Skip to content

Security

How we protect your sessions

A plain description of what happens to your data on YouLinker: what is encrypted, who can get into a workspace, where files are stored, and how to reach us if something looks wrong.

At a glance

The measures behind every workspace

Nothing on this page is aspirational. Each item describes how the platform works today.

  • Encrypted in transit

    All traffic between your browser and YouLinker travels over TLS — poll votes, chat messages, file uploads and the real-time connection alike.

  • Hashed passwords

    Passwords are stored as bcrypt hashes. Nobody at YouLinker can read them; a forgotten password is reset by email, never recovered.

  • Sessions that expire

    Signed-in sessions use JSON Web Tokens with an expiry, so a token left on a shared computer stops working on its own.

  • A PIN for every workspace

    Participants join with a 6-digit PIN or its QR code. Regenerate it whenever you want to close a workspace to a previous audience.

  • Three access modes

    Open to anyone with the PIN, registered users only, or an invite-only whitelist of email addresses — chosen per workspace.

  • Permissions on the canvas

    Decide per object type whether participants may add, edit, connect or delete, so a brainstorm stays a brainstorm.

  • Hosted in the EU

    The application runs on Microsoft Azure in the Germany West Central region. Uploaded files live in Azure Blob Storage.

  • Card data stays with Stripe

    Paid plans are billed by Stripe. Card numbers are entered on Stripe’s forms and never touch YouLinker’s servers.

Who gets into a workspace

Every workspace has a 6-digit PIN and a QR code. The PIN is the door; the access mode decides who may walk through it.

Open
Anyone with the PIN can join, anonymously. Suited to lectures and public talks where the PIN is on the screen.
Registered users only
Participants must sign in with a YouLinker account (email and verification code, or Google sign-in) before the PIN lets them in.
Invite-only whitelist
Only the email addresses you list can join. Combine it with email invitations, which carry the PIN and join link to the right people.

Limits you set yourself

The presenter stays in control of the room, not just of the slides.

  • A participant limit and a session duration for each workspace
  • Regenerate the PIN whenever you want; the previous PIN stops opening the workspace
  • Email invitations to named people, with the PIN and join link included
  • Per-object canvas permissions: what participants may add, edit, connect or delete
  • Presenter-controlled polls: questions and results appear only when you show them
  • Page share links that are public, expiring or protected by a PIN

What participants share

Most people who use YouLinker never create an account. The platform is built so that this costs them nothing in privacy.

Anonymous participants

Join with the PIN and receive a generated display name. No personal data is stored unless they choose to enter an email address.

Registered participants

Sign in with an account, so the workspace knows their name and email address. Required when a presenter chooses registered-only or invite-only access.

Poll responses

Presenters decide per poll whether votes are anonymous or shown with names. Participants see the setting before they answer.

Presenters

Hold an account with an email address and, on paid plans, a Stripe subscription. Card details are held by Stripe, not by us.

Infrastructure

Where your data lives

YouLinker runs on Microsoft Azure in the European Union. We keep the list of providers short and name each one.

Application and database

Hosted on Microsoft Azure in the Germany West Central region.

Uploaded files

Slides, PDFs and images are stored in Azure Blob Storage and served to participants through the workspace.

Payments

Handled by Stripe. YouLinker never stores card numbers.

The full list of processors, including sign-in, video and AI providers, is in the privacy policy.

Deletion and the GDPR

Processing is aligned with the GDPR. You can ask for a copy of your data, a correction, or deletion of your account and the workspaces you own by emailing support@youlinker.com from the address on your account.

Retention periods and your rights are set out in the privacy policy.

What this page does not claim

Security pages tend to collect badges. We would rather list what we do not have yet, so you can decide with the facts.

  • SOC 2, ISO 27001 or HIPAA certification
  • Penetration-test reports or certificates
  • End-to-end encryption (traffic is encrypted in transit with TLS)
  • Single sign-on through SAML or an identity provider
  • Audit logs of administrator actions

If any of these is a requirement for your institution, tell us what you need.

Responsible disclosure

If you believe you have found a vulnerability in YouLinker, email support@youlinker.com with the subject “Security report”. Reports go directly to the team that runs the platform.

  • Describe the issue, the steps to reproduce it and the impact you observed
  • Include the URL, workspace PIN (if it is your own test workspace) and browser version
  • Do not access, change or delete data that belongs to other people while testing
  • Give us reasonable time to fix the issue before sharing it publicly

Security questions

Do participants have to give any personal data?

No. Anonymous participants join with the PIN and get a generated display name. We hold no personal data about them unless they choose to enter an email address — for example when a presenter turns on participant verification.

Where is my data stored?

On Microsoft Azure in the Germany West Central region of the EU. Uploaded files are kept in Azure Blob Storage.

How do I delete my data?

Email support@youlinker.com from the address on your account and ask for deletion. We remove your account data and the workspaces you own. The privacy policy describes retention in detail.

Is YouLinker certified under SOC 2 or ISO 27001?

No. We do not currently hold these certifications and we do not claim them. If your institution needs specific documentation, contact us and we will tell you exactly what we can provide.

Can I use single sign-on?

Google sign-in is available for accounts. SAML-based single sign-on is not offered today.

How are payments protected?

Paid plans are billed by Stripe. You enter card details on Stripe’s payment form; YouLinker only learns that the subscription is active.

Run your next session on infrastructure you can explain

Free to start. Participants join with a PIN and never need an account.