Skip to main content

LinkedIn Tool Privacy Notice

Version 1.0 · Last updated July 2026

SWIFT operates an internal tool that publishes and measures our own LinkedIn content, and helps us reply to people who engage with it. This notice explains what that tool does with personal data. It is separate from our website policy: nothing here applies to swiftrocket.org, and nothing in the website policy applies to this tool.

All SWIFT privacy notices

What this covers

SWIFT (Space Workforce Incubator for Texas), an Austin-based 501(c)(3) nonprofit, is the data controller for this tool. The tool is private, internal, and used only by authorised SWIFT staff — it has no public interface and no user accounts beyond our own.

Any question or request about it: leon@swiftrocket.org.

How the tool connects to LinkedIn

An authorised SWIFT representative signs in through LinkedIn's standard OAuth consent screen and grants the tool permission to act on their behalf. We store the resulting access token so the tool can schedule posts and read performance data without a person present.

That permission can be withdrawn at any time, either inside the tool or from LinkedIn's own settings. Withdrawing it stops all further access immediately.

What we receive from LinkedIn

  • The authorised representative: their LinkedIn profile, the posts published through the tool, and the performance data for those posts (impressions, reactions, comments, reshares, saves, link clicks, follower and profile-view counts).
  • Other LinkedIn members: when someone comments on or reacts to one of our posts, we receive their name, headline, profile photo, and the text of their comment, so we can read and respond to it.
  • Identifiers: the stable LinkedIn reference codes (URNs) for people, posts, and comments.
  • Access tokens issued by LinkedIn, held encrypted.

What we do with it

  • Schedule and publish SWIFT's own LinkedIn content.
  • Measure how that content performs, so we can write better content.
  • Read and reply to comments on our own posts.

Why we use it (legal bases)

  • Consent — from the authorised SWIFT representative who connects their LinkedIn account, given through LinkedIn's own consent screen and withdrawable at any time.
  • Legitimate interests — for members who comment on or react to our posts. Responding to public engagement on our own content is a normal and expected part of using the platform. We use the minimum data needed to do it, keep it for a short fixed period, and never repurpose it.

What we never do with it

LinkedIn member data reaches this tool under LinkedIn's API terms, which bind us to a narrow set of uses. We do not:

  • Use it for advertising, sales, or recruiting — including identifying prospects, building audience or lead lists, or ad targeting.
  • Add it to a CRM, mailing list, or any other SWIFT system.
  • Combine it with data we hold elsewhere, or use it to build or enrich profiles of individuals.
  • Export, sell, publish, or otherwise pass it to anyone outside the tool.

How long we keep it

LinkedIn sets maximum retention periods for data drawn from its APIs, and we hold to them. Data is deleted automatically once its period expires — this is enforced by the tool, not left to memory.

  • Other members' profile data (name, headline, photo): cached no longer than 24 hours.
  • Members' social activity, including comment text and mentions: no longer than 48 hours.
  • LinkedIn identifiers (URNs) for people, posts, and comments: retained, so historical performance stays linkable. These are reference codes, not profile information.
  • SWIFT's own posts and their performance figures: retained. This is our own content and our own statistics.

Service providers

The tool relies on a small number of processors, each under a data-processing agreement:

  • LinkedIn — the source of the data, and the platform the tool publishes to.
  • Neon — database hosting.
  • Vercel — application hosting.
  • Anthropic — AI drafting assistance (see below).
  • Sentry — error monitoring, configured to exclude personal data.

AI-assisted drafting

The tool uses an AI model to help draft posts and suggest replies. Where a suggested reply refers to someone's comment, that comment text is sent to our AI provider to generate the draft.

This runs under a data-processing agreement on a zero-retention basis: the provider does not store the content after returning a response, and does not train models on it. A person at SWIFT reviews and approves every reply before it is published — nothing is posted automatically without review.

Your rights

If you have commented on or reacted to a SWIFT post, this notice applies to you even though you have never used our website. You may ask what we hold about you, ask us to correct or delete it, or object to our processing it. Email leon@swiftrocket.org and we will respond within the time the law requires, and in any case promptly — LinkedIn's terms oblige us to action deletion requests without delay.

In most cases the honest answer will be that we no longer hold anything: the retention periods above are short by design.

Security

Access tokens are encrypted at rest, and the tool is reachable only by authenticated SWIFT staff — it is not exposed publicly. We collect no payment data and no special-category data through it.

International transfers

SWIFT is based in the United States, and our providers may process data in the US. Where required, transfers rely on appropriate safeguards.

Changes to this notice

We version this notice. If the tool's data handling changes materially, the version above changes with it.

Contact

Questions or requests about this tool: leon@swiftrocket.org. For anything relating to swiftrocket.org itself, use geoff@swiftrocket.org.