their own words. Please do not include sensitive details (for example health, religion, or anything revealing sexual orientation). If you choose to, you give explicit consent for us to process that content. Lawful basis: consent; Art. 9(2)(a) explicit consent for any sensitive content you volunteer.
  • Your photograph. If you sign in with LinkedIn, we take the profile picture from your LinkedIn account and save a copy of it in our own storage. We do this because the link LinkedIn gives us expires after a short time, and a profile with a broken photograph is no use to anybody. The copy is held privately, in the European Union, alongside the rest of your data. You can replace it with a photo of your own, or remove it, at any time, and it is not shown to another member until you have both said yes. It is deleted when you delete your account. Lawful basis: our contract with you (Art. 6(1)(b)).
  • How you signed in: through Apple, through LinkedIn, or with an email address and password. Where you use LinkedIn or Apple, we receive your name and email address from them, and from LinkedIn your profile picture. Lawful basis: contract (Art. 6(1)(b)).
  • Your gender. We ask for this during onboarding, and Prefer not to say is always one of the answers, so you never have to tell us. We want to be straightforward about this one. We do not use gender to choose or filter your matches, and it is not shown to anyone. We hold it so that we can understand the balance of our membership. We are considering a change under which you could choose to show your gender to a potential match at the moment you are each deciding whether to be introduced. That would be off unless you turned it on, and we would tell you before it went live. Lawful basis: our legitimate interest in understanding the balance of our membership (Art. 6(1)(f)). Because the question is part of onboarding, we do not describe this as consent, because "Prefer not to say" is a real answer and costs you nothing. Gender is ordinary personal data, not special-category, and we still treat it carefully. You can object at any time.
  • Cohort tags. Where you joined through a particular programme, alumni group or cohort, we may tag your record with it, so that a concierge can run a set of introductions within that group, or deliberately avoid pairing two people from it. A tag is never scored and never shown to another member. You can ask us what tags we hold for you, and ask us to remove them. Lawful basis: our legitimate interest in making relevant introductions (Art. 6(1)(f)).
  • Your email and basic contact details, so we can run the service and talk to you. Lawful basis: contract and our legitimate interest in operating the service (Art. 6(1)(b)/(f)).
  • Records of how you use the service: when you asked us to read a CV, which emails and notifications we have sent you, failed invitation-code attempts, and, where a member of staff edits your profile, what was changed. We keep these to stop the service being abused, to avoid sending you the same thing twice, and so that a change to your profile can always be accounted for. Lawful basis: our legitimate interests in protecting the service and being accountable for it (Art. 6(1)(f)).
  • Basic device and diagnostic data, to keep the app working and to find and fix crashes. Lawful basis: legitimate interests.

4. Your CV or LinkedIn screenshots, and what happens to them

We never store your CV. When you hand over a CV file, or screenshots of your LinkedIn About, Experience and Education sections (up to five at a time), each one is read once and then discarded. It is held in memory for that single request and is never written to our database or our file storage. There is no copy of it on our systems, and so there is no CV file for you to delete.

What we keep is only what comes out of it: your roles, companies, years and education, a first draft of your headline, your proof points and where you can help, and, if you choose it, a description of how you work (section 5). We keep it only once you have reviewed and confirmed it, and you can edit or remove any of it at any time.

Before anything leaves your device we ask your permission, and we name the provider that will read it. Nothing is sent until you agree. If you would rather not send a file at all, you can type your roles in by hand, and nothing on this page about CV reading then applies to you.

5. Automated processing, AI drafting, and the human in the loop

We use software, including AI, to draft your trajectory and suggest matches. A human concierge reviews every introduction. You are never matched by machine alone. You can ask us how this works, and contest or ask us to review any result. Because a human is always in the loop, the automated processing has no legal or similarly significant effect on you without human involvement (GDPR Art. 22).

Some of the words on your profile are drafted by AI from what you gave us: your headline, your proof points and where you can help. They are a starting point, not a verdict. You read them, change them or delete them before anything is saved, and you can change them afterwards at any time. Wherever AI-drafted text about a member is shown, we say so on the same screen, so that nobody reads a machine's draft believing a person wrote it.

The same is true of the messages you get from your concierge. Some of them are written by software rather than typed by a person, and those ones are marked, so you can always tell which is which. Messages a person typed carry no mark. If you would rather a person wrote to you, say so and one will.

If you ask us to, we will also describe how you work

When you hand over a CV or LinkedIn screenshots you can choose to have the same reading draft a description of how you work: a short list of personality traits, your top strengths, and a working-style reading on four of the Big Five traits, which are openness, conscientiousness, extraversion and agreeableness. It is a separate choice, offered before the file leaves your phone. One of the two answers is Roles only, which takes your roles, employers, dates and education and nothing else, and it is a complete way to use Plinker. If you type your roles in by hand instead, none of this happens at all.

Some things about it are deliberate, and we would rather state them than let you assume them:

  • It is described in words, never in a score, a percentage or a ranking. We do not show you a number about yourself, and we do not show one to anybody else. We do not keep the underlying numerical readings either. They are used to pick the wording and then discarded with the file.
  • Four traits, not five. We leave out neuroticism. A CV carries no honest signal for it, and a low score for emotional stability on somebody's profile could do real harm.
  • It is an estimate from a document, not an assessment of you. A CV is written to get you a job, not to describe your character, and we treat what it suggests accordingly.
  • You have the last word before anything is saved. You read it, change it, drop any part of it, or clear all of it, then and at any time afterwards from Profile → details. It goes when your account goes.
  • It is shown to members you are introduced to, before and after you have both said yes, and it is always labelled as AI-drafted wherever it appears, so nobody reads a machine's draft believing you wrote it.
  • It is not used to decide who is introduced to whom. Our matching never reads these fields.

The document it was drafted from is still never kept. What is kept is what you chose to keep from what it drafted, and those are two different things, so we say both.

And none of this changes what section 3 says about your goals: what you write about your goals is still never shown to another member, in your words or at all.

6. Messages between members

When you and another member have both said yes to an introduction, a private conversation opens between the two of you. Nobody else is in it. We do not read it, we do not use it to make matches, and it is never sent to our AI provider. It stays in the European Union on our own database.

Two things you should know before you use it.

If you report a conversation, a person at Plinker will read it. That is the point of reporting, and there is no way to look into what happened without looking at what was said. Every time a member of staff opens a conversation we record who opened it, when, and why, and we keep that record.

If either of you deletes their account, the conversation goes for both of you. It is one conversation, not two copies, so it cannot survive for one person and not the other. If that matters to you, keep your own copy before you go. The one exception is a conversation that has been reported, and it is set out immediately below.

We delete a conversation twelve months after the last message in it. If a report is open, we keep it until the report is settled and for twelve months after that.

If a report is made, we keep a copy of part of that conversation, and it outlives both accounts. At the moment a report is filed we take a bounded copy, the messages from around the time of the report rather than the whole history, and attach it to the report. We keep that copy for up to twelve months after the report is settled, and never longer than two years after it was taken. The report itself, which holds no messages, is kept for up to two years after it is settled. It survives even if you or the other member deletes their account, because a report that loses its evidence the moment somebody leaves protects nobody. Your identity is removed from what is kept: what remains is a coded reference rather than your name. Only a member of staff can read it, only with a reason, and every reading is recorded.

You can ask us for a copy of your conversations at any time at privacy@plinker.app.

7. Who we share it with

We share your data only with the service providers that make Plinker work, each under a written data-processing agreement, and we never sell your data or run ads. In particular, we ask for your explicit permission in the app before your CV or screenshots are shared with our AI provider to be read, and nothing is sent until you consent. Our providers are:

ProviderWhat they doWhere
Anthropic (Claude API)Reads your CV or LinkedIn screenshots and helps draft your profile and match suggestionsUnited States. See transfers below
SupabaseSecure cloud hosting, database, authentication and storageStored in the EU (Ireland, EU-West). See transfers below
ResendSends our emails to youDelivers from the EU (Ireland, EU-West). See transfers below
SentryCrash and error monitoring, so we can find and fix crashes in the appEuropean Union (Frankfurt)
ExpoDelivers app updates, and passes our push notifications to Apple and GoogleUnited States. See transfers below
Google (Firebase Cloud Messaging)Delivers push notifications to Android devicesUnited States. See transfers below
Apple (Push Notification service)Delivers push notifications to iPhones and iPadsApple's own infrastructure

If you enable push notifications, a device token is passed to Expo and from there to Apple or Google so that the message reaches your phone. The message text is written by us.

International transfers. Your Plinker data is stored in the EU (Ireland). Some of it is nonetheless handled outside the European Economic Area, and we would rather tell you plainly than imply otherwise:

  • Anthropic, our CV-reading and AI provider, processes data in the United States. It does not use your data to train its models and applies short, contractually limited retention.
  • Supabase, which hosts our database, stores your data in Ireland but contracts through a Singapore entity and relies on a global chain of infrastructure and support providers, some of them in the United States. This means Supabase staff or systems may access your data from outside the EEA for support, monitoring and maintenance of the service.
  • Resend, which sends our emails, delivers from the EU but contracts through a United States entity, so your email address may be handled outside the EEA.
  • Expo and Google, which carry our push notifications to your phone, process in the United States. What reaches them is a device token and the text of the notification, never your profile.

Every one of these transfers is governed by the European Commission's Standard Contractual Clauses, supported by a transfer-impact assessment we carry out and keep under review. We keep provider handling to the minimum needed to run the service, and we will update this page if our providers change.

Sentry is not in that list, and deliberately so. It processes in the European Union (Frankfurt), so no transfer outside the EEA arises.

8. How long we keep it

We keep your information for as long as you are a member, and no longer than we need it.

  • Your CV file or LinkedIn screenshots, not retained at all. Read once to draft your roles and, if you choose, your description of how you work, then discarded. We never hold a copy.
  • Your profile, your photograph, your trajectory and your introduction history, kept while your account is open.
  • Private conversations with other members, twelve months after the last message. Longer if a report is open.
  • Records of how you use the service: CV-reading requests, notifications sent, failed invitation-code attempts, and the log of any staff edit to your profile. Kept while your account is open and deleted with it.
  • After you close your account, or ask us to delete, erased within 30 days. From inside the app it is immediate.
  • A report, and the bounded copy of the conversation attached to it. The copy of the conversation goes within twelve months of the report being settled, and never later than two years after it was taken. The report itself, which holds no messages, is kept for up to two years after it is settled. This is the one thing that outlives both accounts, and identities are removed from it. See sections 6 and 10.
  • Records we are required to keep by law (for example tax or accounting records), kept only for the period the law requires, and used for nothing else.

You do not have to wait for any of this. You can ask us to delete your data at any time and we will action it and confirm.

9. Your rights

You can access, correct, delete, port, and object to our use of your data, and withdraw consent at any time. Withdrawal is as easy as giving it, and does not affect anything we did beforehand. In the app you will find Profile → Settings → Delete account, which erases your Plinker data and closes your account. Your CV is never stored, so there is no CV file to delete separately. You can also email privacy@plinker.app. You have the right to complain to the Irish Data Protection Commission at dataprotection.ie.

10. Deleting your account and data

You can delete your account and associated personal data at any time from Profile → Settings → Delete account inside the app. It is immediate and it cannot be undone.

Nothing holds it up. If a report has been made, by you or about you, you can still leave, straight away, and you do not have to ask anyone's permission. We take the view that telling someone who has been harassed that they cannot leave is the worst thing this service could do, and we have built it so that we never have to.

Deleting your account also removes your introductions. An introduction is one shared record, so it disappears from the other member's history too, along with anything they noted about your meeting. The same is true of a private conversation: it goes for both of you.

One thing outlives your deletion, and we would rather set it out than have you discover it. If a report has been made, the report itself and a bounded copy of the conversation attached to it are kept after your account is gone. The copy of the conversation goes within twelve months of the report being settled, and never later than two years after it was taken. The report itself, which holds no messages, is kept for up to two years after it is settled. Your account and your name go. Your identity is removed from what remains and replaced by a coded reference derived from your email address, so that a pattern of reports is not lost if somebody leaves and rejoins under a new account. A report that vanished the moment one side left would protect nobody, least of all the person who made it.

You can also request deletion by emailing privacy@plinker.app. That route is not instant: we will delete your account and confirm to you within 30 days, and usually much sooner. There is a page explaining both routes at plinker.app/delete-account.

11. Age

Plinker is for adults; you must be 18 or older to take part.

12. Changes

We will update this policy as Plinker develops and post the new version here, with the date at the top. Where a change materially affects you, as the move of controllership to Plinker Limited did, we will tell you directly rather than relying on you noticing.

Privacy questions: Sukhmani Khanna, privacy lead, at privacy@plinker.app. General enquiries: support@plinker.app. Supervisory authority: Irish Data Protection Commission, dataprotection.ie.
Executive woman in an ice blue suit and executive man in a grey suit walking through a concrete gallery

Plinker

Relationship intelligence for executives

Download on the App Store